Unified management method and equipment for dynamic permissions of multiple applications and medium

By setting up a unified management gateway and authorization center in multiple application systems, context information is collected in real time and dynamic permission rules are matched, which solves the problem of difficulty in dynamically adjusting permissions in existing technologies, realizes unified permission management of multiple application systems, and improves security and user experience.

CN121283731APending Publication Date: 2026-01-06INSPUR GENERSOFT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511444880.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2026-01-06

AI Technical Summary

Technical Problem

Existing technologies struggle to dynamically adjust permissions in complex scenarios, leading to complex permission management, security vulnerabilities, and a poor user experience.

Method used

By setting up a unified management gateway between multiple applications and user terminals, context information is collected in real time, and dynamic permission rules are matched with user identity information. Dynamic permissions for different applications are configured for user terminals under different access scenarios, and permission management and adjustment are carried out using the authorization center.

Benefits of technology

It achieves unified permission management for multiple application systems, improves the flexibility of user operations within the scope of dynamic permissions, and enhances system security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283731A_ABST
    Figure CN121283731A_ABST
Patent Text Reader

Abstract

The invention provides a unified management method and equipment for dynamic permissions of multiple applications and a medium, and belongs to the technical field of application management. The unified management method comprises the following steps: collecting context information of a user side in real time by using a unified management gateway; the context information is called from the unified management gateway through the authorization center, the context information is combined with the identity information of the user side to match a dynamic permission rule, and dynamic permissions of the user side corresponding to different applications in different access scenes are configured; when the user side logs in, permission information of the user side for any application in the current use scene is requested from the authorization center according to identity information of the user side through the unified management gateway, and the permission information comprises dynamic permission and corresponding permission keeping conditions; and forwarding or rejecting the access request of the user side through the unified management gateway according to the dynamic authority and the authority keeping condition. The problems that in the prior art, an efficient dynamic permission allocation implementation mechanism is lacked, the user experience is poor, and potential safety hazards exist can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of application permission management technology, specifically relating to a unified management method, device and medium for dynamic permissions of multiple applications. Background Technology

[0002] With the rapid development of mobile internet and cloud computing, a single user often needs to install and use multiple applications simultaneously. These applications require access to the user's sensitive information and resources, making access control particularly important.

[0003] Currently, application permission management methods have the following main problems: First, permission management is fragmented: different applications usually have independent permission management mechanisms, which makes permission configuration and management increasingly complex, and users have inconsistent permission experiences across different applications; second, dynamic permissions are insufficient: traditional permission management methods are often static, and users cannot dynamically adjust permissions according to actual needs during use, resulting in excessive or insufficient permissions, which affects the normal use of applications.

[0004] To address the aforementioned issues, existing technologies have proposed several solutions. For example, existing technologies provide a role-based application access control method. This method uses role-based partitioning, detects the user's role when the user logs in, and dynamically assigns permissions based on the user's role.

[0005] While this method can improve flexibility to some extent, it is difficult to dynamically adjust permissions, making it difficult to meet the dynamic permission requirements in complex scenarios. Therefore, in practical applications, there is often a lack of efficient dynamic permission allocation mechanisms, resulting in poor user experience and security risks in applications. Summary of the Invention

[0006] This application aims to provide a unified management method, device, and media solution for dynamic permissions across multiple applications, which can solve the problem that existing technologies are difficult to dynamically adjust permissions, making it difficult to meet the dynamic permission requirements in complex scenarios. Therefore, in practical applications, there is often a lack of efficient dynamic permission allocation mechanisms, resulting in poor user experience and security risks in applications.

[0007] According to a first aspect of this application, this application provides a unified management method for dynamic permissions across multiple applications, comprising: Use a unified management gateway set up between multiple applications and user terminals to collect context information from the user terminals in real time; The authorization center retrieves context information from the unified management gateway, and uses the context information in combination with the user's identity information to match dynamic permission rules, configuring dynamic permissions for different applications for the user in different access scenarios. When a user logs into any of the multiple applications, the unified management gateway requests permission information for the user to access any application in the current usage scenario from the authorization center based on the user's identity information. The permission information includes dynamic permissions and corresponding permission retention conditions. Through a unified management gateway, access requests from users can be forwarded or rejected based on dynamic permissions and permission retention conditions.

