Freight driver admission method and device, storage medium and electronic equipment
By obtaining the admission applications of freight drivers, dynamically adding scenario rules to the admission policy aggregation module, and using the rule engine to evaluate the admission results, the problems of poor flexibility and scalability of the traditional freight driver admission system are solved, and flexible admission control and cost reduction are achieved.
Patent Information
- Application Number
- CN202510743543.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-09-19
AI Technical Summary
The hard-coded rules of the traditional freight driver access system result in poor flexibility and difficulty in adapting to changes in business needs. It also encounters technical problems that cannot be solved by existing technologies. The technical problem that cannot be solved by existing technologies is the poor scalability of the system, which increases the cost and difficulty of modifying the code.
By obtaining the admission application of freight drivers, determining the application scenario information, dynamically adding scenario rules to the admission policy aggregation module, using the rule engine to evaluate the admission policy, and generating admission results, it avoids modifying the system code.
It realizes flexible access control when business needs change, reduces the development cost of the access control system, improves the flexibility of access control and reduces the maintenance cost of the system.
Smart Images

Figure CN120672304A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a freight driver access method and device, a storage medium, and an electronic device. Background Art
[0002] As the freight logistics industry digitizes, intelligent upgrades to driver access control systems have become a key technology for improving operational safety and compliance. Existing professional access systems typically employ a hard-coded, rule-based approach. This approach implements access control by pre-defining a series of rules within the system and then performing logical analysis on these rules at runtime.
[0003] The rules applied in traditional access control methods are fixed. When business requirements change or are applied to new business requirements, the code in the system needs to be modified to adapt to the changed or new business requirements. The process of modifying the code is complicated and requires high costs, which increases the cost of access control. Summary of the Invention
[0004] In view of this, the embodiments of the present application provide a method and device for the admission of freight drivers, a storage medium and an electronic device. The solution provided by the present application can determine various scenario rules based on the application scenario information in the admission application of the freight driver, and add the various scenario rules to the admission policy aggregation module, and then apply the admission policy aggregation module to generate the admission policy of the admission application, and use the rule engine to evaluate each admission rule in the admission policy, so as to obtain the admission result of the freight driver. In the solution of the present application, new admission rules can be added to the admission policy aggregation module, so that admission rules can be dynamically added to the admission policy aggregation module according to changes in business needs, without modifying the system code, reducing the cost required to modify the code, and reducing the cost of the entire admission control.
[0005] To achieve the above objectives, the present invention provides the following technical solutions:
[0006] The first aspect of the present application provides a method for admitting freight drivers, comprising:
[0007] Obtain access applications submitted by freight drivers;
[0008] Obtaining application scenario information from the admission application, and when a preset admission policy aggregation module does not include an admission rule corresponding to the application scenario information, determining each scenario rule corresponding to the application scenario information, and adding each scenario rule as an admission rule to a rule set of the admission policy aggregation module;
[0009] Obtaining an admission policy corresponding to the admission application through a rule set in the admission policy aggregation module, wherein the admission policy includes multiple admission rules;
[0010] The preset rule engine is called to evaluate each admission rule in the admission strategy to obtain the admission result of the freight driver's admission application.
[0011] A second aspect of the present application provides a freight driver access device, comprising:
[0012] The first acquisition unit is used to obtain the access application submitted by the freight driver;
[0013] a second acquisition unit, configured to acquire application scenario information from the admission application, and when a preset admission policy aggregation module does not include an admission rule corresponding to the application scenario information, determine each scenario rule corresponding to the application scenario information, and add each scenario rule as an admission rule to a rule set of the admission policy aggregation module;
[0014] a determining unit, configured to obtain an admission policy corresponding to the admission application through a rule set in the admission policy aggregation module, wherein the admission policy includes a plurality of admission rules;
[0015] An evaluation unit is used to call a preset rule engine to evaluate each admission rule in the admission strategy to obtain an admission result of the freight driver's admission application.
[0016] A third aspect of the present application provides a storage medium, which includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the freight driver admission method as described above.
