Multi-platform client unified identity authentication and organizational structure dynamic synchronization system and method
Through adaptive policy matching and multi-module collaboration, unified identity authentication and dynamic synchronization of organizational structure are achieved for multi-platform clients, solving the problems of cumbersome user operations and inaccurate authentication results in existing technologies, and improving the security and efficiency of enterprise digital office.
Patent Information
- Application Number
- CN202510709669.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-05-29
AI Technical Summary
Existing technologies are unable to achieve convenient unified identity authentication for multi-platform clients and dynamic synchronization of organizational structures, resulting in cumbersome user operations, inaccurate permission management, inaccurate authentication results and poor reliability, and are unable to meet the complex needs of enterprise digital office.
The policy adaptive matching module matches the optimal data transmission strategy according to the network environment perception value and the third-party authentication method selected by the user. Combined with the third-party authorization authentication module, the first authentication module, the architecture dynamic synchronization module and the second authentication module, efficient and secure multi-platform client unified identity authentication and organizational structure dynamic synchronization are achieved.
Ensure efficient and secure data transmission, improve authentication efficiency, reduce user waiting time, prevent illegal users from impersonating identities, realize dynamic management and optimization of permissions, enhance system information security, improve authentication accuracy and the ability to respond to complex security threats.
Smart Images

Figure CN120639355A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cross-platform identity authentication, and in particular to a system and method for unified identity authentication and dynamic synchronization of organizational structures on multiple platforms. Background Art
[0002] Currently, with the trend toward digital office and information-based management, enterprises often use multiple platforms and clients to meet diverse business needs, encompassing areas such as project management, customer relationship management, and office automation. While this multi-platform client environment enriches business processing methods, it also introduces complexity in identity authentication and organizational structure management. A unified identity authentication and dynamic organizational structure synchronization system for multiple platforms and clients is crucial in this context. Unified identity authentication provides users with a convenient, one-stop login experience, improving work efficiency and enhancing security. Dynamic organizational structure synchronization ensures real-time updates to the enterprise's organizational structure are synchronized across all platforms and clients, ensuring that permission allocation and business processes remain consistent with the actual organizational structure. This helps enterprises achieve efficient internal management and promotes collaboration and communication across departments. As digital transformation continues to advance, this system has broad application prospects for enterprises of all sizes and industries, and is expected to become a core component of their digital management systems.
[0003] However, the existing system is unable to accurately match the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user. In terms of identity authentication, it is impossible to achieve portable and unified authentication between multiple clients and third-party platforms, resulting in cumbersome user operations. It is also impossible to perceive changes in the organizational structure on the third-party platform and synchronize them to multiple clients, so it is impossible to determine the consistency of organizational structure information on multiple terminals. Ultimately, due to the cross-platform deviation of architectural information, which leads to inaccurate permission management, and the lack of an effective mechanism for secondary identity authentication based on the coexistence of multiple authentication methods, it is impossible to ensure the accuracy and reliability of the final authentication results, and thus it is difficult to meet the increasingly complex digital office needs of enterprises.
[0004] Therefore, the present invention proposes a multi-platform client unified identity authentication and organizational structure dynamic synchronization system and method. Summary of the Invention
[0005] The present invention provides a system and method for unified identity authentication and dynamic synchronization of organizational structures on multiple platforms. The system uses a policy adaptive matching module to match the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user, ensuring efficient and secure data transmission. The third-party authorization authentication module connects to the third-party authentication platform through a preset authentication protocol, triggers the authorization process according to the client authentication mode, and uses the optimal data transmission strategy to obtain authorized user information, achieving efficient authentication docking. When the authorized user information matches the backend storage information and the corresponding architecture information, the first authentication module returns authentication success feedback to the client based on the optimal strategy. When the information does not match, the architecture dynamic synchronization module returns authentication failure feedback, simultaneously obtains the dynamic variables of the enterprise organizational structure and triggers permission propagation deduction to update user permissions. The second authentication module authenticates the user based on the permission update result and the hybrid authentication mode until the final authentication result is obtained. By reasonably supporting the coexistence of multiple authentication methods, the accuracy and flexibility of authentication are ensured, and the unified identity authentication and dynamic synchronization of organizational structures on multiple platforms are achieved. The system also comprehensively considers synchronization timing, compatibility, security, reliability, and other aspects, enabling it to meet the increasingly complex digital office needs of enterprises.
[0006] The present invention provides a multi-platform client unified identity authentication and organizational structure dynamic synchronization system, including:
[0007] A policy adaptive matching module is used to match the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user;
[0008] The third-party authorization and authentication module is used to connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the authentication mode of the corresponding client, receive the authorization code of the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information based on the received authorization code;
[0009] The first authentication module is configured to return an authentication success feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend;
[0010] The architecture dynamic synchronization module is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the back-end or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the back-end. It also synchronously obtains the dynamic variables of the enterprise organizational structure relationship network and triggers the permission propagation deduction to obtain the user's permission update result;
[0011] The second authentication module is used to authenticate the user based on the user's authority update result and the hybrid authentication mode until a final authentication result is obtained.
[0012] Preferably, the strategy adaptive matching module includes:
[0013] The network environment perception submodule is used to perceive the network environment characteristics of each authentication request client received by the backend at the current moment in real time, and calculate the network environment perception value of the current client based on the real-time network environment characteristics;
[0014] The transmission strategy screening submodule is used to determine all matching data transmission strategies for each authentication request client based on the network environment perception value of each authentication request client received by the backend at the current moment;
[0015] The authentication busyness evaluation submodule is used to calculate the relative authentication busyness of the current client under each matching data transmission strategy based on all matching data transmission strategies of all authentication request clients received by the backend at the current moment and the authentication protocols corresponding to the corresponding selected third-party authentication methods;
[0016] The optimal transmission strategy determination submodule is used to regard the matching data transmission strategy with the maximum relative authentication busyness among all corresponding matching data transmission strategies of the current client as the optimal matching data transmission strategy of the current client.
[0017] Preferably, the authentication busyness evaluation submodule includes:
[0018] A resource consumption amplification factor determination unit, configured to determine the resource consumption amplification factor of all resource types under each matching data transmission strategy;
[0019] a resource consumption coefficient determining unit, configured to use an average of resource consumption ratios of each resource type in all authentication instances under the authentication protocol corresponding to each third-party authentication method as the resource consumption coefficient of the corresponding resource type under the authentication protocol corresponding to the corresponding third-party authentication method;
[0020] A resource occupancy determination unit is configured to determine the resource occupancy of all resource types under each matching data transmission policy and the authentication protocol corresponding to the selected third-party authentication method for each authentication request client simultaneously received by the backend at the current moment based on the resource consumption amplification coefficients of all resource types under each matching data transmission policy and the resource consumption coefficients under the authentication protocol corresponding to each third-party authentication method;
[0021] A global resource pressure determination unit is configured to normalize the sum of the resource occupancy of all resource types under the authentication protocol corresponding to all matching data transmission policies and corresponding selected third-party authentication methods of all authentication request clients received by the backend at the current moment, and the resource occupancy of the same resource type under the same matching data transmission policy to the maximum resource occupancy of the corresponding resource type, thereby obtaining the global resource pressure of the corresponding resource type under the corresponding matching data transmission policy;
[0022] The relative authentication busyness determination unit is used to determine the relative authentication busyness of the current client under each corresponding matching data transmission policy based on the resource occupancy of all resource types of the current client under the authentication protocol corresponding to each corresponding matching data transmission policy and the corresponding third-party authentication method, and the global resource pressure of each resource type of the corresponding matching data transmission policy.
[0023] Preferably, the resource consumption amplification factor determining unit includes:
[0024] The consumption value determination subunit is used to perform no-load system testing in an isolated environment and record the basic resource consumption value of each resource type;
[0025] A resource consumption peak determination subunit, used to record the resource consumption peak value achieved when each resource type is enabled separately in an isolated environment and each matching data transmission strategy is used to execute a preset sub-typical authentication request;
[0026] The resource consumption amplification coefficient determination sub-unit is used to use the ratio of the resource consumption peak value reached when each resource type is separately enabled in an isolated environment to execute a preset sub-typical authentication request for each matching data transmission strategy to the basic resource consumption value as the resource consumption amplification coefficient of the corresponding resource type under each matching data transmission strategy.