[0008] Preferably, in the above unified management method, the steps of forwarding or rejecting user access requests through the unified management gateway according to dynamic permissions and permission retention conditions include: Determine whether the context information collected in real time violates the permission retention conditions; If the context information violates the permission preservation conditions, the user's current access request will be blocked, and the context information will be resent to the authorization center. The authorization center re-matches context information based on dynamic permission rules and updates the permission information of the user client in the current usage scenario. The unified management gateway forwards permission information to any application, enabling any application to run according to the permission information or deny access requests.

[0009] Preferably, in the above unified management method, the steps of forwarding or rejecting user access requests through the unified management gateway according to dynamic permissions and permission retention conditions include: If the context information does not violate dynamic conditions, the unified management gateway will forward the access request to any application; When a request or response message is received from any application, the unified management gateway forwards the request or response message to the user. When a request rejection message is received from any application, the unified management gateway obtains the application permissions corresponding to the request rejection message from any application and forwards it to the authorization center; The authorization center adjusts dynamic permission rules based on application permissions.

[0010] Preferably, in the above unified management method, the step of using a unified management gateway set up between multiple applications and the user terminal to collect the context information of the user terminal in real time includes: Using a unified management gateway, access requests from users are intercepted, and context information is collected in real time. This context information includes access information, network environment information, and user identity information. Using a unified management gateway, context information is sent to the authorization center to obtain the corresponding permission information from the authorization center.

[0011] Preferably, in the above unified management method, the steps of retrieving context information from the unified management gateway through the authorization center, using the context information in combination with the user's identity information to match dynamic permission rules, and configuring dynamic permissions for different applications corresponding to different access scenarios for the user include: Through the authorization center, you can set the permission requirements for each application in different access scenarios across multiple applications. Through the authorization center, you can set the permission requirements corresponding to different context information and identity information; Obtain the permission requirements of each application within multiple applications through the authorization center; Through the authorization center, dynamic permission rules are defined based on the permission requirements of each application in different access scenarios, the permission requirements corresponding to context information and identity information, and the permission requirements of each application itself. By combining contextual information with the user's identity information to match dynamic permission rules, dynamic permissions for different applications can be configured for the user in different access scenarios.

[0012] Preferably, in the above unified management method, the step of requesting permission information for any application by the user terminal from the authorization center based on the user terminal's identity information through the unified management gateway, wherein the permission information includes dynamic permissions and corresponding permission retention conditions, includes: The unified management gateway intercepts user access requests and matches them to obtain the corresponding accessed application and the current usage scenario. The unified management gateway combines the user's identity information with the accessed application and the current usage scenario to request the authorization center for the user's permission information for the accessed application in the current usage scenario. The authorization center matches identity information and, based on the dynamic permissions configured for different applications in different access scenarios, sends the user's permission information for the accessed application in the current usage scenario to the unified management gateway.

[0013] Preferably, in the above unified management method, the step of the authorization center matching identity information and, based on the configured dynamic permissions of the user terminal for different applications in different access scenarios, issuing the user terminal's permission information for the accessed application in the current usage scenario to the unified management gateway includes: The authorization center uses the current usage scenario and context information to match dynamic permission rules and configure the permission retention conditions for the accessed application; The conditions for maintaining permissions and dynamic permissions are packaged into permission information and sent to the unified management gateway.

[0014] According to a second aspect of this application, this application also provides a unified management device for dynamic permissions across multiple applications, comprising: Unified management gateway and authorization center; among which, A unified management gateway is set up between multiple applications and user terminals to collect context information from user terminals in real time. The authorization center is used to retrieve context information from the unified management gateway, use the context information in combination with the user's identity information to match dynamic permission rules, and configure dynamic permissions for different applications for the user in different access scenarios. The unified management gateway is also used to request permission information for any application in the current usage scenario from the authorization center when a user logs into any application of multiple applications, based on the user's identity information. The permission information includes dynamic permissions and corresponding permission retention conditions. The unified management gateway is also used to forward or deny user access requests based on dynamic permissions and permission retention conditions.

[0015] According to a third aspect of this application, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the unified management method for dynamic permissions of multiple applications provided by any of the above technical solutions.

