Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Permission system" patented technology

The permission system is the legislated methods of regulating activities that require permission or accreditation under Australian and Queensland government acts, regulations and the Zoning Plan. The Permission System Policy outlines the approach to managing the permission system within the Marine Parks.

Dynamic authority and data boundary control system and method based on behavior credit

The invention discloses a dynamic authority and data boundary control system and method based on behavior credit, and belongs to the technical field of computer security and access control. The method comprises the steps of collecting behavior data of a user in real time and constructing a time sequence feature vector, wherein the behavior data comprises user native data and system interaction data; dynamically calculating a behavior credit score of the user based on a time sequence model; mapping the behavior credit score to a fine-grained dynamic permission level through a nonlinear mapping function; and performing real-time authentication and control on data access, function calling and resource operation requests of the user according to the dynamic permission level. By establishing a dynamic credit evaluation and authority adaptive adjustment mechanism driven by behavior data, the technical problem that a traditional authority system is static and rigid and is difficult to adapt to the real-time trust state change of a user is solved, and the security and adaptive capability of a digital system are improved.
Owner:CHENGDU DUER TIANHONG TECH CO LTD

A search platform object level data permission management method for a non-uniform permission system and multi-source data

The application discloses a search platform object-level data permission management method for a non-uniform permission system and multi-source data, which sequentially comprises classification of multi-source data collectable by a search platform, establishment of search platform permission data standard specification, multi-source data permission requirement analysis, data source permission data processing, search platform target permission data processing, search platform target permission data collection, search platform knowledge production, search platform user permission configuration and personnel authentication in a search request; the method solves the problem that a permission model based on RBAC in the prior art cannot adapt to object-level data permission management requirements in a non-uniform permission system and a multi-data-source enterprise search platform, realizes compatibility of data permission management of different data sources, different permission systems and differentiated organization mechanisms, and the granularity of search platform data permission management reaches the object level.
Owner:CHINA THREE GORGES CORPORATION

Information technology consultation terminal based on big data analysis

ActiveCN114780935BDigital data protectionCo-operative working arrangementsInformation technology consultingPermission system
The application discloses an information technology consultation terminal based on big data analysis, which comprises a search instruction input module, a search instruction analysis module, a search instruction output module and a permission system module; the search instruction input module comprises an instruction input unit; the search instruction analysis module comprises a user unit and a server unit; the user unit comprises a user registration subunit, an identity verification subunit and a login subunit; user information collected by the user unit comprises user name, user certificate information and user face information; the application realizes the function of verifying whether the user is consistent with the registerer through the cooperation among the search instruction analysis unit, the user end, user registration and face recognition, the audit of the user face by face recognition, effectively solves the problem of stealing other people's account search, and avoids the problem of the leakage of personal privacy and enterprise internal server information, which causes great loss of enterprises.
Owner:GUANGZHOU XINGYIN TECH CO LTD

An intra-system dynamic dimension linkage jump method and device, electronic equipment and storage medium

The application provides a system internal dynamic dimension linkage jump method and device, electronic equipment and storage medium, relates to the field of computer software, and in particular to the system internal dynamic dimension linkage jump technology, which comprises the following steps: after a user logs in a system through an account, rendering the data of an initial page; when the user operates the page, recording the real-time data dimension of the page; when jumping to a new page, rendering the data of the new page according to the recorded real-time data dimension of the page before jumping. The application can avoid the data dimension level fault caused by page jumping in a multi-permission system, and has strong practicability.
Owner:CHENGDU MEDICAL STAR TECH CO LTD

Micro-service architecture-oriented user permission system building method and management system

The invention relates to the technical field of data permission, and provides a micro-service architecture-oriented user permission system building method and management system.The method comprises a permission initialization stage and a permission verification stage, in the initialization stage, each micro-service declarates the data permission through annotation, and in the permission verification stage, the data permission is verified; during starting, a permission list is generated through scanning, a mapping relation between interfaces and permissions is established, a unified permission module collects, synchronizes and constructs a global permission list, in a runtime stage, after a user logs in, a permission set of the user is inquired and cached to a session, and when a user request arrives, the permission list is stored. And whether access is allowed or not is determined by matching the permission required by the interface with the user cache permission. According to the method, centralized management and distributed authentication of the authority are realized through annotation, responsive and non-responsive technology stacks are supported, refined authority control is carried out based on the improved RBAC model, and the efficiency and safety of authority management of the micro-service system are improved.
Owner:SSE INFORMATION NETWORK LTD