[0027] Preferably, the third-party authorization authentication module includes:
[0028] The first authorization and authentication submodule is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a desktop client, launch the local browser to request login from the third-party authentication platform, generate and display the login QR code, and receive the authorization code after the user scans the code based on the optimal data transmission strategy. Based on the authorization code, the authorization process is triggered and the back-end authentication interface is called to obtain the authorized user information;
[0029] The second authorization and authentication sub-module is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a mobile terminal, and pull up the third-party client to trigger the authorization process. At the same time, it receives the temporary authorization code based on the optimal data transmission strategy and sends it to the backend, and calls the back-end authentication interface to obtain authorized user information.
[0030] Preferably, the architecture dynamic synchronization module includes:
[0031] The authentication failure feedback submodule is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the backend or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the backend;
[0032] The architecture relationship variable acquisition submodule is used to obtain dynamic variables of the enterprise organizational architecture relationship network;
[0033] The permission update submodule is used to perform permission propagation deduction based on the dynamic variables and permission inheritance rules of the enterprise organizational structure relationship network to obtain the user's permission update results.
[0034] Preferably, the second authentication module includes:
[0035] A hybrid authentication step tree building submodule is used to build a hybrid authentication step tree based on a multi-factor authentication system under a hybrid authentication mode;
[0036] The behavior risk assessment submodule is used to assess the user's behavior risk and obtain the user's behavior risk assessment value;
[0037] A step tree interception submodule is used to intercept and obtain an actual authentication step tree in the hybrid authentication step tree based on the user's permission update result and behavior risk assessment value;
[0038] The identity authentication submodule is used to authenticate the user based on the actual authentication step tree until the final authentication result is obtained.
[0039] Preferably, the step tree interception submodule includes:
[0040] a permission update amount determination unit, configured to determine, based on the permission update result of the user, a permission range relative update factor of all permission update items of the user, taking the ratio of the original weight of each permission update item of the user to the sum of the original weights of all permission update items of the user as the current weight of each permission update item of the user, and performing a weighted sum of the permission range relative update factors of all permission update items of the user based on the current weights of all permission update items of the user to obtain a total permission relative update amount of the user;
[0041] A required authentication level range determination unit, configured to determine the user's current node in the enterprise organizational structure relationship network based on a dynamic variable of the enterprise organizational structure relationship network, and determine the user's current required authentication level range based on the user's current node in the enterprise organizational structure relationship network;
[0042] a first interception unit for intercepting, from the mixed authentication step tree, a currently required authentication step tree for each authentication level within the currently required authentication level range of the user, based on a standard authentication step for each authentication level within the currently required authentication level range of the user and a standard incremental step for a relative update amount of the user's total authority within the currently required authentication level range of the user;
[0043] A second interception unit, configured to intercept a second currently required authentication step tree from the hybrid authentication step tree based on the behavior risk assessment value;
[0044] The third interception unit is used to intercept the current required authentication step tree and the second current required authentication step tree under each authentication level within the user's current required authentication level range from the hybrid authentication step tree, and intercept the actual authentication step tree from the hybrid authentication step tree.
[0045] Preferably, the third intercepting unit includes:
[0046] a tree structure merging subunit, configured to merge the currently required authentication step tree and the second currently required authentication step tree for each authentication level within the range of the currently required authentication level of the user extracted from the hybrid authentication step tree, respectively, to obtain a plurality of merged required authentication step trees, wherein the total number of the merged required authentication step trees is the same as the total number of the currently required authentication step trees;
[0047] An authentication efficiency determination subunit, configured to determine the authentication efficiency of each authentication step tree required for merging based on the authentication effectiveness and operation resource loss of each authentication step tree required for merging;
[0048] The tree structure screening subunit is used to treat the authentication step tree required for merging with maximum authentication efficiency as the actual authentication step tree.
[0049] The present invention provides a multi-platform client unified identity authentication and organizational structure dynamic synchronization method, including:
[0050] S1: Matches the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user;
[0051] S2: Connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the corresponding client's authentication mode, receive the authorization code from the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information by calling the back-end interface based on the received authorization code;
[0052] S3: When it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend, an authentication success feedback result is returned to the client based on the optimal data transmission strategy;
[0053] When it is determined that the authorized user information is not in the user information stored in the backend, or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the backend, the authentication failure feedback result is returned to the client based on the optimal data transmission strategy, and the dynamic variables of the enterprise organizational structure relationship network are simultaneously obtained and the permission propagation calculation is triggered to obtain the user's permission update result;
[0054] S4: Authenticate the user based on the user's permission update result and the hybrid authentication mode until the final authentication result is obtained.
[0055] The beneficial effects of the present invention compared to the prior art are as follows: from the perspective of data transmission, the policy adaptive matching module comprehensively perceives the network environment and the third-party authentication method selected by the user to determine the optimal data transmission strategy, which not only ensures the transmission efficiency and stability of data in a complex and changeable network environment, reduces problems such as packet loss and delay during transmission, but also can strengthen the confidentiality and integrity of data transmission in a targeted manner according to the security requirements of different authentication methods, laying a solid foundation for subsequent authentication processes. In the authentication docking link, the third-party authorization authentication module docks with the third-party authentication platform through a preset authentication protocol, triggers the authorization process in accordance with the client authentication mode, and obtains authorized user information using the optimal data transmission strategy. This process not only improves authentication efficiency and reduces user waiting time, but also ensures the standardization and security of the authentication process through standardized protocols, reducing the security risks caused by non-standard authentication docking. The first authentication module rigorously compares the authorized user information with the back-end storage information and the architecture information to which it belongs, and returns authentication success feedback based on the optimal strategy when matching, ensuring that only legitimate and architecture-matched users can pass the authentication smoothly, effectively preventing illegal users from impersonating identities, and ensuring system information security. When information does not match, the architecture dynamic synchronization module not only returns authentication failure feedback, but also obtains the dynamic variables of the enterprise organizational structure and triggers permission propagation deduction to update user permissions. This mechanism can not only promptly detect the impact of organizational structure changes on user permissions, but also reasonably adjust user permissions based on the new organizational structure relationship, realizing dynamic management and optimization of permissions. The second authentication module performs secondary authentication based on the permission update results and the hybrid authentication mode to further ensure the accuracy of user identity. At the same time, the hybrid authentication mode increases the authentication dimension and enhances the system's ability to respond to complex and changing security threats. Ultimately, it realizes the efficient, secure and intelligent management of unified identity authentication and dynamic synchronization of organizational structures for multiple platform clients, providing strong support for the digital operation of enterprises.
[0056] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in this application document.
[0057] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0059] Figure 1 Schematic diagram of a multi-platform client unified identity authentication and organizational structure dynamic synchronization system in an embodiment of the present invention;
[0060] Figure 2 This is a flowchart of configuring DingTalk on the Portal side in an embodiment of the present invention;
[0061] Figure 3 This is a schematic diagram of the information flow when DingTalk authentication is selected for the desktop system in an embodiment of the present invention. DETAILED DESCRIPTION
[0062] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0063] Example 1:
[0064] The present invention provides a multi-platform client unified identity authentication and organizational structure dynamic synchronization system, referring to Figures 1 to 3 include:
[0065] A policy adaptive matching module is used to match the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user;
[0066] The third-party authorization and authentication module is used to connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the authentication mode of the corresponding client, receive the authorization code of the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information based on the received authorization code;
[0067] The first authentication module is configured to return an authentication success feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend;
[0068] The architecture dynamic synchronization module is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the back-end or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the back-end. It also synchronously obtains the dynamic variables of the enterprise organizational structure relationship network and triggers the permission propagation deduction to obtain the user's permission update result;
[0069] The second authentication module is used to authenticate the user based on the user's authority update result and the hybrid authentication mode until a final authentication result is obtained.
[0070] In this embodiment, the third-party authentication method selected by the user refers to the authentication method selected by the user from the various third-party authentication methods supported by the system. Taking the DingTalk client as an example, other common platforms based on the OAuth2 authentication system include Enterprise WeChat, Feishu, OKTA, etc.
[0071] In this embodiment, the optimal data transmission strategy is a strategy with the maximum relative authentication busyness determined through evaluation from all matching data transmission strategies based on the network environment perception value and the third-party authentication method selected by the user.
