A business access control method, electronic device, storage medium, and program

CN122741118APending Publication Date: 2026-09-11INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610789442.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-03
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

但每次操作都需要重新进行身份认证,且认证结果不能在其他渠道复用

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122741118A_ABST
    Figure CN122741118A_ABST
Patent Text Reader

Abstract

This invention discloses a business access management method, electronic device, storage medium, and program, relating to data security, computer software applications, and financial technology fields. The business access management method includes: responding to a current business association request initiated by a current user terminal, initiating a user authentication request for the current user terminal; generating a current session identifier for the current user if the user authentication is successful; and performing authentication-free processing on the associated target business of the current user based on the current session identifier. The technical solution of this invention can improve the efficiency of business access management, thereby improving business processing efficiency and user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the fields of data security, computer software applications, and financial technology, and particularly to a business access management method, device, electronic device, storage medium, and program. Background Technology

[0002] Currently, identity authentication processes are typically involved in various business scenarios, such as single-channel and multi-channel business scenarios.

[0003] In single-channel business scenarios, the same application or service may involve multiple business operations, and these operations may require repeated identity authentication. In multi-channel business scenarios, the identity authentication result of a single channel cannot be reused in other channels. For example, a user authenticates their identity through a mobile banking app, such as entering a password, fingerprint recognition, or facial recognition. After successful authentication, the user can perform various banking operations within the app, such as transferring funds or checking balances. However, each operation requires re-authentication, and the authentication result cannot be reused in other channels such as counter systems or self-service devices. Similarly, a user authenticates their identity through a counter system, such as entering customer information and verifying documents. After successful authentication, the teller can process various banking transactions for the customer. However, each time the customer conducts business through a different channel, such as mobile banking or self-service devices, identity authentication needs to be repeated. Likewise, a user authenticates their identity through a self-service device, such as entering a password and inserting a bank card. After successful authentication, the user can perform operations such as withdrawing and depositing cash on the device. However, each operation requires re-authentication, and the authentication result cannot be reused in other channels.

[0004] In the process of realizing this invention, the inventors discovered the following defects in the prior art: For business scenarios involving multi-channel collaborative processing, users repeatedly perform authentication operations on different channels or different operations on the same channel, resulting in fragmented user permissions. The authentication mechanisms of different terminals are independent and cannot be reused, leading to low business processing efficiency and poor user experience. Summary of the Invention

[0005] This invention provides a business access management method, apparatus, electronic device, storage medium, and program, which can improve the efficiency of business access management, thereby improving business processing efficiency and user experience.

[0006] According to one aspect of the present invention, a business access control method is provided, comprising: In response to a current service association request initiated by the current user terminal, a user authentication request is initiated for the current user terminal; If user authentication is successful, a current session identifier for the current user is generated; Based on the current session identifier of the current user, the associated target service of the current user is processed without authentication.

[0007] According to another aspect of the present invention, a business access management device is provided, comprising: The identity authentication request initiation module is used to initiate a user identity authentication request to the current user terminal in response to the current business association request initiated by the current user terminal. The current session identifier generation module is used to generate the current session identifier for the current user after confirming that the user's identity authentication has been successful. The business authentication-free processing module is used to perform authentication-free processing on the associated target business of the current user based on the current session identifier of the current user.

[0008] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and a memory communicatively connected to said at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which is then executed by the at least one processor to enable the at least one processor to perform the business access management method according to any embodiment of the present invention.

[0009] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the business access control method described in any embodiment of the present invention.

[0010] According to another aspect of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the business access management method described in any embodiment of the present invention.

[0011] This invention, in response to a current service association request initiated by a current user terminal, initiates a user authentication request to the current user terminal. If the user authentication is successful, a current session identifier for the current user is generated. Then, based on this current session identifier, authentication-free processing is performed on the associated target service for the current user. This service permission management method addresses the problems of permission fragmentation and non-reusability in existing permission management methods, improving the efficiency of service permission management, thereby enhancing service processing efficiency and user experience.