[0016] According to a fourth aspect of this application, this application also provides a computer storage medium storing a computer program thereon, which, when executed, implements the unified management method for dynamic permissions of multiple applications provided by any of the above technical solutions.

[0017] The technical solution of this application has at least the following technical effects: The unified management solution for dynamic permissions across multiple applications provided in this application collects contextual information from the user terminal in real time through a unified management gateway between the multiple applications and the user terminal. This allows the authorization center to use this contextual information, combined with the user terminal's identity information, to match dynamic permission rules and configure dynamic permissions for different applications in different access scenarios, thus achieving unified permission management for multiple applications. When a user terminal logs into any of the multiple applications, the unified management gateway requests permission information for that application from the authorization center based on the user terminal's identity information. This permission information includes the dynamic permissions and corresponding permission retention conditions. The general management gateway can then forward or reject the user terminal's access request according to these dynamic permissions and permission retention conditions. Through this unified management method for dynamic permissions across multiple applications, the user terminal can operate flexibly within the scope of dynamic permissions, improving the security and user experience of the multi-application system. In summary, this method solves the problem of existing technologies struggling to dynamically adjust permissions, making it difficult to meet the dynamic permission requirements in complex scenarios. Therefore, in practical applications, there is often a lack of efficient dynamic permission allocation mechanisms, leading to poor user experience and security vulnerabilities. Attached Figure Description

[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 A flowchart illustrating the first unified management method for dynamic permissions across multiple applications provided in this application embodiment; Figure 2 for Figure 1 The illustrated embodiment provides a flowchart of a method for real-time collection of context information; Figure 3 for Figure 1 The illustrated embodiment provides a flowchart of a dynamic permission configuration method; Figure 4 for Figure 1 The illustrated embodiment provides a flowchart of a method for requesting permission information; Figure 5 for Figure 1 The illustrated embodiment provides a flowchart of a method for forwarding or denying access requests; Figure 6 A flowchart illustrating the second unified management method for dynamic permissions across multiple applications provided in this application embodiment; Figure 7 A flowchart illustrating a unified management device for dynamic permissions across multiple applications, provided as an embodiment of this application; Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0019] To more clearly illustrate the overall concept of this application, a detailed explanation is provided below with reference to the accompanying drawings.

[0020] Many specific details are set forth in the following description to provide a thorough understanding of this application. However, this application may also be implemented in other ways different from those described herein. Therefore, the scope of protection of this application is not limited to the specific embodiments disclosed below. It should be noted that, unless otherwise specified, the embodiments of this application and the features thereof can be combined with each other.

[0021] In this application, unless otherwise expressly specified and limited, the terms "above" and "below" the second feature can refer to direct contact between the first and second features, or indirect contact between the first and second features through an intermediate medium. In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described can be combined in any suitable manner in one or more embodiments or examples.

[0022] The existing technology has the following drawbacks: Existing role-based application access control methods employ role-based classification, detecting the user's role upon login and dynamically assigning permissions accordingly. While this method improves flexibility to some extent, it struggles to dynamically adjust permissions, making it difficult to meet the dynamic permission requirements of complex scenarios. Consequently, in practical applications, there is often a lack of efficient dynamic permission allocation mechanisms, resulting in poor user experience and security vulnerabilities.

[0023] To overcome the aforementioned technical challenges, the following embodiments of this application provide a unified management scheme for dynamic permissions across multiple applications, such as... Figure 7As shown, the unified management system corresponding to this unified management solution includes at least two major modules: a unified management gateway and an authorization center. The unified management gateway is located at the application front-end and is responsible for intercepting user requests and collecting context information; checking whether the context information is within the dynamic permission maintenance conditions; and requesting new permissions and dynamic permission maintenance conditions from the authorization center when permissions are unavailable or exceeded. The authorization center is responsible for converting user identity information and the user's context information into user permission information based on the administrator's dynamic permission rules. Through these two modules, the user's context information can be obtained in real time, and combined with the user's configured dynamic permission rules, unified permission management for multiple applications is achieved. This unified permission management across multiple applications allows users to operate flexibly within the scope of dynamic permissions, thereby improving the overall system security and user experience.