[0072] In this embodiment, the preset authentication protocol is a pre-set authentication rule and standard for connecting to a third-party authentication platform, such as OAuth2, an open standard for authentication and authorization, which includes authorization code mode, simplified mode, password mode, credential mode, etc. Different third-party authentication platforms may perform authentication based on one or more of these modes.
[0073] In this embodiment, the third-party authentication platform is an external platform that users can choose for identity authentication in addition to the system's own authentication method. DingTalk, Enterprise WeChat, Feishu, OKTA, etc. all belong to this category. These platforms have their own user systems and authentication processes.
[0074] In this embodiment, the client refers to the device used by the user to access the system, including desktop terminals (such as Win, Mac) and mobile terminals (such as iOS, Android).
[0075] In this embodiment, the client's authentication mode is based on the specific authentication process adopted by the client type. For example, the desktop terminal may use different methods such as launching a local browser to generate a QR code for scanning and logging in, while the mobile terminal automatically launches a third-party client to trigger the authorization process to complete authentication.
[0076] In this embodiment, the authorization process refers to a series of operational steps to complete user identity authentication and authorization after the client connects to the third-party authentication platform based on a preset authentication protocol. A series of coherent operations such as scanning the code to log in on the desktop and launching the third-party client authorization on the mobile terminal constitute the authorization process.
[0077] In this embodiment, the authorization code of the third-party authentication platform in the corresponding authentication mode is received based on the optimal data transmission strategy, which means that during the authentication process, the authorization code generated by the corresponding authentication mode is obtained from the third-party authentication platform according to the matched optimal data transmission strategy to ensure stable and efficient data transmission. For example, during the desktop QR code scanning login or mobile authorization process, the authorization code is received through this strategy.
[0078] In this embodiment, the authorization code of the third-party authentication platform in the corresponding authentication mode is a code for authorization generated by the third-party authentication platform in accordance with a specific authentication mode after the user completes the relevant authentication operation. After the client obtains this code, it can further obtain authorized user information, such as the temporary authorization code (Code) generated during the DingTalk authentication process.
[0079] In this embodiment, authorized user information is obtained based on the received authorization code. That is, after the client receives the authorization code from the third-party authentication platform, it uses the authorization code to obtain user-related information such as the user's account information and organizational structure information on the third-party platform by calling the back-end authentication interface.
[0080] In this embodiment, the authorized user information is relevant information about the user obtained through the authorization code, including the user's account information on the third-party authentication platform, organization, department, position, etc. This information is used to compare with the back-end stored information to confirm the user's identity and authority.
[0081] In this embodiment, the user information stored in the back-end is the user information pre-stored in the system back-end, including user identity information, architecture information, and permission information, etc., which serves as the comparison basis in the authentication process to determine the legitimacy of the user currently requesting authentication.
[0082] In this embodiment, the authorized user information is in the user information stored in the backend, which means that the obtained authorized user information matches the user information stored in the backend, indicating that the user has a record in the system, which is one of the conditions for successful authentication.
[0083] In this embodiment, the architecture information in the authorized user information refers to the relevant information of the authorized user in his organizational structure, such as the organization, department, position, etc., which is used to compare with the corresponding part in the back-end storage information to confirm the consistency of the user architecture information.
[0084] In this embodiment, the architecture information of the corresponding user in the user information stored in the backend is the relevant information in the organizational structure corresponding to the user currently requesting authentication stored in the backend. By comparing it with the architecture information in the authorized user information, it is determined whether the user organizational structure information matches.
[0085] In this embodiment, the authentication success (failure) feedback result is returned to the client based on the optimal data transmission strategy. After the authentication is completed, the authentication result is fed back to the client based on the optimal data transmission strategy. If the authorized user information and its architecture information match the backend storage information, the authentication success result is returned; otherwise, the authentication failure result is returned.
[0086] In this embodiment, the dynamic variables of the enterprise organizational structure relationship network are synchronously obtained and the permission propagation deduction is triggered to obtain the user's permission update result. When authentication fails, the dynamic change information of the enterprise organizational structure relationship is obtained, and deduction is performed based on the permission inheritance rules to determine the user's permission update caused by the organizational structure change, ensuring that the permission and architecture changes are synchronized.
[0087] In this embodiment, the user is authenticated based on the user's permission update result and the hybrid authentication mode until the final authentication result is obtained. This means that after obtaining the user's permission update result, the user is authenticated again in combination with the hybrid authentication mode (such as local authentication + DingTalk authentication and other combinations). Through multi-dimensional authentication, the user's identity is ensured to be accurate, and finally a conclusion is drawn as to whether the authentication is successful.
[0088] In this embodiment, it should be noted that the current system's support rules for hybrid authentication mode are as follows: Currently, the system only allows customers to enable local authentication or LDAP, and does not allow the two authentications to coexist. The two authentication methods maintain the existing logic unchanged; local authentication + DingTalk authentication, LDAP + DingTalk authentication, both hybrid authentications are supported. In the future, local authentication, LDAP, and DingTalk authentication will all coexist as hybrid authentications. The backend performs authentication according to the authentication type specified by the user (Local / DingTalk / LDAP) until one type succeeds or all types fail. If all types fail to authenticate, the client authentication fails. If any type of authentication in the configured authentication method succeeds, the authentication is considered successful.
[0089] In this embodiment, the third-party authentication method takes the DingTalk client as an example. Figures 2 to 3In the client's mobile configuration, you can enable DingTalk authentication login and bind the corresponding customer's DingTalk organization ID and name. After enabling DingTalk authentication login, users can configure organizational structure information as a policy matcher item, such as "R&D Department" or "Testing Department." This allows for manual synchronization of DingTalk account information and automatic synchronization upon login when changes are detected in the DingTalk account's organization, department, or position. In the client's mobile configuration, add the "OAuth2-DingTalk Authentication" option to enable DingTalk login. After enabling DingTalk login, users must create an enterprise application on the DingTalk SDK embed page, bind the corresponding organization, and provide the relevant organization ID and name on the portal page to retrieve the user's organizational structure information. A user can add one or more organizations, and organizations can be duplicated across multiple customers. After enabling DingTalk login and binding the corresponding organization ID, the backend automatically adds the organizational structure fields "Organization," "Department," and "Position" for the customer and displays them in the policy matcher. This allows users of the customer to automatically populate the organization, department, and position with the DingTalk account automatically created when logging in with DingTalk, facilitating configuration of policy matcher matching rules. After the DingTalk login function is enabled, the backend obtains the user's organizational structure information through the enterprise ID provided by the user. The organizational structure fields such as department and position in the strategy matcher provide a drop-down box for selection.
[0090] OAuth2: An open standard for authentication and authorization, including authorization code mode, simplified mode, password mode, and credential mode. The OAuth2 authorization code mode is the most secure of the four OAuth2 authentication and authorization methods. It requires a two-step request to the authentication server: first, requesting an authorization code with user information, and then using the authorization code to obtain a token. For security reasons, when requesting the authorization code, user information (such as username and password) cannot be entered directly on the client; instead, it must be sent to the authentication server through a third party, such as a browser. Common applications such as DingTalk, WeChat for Enterprise, Lark, and OKTA all fall under the OAuth2 authentication framework.
[0091] Example 2:
[0092] Based on Example 1, the strategy adaptive matching module includes:
[0093] The network environment perception submodule is used to perceive the network environment characteristics of each authentication request client received by the backend at the current moment in real time, and calculate the network environment perception value of the current client based on the real-time network environment characteristics;
[0094] The transmission strategy screening submodule is used to determine all matching data transmission strategies for each authentication request client based on the network environment perception value of each authentication request client received by the backend at the current moment;
[0095] The authentication busyness evaluation submodule is used to calculate the relative authentication busyness of the current client under each matching data transmission strategy based on all matching data transmission strategies of all authentication request clients received by the backend at the current moment and the authentication protocols corresponding to the corresponding selected third-party authentication methods;
[0096] The optimal transmission strategy determination submodule is used to regard the matching data transmission strategy with the maximum relative authentication busyness among all corresponding matching data transmission strategies of the current client as the optimal matching data transmission strategy of the current client.