[0012] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a flowchart of a business access control method provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of a business access control method provided in Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of a business access control device provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation

[0015] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0016] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0017] Example 1 Figure 1This is a flowchart of a business access control method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where user-related services can be quickly processed without authentication using session identifiers generated based on identity authentication information. This method can be executed by a business access control device, which can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can execute the business access control method. The present invention does not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations: S110. In response to the current service association request initiated by the current user terminal, initiate a user identity authentication request for the current user terminal.

[0018] Here, "current user terminal" can be the user terminal that needs to process the service. For example, "current user terminal" could be the current user's mobile device (App). "Current service-related request" can be a service-related request initiated by the current user based on their current user terminal. "User authentication request" can be a request used to authenticate the current user's identity.

[0019] In this embodiment of the invention, the current user can initiate a service-related request for a specific business through a relevant app running on the current user's terminal. For example, in a banking service scenario, the current user can initiate a request to process a certain service through a mobile banking app; in a hospital visit service scenario, the current user can initiate a request for registration or payment through a medical app or mini-program on their mobile phone. Correspondingly, after receiving the service-related request initiated by the current user's terminal, the backend system can first initiate a user identity authentication request for the current user's terminal. Optionally, the backend system can use various optional identity authentication methods to authenticate the user's identity, such as biometric authentication or SMS authentication. This embodiment of the invention does not limit the identity authentication method used in the user identity authentication request. The current user can perform identity authentication on the current user's terminal in response to the user identity authentication request initiated by the backend system.

[0020] S120. If the user's identity authentication is successful, generate the current session identifier for the current user.

[0021] The current session identifier can be used to verify the current user's permission status.

[0022] After receiving the authentication information from the current user, the backend system can confirm whether the user's identity authentication has passed. If the user's identity authentication fails, the backend system can provide a failure notification. If the user's identity authentication passes, the backend system can generate a permission session based on the current authentication result through the permission session management service. This permission session can include the current user's identity authentication information and current permission level. Optionally, the current permission level can be determined based on the priority of the business involved in the current business-related request. The permission session generated by the backend system can be written into the backend system's permission session management service so that subsequent business operations can access and use it.

[0023] Optionally, the backend system's permission session management service can be used to manage the lifecycle of permission sessions, including their creation, use, upgrade, and expiration. Correspondingly, the backend system can use the permission session management service to generate a session ID based on the permission session, which is then fed back to the current user as the current session identifier.

[0024] S130. Based on the current session identifier of the current user, perform authentication-free processing on the associated target service of the current user.

[0025] Among them, the associated target business can be a business related to the current business associated request, the business itself that the current business associated request is processing, or a subsequent business related to the current business associated request, etc.

[0026] The current user's current session identifier can be used in subsequent business operations to verify the current user's permission status, thereby enabling authentication-free processing of the current user's associated target business and avoiding repeated authentication operations in subsequent associated target businesses. For example, when processing the current user's associated target business, the current user's authentication result and current permissions can be directly determined based on the current session identifier, allowing for rapid processing of the associated target business without repeated authentication.

[0027] Therefore, it is evident that during the business transaction process, users only need to undergo identity authentication once to generate a session identifier with authorized information, enabling subsequent related transactions to proceed without further authentication. The entire transaction process ensures that user authentication information is securely managed and used, while providing the necessary authorization support for subsequent business operations.

[0028] This invention, in response to a current service association request initiated by a current user terminal, initiates a user authentication request to the current user terminal. If the user authentication is successful, a current session identifier for the current user is generated. Then, based on this current session identifier, authentication-free processing is performed on the associated target service for the current user. This service permission management method addresses the problems of permission fragmentation and non-reusability in existing permission management methods, improving the efficiency of service permission management, thereby enhancing service processing efficiency and user experience.

[0029] Example 2 Figure 2 This is a flowchart of a business access control method provided in Embodiment 2 of the present invention. This embodiment is based on the above embodiment and is further specified. In this embodiment, several specific optional implementation methods are given for initiating a user authentication request for the current user terminal and performing authentication-free processing on the associated target business of the current user. Accordingly, as Figure 2 As shown, the method in this embodiment may include: S210. In response to the current service association request initiated by the current user terminal, initiate a user identity authentication request for the current user terminal.