[0017] The fourth aspect of the present application provides an electronic device comprising a memory and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to implement the freight driver access method as described above.
[0018] Compared with the prior art, this application has the following advantages:
[0019] The present application provides a method and device for accessing freight drivers, a storage medium and an electronic device, including: obtaining an access application submitted by a freight driver, obtaining application scenario information in the access application, and when the preset access policy aggregation module does not include the access rule corresponding to the application scenario information, determining each scenario rule corresponding to the application scenario information, and adding each scenario rule as an access rule to the rule set of the access policy aggregation module; obtaining the access policy corresponding to the access application through the rule set in the access policy aggregation module, the access policy including multiple access rules; calling the preset rule engine to evaluate each access rule in the access policy, and obtaining the access result of the freight driver's access application. The solution provided by the present application can dynamically add access rules, and there is no need to change the system code when adding rules, thereby reducing the cost of access control, and the solution provided by the present application is suitable for access control with changing business needs, and improves the flexibility of access control. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0021] Figure 1 A flowchart of a method for admitting freight drivers provided in an embodiment of the present application;
[0022] Figure 2 A flowchart of a method for determining an admission policy corresponding to an admission application by using a rule set in an admission policy aggregation module provided in an embodiment of the present application;
[0023] Figure 3 A flowchart of a method for calling a rule engine to evaluate each admission rule in an admission policy and obtaining an admission result for a freight driver's admission application provided in an embodiment of the present application;
[0024] Figure 4 This is an example diagram of the architecture of a freight driver access system provided in an embodiment of the present application;
[0025] Figure 5 A schematic diagram of the structure of a freight driver access device provided in an embodiment of the present application;
[0026] Figure 6 A structural diagram of an electronic device provided for the implementation of this application. DETAILED DESCRIPTION
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0028] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0029] In modern society, with the continuous development of information technology, computer technology and information systems are increasingly being used in various fields. Computer technology has become an indispensable tool, particularly in the management of professional access. Traditional access management systems typically employ a hard-coded, rule-based approach, implementing access control by pre-defining a series of rules within the system and then applying logical judgment to these rules at runtime.
[0030] The traditional access method has the following problems:
[0031] First, due to the hard-coded nature of the rules, the system lacks flexibility and cannot adapt to changing business needs. Changes in business requirements require code modifications, which not only increases developer workload but also easily introduces new errors. Second, due to the distributed storage of rules, the system's scalability is poor. When the system needs to expand, all rules need to be redesigned and implemented, which is not only time-consuming and labor-intensive but also easily leads to system chaos. Finally, due to the interdependencies of the rules, the system is difficult to maintain. When problems arise, it is difficult to quickly locate the root cause, making resolution more challenging.
[0032] In order to solve the above-mentioned problems, the present application provides a freight driver access solution. During the implementation of the solution, after obtaining the access application submitted by the freight driver, it is determined whether it is necessary to import new access rules into the access policy aggregation module; when necessary, new access rules are imported based on the application scenario information of the access application, and then the access policy aggregation module is used to determine the access policy of the access application, and the rule engine is used to evaluate the access rules in the access policy, thereby obtaining the access result of the freight driver's access application. The present application imports new access rules into the access policy aggregation module, so that different business needs can be met when the business changes dynamically, without modifying the system code, thereby reducing the workload of staff and reducing the cost of access control.
[0033] This application can be used in a variety of general-purpose or specialized computing device environments or configurations, such as personal computers, server computers, handheld or portable devices, tablet devices, multi-processor devices, and distributed computing environments that include any of the above. This application can also be applied to a freight driver access system.
[0034] Reference Figure 1 , is a flow chart of a freight driver admission method provided in an embodiment of the present application, and is specifically described as follows:
[0035] S101. Obtain an access application submitted by a freight driver.
[0036] Freight drivers can submit access applications through the operation interface, or obtain access applications through the defined standard interface.
[0037] The access application includes but is not limited to freight driver identity information, vehicle information, application scenario information, and access field information.