[0024] To achieve the above objectives, see [link to relevant documentation]. Figure 1 , Figure 1 A flowchart illustrating a unified management method for dynamic permissions across multiple applications provided in this application embodiment is shown below. Figure 1 As shown, this unified management method for dynamic permissions across multiple applications includes: S110: Uses a unified management gateway configured between multiple applications and user terminals to collect context information from user terminals in real time.

[0025] In this application embodiment, a unified management gateway is added before the application, which is responsible for collecting context information from the user terminal in real time (such as time, location, and network environment).

[0026] Specifically, as a preferred embodiment, such as Figure 2 As shown, S110: the step of collecting context information from the user terminal in real time using a unified management gateway set up between multiple applications and the user terminal, includes: S111: Use a unified management gateway to intercept user access requests and collect context information in real time, including access information, network environment information, and user identity information.

[0027] S112: Use the unified management gateway to send the context information to the authorization center in order to obtain the permission information corresponding to the context information from the authorization center.

[0028] The technical solution provided in this application first deploys a gateway at the application front-end, responsible for intercepting user requests and collecting context information. This context information includes access information, network environment information, and user identity information. Specifically, this context information includes, but is not limited to: current time (e.g., weekdays and non-weekdays), user geographic location (e.g., IP address and GPS location), network environment (e.g., company network and public Wi-Fi), and user device information (e.g., device type, operating system, and browser type). After collecting the context information, the unified management gateway sends it to the authorization center to obtain the corresponding permission information. This method enables the verification of user access requests using the corresponding permission information.

[0029] Figure 1 The unified management method for dynamic permissions across multiple applications provided in the illustrated embodiment further includes, after the step of collecting context information from the user terminal in real time using a unified management gateway set up between the multiple applications and the user terminal: S120: Retrieves context information from the unified management gateway through the authorization center, uses the context information in combination with the user's identity information to match dynamic permission rules, and configures dynamic permissions for different applications for the user in different access scenarios.

[0030] The authorization center is responsible for converting user identity information and client context information into user permission information based on the administrator's dynamic permission rules. This requires the administrator to configure dynamic permission rules.

[0031] Specifically, as a preferred embodiment, such as Figure 3 As shown, step S120 above involves retrieving context information from the unified management gateway through the authorization center, using the context information in conjunction with the user's identity information to match dynamic permission rules, and configuring dynamic permissions for different applications on the user's end under different access scenarios. Specifically, this includes: S121: Through the authorization center, set the permission requirements for each application in multiple applications for different access scenarios.

[0032] S122: Through the authorization center, set the permission requirements corresponding to different context information and identity information.

[0033] S123: Obtain the permission requirements of each application within multiple applications through the authorization center.

[0034] S124: Through the authorization center, define dynamic permission rules based on the permission requirements of each application in different access scenarios, the permission requirements corresponding to context information and identity information, and the permission requirements of each application itself.

[0035] S125: Use context information combined with the user's identity information to match dynamic permission rules and configure dynamic permissions for different applications for the user in different access scenarios.

[0036] In the authorization center, administrators can configure dynamic permission rules through the permission management interface, thereby defining the permission requirements for each application in different access scenarios across the multiple applications. Example rule: Within the company network, access to sensitive data is allowed; outside of working hours, access to specific functions is restricted. Additionally, the authorization center allows setting permission requirements corresponding to different context information and identity information; and by connecting with multiple applications, it can obtain the permission requirements of each application itself. Through the authorization center, based on the permission requirements of each application in different access scenarios, the permission requirements corresponding to context information and identity information, and the application's own permission requirements, the aforementioned dynamic permission rules can be defined. Subsequently, after obtaining the user's access scenario, accessed application, and identity information, the unified management gateway can assign dynamic permissions to that user according to the aforementioned dynamic permission rules.

[0037] Figure 1 The unified management method for dynamic permissions of multiple applications provided in the illustrated embodiment, after step S120: retrieving context information from the unified management gateway through the authorization center, using the context information combined with the user's identity information to match dynamic permission rules, and configuring the dynamic permissions of the user for different applications in different access scenarios, further includes: S130: When a user logs into any of the multiple applications, the unified management gateway requests permission information for the user to access any application in the current usage scenario from the authorization center based on the user's identity information. The permission information includes dynamic permissions and corresponding permission retention conditions.