Data resource authority management method and system, authentication method and change method

ActiveCN121525073ADigital data protectionPermission systemEngineering
The invention provides a data resource authority management method and system, an authentication method and a change method.The management method comprises the steps that after an authority application of a data resource is received, a data resource ID and a data resource type ID corresponding to the data resource are searched for in an authority system, whether an authority subject corresponding to the authority application exists or not is determined, and if yes, the authority subject corresponding to the authority application does not exist; judging whether the data resource type is registered in the permission system or not; determining a corresponding data resource operation attribute, a data resource operation rule and an authorization decision rule according to the data resource ID and the data resource type ID; judging whether an authorization record which belongs to the same as the permission application exists or not, and performing permission approval on the permission application according to a judgment result and the data resource operation rule; granting a corresponding authority to the authority subject according to the authorization decision rule; according to the method, the security in the data resource authority management process is improved.
Owner:SHANGHAI SHUHE INFORMATION TECH CO LTD

Multi-user system authority management method and system applied to micro-service architecture, medium and computer program product

The invention provides a multi-user system authority management method and system applied to a micro-service architecture, a medium and a computer program product, belongs to the field of authority management, and solves the problem of how to perform multi-user system authority management under the condition of not modifying an authority system. The method comprises the following steps: receiving a micro-service login request sent by at least one user system through an account password for the first time after registering a login interface as a micro-service by modifying configuration file information; annotating role information generated by the user system in the micro-service through the configuration file information; after the account password is verified to be correct, marking the annotated role information as legal information, and allocating role permission; generating and returning a token for requesting resource data to the user system; and when the user system requests to access the resource data through the token, the user system can only request the resource data corresponding to the role permission carried by the token. The authority system of the user system does not need to be modified during authority management of the multi-user system.
Owner:PLA PEOPLES LIBERATION ARMY OF CHINA STRATEGIC SUPPORT FORCE AEROSPACE ENG UNIV

Resource permission data processing method and device, electronic equipment and storage medium

The application discloses a resource permission data processing method and device, electronic equipment and storage medium, including responding to a data change request of a target resource, updating a resource tree structure in which the target resource is located in a cache based on a content addressing strategy; in response to a permission change request for a target role, updating a compressed bitmap associated with the target role in the cache, the compressed bitmap containing resource identifiers of resources authorized by the target role; in response to a permission judgment request of a target user on a target resource, reading cache role data associated with the target user and obtaining current role data based on a lazy loading mode; comparing the current role data and the cache role data to determine the validity of the permission. The application can avoid write amplification and cascading update storm caused by permission changes, and improve the overall performance of the permission system.
Owner:ZHUHAI XIANGGUO TECHNOLOGY CO LTD

Satellite API service access control and data service system

The invention discloses a satellite API (Application Program Interface) service access control and data service system, which relates to the field of satellite data processing, and comprises a Web interface presentation layer, a back-end service engine layer and a basic storage component layer, and the back-end service engine layer is integrated with a gateway system, an API spatial data service, an API model data service and an authority system. The gateway system carries out unified routing, identity authentication, access authority verification and calling frequency statistics on API access requests from a Web end or a third party, and forwards the requests passing verification to corresponding data services. The authority system is used for managing API authorization information and user identity certificates in a centralized mode, and the basic storage component layer supports efficient storage and access of API management data, authority data and satellite data through a relational database, object storage and cache storage. According to the invention, unified access control of multi-star-source satellite data is realized, and the security, controllability and expansibility of data service are improved.
Owner:CHINA SURVEY SURVEYING & MAPPING TECH

A dynamic multi-role multi-level-based permission management method

The present application relates to the technical field of system information security, and in particular to a permission management method based on dynamic multi-role and multi-classification, which constructs a three-level linkage permission model of personnel classification, project classification and file classification, stipulates the constraint relationship of the classification, and combines the automatic processes such as the classification audit at the project creation, the real-time verification of the access request, the linkage control of the member invitation and the file creation, to realize a dynamic, scalable and refined permission management system. An intelligent classification evaluation mechanism based on the BERT model and the industry knowledge graph is also introduced to support the automatic suggestion and dynamic adjustment of the file classification. The present application overcomes the problem of static rigidity of the classification division in the traditional permission system, which cannot adapt to the dynamic changes of the business; significantly reduces the operation complexity and the manual intervention cost, and improves the management efficiency; effectively solves the problem of insufficient permission control granularity and high security risk in the prior art.
Owner:CHENGDU DIZHEN COMPUTER TECH CO LTD