[0038] The application scenario information includes information describing the freight driver's current application scenario. For example, the application scenarios include but are not limited to cross-border logistics scenarios, dangerous goods transportation scenarios, cold chain logistics scenarios, public emergency scenarios, new energy logistics scenarios, autonomous driving freight scenarios, multimodal transport scenarios, green city distribution scenarios, new driver access scenarios, or driver change review scenarios, etc.
[0039] The access field information includes various fields in the freight access management involved in the access application, including but not limited to review, invitation, deposit, vehicle sticker, education and transportation capacity.
[0040] S102. Obtain application scenario information in the admission application. When the preset admission policy aggregation module does not include admission rules corresponding to the application scenario information, obtain each scenario rule corresponding to the application scenario information, and add each scenario rule as an admission rule to the rule set of the admission policy aggregation module.
[0041] It should be noted that different application scenarios have different scenario rules. For example, the scenario rules for cross-border logistics scenarios include the latest customs access rules of the countries through which the vehicle passes; the scenario rules for dangerous goods transportation scenarios include transportation license verification rules, escort qualification verification rules, and vehicle inspection report validity period verification rules for the transported dangerous goods; the scenario rules for cold chain logistics scenarios include but are not limited to vehicle temperature record verification rules and refrigeration maintenance record verification rules; the scenario rules for public emergency scenarios include but are not limited to communication certificate verification rules, whitelist verification rules, etc.; the scenario rules for new energy logistics scenarios include but are not limited to vehicle carbon reduction detection rules, carbon emission subsidy rules, and preferred dispatch order rules, etc.; the scenario rules for other application scenarios will no longer be given examples one by one.
[0042] Obtain application scenario information from the access application and determine whether the access policy aggregation module includes access rules corresponding to the application scenario. It should be noted that some basic access rules are pre-set in the rule set of the access policy aggregation model, such as basic driver authentication rules, driver registration rules, single field rules, and compliance field rules.
[0043] When the admission policy aggregation module includes admission rules corresponding to the application scenario, S103 is directly executed; when the admission policy aggregation module does not include admission rules corresponding to the application scenario, it is necessary to obtain various scenario rules corresponding to the application scenario information.
[0044] The process of obtaining various scenario rules corresponding to the application scenario information includes: establishing a communication link with the scenario rule system of the application scenario information; and obtaining various scenario rules from the scenario rule system through the communication link.
[0045] In another embodiment provided by the present application, the process of establishing a communication link with the scenario rule system of the application scenario information is as follows:
[0046] Establish a conversation link with the scenario rule system;
[0047] Obtain environmental information of the scene rule system;
[0048] Evaluate the environmental safety level of the scenario rule system based on environmental information;
[0049] Determine whether to encrypt the session link based on the security level of the environment;
[0050] When it is determined that the session link does not need to be encrypted, determining the session link as a communication link;
[0051] When it is determined that the session link needs to be encrypted, the session link is encrypted based on the communication protocol applied to the session link to obtain an encrypted communication link.
[0052] When establishing a session link with the scenario rule system, the session link may be established using a communication protocol supported by both parties, or through a handshake protocol.
[0053] Environmental information is multi-dimensional information, which includes but is not limited to the system type of the scenario rule system, system antivirus records, system maintenance records, system security component information, system network information, system access records, etc., among which the system type can be divided into enterprise type, government type, private type, etc.
[0054] Apply the preset risk assessment model to process the environmental information and obtain risk assessment values in multiple dimensions; for each dimension, calculate the preset weight value of the dimension and the risk assessment value of the dimension to obtain the risk value of the dimension; summarize the various risk values to obtain the total risk value, and determine the security level corresponding to the total risk value as the environmental safety level of the scenario rule system; the higher the environmental safety level, the safer the environment in which the scenario rule system is located.
[0055] When determining the environmental safety level of the scenario rule system, an assessment is performed from multiple dimensions to obtain the corresponding risk assessment value, and then the corresponding weight value is used to determine the risk value. The various risk values are then aggregated to determine the environmental safety level. By performing risk assessment from multiple dimensions, the accuracy of the final determined environmental safety level is improved.