[0097] In this embodiment, the authentication request client refers to the device that initiates the identity authentication request, including a desktop terminal (such as Win, Mac) and a mobile terminal (such as iOS, Android).
[0098] In this embodiment, the network environment perception value of the current client is calculated based on the real-time network environment characteristics, for example, using the formula: Network Environment Perception Value = 0.4 × Network Bandwidth Normalization Value + 0.3 × Delay Normalization Value + 0.3 × Packet Loss Rate Normalization Value. For example, if the network bandwidth is 100Mbps (maximum 1000Mbps), the normalization value is 0.1; the delay is 50ms (maximum 200ms), the normalization value is 0.25; the packet loss rate is 2% (maximum 10%), the normalization value is 0.2, and the calculated network environment perception value is 0.175.
[0099] In this embodiment, all matching data transmission strategies are determined based on the network environment perception value of each authentication requesting client. The system pre-sets rules, divided by perception value range, with different policy combinations corresponding to different ranges. For example, when the network environment perception value is greater than 0.6 and less than 0.9, the high-speed direct transmission strategy is adopted, while when the network environment perception value is greater than 0 and less than or equal to 0.6, the priority encryption transmission strategy is adopted.
[0100] In this embodiment, all matchable data transmission strategies of the authentication request client are data transmission methods screened based on the network environment perception value. For example, the high-speed direct transmission strategy focuses on fast data transmission, but may have high requirements for network stability and relatively weak security; the priority encryption transmission strategy emphasizes the confidentiality of data transmission, but may reduce the transmission speed.
[0101] In this embodiment, the authentication protocol corresponding to the third-party authentication method is the standard and process followed by a specific third-party authentication platform to perform authentication. For example, different authentication modes under the OAuth2 protocol have their own request and verification steps, including: Step 1: The authentication server verifies the client information and user authorization. If successful, it sends an authorization code to the redirection URI. After the application client receives the authorization code, it carries the authorization code, client ID, client key, etc. to request an access token from the authentication server. The authentication server verifies this information and returns an access token if it is correct. Step 2: The authentication server verifies the client credentials. If the verification is successful, an access token is returned. This mode is often used for authentication between server-side applications and does not involve user participation.
[0102] In this embodiment, the relative authentication busyness of the current client under each corresponding matchable data transmission policy reflects the relative busyness of the current client when authenticating using the policy.
[0103] The beneficial effects of the above technologies are as follows: the network environment perception submodule perceives the network environment characteristics of the authentication request client in real time, calculates the network environment perception value, accurately grasps the real-time network status of each client, and provides a reliable basis for subsequent policy formulation, so that the system can adapt to dynamic changes in the network. The transmission policy screening submodule determines all matching data transmission strategies based on the perception value, expands the range of policy selection, and greatly enhances the system's adaptability to complex and diverse network environments. The authentication busyness evaluation submodule comprehensively calculates the relative authentication busyness based on the matching strategies and authentication protocols, comprehensively taking into account the network and authentication characteristics, so that the policy evaluation is more in line with the actual authentication scenario. The optimal transmission strategy determination submodule selects the strategy with the maximum relative authentication busyness as the optimal, effectively balancing authentication efficiency and resource utilization, avoiding unreasonable use of resources, and realizing the optimal configuration of network resources and authentication processes, significantly improving the data transmission stability and authentication efficiency of unified identity authentication for multi-platform clients.
[0104] Example 3:
[0105] Based on Example 2, the authentication busyness evaluation submodule includes:
[0106] A resource consumption amplification factor determination unit, configured to determine the resource consumption amplification factor of all resource types under each matching data transmission strategy;
[0107] a resource consumption coefficient determining unit, configured to use an average of resource consumption ratios of each resource type in all authentication instances under the authentication protocol corresponding to each third-party authentication method as the resource consumption coefficient of the corresponding resource type under the authentication protocol corresponding to the corresponding third-party authentication method;
[0108] The resource occupancy determination unit is used to determine the resource occupancy of all resource types under each matching data transmission strategy and the authentication protocol corresponding to the corresponding third-party authentication method of each authentication request client received by the back-end at the current moment based on the resource consumption amplification coefficient of all resource types under each matching data transmission strategy and the resource consumption coefficient under the authentication protocol corresponding to each third-party authentication method; assuming that the CPU resource consumption coefficient under a certain authentication protocol is 0.2 and the consumption amplification coefficient under a certain matching data transmission strategy is 3, if the total CPU resource amount is 100 (assumed unit), then the CPU resource occupancy of the client under the strategy and authentication protocol is 100×0.2×3=60.
[0109] The global resource pressure determination unit is used to normalize the sum of the resource occupancy of all resource types under the authentication protocol corresponding to all matching data transmission policies and the corresponding selected third-party authentication method of all authentication request clients received by the back-end at the current moment, and the resource occupancy of the same resource type of the same matching data transmission policy to the maximum resource occupancy of the corresponding resource type, to obtain the global resource pressure of the corresponding resource type of the corresponding matching data transmission policy; for example, the total CPU resource occupancy of all clients under a certain matching data transmission policy is 200 (assumed unit), and the maximum CPU resource occupancy of the system is 500, then the global resource pressure of the CPU resource under the matching data transmission policy is 200÷500=0.4.
[0110] The relative authentication busyness determination unit is used to determine the relative authentication busyness of the current client under each corresponding matching data transmission policy based on the resource occupancy of all resource types of the current client under the authentication protocol corresponding to each corresponding matching data transmission policy and the corresponding third-party authentication method, and the global resource pressure of each resource type of the corresponding matching data transmission policy.
[0111] In this embodiment, all resource types refer to various types of resources involved in the system authentication process, such as CPU resources, memory resources, network bandwidth resources, etc.
[0112] In this embodiment, all authentication instances under the authentication protocol corresponding to each third-party authentication method refer to all authentication operation records processed by the system under a specific third-party authentication method (such as DingTalk OAuth2 authentication) and its corresponding authentication protocol. These instances include the usage of various resources during the authentication process.
[0113] In this embodiment, the resource consumption ratio for each resource type across all authentication instances under each authentication protocol corresponding to each third-party authentication method refers to the ratio of the actual usage of each resource type in each authentication instance to the total amount of that resource under each authentication protocol corresponding to each third-party authentication method. For example, in an authentication instance under the DingTalk OAuth2 authentication protocol, if the total memory is 100MB and the actual memory usage is 20MB, the memory resource consumption ratio for this instance is 20 ÷ 100 = 0.2.
[0114] In this embodiment, the relative authentication busyness is determined by calculating the relative authentication busyness according to the current client's occupancy of various resources under the corresponding matching data transmission strategy and authentication protocol, and the global resource pressure of each resource type of the matching data transmission strategy, using the following formula: relative authentication busyness = 0.4×(client CPU resource occupancy + CPU global resource pressure) + 0.3×(client memory resource occupancy + memory global resource pressure) + 0.3×(client network bandwidth resource occupancy + network bandwidth global resource pressure).
[0115] The beneficial effects of the above technologies are as follows: The resource consumption amplification coefficient determination unit specifies the consumption amplification coefficients of various resources under different compatible data transmission strategies, providing basic parameters for evaluating resource usage changes and enabling policy evaluation to consider the impact of different strategies on resource consumption. The resource consumption coefficient determination unit calculates the average value to obtain the consumption coefficient of each resource under different authentication protocols, quantifying the resource consumption during the authentication process and making the evaluation more scientific and accurate. The resource usage determination unit combines the above two to determine the resource usage of each authentication request client under different strategies and authentication protocols, clearly presenting the resource usage of each client. The global resource pressure determination unit normalizes the resource usage to obtain the global resource pressure, reflecting the resource pressure status under different strategies from a holistic perspective, which helps the system to allocate resources rationally. The relative authentication busyness determination unit combines the client resource usage and global resource pressure to accurately determine the relative authentication busyness, providing a comprehensive and practical reference for selecting the optimal transmission strategy, ultimately optimizing resource allocation and authentication efficiency in the unified identity authentication process for multi-platform clients.