[0038] When a user logs into an application, the system can obtain the user's current usage scenario and the applications the user is accessing. The dynamic permission rules mentioned above are defined based on the permission requirements of each application in different access scenarios, the permission requirements corresponding to context information and identity information, and the permission requirements of each application itself. Therefore, given that the user's identity information and context information are already known, the authorization center can clearly know the user's permission information for any of the above applications in the current usage scenario by using the current usage scenario and the accessed applications, and send it to the unified management gateway.

[0039] Specifically, as a preferred embodiment, such as Figure 4 As shown, step S130 involves requesting permission information for any application from the authorization center based on the user's identity information via the unified management gateway. This permission information includes dynamic permissions and corresponding permission retention conditions, specifically including: S131: The unified management gateway intercepts user access requests and matches them to obtain the corresponding accessed application and the current usage scenario.

[0040] S132: The unified management gateway combines the user's identity information with the accessed application and the current usage scenario to request the authorization center for the user's permission information for the accessed application in the current usage scenario.

[0041] S133: The authorization center matches identity information and, based on the dynamic permissions of the user terminal corresponding to different applications in different access scenarios, sends the user terminal's permission information for the accessed application in the current usage scenario to the unified management gateway.

[0042] The technical solution provided in this application embodiment requires the unified management gateway to perform permission checks and allocations after intercepting access requests from users. Specifically, regarding permission checks: the unified management gateway checks whether the user already has permission information. If not, the unified management gateway requests permissions from the authorization center. Regarding permission allocation: the authorization center assigns permissions to the user based on the user's identity and dynamic permission rules, and returns the assignment to the gateway. Simultaneously, dynamic permission retention conditions are set, for example: IP address in the company network segment, userAgent = company APP agent.

[0043] In one preferred embodiment, step S133 involves the authorization center matching identity information and, based on the configured dynamic permissions of the user terminal for different applications in different access scenarios, sending the user terminal's permission information for the accessed application in the current usage scenario to the unified management gateway. This specifically includes: The authorization center uses the current usage scenario and context information to match dynamic permission rules and configure the permission retention conditions for the accessed application. The permission retention conditions and dynamic permissions are then packaged into permission information and sent to the unified management gateway.

[0044] The technical solution provided in this application requires the unified management gateway to monitor context information in real time. Specifically, the unified management gateway continuously monitors the user's context information; once it detects that the context information exceeds the dynamic permission retention conditions corresponding to the current permissions, it immediately blocks the request. The changed information (such as a new IP address and time) is then submitted to the authorization center.

[0045] Figure 1 The unified management method for dynamic permissions across multiple applications provided in the illustrated embodiment, after step S130: when a user logs into any application of the multiple applications, the unified management gateway requests permission information for the user's current usage scenario from the authorization center based on the user's identity information, the method further includes: S140: Through a unified management gateway, forward or deny user access requests according to dynamic permissions and permission retention conditions.

[0046] Specifically, the authorization center assigns new permissions to the user based on the new context information; the triggering conditions are as follows: new dynamic permission triggering conditions are generated to ensure real-time updates of user permissions.

[0047] As a preferred embodiment, such as Figure 5 As shown, step S140 above, which involves forwarding or rejecting user access requests through a unified management gateway based on dynamic permissions and permission retention conditions, includes: S141: Determine whether the context information collected in real time violates the permission retention conditions.

[0048] S142: If the context information violates the permission preservation conditions, then block the current access request from the user and resend the context information to the authorization center.

[0049] S143: The authorization center re-matches the context information according to the dynamic permission rules and updates the permission information of the user terminal in the current usage scenario.

[0050] S144: The unified management gateway forwards permission information to any application, so that any application can run according to the permission information or deny access requests.

[0051] In the technical solution provided in this application embodiment, the unified management gateway is responsible for checking whether the context information is within the dynamic permission retention conditions; when there is no permission or the dynamic permission retention conditions are exceeded, it requests new permissions and dynamic permission retention conditions from the authorization center. Once it is found that the context information exceeds the range corresponding to the current permission's dynamic permission retention conditions, the access request from the user terminal is immediately blocked, and the change information is submitted to the permission center.