[0056] When the environmental security level is lower than the preset level, it means that the security risk of communicating with the scenario rule system is high and there is a communication risk. The session link needs to be encrypted to improve communication security. When the environmental security level is not lower than the preset level, it means that the security risk of communicating with the scenario rule system is low and there is no need to encrypt the communication process.
[0057] Use the communication protocol used for the session link to determine the encryption method compatible with the communication protocol, and then encrypt the session link using that encryption method. Different communication protocols are compatible with different encryption methods. If encryption is performed using an encryption method incompatible with the communication protocol of the session link, data loss, communication failures, slow data transmission, and other issues may occur during the encrypted session link. Therefore, by encrypting with an encryption method compatible with the communication protocol of the session link, you can ensure smooth subsequent communication using the link and avoid data loss.
[0058] Using encrypted communication links for communication can effectively prevent data leakage or theft and modification by criminals, thereby improving the communication security between the two systems.
[0059] S103: Determine an admission policy corresponding to the admission application through a rule set in an admission policy aggregation module, where the admission policy includes multiple admission rules.
[0060] Reference Figure 2 , which is a flow chart of a method for determining an admission policy corresponding to an admission application through a rule set in an admission policy aggregation module according to an embodiment of the present application, and is specifically described as follows:
[0061] S201: Acquire access domain information in an access application, and determine a service node based on the access domain information.
[0062] In another embodiment provided by the present application, the access domain information includes multiple service description information, and the service node is determined by the service description information. Different services correspond to different service nodes.
[0063] Business nodes include but are not limited to driver registration nodes, authentication nodes, review nodes, invitation nodes, etc. Different business nodes execute different business processes, and you can define the business processes of business nodes yourself.
[0064] S202 : Based on the business process of each business node, determine the admission rule of each business node in the rule set of the admission policy aggregation module.
[0065] It's important to note that the business process of a business node involves at least one business object. Business objects, such as drivers, vehicles, and documents, are modeled using domain-driven design (DDD) methods to represent core concepts in the business process. Business logic is implemented by defining the attributes, behaviors, and relationships between multiple business objects. The domain-driven layer in the system defines the attributes, behaviors, and relationships of business objects, and defines the domain logic.
[0066] In another embodiment provided by the present application, a service node can be flexibly added to the system or the properties and behaviors of an existing service node can be adjusted through a node configuration component; the service node is obtained through standardized node design.
[0067] The business process includes but is not limited to the triggering conditions of the node, the access rules involved, and the processing logic.
[0068] Based on the information of the admission rules involved in the business process, each admission rule of the business node is determined in the policy aggregation model.
[0069] S203: Apply the admission rules of each service node and the admission rules corresponding to the application scenario information in the admission policy aggregation module to generate an admission policy for the admission application.
[0070] Aggregate the admission rules of each business node and the admission rules corresponding to the application scenario information in the admission policy aggregation model to form an admission process, thereby generating an admission policy for the admission application.
[0071] In the method provided in the embodiment of the present application, when generating the admission policy for the admission application, the admission rules corresponding to the application scenario information of the admission application are used to generate the admission policy, thereby dynamically generating the admission policy, so it can be applied to a variety of application scenarios, and rules for different application scenarios can be added, thereby adding rules according to needs, thereby improving the flexibility of system access.
[0072] S104: Call a preset rule engine to evaluate each admission rule in the admission strategy to obtain the admission result of the freight driver's admission application.
[0073] In another implementation provided by the present application, before executing the call to the preset rule engine to evaluate the various access rules in the access policy, the various access rules in the access policy can be checked to determine whether there are conflicting access rules; when there are conflicting access rules, the conflicting access rules will be deleted from the access policy; by deleting the conflicting access rules, conflicts can be avoided during subsequent rule evaluations, and the accuracy of subsequent access results can be effectively improved.