[0116] Example 4:
[0117] Based on Example 3, the resource consumption amplification factor determining unit includes:
[0118] The consumption value determination subunit is used to perform no-load system testing in an isolated environment and record the basic resource consumption value of each resource type;
[0119] A resource consumption peak determination subunit, used to record the resource consumption peak value achieved when each resource type is enabled separately in an isolated environment and each matching data transmission strategy is used to execute a preset sub-typical authentication request;
[0120] The resource consumption amplification coefficient determination sub-unit is used to use the ratio of the resource consumption peak value reached when each resource type is separately enabled in an isolated environment to execute a preset sub-typical authentication request for each matching data transmission strategy to the basic resource consumption value as the resource consumption amplification coefficient of the corresponding resource type under each matching data transmission strategy.
[0121] In this embodiment, a no-load system test is performed in an isolated environment, and the basic resource consumption value of each resource type is recorded. That is, a test environment isolated from external interference factors is built. The system is run in this environment without performing additional operations related to actual authentication. The resource usage values of various resources such as CPU, memory, and network bandwidth are recorded when the system is in a no-load state. These values serve as a benchmark for subsequent evaluation of resource consumption changes. For example, the basic resource consumption value recorded for the CPU is 10% (usage rate) and the memory is 200M (occupancy).
[0122] In this embodiment, the term "preset sub-typical authentication requests" refers to a pre-set number and type of representative authentication requests to simulate actual authentication scenarios. These requests cover common third-party authentication methods and typical operational processes under the corresponding authentication protocols, allowing for testing system resource consumption under different data transmission strategies. For example, 10 login requests based on the DingTalk OAuth2 authentication protocol are set as the pre-set sub-typical authentication requests.
[0123] In this embodiment, the peak resource consumption reached by each resource type when each matching data transmission strategy is enabled in an isolated environment and a preset number of typical authentication requests is executed is recorded. That is, in the above-mentioned isolated environment, only one matching data transmission strategy is enabled at a time, and a preset number of typical authentication requests are executed. The highest consumption value reached by each type of resource during the execution process is monitored and recorded. For example, when the fast direct connection transmission strategy is enabled and 10 DingTalk OAuth2 authentication login requests are executed, the peak CPU resource consumption is observed to reach 50% (usage rate) and the peak memory resource consumption is 500MB (occupancy).
[0124] The beneficial effects of the above technologies are as follows: the consumption value determination subunit records the basic resource consumption value of each resource type by performing no-load system testing in an isolated environment, providing a stable and reliable benchmark data for subsequent evaluation, so that the resource consumption evaluation has a clear reference starting point, eliminating other interference factors, and making the evaluation more accurate. The resource consumption peak determination subunit records the resource consumption peak reached by each resource type when each matching data transmission strategy is enabled separately in an isolated environment to execute a preset typical authentication request, and obtains detailed information on the resource consumption limits under different strategies, which helps to fully understand the maximum resource demand of each strategy. The resource consumption amplification coefficient determination subunit uses the ratio of the resource consumption peak to the basic resource consumption value as the resource consumption amplification coefficient. This quantitative calculation method can intuitively reflect the degree to which each matching data transmission strategy amplifies the consumption of various types of resources, and provides the system with clear and comparable quantitative indicators when considering different strategies, so that the system can more scientifically and reasonably select the optimal transmission strategy based on these accurate indicators, optimize resource utilization in the unified identity authentication process of multi-platform clients, and improve overall authentication efficiency and stability.
[0125] Example 5:
[0126] Based on Example 1, the third-party authorization and authentication module includes:
[0127] The first authorization and authentication submodule is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a desktop client, launch the local browser to request login from the third-party authentication platform, generate and display the login QR code, and receive the authorization code after the user scans the code based on the optimal data transmission strategy. Based on the authorization code, the authorization process is triggered and the back-end authentication interface is called to obtain the authorized user information;
[0128] The second authorization and authentication sub-module is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a mobile terminal, and pull up the third-party client to trigger the authorization process. At the same time, it receives the temporary authorization code based on the optimal data transmission strategy and sends it to the backend, and calls the back-end authentication interface to obtain authorized user information.
[0129] In this embodiment, when the client is a desktop terminal (such as a Win or Mac system device), the system establishes a connection with the third-party authentication platform based on a preset authentication protocol. Then, the local browser is opened, a login request is initiated to the third-party authentication platform, a QR code for login is generated and displayed on the browser page. The user uses a mobile device to scan the QR code. After the scan is successful, the system receives the authorization code generated by the third-party authentication platform after the user scans the code according to the optimal data transmission strategy. Then, this authorization code is used to trigger the authorization process, and the authorized user information is obtained by calling the back-end authentication interface to complete the authentication process. For example, if DingTalk is used as a third-party authentication platform, the desktop system is connected to the DingTalk platform according to preset authentication protocols such as OAuth2. After the user scans the QR code, the system receives the authorization code to obtain the user's relevant information in DingTalk for authentication.
[0130] In this embodiment, when the client is a mobile terminal (such as an iOS or Android system device), it is also connected to the third-party authentication platform according to the preset authentication protocol. After that, the third-party client (such as the DingTalk client) is automatically pulled up, and the authorization interface pops up on the mobile terminal to trigger the authorization process. After the user agrees to the authorization, the system receives the temporary authorization code generated by the third-party client based on the optimal data transmission strategy, and sends it to the backend. After the backend receives the temporary authorization code, it obtains the authorized user information by calling the authentication interface to complete the authentication. For example, when using DingTalk authentication on the mobile phone, the system connects to DingTalk based on the preset protocol, pulls up the DingTalk client to obtain a temporary authorization code and sends it to the backend, and the backend obtains the user information based on this to complete the authentication.
[0131] The beneficial effects of the above technology are as follows: for the desktop side, the first authorization and authentication submodule is connected to the third-party authentication platform based on the preset protocol, and by launching the local browser to request login, generate and display the login QR code, it is convenient for users to scan the code. This method conforms to the characteristics of desktop devices and improves the convenience of user authentication. At the same time, based on the optimal data transmission strategy, the authorization code is received to ensure efficient and stable data transmission, ensure the smooth progress of the authorization process, and call the back-end interface to obtain the authorized user information to realize the authentication closed loop. For the mobile side, the second authorization and authentication submodule is also connected based on the preset protocol, and the third-party client is launched to trigger authorization, which is in line with the usage habits of the mobile side, and the temporary authorization code is received and sent to the back-end based on the optimal strategy, and then the authorized user information is obtained to ensure the smooth authentication process of the mobile side. Overall, this module provides adaptive authentication methods for different client types, uses the optimal data transmission strategy to ensure stable and efficient data interaction, and comprehensively improves the user experience and authentication efficiency of unified identity authentication of multi-platform clients.
[0132] Example 6:
[0133] Based on Example 1, a dynamic synchronization module is constructed, including:
[0134] The authentication failure feedback submodule is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the back-end or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the back-end. This means that during the authentication process, the system will compare the authorized user information received from the third-party authentication platform with the user information and corresponding architecture information stored in the back-end. If it is found that the authorized user is a new user (the information is not in the back-end storage), or the user already exists but its organizational structure information (such as department, position, etc.) does not match the back-end records, the subsequent process will be triggered. For example, a user stored in the back-end belongs to the "sales department", but the authorized user information obtained through third-party authentication shows that the user has been transferred to the "marketing department", which means that the architecture information is inconsistent.
[0135] The architecture relationship variable acquisition submodule is used to obtain dynamic variables of the enterprise organizational architecture relationship network;
[0136] The permission update submodule is used to perform permission propagation deduction based on the dynamic variables and permission inheritance rules of the enterprise organizational structure relationship network to obtain the user's permission update results.
[0137] In this embodiment, acquiring dynamic variables from the enterprise organizational structure network refers to capturing real-time changes in the enterprise's organizational structure during operation. These variables may include the addition, deletion, or merger of departments, changes in employee positions, and adjustments to reporting relationships. For example, if a company establishes a new "digital transformation project team" or an employee is promoted from "development team" to "technical director," these changes are dynamic variables.
[0138] In this embodiment, permission inheritance rules are a set of pre-defined criteria that determine which permissions a user inherits based on their position and role in the enterprise organizational structure. For example, within an enterprise, a department manager might automatically inherit the view permissions of all employees within the department, with the added bonus of approval permissions; or specific project team members might inherit read and write permissions for project-related documents. These rules clarify how permissions are assigned to different organizational structure positions.