[0052] In addition, as a preferred embodiment, step S140 above, which involves forwarding or rejecting user access requests through a unified management gateway according to dynamic permissions and permission retention conditions, specifically includes: If the context information does not violate dynamic conditions, the unified management gateway will forward the access request to any application.

[0053] When a request or response message is received from any application, the unified management gateway forwards the request or response message to the user.

[0054] When a request rejection message is received from any application, the unified management gateway obtains the application permissions corresponding to the request rejection message from any application and forwards it to the authorization center; The authorization center adjusts dynamic permission rules based on application permissions.

[0055] In the technical solution provided in this application embodiment, the permission center can assign new permissions to users based on new context information and generate new dynamic permission triggering conditions to ensure real-time updates of user permissions. The dynamic permission rules include the valid scope of the context information, such as specific IP ranges and user agents. Furthermore, if the authorization center has already authorized the user client to access the application, but the application still denies the access request, the unified management gateway will forward the application's request denial information to the authorization center to investigate the reason for the application's denial. If the application's access permissions are not met, the dynamic permission rules will be adjusted based on the application's permissions. The method for adjusting the dynamic permission rules is described in [link to relevant documentation]. Figure 4 This will not be elaborated upon here.

[0056] In summary, the unified management method for dynamic permissions across multiple applications provided in this application uses a unified management gateway between the multiple applications and the user terminal to collect the user terminal's context information in real time. This allows the authorization center to use this context information, combined with the user terminal's identity information, to match dynamic permission rules and configure dynamic permissions for different applications in different access scenarios, thus achieving unified permission management for multiple applications. When a user terminal logs into any of the multiple applications, the unified management gateway requests permission information for that application from the authorization center based on the user terminal's identity information. This permission information includes the dynamic permissions and corresponding permission retention conditions. The general management gateway can then forward or reject the user terminal's access request according to these dynamic permissions and permission retention conditions. Through this unified management method for dynamic permissions across multiple applications, the user terminal can operate flexibly within the scope of dynamic permissions, improving the security and user experience of the multi-application system. In conclusion, this method solves the problem of existing technologies struggling to dynamically adjust permissions, making it difficult to meet the dynamic permission requirements in complex scenarios. Therefore, in practical applications, there is often a lack of efficient dynamic permission allocation mechanisms, leading to poor user experience and security vulnerabilities in applications.

[0057] Additionally, see Figure 6 , Figure 6 This is a flowchart illustrating a second method for unified management of dynamic permissions across multiple applications, provided in an embodiment of this application. Figure 6 As shown, this unified management method for dynamic permissions across multiple applications includes: S210: The user sends a request.

[0058] S220: Unified Management Gateway collects context information.

[0059] S230: The unified management gateway checks whether it has obtained the permission information; if yes, proceed to step S240; if no, proceed to step S250.

[0060] S240: Check if the dynamic permission retention conditions have been exceeded; if yes, proceed to step S2110; if no, proceed to step S250.

[0061] S250: Block the request and forward the context information, which is forwarded by the unified management gateway to the authorization center.

[0062] S260: The authorization center generates dynamic permissions that match the context information. Execute steps S270 and S290 respectively.

[0063] S270: The authorization center generates dynamic permission retention conditions.

[0064] S280: Gateway dynamic permission retention condition update S290: Application permission update.

[0065] S2110: The application processes this request.

[0066] Furthermore, the beneficial effects of the product embodiments provided in the following embodiments of this application are the same as the beneficial effects of the unified management method for dynamic permissions of multiple applications provided in the above embodiments, and other technical features in the product embodiments are the same as the features disclosed in the methods of the above embodiments, and will not be repeated here.

[0067] See Figure 7 This application also provides a unified management device for dynamic permissions across multiple applications, including: Unified management gateway 110 and authorization center 120; among which, The unified management gateway 110 is set up between multiple applications and user terminals to collect context information from user terminals in real time. The authorization center 120 is used to retrieve context information from the unified management gateway 110, use the context information in combination with the user's identity information to match dynamic permission rules, and configure the dynamic permissions of the user for different applications in different access scenarios. The unified management gateway 110 is also used to request permission information of the user terminal for any application in the current usage scenario from the authorization center 120 when the user terminal logs into any application of multiple applications, based on the user terminal's identity information. The permission information includes dynamic permissions and corresponding permission retention conditions. The unified management gateway 110 is also used to forward or reject user access requests based on dynamic permissions and permission retention conditions.