[0074] Reference Figure 3 , which is a flowchart of a method for calling a rule engine to evaluate each admission rule in an admission policy and obtaining an admission result of a freight driver's admission application provided in an embodiment of the present application, as specifically described below:
[0075] S301: For each access rule, call a preset rule engine to obtain rule information corresponding to the access rule, apply the rule information to execute the access rule, and obtain an execution result of the access rule.
[0076] Before executing the access rules, it is necessary to obtain the rule information corresponding to the access rules. Some rule information can be obtained locally, and some rule information needs to be obtained from an external information system. For example, when the access rule is a dangerous goods transportation license verification rule, it is necessary to obtain the truck driver's dangerous goods transportation license information from the dangerous goods transportation information system.
[0077] The rule engine applies the obtained rule information to execute the access rule, thereby obtaining the execution result of the access rule. It should be noted that there are two types of execution results. One is characterized as a satisfied result, which means that the freight driver meets the access rule, and the other is characterized as a dissatisfied result, which means that the freight driver does not meet the access rule.
[0078] S302: Based on the execution results of each admission rule, obtain the admission result of the freight driver's admission application.
[0079] When there is an execution result that is characterized as unsatisfied among the execution results, an admission result is generated indicating that the freight driver's admission application is rejected; when all the execution results are characterized as satisfied, an admission result is generated indicating that the freight driver's admission application is approved.
[0080] In the embodiment provided in the present application, a rule engine is used to execute the admission rules in the admission strategy, and the admission results of the admission rules are obtained, thereby obtaining the admission results of the freight driver's admission application.
[0081] In the method provided in the embodiment of the present application, the access application submitted by the freight driver is obtained, and the application scenario information in the access application is obtained. When the preset access policy aggregation module does not include the access rules corresponding to the application scenario information, the various scenario rules corresponding to the application scenario information are determined, and each scenario rule is added as an access rule to the rule set of the access policy collection module; the access policy corresponding to the access application is obtained through the rule set in the access policy aggregation module, and the access policy includes multiple access rules; the preset rule engine is called to evaluate the various access rules in the access policy, and the access result of the freight driver's access application is obtained. The solution provided by the present application can dynamically add access rules, and there is no need to change the system code when adding rules, thereby reducing the cost of access control, and the solution provided by the present application is suitable for access control with changing business needs, and improves the flexibility of access control.
[0082] Reference Figure 4 , is an example diagram of the architecture of a freight driver access system provided in an embodiment of the present application, and the relevant descriptions are as follows:
[0083] The freight driver access system can be divided into a domain model layer and a rule engine layer; the domain model layer includes an access policy selector, an access policy aggregation module, and a joining work order aggregation; it should be noted that the access policy aggregation module includes rule sets and nodes, and the access policy interacts with other domains through node customization; the rule engine layer includes a rule engine.
[0084] Furthermore, the domain model layer uses domain-driven design methodology to model core concepts in the freight business. These include key business objects such as drivers, vehicles, and documents. The domain model layer defines the attributes, behaviors, and relationships of these objects, and defines the domain logic for practical application within the system. For example, process configuration is used to define and manage the access process. The process configuration component allows users to design the nodes of the access process and define the logical relationships between them. Each node can be configured with trigger conditions, rule execution, and subsequent processing logic. The process configuration component is highly scalable, facilitating the addition or modification of process nodes. Node configuration provides standardized configuration for each node in the access process, including node attributes, behaviors, and rules. The node configuration component supports parameterization, allowing nodes to be replaced or added to adapt to different business scenarios. This standardized configuration significantly reduces the complexity of system maintenance and improves overall flexibility.
[0085] The rule engine layer uses a configurable rule engine to manage and enforce access rules. Based on predefined rule sets, the rule engine can dynamically load, update, and delete rules, supporting flexible configuration of complex rules. System administrators can intuitively manage business rules through the user interface without touching core code, significantly improving system maintainability.