[0139] In this embodiment, permission propagation deduction is performed based on the dynamic variables of the enterprise organizational structure relationship network and the permission inheritance rules to obtain the user's permission update result. This is to recalculate the user's appropriate permissions based on the obtained information about the dynamic changes in the organizational structure and the permission inheritance rules. For example, if a department in the enterprise is split and some employees are transferred to the new department, according to the permission inheritance rules, the transferred employees may obtain specific permissions corresponding to the new department, while losing certain permissions that no longer apply to the original department. The new permission range of the user obtained through this deduction is the permission update result.
[0140] The beneficial effects of the above technologies are as follows: the authentication failure feedback submodule, when the authorized user information does not match the back-end storage information, can use the optimal data transmission strategy to quickly return the authentication failure feedback result to the client, promptly inform the user of the authentication status, avoid invalid waiting for the user, improve the user experience, and maintain the accuracy and rigor of the system authentication process. The architecture relationship variable acquisition submodule is responsible for obtaining the dynamic variables of the enterprise organizational structure relationship network, providing real-time data support for the system to follow up on organizational structure changes, so that the system can adapt to the dynamic adjustment of the enterprise architecture. The permission update submodule performs permission propagation deduction based on the above dynamic variables and permission inheritance rules, and obtains the user permission update result, ensuring that user permissions are synchronized with enterprise architecture changes, ensuring the rationality and effectiveness of system permission management, and then maintaining the orderly operation of the entire system based on the enterprise organizational structure, and improving the system's adaptability to changes in actual business scenarios of the enterprise.
[0141] Example 7:
[0142] Based on Example 1, the second authentication module includes:
[0143] A hybrid authentication step tree building submodule is used to build a hybrid authentication step tree based on a multi-factor authentication system under a hybrid authentication mode;
[0144] The behavior risk assessment submodule is used to assess the user's behavior risk and obtain the user's behavior risk assessment value;
[0145] A step tree interception submodule is used to intercept and obtain an actual authentication step tree in the hybrid authentication step tree based on the user's permission update result and behavior risk assessment value;
[0146] The identity authentication submodule is used to authenticate the user based on the actual authentication step tree until the final authentication result is obtained.
[0147] In this embodiment, a multi-factor authentication system is a mechanism that verifies a user's identity by combining multiple different types of authentication factors. These factors are generally divided into three categories: known factors (such as passwords and PIN codes), all factors (such as mobile phones and smart cards), and inherent factors (such as fingerprints and facial recognition). For example, when logging in, a user not only needs to enter a password (known factor), but may also need to obtain a dynamic verification code through their mobile phone (all factors) or even perform fingerprint recognition (inherent factor). The combination of multiple factors improves the security of authentication.
[0148] In this embodiment, building a hybrid authentication step tree based on a multi-factor authentication system under a hybrid authentication mode means building a tree structure based on the hybrid authentication mode supported by the system (such as local authentication + DingTalk authentication, etc.) and combining various authentication factors in the multi-factor authentication system. This tree structure uses different authentication steps as nodes to show a series of operation processes and sequences required to complete user identity authentication. For example, starting from the root node, local password verification may be performed first, and after the verification is passed, the next level node is entered, such as selecting a third-party authentication method (DingTalk authentication), and then continuing with subsequent authentication steps such as scanning or authorization to form an orderly authentication process tree.
[0149] In this embodiment, the user's behavioral risk is assessed to obtain a behavioral risk assessment value by analyzing the user's operational behavior in the system, such as login frequency, operation time, operation type, etc., and applying a specific algorithm or model to quantify the degree of risk that the user's behavior may bring, thereby obtaining a specific numerical value. Assume that a weighted summation algorithm is used to assess user behavioral risk. The login frequency weight is 0.4, the operation time weight is 0.3, and the operation type weight is 0.3. The normal login frequency range is set to 1-5 times per week, the operation time is 9-18 o'clock on weekdays, and the operation type is divided into normal (weight 0.2) and sensitive (weight 0.8). A user logs in 3 times a week, with a score of (3-1) / (5-1)×0.4=0.2; 80% of the operation time is during normal hours, with a score of 0.8×0.3=0.24; 80% of the operation type is normal and 20% is sensitive, with a score of (0.2×0.8+0.8×0.2)×0.3=0.096. Behavioral risk assessment value = 0.2 + 0.24 + 0.096 = 0.536. The closer the value is to 1, the higher the risk.
[0150] In this embodiment, the actual authentication step tree is an authentication process tree tailored to the user's specific circumstances, extracted from the hybrid authentication step tree based on the user's updated permissions and behavioral risk assessment. For example, if the user's permissions are updated to allow access to more confidential information and the behavioral risk assessment is high, the actual authentication step tree may include additional identity verification steps, such as secondary facial recognition or supervisor approval.
[0151] In this embodiment, the user's identity is authenticated based on the actual authentication step tree until the final authentication result is obtained. Specifically, the user is guided through each authentication step in sequence according to the process and order determined by the actual authentication step tree. After each authentication step is completed, the system verifies whether the authentication result passes. If all steps pass verification, the final authentication result is successful. If the authentication fails at any step, the authentication result is failed.
[0152] The beneficial effects of the above technologies are: the second authentication module optimizes the authentication process from many aspects, and improves the authentication security and adaptability. The hybrid authentication step tree building sub-module builds a hybrid authentication step tree based on the multi-factor authentication system, constructs a comprehensive and hierarchical authentication framework, and provides systematic support for complex authentication needs. The behavioral risk assessment sub-module evaluates the user's behavioral risk to obtain an assessment value, introduces a dynamic risk assessment mechanism, so that the authentication can be adjusted according to the user's real-time behavioral characteristics, and enhances the pertinence of the authentication. The step tree interception sub-module combines the user's permission update results and the behavioral risk assessment value to intercept the actual authentication step tree to achieve personalized customization of the authentication process, taking into account the impact of organizational structure changes on permissions, and taking into account user behavior risks, to avoid excessive or insufficient authentication. The identity authentication sub-module carries out authentication based on the actual authentication step tree to obtain the final result, ensuring that the authentication process is rigorous and orderly. Through the above collaboration, while ensuring the security of authentication, it improves the user experience, adapts to the needs of diverse authentication scenarios, and strengthens the overall security and flexibility of the system.
[0153] Example 8:
[0154] Based on Example 7, the step tree interception submodule includes:
[0155] The permission update amount determination unit is used to determine the relative update factor of the permission range of all the user's permission update items based on the user's permission update results. That is, for each item whose user permissions have changed, the percentage of change in its permission range relative to the previous change is calculated. For example, if a user originally only had read permission for a certain type of file, and after the permission update, write permission was added, assuming the read permission range was set to 1, and the permission range becomes 2 after the addition of write permission, then the relative update factor of the permission range of this permission update item is (2-1) / 1=1.
[0156] The ratio of the original weight of each permission update item of the user (set according to factors such as the importance of the permission and the degree of impact on the business) to the sum of the original weights of all the permission update items of the user is used as the current weight of each permission update item of the user. Based on the current weights of all the permission update items of the user, the permission range relative update factors of all the permission update items of the user are weightedly summed to obtain the total relative update amount of the user's permissions. Assuming that the user has two permission update items, the permission range relative update factors are 1 and 0.5 respectively, and the current weights are 0.6 and 0.4 respectively, then the total relative update amount of permissions = 1×0.6+0.5×0.4=0.8.
[0157] The required authentication level range determination unit is used to determine the user's current node in the enterprise organizational structure relationship network based on the dynamic variables of the enterprise organizational structure relationship network. As the enterprise organizational structure changes, such as department adjustments and job promotions, the user's position in the latest organizational structure can be determined. This position is the current node. For example, if a company establishes a new project team and a user is transferred to this project team, this project team will be the user's current node in the organizational structure relationship network.
[0158] The user's current required authentication level range is determined based on their current node in the enterprise organizational structure. According to a pre-set node-authentication level range mapping table, different organizational structure nodes may correspond to different security requirements, which in turn determines the required authentication level range. For example, senior management nodes may require the highest level of authentication, while ordinary employee nodes may require lower levels of authentication. If a user is in a key position in a core business department, the required authentication level may range from advanced to top-level authentication.