[0068] In addition, as a preferred embodiment, Figure 7In the unified management device shown, 1. If the user client lacks permissions or the context changes exceed the dynamic permission retention conditions, 2. the unified management gateway 110 blocks the request and requests new permission information. 3. The authorization center 120 returns the new dynamic permissions and dynamic permission retention conditions to the unified management gateway 110 based on the user's identity information and context information. 4. The unified management gateway 110 forwards the new permission information and request to the application. 5. The application rejects the request or returns a normal response based on the new permission information. 6. The user receives the request return result.

[0069] See below. Figure 8 , Figure 8 An electronic device provided in this application includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the unified management method for dynamic permissions of multiple applications provided in any of the above embodiments.

[0070] The following is for reference. Figure 8 The diagram illustrates a structural schematic of an electronic device suitable for implementing embodiments of this application. The electronic devices in the embodiments of this application may include, but are not limited to, mobile terminals and / or fixed terminals. Figure 8 The device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0071] like Figure 8 As shown, the electronic device can include a processing unit 1001, such as a central processing unit and / or a graphics processing unit, which can perform various appropriate actions and processes according to a program stored in ROM 1002 or a program loaded from storage device 1003 into RAM 1004. RAM 1004 also stores various programs and data required for the operation of the electronic device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. Input / output interface 1006 is also connected to bus 1005. Typically, the following systems can be connected to input / output interface 1006: input devices 1007, such as touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, and / or gyroscopes; output devices 1008, such as liquid crystal displays (LCDs), speakers, and / or vibrators; storage devices 1003, such as magnetic tape and / or hard disks; and communication devices 1009. Communication device 1009 is capable of enabling the electronic device to exchange data with other devices wirelessly or via wired communication. Although the diagram shows a model building device with various systems, it should be understood that it is not required to implement or have all of the systems shown. It is possible to implement or have more or fewer systems alternatively.

[0072] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0073] This application provides a computer-readable storage medium having computer-readable program instructions stored thereon, namely the computer program described above, which is used to perform the methods in the above embodiments. The computer-readable storage medium carries one or more programs that, when executed by a model-building device, can be used to write computer program code for performing the operations of this application in one or more programming languages ​​or combinations thereof. The programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, or C++—and conventional procedural programming languages—such as the "C" language or similar programming languages.

[0074] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram can represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.

[0075] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0076] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

[0077] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for unified management of multi-application dynamic permissions, characterized in that, The application comprises the following steps: Collecting context information of a user terminal in real time by using a unified management gateway arranged between a plurality of applications and the user terminal; Obtaining the context information from the unified management gateway by an authorization center, matching dynamic permission rules by using the context information in combination with identity information of the user terminal, and configuring dynamic permissions of the user terminal corresponding to different applications in different access scenarios; When the user terminal logs in any application of the plurality of applications, requesting permission information of the user terminal for the any application in a current use scenario from the authorization center according to the identity information of the user terminal by the unified management gateway, wherein the permission information comprises the dynamic permissions and corresponding permission maintaining conditions; Forwarding or rejecting an access request of the user terminal according to the dynamic permissions and the permission maintaining conditions by the unified management gateway.

2. The method of claim 1, wherein, The step of forwarding or rejecting the access request of the user terminal according to the dynamic permissions and the permission maintaining conditions by the unified management gateway comprises: Judging whether the collected context information in real time violates the dynamic permission maintaining conditions; If the context information violates the permission maintaining conditions, blocking the current access request of the user terminal and re-sending the context information to the authorization center; Updating the corresponding permission information of the user terminal in the current use scenario by re-matching the context information according to the dynamic permission rules by the authorization center; The unified management gateway forwards the permission information to the any application, so that the any application operates according to the permission information or rejects the access request.