[0086] The freight driver access system can achieve the following functions:
[0087] 1. Standardized process design:
[0088] The system standardizes process design through process configuration components. Users can define and modify access processes through a graphical interface. Standardized design reduces human error and ensures process consistency and efficiency.
[0089] 2. Flexible expansion mechanism:
[0090] The node configuration component enables the system to flexibly add new process nodes or adjust the properties and behaviors of existing nodes. Through standardized node design, new business requirements can be quickly integrated into the system, making the expansion process efficient and stable.
[0091] 3. Dynamic rule management:
[0092] The system allows administrators to dynamically manage the rule engine through the user interface. The rule base can be updated in real time without stopping the system or redeploying it. The rule engine supports the combination and configuration of complex logic, ensuring flexible adjustment and efficient execution of access rules.
[0093] 4. Real-time monitoring and alarm:
[0094] The system features a built-in real-time monitoring and alarm module, enabling comprehensive oversight of the entire access process. If an anomaly occurs, the system will send a real-time alarm notification to ensure prompt resolution. This feature enhances system stability and reliability.
[0095] 5. Data interaction and integration:
[0096] A rich set of APIs supports data interaction and integration with external systems. The system can retrieve required data from third-party data sources, further enhancing the accuracy and comprehensiveness of admission decisions. The API design ensures efficient and secure data interaction.
[0097] In another embodiment provided by this application, the application case of this application is as follows:
[0098] Use Case 1: New Driver Onboarding. After a new driver submits an application, the system receives the application data through an API and triggers the onboarding process. The rules engine executes rules based on the driver's driving experience, background check, and other criteria, determining in real time whether the driver meets the onboarding requirements. Each node in the process, such as background check and test drive testing, is standardized using the node configuration component. The entire process is presented in a graphical interface within the process configuration component, allowing users to adjust and optimize the process at any time.
[0099] Use Case 2: Existing driver change review: Existing drivers need re-review due to qualification changes or other reasons and submit an information update application. The system calls the rules engine and re-executes the review process based on the new entry requirements. Through standardized processes and node configuration, the review process is efficient and transparent, and can be dynamically adjusted according to business needs.
[0100] This application proposes a highly efficient, flexible, maintainable, and scalable freight driver access system by combining domain-driven design with a rule engine. This system not only dynamically manages complex access rules but also features flexible process configuration and standardized node design to meet the ever-changing business needs of the modern freight industry.
[0101] Through the dynamic management of the rule engine and the standardized design of process configuration components, this application enables the system to quickly respond to changes in business needs. The use of domain-driven design methods and standardized node configuration greatly reduces the complexity of system maintenance, so that changes to business rules do not require modifications to the core code; the highly configurable design of the system enables flexible adjustment of business processes and rules, has good scalability, and can support changes in various business scenarios; standardized process design and node configuration improves the transparency and consistency of the process, reduces human errors, and ensures the reliability and efficiency of system operation.
[0102] Although the present invention depicts operations in a particular order, this should not be understood as requiring that the operations be performed in the particular order shown or in a sequential order. Multitasking and parallel processing may be advantageous under certain circumstances.
[0103] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0104] and Figure 1 Correspondingly, this application provides a freight driver access device, which is used to support Figure 1 The implementation of the method shown, refer to Figure 5 , is a structural diagram of a freight driver access device provided in an embodiment of the present application, and the relevant description is as follows:
[0105] The first obtaining unit 501 is used to obtain the admission application submitted by the freight driver;
[0106] A second obtaining unit 502 is configured to obtain application scenario information from the admission application, and when a preset admission policy aggregation module does not include an admission rule corresponding to the application scenario information, determine each scenario rule corresponding to the application scenario information, and add each scenario rule as an admission rule to a rule set of the admission policy aggregation module;
[0107] The determining unit 503 is configured to obtain an admission policy corresponding to the admission application through a rule set in the admission policy aggregation module, wherein the admission policy includes multiple admission rules;
[0108] The evaluation unit 504 is configured to call a preset rule engine to evaluate each admission rule in the admission strategy to obtain an admission result of the freight driver's admission application.