[0159] The first interception unit is used to intercept the currently required authentication step tree for each authentication level within the user's currently required authentication level range from the hybrid authentication step tree based on the standard authentication steps for each authentication level within the user's currently required authentication level range and the standard incremental steps for each authentication level within the user's currently required authentication level range. That is, based on the above-mentioned standard authentication steps and standard incremental steps, an authentication process tree suitable for the user's currently required authentication level range and permission update situation is extracted from the general hybrid authentication step tree. For example, if the user's currently required authentication level is intermediate to advanced, based on the standard authentication steps and the standard incremental steps generated by the relative update amount of total permissions, the authentication step sequences corresponding to the intermediate and advanced authentication levels are determined and intercepted in the hybrid authentication step tree to form the currently required authentication step tree.
[0160] The second interception unit is configured to intercept a second currently required authentication step tree from the hybrid authentication step tree based on the behavioral risk assessment value. This interception is also performed based on a preset correspondence relationship. Based on the user's behavioral risk assessment value, the hybrid authentication step tree is adjusted to intercept an authentication step tree that meets the behavioral risk profile. If the behavioral risk assessment value is high, more risk prevention-related authentication steps may be added to the hybrid authentication step tree, such as identity verification and operation confirmation steps, thereby forming the second currently required authentication step tree.
[0161] The third interception unit is used to intercept the current required authentication step tree and the second current required authentication step tree under each authentication level within the user's current required authentication level range from the hybrid authentication step tree, and intercept the actual authentication step tree from the hybrid authentication step tree.
[0162] In this embodiment, the standard authentication steps for each authentication level are pre-defined, standardized authentication procedures for different authentication levels. For example, a low-level authentication level may only require entering a password; an intermediate-level authentication level may require an SMS verification code in addition to a password; and a high-level authentication level may require a combination of multiple biometric technologies such as fingerprint recognition and facial recognition.
[0163] In this embodiment, the standard incremental steps for each authentication level within the user's current required authentication level range refer to the number of additional authentication steps or the degree of difficulty that should be added to each authentication level within the current required authentication level range based on the relative update amount of the user's total permissions. For example, when the relative update amount of the total permissions is high, additional security question answering steps may be required as standard incremental steps at the intermediate authentication level.
[0164] The beneficial effects of the above technology are as follows: The step tree interception submodule optimizes the authentication process in multiple aspects, improving the scientificity and adaptability of authentication. The permission update amount determination unit uses complex calculations to calculate the relative update amount of total permissions based on the user's permission update results, accurately quantifying the permission changes and providing a precise basis for adjusting authentication steps. The required authentication level range determination unit determines the user's node in the architecture and the required authentication level range based on the dynamic variables of the enterprise organizational structure, closely linking the authentication level to the actual organizational situation. The first interception unit combines standard authentication steps, standard incremental steps, and the relative update amount of total permissions to intercept the current required authentication step tree for each authentication level in the hybrid authentication step tree, enabling customization of authentication steps based on permissions and architecture. The second interception unit intercepts another authentication step tree based on the behavioral risk assessment value, taking behavioral risks into consideration and strengthening risk prevention. Finally, the third interception unit integrates the results of the first two to obtain the actual authentication step tree. This fully integrates multi-dimensional information such as permissions, architecture, and behavioral risks, making the authentication process more adaptable to complex scenarios, significantly improving the scientificity, security, and adaptability of authentication, and ensuring the accuracy and efficiency of the authentication process.
[0165] Example 9:
[0166] Based on Example 8, the third interception unit includes:
[0167] a tree structure merging subunit, configured to merge the currently required authentication step tree and the second currently required authentication step tree for each authentication level within the range of the currently required authentication level of the user extracted from the hybrid authentication step tree, respectively, to obtain a plurality of merged required authentication step trees, wherein the total number of the merged required authentication step trees is the same as the total number of the currently required authentication step trees;
[0168] An authentication efficiency determination subunit, configured to determine the authentication efficiency of each authentication step tree required for merging based on the authentication effectiveness and operation resource loss of each authentication step tree required for merging;
[0169] The tree structure screening subunit is used to treat the authentication step tree required for merging with maximum authentication efficiency as the actual authentication step tree.
[0170] In this embodiment, the merged required authentication step tree is obtained by merging the current required authentication step tree for each authentication level within the range of the user's current required authentication level and the second current required authentication step tree intercepted based on the behavioral risk assessment value from the mixed authentication step tree to obtain multiple authentication step trees. For example, the current required authentication step tree for the current required authentication level of intermediate is merged with the second current required authentication step tree corresponding to the intermediate authentication portion intercepted based on the behavioral risk assessment value to generate a merged required authentication step tree for the intermediate authentication level. Similarly, merged required authentication step trees for each authentication level are generated, and the total number of merged required authentication step trees is consistent with the total number of current required authentication step trees for the current required authentication level.
[0171] In this embodiment, the authentication efficiency of each authentication step tree required for merging is determined based on the authentication effectiveness and operating resource consumption of each authentication step tree required for merging. Authentication effectiveness refers to the ability of the authentication step tree to accurately verify the identity of the user. For example, the sum of the preset authentication effectiveness of all authentication steps in each authentication step tree required for merging is taken as the authentication effectiveness of the authentication step tree required for merging. Operating resource consumption is the sum of the consumption of system resources such as CPU, memory, network bandwidth, etc. by all authentication steps in each authentication step tree required for merging. The authentication efficiency is determined by comprehensively considering these two factors, for example, using the formula: authentication efficiency = authentication effectiveness / operating resource consumption.
[0172] The beneficial effects of the above technology are as follows: the tree structure merging sub-unit merges the authentication step trees intercepted based on different criteria respectively, and generates multiple authentication step trees required for merging. This integration method fully integrates the influence of multiple factors such as authority, organizational structure and behavioral risks on the authentication steps, forming a more comprehensive and targeted set of authentication steps. The authentication efficiency determination sub-unit determines the authentication efficiency of each authentication step tree required for merging based on the authentication effectiveness and operating resource loss. It not only focuses on the accuracy and security of the authentication, but also takes into account the resource consumption during system operation, making the evaluation of the authentication step tree more comprehensive and scientific. The tree structure screening sub-unit uses the authentication step tree required for merging with the maximum authentication efficiency as the actual authentication step tree, ensuring that the authentication step tree finally adopted can maximize the use of system resources while ensuring the quality of authentication, improve authentication efficiency and avoid resource waste. Through this series of operations, the accuracy, efficiency and rationality of resource utilization of the authentication process are further improved, better adapting to diverse and complex authentication scenarios, and providing users with better quality and safer authentication services.
[0173] Example 10:
[0174] The present invention provides a multi-platform client unified identity authentication and organizational structure dynamic synchronization method, including:
[0175] S1: Matches the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user;
[0176] S2: Connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the corresponding client's authentication mode, receive the authorization code from the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information based on the received authorization code;
[0177] S3: When it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend, an authentication success feedback result is returned to the client based on the optimal data transmission strategy;
[0178] When it is determined that the authorized user information is not in the user information stored in the backend, or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the backend, the authentication failure feedback result is returned to the client based on the optimal data transmission strategy, and the dynamic variables of the enterprise organizational structure relationship network are simultaneously obtained and the permission propagation calculation is triggered to obtain the user's permission update result;
[0179] S4: Authenticate the user based on the user's permission update result and the hybrid authentication mode until the final authentication result is obtained.
[0180] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalents, the present invention is intended to include these modifications and variations.
Claims
1. A unified identity authentication and organizational structure dynamic synchronization system for multi-platform clients, characterized by: include: A policy adaptive matching module is used to match the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user; The third-party authorization and authentication module is used to connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the authentication mode of the corresponding client, receive the authorization code of the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information based on the received authorization code; The first authentication module is configured to return an authentication success feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend; The architecture dynamic synchronization module is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the back-end or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the back-end. It also synchronously obtains the dynamic variables of the enterprise organizational structure relationship network and triggers the permission propagation deduction to obtain the user's permission update result; The second authentication module is used to authenticate the user based on the user's authority update result and the hybrid authentication mode until a final authentication result is obtained.
2. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 1 is characterized in that: Strategy adaptive matching module, including: The network environment perception submodule is used to perceive the network environment characteristics of each authentication request client received by the backend at the current moment in real time, and calculate the network environment perception value of the current client based on the real-time network environment characteristics; The transmission strategy screening submodule is used to determine all matching data transmission strategies for each authentication request client based on the network environment perception value of each authentication request client received by the backend at the current moment; The authentication busyness evaluation submodule is used to calculate the relative authentication busyness of the current client under each matching data transmission strategy based on all matching data transmission strategies of all authentication request clients received by the backend at the current moment and the authentication protocols corresponding to the corresponding selected third-party authentication methods; The optimal transmission strategy determination submodule is used to regard the matching data transmission strategy with the maximum relative authentication busyness among all corresponding matching data transmission strategies of the current client as the optimal matching data transmission strategy of the current client.
3. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 2 is characterized in that: The authentication busyness evaluation submodule includes: A resource consumption amplification factor determination unit, configured to determine the resource consumption amplification factor of all resource types under each matching data transmission strategy; a resource consumption coefficient determining unit, configured to use an average of resource consumption ratios of each resource type in all authentication instances under the authentication protocol corresponding to each third-party authentication method as the resource consumption coefficient of the corresponding resource type under the authentication protocol corresponding to the corresponding third-party authentication method; A resource occupancy determination unit is configured to determine the resource occupancy of all resource types under each matching data transmission policy and the authentication protocol corresponding to the selected third-party authentication method for each authentication request client simultaneously received by the backend at the current moment based on the resource consumption amplification coefficients of all resource types under each matching data transmission policy and the resource consumption coefficients under the authentication protocol corresponding to each third-party authentication method; A global resource pressure determination unit is configured to normalize the sum of the resource occupancy of all resource types under the authentication protocol corresponding to all matching data transmission policies and corresponding selected third-party authentication methods of all authentication request clients received by the backend at the current moment, and the resource occupancy of the same resource type under the same matching data transmission policy to the maximum resource occupancy of the corresponding resource type, thereby obtaining the global resource pressure of the corresponding resource type under the corresponding matching data transmission policy; The relative authentication busyness determination unit is used to determine the relative authentication busyness of the current client under each corresponding matching data transmission policy based on the resource occupancy of all resource types of the current client under the authentication protocol corresponding to each corresponding matching data transmission policy and the corresponding third-party authentication method, and the global resource pressure of each resource type of the corresponding matching data transmission policy.
4. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 3 is characterized in that: The resource consumption magnification factor determination unit includes: The consumption value determination subunit is used to perform no-load system testing in an isolated environment and record the basic resource consumption value of each resource type; A resource consumption peak determination subunit, used to record the resource consumption peak value achieved when each resource type is enabled separately in an isolated environment and each matching data transmission strategy is used to execute a preset sub-typical authentication request; The resource consumption amplification coefficient determination sub-unit is used to use the ratio of the resource consumption peak value reached when each resource type is separately enabled in an isolated environment to execute a preset sub-typical authentication request for each matching data transmission strategy to the basic resource consumption value as the resource consumption amplification coefficient of the corresponding resource type under each matching data transmission strategy.
5. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 1 is characterized in that: Third-party authorization and authentication module, including: The first authorization and authentication submodule is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a desktop client, launch the local browser to request login from the third-party authentication platform, generate and display the login QR code, and receive the authorization code after the user scans the code based on the optimal data transmission strategy. Based on the authorization code, the authorization process is triggered and the back-end authentication interface is called to obtain the authorized user information; The second authorization and authentication sub-module is used to connect to the third-party authentication platform based on the preset authentication protocol when the client is a mobile terminal, and pull up the third-party client to trigger the authorization process. At the same time, it receives the temporary authorization code based on the optimal data transmission strategy and sends it to the backend, and calls the back-end authentication interface to obtain authorized user information.
6. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 1 is characterized in that: Architecture dynamic synchronization module, including: The authentication failure feedback submodule is used to return the authentication failure feedback result to the client based on the optimal data transmission strategy when it is determined that the authorized user information is not in the user information stored in the backend or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the backend; The architecture relationship variable acquisition submodule is used to obtain dynamic variables of the enterprise organizational architecture relationship network; The permission update submodule is used to perform permission propagation deduction based on the dynamic variables and permission inheritance rules of the enterprise organizational structure relationship network to obtain the user's permission update results.
7. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 1 is characterized in that: The second authentication module includes: A hybrid authentication step tree building submodule is used to build a hybrid authentication step tree based on a multi-factor authentication system under a hybrid authentication mode; The behavior risk assessment submodule is used to assess the user's behavior risk and obtain the user's behavior risk assessment value; A step tree interception submodule is used to intercept and obtain an actual authentication step tree in the hybrid authentication step tree based on the user's permission update result and behavior risk assessment value; The identity authentication submodule is used to authenticate the user based on the actual authentication step tree until the final authentication result is obtained.
8. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 7, characterized in that: Step tree interception submodule, including: a permission update amount determination unit, configured to determine, based on the permission update result of the user, a permission range relative update factor of all permission update items of the user, taking the ratio of the original weight of each permission update item of the user to the sum of the original weights of all permission update items of the user as the current weight of each permission update item of the user, and performing a weighted sum of the permission range relative update factors of all permission update items of the user based on the current weights of all permission update items of the user to obtain a total permission relative update amount of the user; A required authentication level range determination unit, configured to determine the user's current node in the enterprise organizational structure relationship network based on a dynamic variable of the enterprise organizational structure relationship network, and determine the user's current required authentication level range based on the user's current node in the enterprise organizational structure relationship network; a first interception unit for intercepting, from the mixed authentication step tree, a currently required authentication step tree for each authentication level within the currently required authentication level range of the user, based on a standard authentication step for each authentication level within the currently required authentication level range of the user and a standard incremental step for a relative update amount of the user's total authority within the currently required authentication level range of the user; A second interception unit, configured to intercept a second currently required authentication step tree from the hybrid authentication step tree based on the behavior risk assessment value; The third interception unit is used to intercept the current required authentication step tree and the second current required authentication step tree under each authentication level within the user's current required authentication level range from the hybrid authentication step tree, and intercept the actual authentication step tree from the hybrid authentication step tree.
9. The multi-platform client unified identity authentication and organizational structure dynamic synchronization system according to claim 8, characterized in that: The third interception unit includes: a tree structure merging subunit, configured to merge the currently required authentication step tree and the second currently required authentication step tree for each authentication level within the range of the currently required authentication level of the user extracted from the hybrid authentication step tree, respectively, to obtain a plurality of merged required authentication step trees, wherein the total number of the merged required authentication step trees is the same as the total number of the currently required authentication step trees; An authentication efficiency determination subunit, configured to determine the authentication efficiency of each authentication step tree required for merging based on the authentication effectiveness and operation resource loss of each authentication step tree required for merging; The tree structure screening subunit is used to treat the authentication step tree required for merging with maximum authentication efficiency as the actual authentication step tree.
10. A method for unified identity authentication and dynamic synchronization of organizational structure for multi-platform clients, characterized in that: include: S1: Matches the optimal data transmission strategy based on the network environment perception value and the third-party authentication method selected by the user; S2: Connect to the third-party authentication platform based on the preset authentication protocol, trigger the authorization process according to the corresponding client's authentication mode, receive the authorization code from the third-party authentication platform in the corresponding authentication mode through the optimal data transmission strategy, and obtain the authorized user information based on the received authorization code; S3: When it is determined that the authorized user information is in the user information stored in the backend and the architecture information in the authorized user information is consistent with the architecture information of the corresponding user in the user information stored in the backend, an authentication success feedback result is returned to the client based on the optimal data transmission strategy; When it is determined that the authorized user information is not in the user information stored in the backend, or the architecture information in the authorized user information is inconsistent with the architecture information of the corresponding user in the user information stored in the backend, the authentication failure feedback result is returned to the client based on the optimal data transmission strategy, and the dynamic variables of the enterprise organizational structure relationship network are simultaneously obtained and the permission propagation calculation is triggered to obtain the user's permission update result; S4: Authenticate the user based on the user's permission update result and the hybrid authentication mode until the final authentication result is obtained.
Citation Information
Patent Citations
Multi-factor login authentication method and system, electronic equipment and storage medium
CN117879923A
Multi-mode unified identity authentication method based on OAuth2.0 technology
CN119484033A