3. The method of claim 2, wherein, The step of forwarding or rejecting the access request of the user terminal according to the dynamic permissions and the permission maintaining conditions by the unified management gateway comprises: If the context information does not violate the dynamic conditions, the unified management gateway forwards the access request to the any application; When receiving a request response information of the any application, the unified management gateway forwards the request response information to the user terminal; When receiving request rejection information of the any application, the unified management gateway obtains application permissions corresponding to the request rejection information from the any application and forwards the application permissions to the authorization center; The authorization center adjusts the dynamic permission rules according to the application permissions.

4. The method of claim 1, wherein, The step of collecting context information of a user terminal in real time by using a unified management gateway arranged between a plurality of applications and the user terminal comprises: Intercepting an access request of the user terminal by using the unified management gateway and collecting the context information in real time, wherein the context information comprises access information, network environment information and identity information of the user terminal; Sending the context information to the authorization center by using the unified management gateway to obtain permission information corresponding to the context information from the authorization center.

5. The method of claim 1, wherein, The step of obtaining the context information from the unified management gateway by an authorization center, matching dynamic permission rules by using the context information in combination with identity information of the user terminal, and configuring dynamic permissions of the user terminal corresponding to different applications in different access scenarios comprises: The authorization center is configured to set the permission requirements of each application in the plurality of applications in different access scenarios respectively; The authorization center is configured to set the permission requirements corresponding to different context information and identity information; The authorization center is configured to obtain the permission requirements of each application in the plurality of applications itself; The authorization center is configured to define the dynamic permission rules according to the permission requirements of each application in different access scenarios, the permission requirements corresponding to the context information and the identity information, and the permission requirements of each application itself; The context information is used to match the dynamic permission rules in combination with the identity information of the user terminal, and the dynamic permissions of the user terminal corresponding to different applications in different access scenarios are configured.

6. The method of claim 1 or 5, wherein, The unified management gateway is configured to request the authorization center for the permission information of the user terminal to any application in the current use scenario according to the identity information of the user terminal, wherein the permission information includes the dynamic permission and the corresponding permission retention condition. The unified management gateway intercepts the access request of the user terminal, and matches the access request to obtain the corresponding accessed application and the current use scenario. The unified management gateway requests the authorization center for the permission information of the user terminal to the accessed application in the current use scenario in combination with the identity information of the user terminal, the accessed application and the current use scenario. The authorization center matches the identity information, and according to the configured dynamic permissions of the user terminal corresponding to different applications in different access scenarios, the unified management gateway is configured to issue the permission information of the user terminal to the accessed application in the current use scenario.

7. The method of claim 6, wherein, The authorization center matches the identity information, and according to the configured dynamic permissions of the user terminal corresponding to different applications in different access scenarios, the unified management gateway is configured to issue the permission information of the user terminal to the accessed application in the current use scenario. The authorization center uses the current use scenario and the context information to match the dynamic permission rules, and configures the permission retention condition of the accessed application. The permission retention condition and the dynamic permission are packaged into the permission information and issued to the unified management gateway. 8.A device for unified management of multi-application dynamic permissions, characterized in that, It includes: A unified management gateway and an authorization center; wherein The unified management gateway is arranged between the plurality of applications and the user terminal, and is configured to collect the context information of the user terminal in real time; The authorization center is configured to call the context information from the unified management gateway, match the dynamic permission rules in combination with the identity information of the user terminal using the context information, and configure the dynamic permissions of the user terminal corresponding to different applications in different access scenarios; The unified management gateway is further configured to request the authorization center for the permission information of the user terminal to any application in the current use scenario according to the identity information of the user terminal when the user terminal logs in any application of the plurality of applications, wherein the permission information includes the dynamic permission and the corresponding permission retention condition. The unified management gateway is further configured to forward or reject the access request of the user terminal according to the dynamic permission and the permission maintenance condition.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the method for unified management of dynamic permissions of multiple applications according to any one of claims 1 to 7 when executing the program.

10. A computer storage medium having stored thereon a computer program, characterized in that The computer program implements the method for unified management of dynamic permissions of multiple applications according to any one of claims 1 to 7 when being executed.

Citation Information

Patent Citations

  • User privilege management method, system and device and computer readable storage medium

    CN109286620A

  • Data access authentication method and device, authentication equipment and authentication system

    CN112738100A