[0109] In the device provided by the embodiment of the present application, the access application submitted by the freight driver is obtained, and the application scenario information in the access application is obtained. When the preset access policy aggregation module does not include the access rules corresponding to the application scenario information, the various scenario rules corresponding to the application scenario information are determined, and each scenario rule is added as an access rule to the rule set of the access policy collection module; the access policy corresponding to the access application is obtained through the rule set in the access policy aggregation module, and the access policy includes multiple access rules; the preset rule engine is called to evaluate the various access rules in the access policy, and the access result of the freight driver's access application is obtained. The solution provided by the present application can dynamically add access rules, and there is no need to change the system code when adding rules, thereby reducing the cost of access control, and the solution provided by the present application is suitable for access control with changing business needs, improving the flexibility of access control.
[0110] In another embodiment provided by the present application, the second obtaining unit 502 of the device performs the process of determining each scenario rule corresponding to the application scenario information, including:
[0111] Establishing a communication link with a scenario rule system for the application scenario information;
[0112] Various scene rules are obtained from the scene rule system via the communication link.
[0113] In another embodiment provided by the present application, the determination unit 503 of the device executes the process of obtaining the admission policy corresponding to the admission application by using the rule set in the admission policy aggregation module, including:
[0114] Obtaining access domain information from the access application, and determining a service node based on the access domain information;
[0115] Determining, based on the business process of each of the business nodes, an admission rule for each of the business nodes in a rule set of the admission policy aggregation module;
[0116] The admission rules of the service nodes and the admission rules corresponding to the application scenario information in the admission policy aggregation module are applied to generate an admission policy for the admission application.
[0117] In another embodiment provided by the present application, the evaluation unit 504 of the device executes the process of calling the preset rule engine to evaluate each admission rule in the admission policy to obtain the admission result of the freight driver's admission application, including:
[0118] For each of the access rules, calling a preset rule engine to obtain rule information corresponding to the access rule, and applying the rule information to execute the access rule to obtain an execution result of the access rule;
[0119] Based on the execution results of each of the admission rules, the admission result of the freight driver's admission application is obtained.
[0120] In another embodiment provided by the present application, the apparatus further includes: a verification unit;
[0121] The verification unit is configured to verify each admission rule in the admission policy to determine whether there are conflicting admission rules; if there are conflicting admission rules, the conflicting admission rules are deleted from the admission policy.
[0122] In another embodiment provided by the present application, the second obtaining unit 502 of the device executes the process of establishing a communication link with the scenario rule system of the application scenario information, including:
[0123] Establishing a conversation link with the scenario rule system;
[0124] Obtaining environmental information of the scene rule system;
[0125] evaluating an environmental safety level of the scenario rule system based on the environmental information;
[0126] Determining whether to encrypt the session link based on the environmental security level;
[0127] When it is determined that the session link does not need to be encrypted, determining the session link as a communication link;
[0128] When it is determined that the session link needs to be encrypted, the session link is encrypted based on the environmental security level and the communication protocol applied to the session link to obtain an encrypted communication link.
[0129] In another embodiment provided by the present application, the evaluation unit 504 of the device executes the process of obtaining the admission result of the freight driver's admission application based on the execution results of each of the admission rules, including:
[0130] When there is an execution result characterized as unsatisfactory among the execution results, generating an admission result indicating that the admission application of the freight driver is rejected;
[0131] When all the execution results are characterized as satisfied execution results, an admission result indicating approval of the freight driver's admission application is generated.
[0132] An embodiment of the present invention further provides a storage medium, which includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the above-mentioned freight driver access method.
[0133] The embodiment of the present invention further provides an electronic device, the structural diagram of which is shown in FIG. Figure 6 As shown, it specifically includes a memory 601 and one or more instructions 602, wherein one or more instructions 602 are stored in the memory 601 and are configured to be executed by one or more processors 603 to execute the one or more instructions 602 to execute the above-mentioned freight driver access method.
[0134] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of the relevant regions.