[0030] In an optional embodiment of the present invention, the step of initiating a user authentication request to the current user terminal in response to a current service association request initiated by the current user terminal may include: in response to a first current service association request initiated by the current user terminal, determining a target authentication method based on the service type corresponding to the first current service association request; and initiating the user authentication request to the current user terminal based on the target authentication method.

[0031] Among them, the first current business-related request can be a type of business request initiated by the current user based on the current user terminal, or it can be a default form of business request triggered by the user to process the business.

[0032] Optionally, if the current user initiates a first current business-related request based on their current terminal without carrying any additional information—that is, triggering a default business request using standard operations—the backend system can determine the appropriate target authentication method based on the business type triggered by the first current business-related request. For example, if the current user triggers a login request for an app based on their current terminal, the backend system can determine that username and password are the target authentication method; if the current user triggers a transfer request for a bank app based on their current terminal, the backend system can determine that facial recognition is the target authentication method, and so on. It is understandable that lower-risk business types can have lower authentication levels, while higher-risk business types can have higher authentication levels. Therefore, determining the appropriate target authentication method based on the business type improves the flexibility and security of identity authentication.

[0033] In an optional embodiment of the present invention, the step of initiating a user authentication request to the current user terminal in response to a current service association request initiated by the current user terminal may include: in response to a second current service association request initiated by the current user terminal, determining an initial authentication method and obtaining authentication upgrade information based on the second current service association request; upgrading the initial authentication method according to the authentication upgrade information to obtain a target authentication method; and initiating the user authentication request to the current user terminal according to the target authentication method.

[0034] The second current business-related request can be another type of business request initiated by the current user based on the current user's terminal. The initial authentication method can be the authentication method initially determined by the backend system. Authentication upgrade information can be used to upgrade the initial authentication method to improve its level. It is understood that the higher the level of the authentication method, the higher the security of the authentication result.

[0035] Optionally, when triggering a business request, the current user can also include additional information in the request. That is, the current user can initiate a second current business-related request with additional information based on their current terminal, i.e., using unconventional operations to trigger the business request. For example, when a user triggers a transfer request, their terminal can simultaneously display an option to upgrade the authentication method in the transfer request display interface. The current user can simultaneously select the option to upgrade the authentication method while triggering the transfer request, ensuring that the second current business-related request initiated by the current user terminal includes both the business request and the authentication upgrade request.

[0036] When a current user triggers a second current business association request, the backend system can determine the business type triggered by the current user based on the business request in the second current business association request, such as a login service or a transfer service. Based on the business type corresponding to the business request, the system can then determine the initial authentication method suitable for that business. Furthermore, the backend system can obtain authentication upgrade information based on the authentication upgrade request in the second current business association request. This authentication upgrade information can be default upgrade information or upgrade information specified by the current user; this embodiment of the invention does not limit this. Accordingly, the backend system can upgrade the initial authentication method based on the authentication upgrade information to obtain the target authentication method, and then initiate a user authentication request for the current user terminal based on the target authentication method.

[0037] For example, if a user triggers a transfer request through a bank app on their current device, and simultaneously initiates an upgrade authentication request, this request asks the backend system to use the highest-level authentication method. In this case, the backend system can determine that facial recognition is the initial authentication method. Since the user has also triggered an upgrade authentication request, the backend system will upgrade the facial recognition method to the highest-level authentication method. For example, the target authentication method could be "facial recognition + dynamic password authentication." Accordingly, the backend system will then initiate a user authentication request to the current user's device based on the final upgraded target authentication method.

[0038] Therefore, by combining the business type with the identity authentication upgrade request, the target identity authentication method suitable for handling the business can be determined, which can further improve the flexibility and security of identity authentication.

[0039] S220. If the user's identity authentication is successful, generate the current session identifier for the current user.

[0040] S230. In response to the current user terminal's trigger operation on the session feedback identifier, obtain the current session identifier of the current user provided by the current user terminal.

[0041] The session feedback identifier can be an identifier that can provide feedback on the current session. For example, the session feedback identifier can be a QR code, an NFC (Near Field Communication) identifier, or a URL (Uniform Resource Locator) link.

[0042] S240. Verify the validity of the current session identifier of the current user.