Method for productization of Flowable workflow engine

The invention discloses a productization method of a Flowable workflow engine. The productization method comprises the following steps: carrying out multi-data source configuration based on a Springboot framework; determining an authority system introduction mechanism; and uniformly opening interfaces. The isolation of the double data sources ensures the data independence of the engine service and the business service, avoids mutual interference, and improves the security and processing efficiency of the data. According to the method, a clear permission introduction path is established, generation of permission vulnerabilities is avoided, only authorized users can perform corresponding operation on the workflow, and the security and reliability of the system are improved.
Owner:BEIYIN FINANCIAL TECH CO LTD

A message encryption authentication method based on a Wayland protocol

ActiveCN120956525BEncryption apparatus with shift registers/memoriesUnixPermission system
The application provides a message encryption authentication method based on a Wayland protocol and belongs to the technical field of message encryption authentication. The method comprises the following steps: based on a Wayland library, extending a connection module, and according to an advanced encryption standard encryption and decryption process, overloading communication write data and read data function interfaces to obtain overloaded communication write and read data function interfaces; through adding judgment logic of a key and judgment logic of an encryption algorithm, obtaining an overloaded client connection request function interface and an overloaded server communication channel creation function interface; defining a working mode and judging, and communicating through a Unix Socket channel to complete message encryption authentication. The application solves the problem that in the case that an existing message transmission is destroyed in a permission system, an attacker can hijack and monitor transmission data, and simultaneously realizes a client whitelist function, so that an illegal application not in the whitelist cannot initiate a connection request.
Owner:成都菁蓉联创科技有限公司

Network-based real-time special effects

A system and method for enabling augmented reality effects in a web browser without requiring additional software installation are disclosed. A web server provides a range of selectable effects to a website. When an effect is selected, the website loads a page specific to that effect, including a live preview of the effect applied to a video feed from the user's webcam. This allows the user to see themselves with the effect applied in real time. The website requests access to the webcam and microphone via the browser's built-in permissions system. Captured photos and videos with the effect applied can be saved locally or shared via native operating system tools. This system provides an engaging augmented reality experience that is directly accessible via a standard web browser without the need for a dedicated app.
Owner:SNAP INC

Permission system implementation method and system based on interface detection

PendingCN121744358ADigital data protectionMaintainabilityPermission system
The invention discloses a permission system implementation method and system based on interface detection, and relates to the technical field of computer software security, and the method comprises the following steps: full-interface forced permission verification: all service interfaces are covered by a permission verification layer; centralized dynamic authority management and unified maintenance of authority configuration are realized, updating during operation and business customization expansion are supported, and authority rules are associated to an interface through annotations; front and back end authority processing is simplified, and the server side directly configures the authority through interface layer annotation. According to the method, all service interfaces are ensured to be verified by a unified permission verification layer without exception, security vulnerabilities caused by verification omission are thoroughly eliminated, the maintainability and the flexibility of a system are remarkably improved, permission rules are directly bound to the interfaces in an annotation-driven mode, and the permission rules are intercepted by a section to automatically execute verification, so that the verification efficiency is improved. Therefore, the server does not need to write redundant permission codes, the development complexity is greatly reduced, the development efficiency is improved, and meanwhile the consistency, integrity and safety of permission control are guaranteed.
Owner:ZHEJIANG READ TECH CO LTD