[0135] The specific implementation processes and derivative methods of the above embodiments are all within the protection scope of the present invention.
[0136] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without expending creative work.
[0137] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0138] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for admitting freight drivers, characterized in that: include: Obtain access applications submitted by freight drivers; Obtaining application scenario information from the admission application, and when a preset admission policy aggregation module does not include an admission rule corresponding to the application scenario information, determining each scenario rule corresponding to the application scenario information, and adding each scenario rule as an admission rule to a rule set of the admission policy aggregation module; Obtaining an admission policy corresponding to the admission application through a rule set in the admission policy aggregation module, wherein the admission policy includes multiple admission rules; The preset rule engine is called to evaluate each admission rule in the admission strategy to obtain the admission result of the freight driver's admission application.
2. The method according to claim 1, characterized in that The determining of various scenario rules corresponding to the application scenario information includes: Establishing a communication link with a scenario rule system for the application scenario information; Various scene rules are obtained from the scene rule system via the communication link.
3. The method according to claim 1, characterized in that The obtaining, through the rule set in the admission policy aggregation module, an admission policy corresponding to the admission application, includes: Obtaining access domain information from the access application, and determining a service node based on the access domain information; Determining, based on the business process of each of the business nodes, an admission rule for each of the business nodes in a rule set of the admission policy aggregation module; The admission rules of the service nodes and the admission rules corresponding to the application scenario information in the admission policy aggregation module are applied to generate an admission policy for the admission application.
4. The method according to claim 1, wherein The calling of a preset rule engine evaluates each admission rule in the admission strategy to obtain an admission result of the freight driver's admission application, including: For each of the access rules, calling a preset rule engine to obtain rule information corresponding to the access rule, and applying the rule information to execute the access rule to obtain an execution result of the access rule; Based on the execution results of each of the admission rules, the admission result of the freight driver's admission application is obtained.
5. The method according to claim 1, wherein Before executing the call of the preset rule engine to evaluate each admission rule in the admission policy, the method further includes: Verify the admission rules in the admission policy to determine whether there are conflicting admission rules; When there are conflicting admission rules, the conflicting admission rules are deleted from the admission policy.
6. The method according to claim 2, characterized in that The establishing of a communication link with the scenario rule system of the application scenario information includes: Establishing a conversation link with the scenario rule system; Obtaining environmental information of the scene rule system; evaluating an environmental safety level of the scenario rule system based on the environmental information; Determining whether to encrypt the session link based on the environmental security level; When it is determined that the session link does not need to be encrypted, determining the session link as a communication link; When it is determined that the session link needs to be encrypted, the session link is encrypted based on the environmental security level and the communication protocol applied to the session link to obtain an encrypted communication link.
7. The method according to claim 1, characterized in that The obtaining of the admission result of the freight driver's admission application based on the execution results of each of the admission rules includes: When there is an execution result characterized as unsatisfactory among the execution results, generating an admission result indicating that the admission application of the freight driver is rejected; When all the execution results are characterized as satisfied execution results, an admission result indicating approval of the freight driver's admission application is generated.
8. A freight driver access device, characterized in that: include: The first acquisition unit is used to obtain the access application submitted by the freight driver; a second acquisition unit, configured to acquire application scenario information from the admission application, and when a preset admission policy aggregation module does not include an admission rule corresponding to the application scenario information, determine each scenario rule corresponding to the application scenario information, and add each scenario rule as an admission rule to a rule set of the admission policy aggregation module; a determining unit, configured to obtain an admission policy corresponding to the admission application through a rule set in the admission policy aggregation module, wherein the admission policy includes a plurality of admission rules; An evaluation unit is used to call a preset rule engine to evaluate each admission rule in the admission strategy to obtain an admission result of the freight driver's admission application.
9. A storage medium, characterized in that: The storage medium includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the freight driver admission method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: It includes a memory and one or more instructions, wherein the one or more instructions are stored in the memory and are configured to be executed by one or more processors to implement the freight driver access method as described in any one of claims 1-7.