[0043] Optionally, when a user continues to conduct business at their current user terminal or other terminals (such as counter system terminals or self-service equipment terminals), if user identity verification is required again, the backend system can generate a session feedback identifier at the current user terminal or other terminal. This allows the current user to return the previously generated current session identifier based on the session feedback identifier. Correspondingly, the current user can trigger the session feedback identifier through their current user terminal to return the current session identifier to the current user terminal or other terminal, which then further sends the returned current session identifier to the backend system for verification.

[0044] For example, the current user terminal or other terminals can generate a QR code and provide it to the current user. The current user can scan the QR code through the current user terminal and get feedback on the current session identifier through the scanning result.

[0045] In an optional embodiment of the present invention, verifying the validity of the current user's current session identifier may include: verifying the timeliness of the current user's current session identifier; determining the current permission level corresponding to the current user's current session identifier; querying a session identifier permission level mapping table to determine the mapped permission level corresponding to the current session identifier; and verifying the matching between the current permission level and the mapped permission level corresponding to the current session identifier.

[0046] The session identifier permission level mapping table establishes a mapping relationship between each session identifier and its corresponding permission level. The current permission level can be the permission level corresponding to the currently processed business. The mapped permission level can be the permission level bound to the current session identifier.

[0047] Understandably, after receiving the current session identifier from the current user, the backend system needs to verify its validity to ensure its availability. Specifically, the backend system can verify the timeliness of the current session identifier. Optionally, the validity period of session identifiers generated for different services can be the same or different. For example, services with higher security requirements can generate session identifiers with relatively shorter validity periods, while services with lower security requirements can generate session identifiers with relatively longer validity periods.

[0048] In this embodiment of the invention, each user's authentication operation during business processing generates a corresponding session identifier. Different authentication operations generate different session identifiers. The backend system can centrally manage and maintain the session identifiers generated for each authentication operation using a session identifier permission level mapping table. To achieve efficient permission management, each session identifier can be bound to a mapped permission level. Different permission levels indicate different scopes of user operation permissions.

[0049] Correspondingly, while the current user provides the current session identifier, the current user's terminal or other terminals can also determine the current permission level of the service the current user is currently handling. The current user's terminal or other terminals can then simultaneously send the current user's current session identifier and the real-time determined current permission level to the backend system. The backend system can verify the timeliness of the current session identifier and whether the mapped permission level corresponding to the current session identifier matches the current permission level required for the current user to process the service. If both the timeliness and permission level verification pass, the current session identifier can be determined to be valid.

[0050] By performing dual verification on the timeliness and permission level of session identifiers, the availability and security of session identifiers can be improved, and abuse of session identifiers can be prevented.

[0051] S250. If the current session identifier of the current user is verified, obtain the associated business context information of the current user.

[0052] S260. Perform authentication-free processing on the associated target business of the current user based on the associated business context information of the current user.

[0053] The associated business context information can be the context information associated with the current user when processing the current business. For example, it can include information filled in before processing the current business, submitted files or images, etc., as long as it is related to the business. This embodiment of the invention does not limit the type of associated business context information.

[0054] It is understandable that users may trigger identity authentication at any time during the process of conducting business. When the current user's identity needs to be authenticated again, if the current user's current session identifier passes the verification, the user's identity authentication can be directly confirmed. The backend system can then obtain the context information of the related business transactions involved in the current user's business transactions. Based on this context information, the system can continue to process the related target business transactions of the current user without requiring the user to repeatedly provide the business information already provided, thereby further improving the efficiency of business processing.

[0055] In a specific example, a user initiates a transaction request for the first service through a mobile banking app and generates a current session identifier after successful identity authentication. When the user initiates a second transaction request through the same app within the session identifier's validity period, only the current session identifier needs to be verified in the background. If the verification passes, the processing flow for the second service continues. During this process, the user's terminal is unaware of the background system's verification of the current session identifier, and the user does not need to undergo repeated identity authentication during the second transaction. This ensures both security and efficiency when users conduct consecutive transactions on the same device.

[0056] In a specific example, a user initiates a transaction request for the first service through a mobile banking app and generates a current session identifier after identity authentication. When the user moves to a counter system or self-service terminal system to conduct a second service within the validity period of the session identifier, the counter system or self-service terminal system can provide the user with a QR code to obtain the session identifier. The user can scan the QR code using their current device, thereby providing the current session identifier to the back-end system. After obtaining the current session identifier, the back-end system verifies it and, upon successful verification, confirms the validity of the session identifier and sends the validity information back to the counter system or self-service terminal system. The counter system or self-service terminal system can then continue processing the second service based on the business context information. This process ensures that users can conduct business continuously across different terminals without repeating identity authentication, improving user experience and business processing efficiency.

[0057] In this context, "first service" and "second service" are merely used to distinguish the types of services. The first service and the second service can be the same service or different services; this embodiment of the invention does not impose any limitations on this.

[0058] Optionally, when the backend system verifies the current session identifier, it can perform request transformation and security control through the API (Application Programming Interface) gateway at the access layer, thereby sending the current session identifier to the permission session management service. The permission session management service can maintain the mapping relationship between session identifiers and permission levels through a session identifier permission level mapping table, and verify the validity of the current session identifier based on this mapping relationship.

[0059] Compared to tokens, session identifiers allow for the maintenance and binding of user permission information within the backend system, whereas tokens require user information to be directly bound to the token. Therefore, binding user information via session identifiers offers higher security. Furthermore, session identifiers enable the maintenance of more comprehensive user information on the backend server, resulting in greater usability and applicability.

[0060] In an optional embodiment of the present invention, the above method may further include: generating a renewal token for the current processing service when it is determined that the current user's current processing service has been interrupted; receiving renewal token information to be verified from the current user terminal based on the renewal token for the current processing service; verifying the renewal token information to be verified; and restoring the service status of the current processing service when it is determined that the renewal token information to be verified has passed the verification.

[0061] The renewal token is a temporary credential issued by the access control session management service for authentication of subsequent requests. The renewal token information to be verified can be the authentication information provided by the user in response to the renewal token request. It is understandable that business interruptions may occur during processing. Accordingly, if a user's current business transaction is interrupted, the backend system can generate a renewal token and display it on the relevant terminal (such as the user's current mobile device or other terminals). The user can then input the renewal token information or scan a QR code on their mobile device to submit the renewal token for verification. Optionally, the renewal token information can be submitted to the backend system's permission session management service through the access layer. The permission session management service can verify the renewal token information submitted by the user. If the backend system determines that the renewal token information passes verification, it can restore the current business transaction status and allow processing to continue.

[0062] The application of renewal tokens can ensure that users can seamlessly renew their business when conducting business on different terminals, avoiding the inconvenience caused by business interruption.

[0063] In an optional embodiment of the present invention, the above method may further include: real-time monitoring of the current user's current business operation behavior; if it is determined that the current permission level of the current user's current business operation behavior does not match the mapped permission level bound to the current session identifier, initiating a secondary user authentication request to the current user's terminal; and updating the mapped permission level bound to the current session identifier according to the current user's response to the secondary user authentication request.

[0064] During the processing of a user's current business transaction, the backend system can monitor the user's current business operation in real time and verify whether the operation matches the current permission level corresponding to the current session identifier. For example, when a user performs a sensitive operation (such as a transfer), the backend system detects that the current permission level is the highest (Level 1). Simultaneously, the system determines that the mapped permission level bound to the current session identifier is the lowest (Level 3). In other words, the system determines that the current permission level does not match the mapped permission level. To enhance security, the backend system can initiate a secondary authentication request to the user's terminal. The user then performs secondary authentication through their terminal. Upon successful authentication, the backend system receives the user's response and updates the information bound to the current session identifier, such as updating the mapped permission level. In mobile banking scenarios, this permission update can support requirements for amount limits (such as single transaction limits).

[0065] For example, when a user performs abnormal behavior (such as high-frequency operations), the backend system can also activate the risk control engine to assess the risk of the behavior. If the risk control engine determines that the behavior risk has increased or is abnormal, it can directly reduce the current permission level of the current business operation. Alternatively, it can initiate a secondary user authentication request for the current user's terminal, and after confirming that the secondary authentication is successful, the backend system updates the mapped permission level bound to the current session identifier.

[0066] By monitoring sensitive and abnormal operations and adjusting their permission levels in real time, the security of sensitive and abnormal operations and business systems can be ensured, potential risks can be prevented, and necessary permission support can be provided to users.

[0067] The above technical solution utilizes session identifiers to implement a session migration mechanism, supporting seamless migration of business processing across devices. During business processing, user permission levels can be categorized and dynamically updated according to operation type, ensuring uninterrupted authentication, avoiding duplicate authentication, and intercepting risks in real time, thus ensuring the efficiency and security of the business system in processing business transactions.

[0068] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data comply with the relevant laws, regulations and standards of the relevant regions.

[0069] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.

[0070] Example 3 Figure 3 This is a schematic diagram of a business access management device provided in Embodiment 3 of the present invention, as shown below. Figure 3 As shown, the device includes: an authentication request initiation module 310, a current session identifier generation module 320, and a service authentication-free processing module 330, wherein: The identity authentication request initiation module 310 is used to initiate a user identity authentication request to the current user terminal in response to the current service association request initiated by the current user terminal. The current session identifier generation module 320 is used to generate the current session identifier of the current user when it is determined that the user's identity authentication has been successful; The business authentication-free processing module 330 is used to perform authentication-free processing on the associated target business of the current user based on the current session identifier of the current user.

[0071] This invention, in response to a current service association request initiated by a current user terminal, initiates a user authentication request to the current user terminal. If the user authentication is successful, a current session identifier for the current user is generated. Then, based on this current session identifier, authentication-free processing is performed on the associated target service for the current user. This service permission management method addresses the problems of permission fragmentation and non-reusability in existing permission management methods, improving the efficiency of service permission management, thereby enhancing service processing efficiency and user experience.

[0072] Optionally, the identity authentication request initiation module 310 is further configured to: respond to the first current service association request initiated by the current user terminal, determine the target identity authentication method according to the service type corresponding to the first current service association request; and initiate the user identity authentication request to the current user terminal according to the target identity authentication method.

[0073] Optionally, the identity authentication request initiation module 310 is further configured to: respond to a second current service association request initiated by the current user terminal, determine an initial identity authentication method and obtain identity authentication upgrade information based on the second current service association request; upgrade the initial identity authentication method according to the identity authentication upgrade information to obtain a target identity authentication method; and initiate the user identity authentication request to the current user terminal according to the target identity authentication method.

[0074] Optionally, the service authentication-free processing module 330 is further configured to: in response to the current user terminal's trigger operation on the session feedback identifier, obtain the current session identifier of the current user provided by the current user terminal; verify the validity of the current session identifier of the current user; if it is determined that the current session identifier of the current user has passed the verification, obtain the associated service context information of the current user; and perform authentication-free processing on the associated target service of the current user according to the associated service context information of the current user.

[0075] Optionally, the business authentication-free processing module 330 is further configured to: verify the timeliness of the current user's current session identifier; determine the current permission level corresponding to the current user's current session identifier; query the session identifier permission level mapping table to determine the mapped permission level corresponding to the current session identifier; and verify the matching between the current permission level and the mapped permission level corresponding to the current session identifier.

[0076] Optionally, the above apparatus further includes a service recovery processing module, configured to: generate a renewal token for the current processing service when it is determined that the current user's current processing service has been interrupted; receive pending verification renewal token information from the current user terminal based on the renewal token for the current processing service; verify the pending verification renewal token information; and restore the service status of the current processing service when it is determined that the pending verification renewal token information has passed verification.

[0077] Optionally, the above device further includes a session identifier information update module, used for: real-time monitoring of the current user's current business operation behavior; when it is determined that the current permission level of the current user's current business operation behavior does not match the mapped permission level bound to the current session identifier, initiating a secondary user authentication request to the current user's terminal; and updating the mapped permission level bound to the current session identifier according to the current user's response to the secondary user authentication request.

[0078] The aforementioned business access management device can execute the business access management method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the business access management method provided in any embodiment of the present invention.

[0079] Since the business access management device described above is an apparatus capable of executing the business access management method in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the business access management device in this embodiment based on the business access management method described in the embodiments of the present invention. Therefore, how the business access management device implements the business access management method in the embodiments of the present invention will not be described in detail here. Any apparatus used by those skilled in the art to implement the business access management method in the embodiments of the present invention falls within the scope of protection of this application.

[0080] Example 4 Figure 4 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0081] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded into the RAM 13 from storage unit 18. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0082] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0083] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as business access control methods.

[0084] In some embodiments, the business access management method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the business access management method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the business access management method by any other suitable means (e.g., by means of firmware).

[0085] Optionally, the business access management method may include: responding to a current business association request initiated by the current user terminal, initiating a user authentication request to the current user terminal; if the user authentication is successful, generating a current session identifier for the current user; and performing authentication-free processing on the associated target business of the current user based on the current session identifier of the current user.

[0086] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0087] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0088] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0089] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0090] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0091] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0092] This invention also discloses a computer program product, which includes a computer program that, when executed by a processor, implements the business access control method provided in any embodiment of this invention. This program product shares the same inventive concept as the business access control methods disclosed in the embodiments of this invention, and therefore will not be described in detail here.

[0093] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the embodiments of the present invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in the embodiments of the present invention can be achieved, and this is not limited herein.

[0094] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for managing business access permissions, characterized in that, include: In response to a current service association request initiated by the current user terminal, a user authentication request is initiated for the current user terminal; If user authentication is successful, a current session identifier for the current user is generated; Based on the current session identifier of the current user, the associated target service of the current user is processed without authentication.

2. The method according to claim 1, characterized in that, The step of responding to a current service association request initiated by the current user terminal and initiating a user authentication request for the current user terminal includes: In response to the first current service association request initiated by the current user terminal, the target identity authentication method is determined according to the service type corresponding to the first current service association request; The user authentication request is initiated to the current user terminal according to the target authentication method.

3. The method according to claim 1, characterized in that, The step of responding to a current service association request initiated by the current user terminal and initiating a user authentication request for the current user terminal includes: In response to the second current service association request initiated by the current user terminal, the initial identity authentication method is determined according to the second current service association request and identity authentication upgrade information is obtained; The initial identity authentication method is upgraded based on the identity authentication upgrade information to obtain the target identity authentication method; The user authentication request is initiated to the current user terminal according to the target authentication method.

4. The method according to claim 1, characterized in that, The step of performing authentication-free processing on the associated target service of the current user based on the current user's current session identifier includes: In response to the current user terminal's trigger operation on the session feedback identifier, the current user's current session identifier provided by the current user terminal is obtained; Verify the validity of the current user's current session identifier; If the current user's current session identifier is verified, the associated business context information of the current user is obtained; Based on the associated business context information of the current user, the associated target business of the current user is processed for authentication exemption.

5. The method according to claim 4, characterized in that, The verification of the validity of the current user's current session identifier includes: Verify the timeliness of the current user's current session identifier; and Determine the current permission level corresponding to the current user's current session identifier; Query the session identifier permission level mapping table to determine the mapping permission level corresponding to the current session identifier; Verify the match between the current permission level and the mapped permission level corresponding to the current session identifier.

6. The method according to claim 1, characterized in that, Also includes: If it is determined that the current user's current processing service has been interrupted, a continuation token for the current processing service is generated; Receive the renewal token information to be verified from the current user terminal based on the renewal token of the currently processed service; The renewal token information to be verified is verified, and if the renewal token information to be verified passes the verification, the business status of the currently processed business is restored.

7. The method according to claim 1, characterized in that, Also includes: Real-time monitoring of the current user's current business operations; If it is determined that the current permission level of the current user's current business operation behavior does not match the mapped permission level bound to the current session identifier, a secondary user authentication request is initiated for the current user's terminal. Based on the current user's response to the secondary user authentication request, update the mapping permission level bound to the current session identifier.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor, such that the at least one processor is able to perform the business access management method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the business access management method according to any one of claims 1-7.

10. A computer program product, characterized in that, It includes a computer program / instruction, wherein when the computer program / instruction is executed by a processor, it implements the business access management method according to any one of claims 1-7.