A natural disaster early warning and tourism safety emergency response system

The application discloses a natural disaster early warning and tourism safety emergency response system, comprising: a data layer constructs a space-time disaster causal network, a root node is configured with a disaster characteristic matrix containing an influence radius and a disaster-causing intensity, nodes and edges have geographic coordinates and time delay attributes, each edge has a time lag coefficient, an intermediate node is activated and needs an upstream weighted summation value to be greater than 0.7, a decision layer establishes disaster interaction edges and coupling operators when multiple root nodes are concurrent, forms a dynamic composite causal graph, outputs a nonlinear superposition effect of facility preservation and evacuation efficiency by a graph neural network, calls a real-time crowd simulation engine to generate a pareto optimal response scheme set, and an edge layer deploys the engine and a decision tree model obtained by knowledge distillation. An interaction layer converts the scheme into differentiated instructions and forcibly pushes the differentiated instructions to a guide and a tourist terminal through a three-level permission system, and the instructions are attached with digital signatures.
Owner:CHENGDU TECH UNIV

Permission processing method and device, storage medium and program product

PendingCN121389142ADigital data protectionPermission systemMaintainability
The embodiment of the invention provides a permission processing method and device, a storage medium and a program product. In the permission processing method, the authorization decision object is associated with the operation permission and is not associated with the resource, so that when the permission of the target object to the first operation type of the first resource is configured, a new authorization decision object does not need to be created according to the first resource and the first operation type; however, the created first authorization decision-making object corresponding to the first operation type can be reused, and the corresponding relation between the first authorization decision-making object and the first resource is dynamically established. Based on the implementation mode, the created authorization decision-making object can be repeatedly used according to the operation type of the requested operation authority, so that the probability that a large number of authorization decision-making objects are newly added due to the fact that the types of resources applicable to the operation authority are increased is reduced; the number of authorization decision-making objects in the authority system can be maintained in a stable range, the definition and maintainability of the authority system are improved, and therefore the management cost of the authority system is reduced.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Identifying a source of a function call and inheriting access permission

Systems and methods provide for inherited access permissions, thereby facilitating read and write access by called contexts. Hardware logic may enforce access permissions in the system. When a processor core executes code associated with a first context, the processor core generates a first hardware signal identifying the first context. The processor core may then switch from the first context to the second context due to the first context calling the second context. The processor core may then generate a second hardware signal identifying the calling (first) context, and then the first hardware signal identifies the called (second) context. The hardware logic that enforces the access permissions may then determine that the second context is being called and that the second context includes either direct access permissions or inherited access permissions associated with the calling (first) context.
Owner:TEXAS INSTRUMENTS INC

Permissions system and method

A system 100 for managing user permissions for accessing a data store comprises a central permissions database 115 storing user permissions for accessing one or more documents stored in a data store,
Owner:ADARGA LTD

Model-driven code-free configuration development method and development system

PendingCN121934833AVersion controlVisual/graphical programmingAbstraction layerDynamic load balancing algorithm
The invention discloses a model-driven code-free configuration development method and system, relates to the technical field of platform development, and aims to construct a visual configuration system based on a metadata model and realize cross-platform data interaction and real-time dynamic updating through a directional data association and multi-modal view rendering technology. A lightweight metadata-driven architecture is adopted as the core, a standardized interface, hierarchical authority control and a dynamic routing strategy are integrated, and the double requirements of high concurrency and high availability are considered. Multi-source data access and efficient scheduling are realized through a unified abstraction layer, and an intelligent cache mechanism and a dynamic load balancing algorithm are combined to ensure that the system is quick in overall response and stable in operation. The overall design gives consideration to expansibility and safety, is compatible with a multi-terminal access scene, realizes deep collaboration and refined management and control of a model, a view and an authority system, and effectively improves the system operation efficiency and the user experience.
Owner:TIANJIN HANHAI INTELLIGENT TECH CO LTD

An industry chain-based catalyst traceability system and method

The application discloses a kind of catalyst traceability system and method based on industry chain, belong to traceability control technical field, specifically include: combing the participating subject of catalyst traceability in industry chain, dividing catalyst related data into sensitive data and basic traceability data, determine the specific traceability demand of each subject;According to the role of participating subject and traceability demand, establish multi-level permission system, each level of permission matches corresponding accessible sensitive data or basic traceability data range;Set the traceability scene trigger rule of data access, subject submits specific traceability link and query purpose, as the basis for activating corresponding level of permission;Identity information and traceability scene description submitted by subject are verified, and after verification, open the data access channel of corresponding permission according to trigger rule;Sensitive data opened for access are subjected to core field hiding processing, retain the key feature information related to traceability, ensure data security and do not affect traceability analysis.
Owner:SHANDONG CHANGZE NEW MATERIAL TECH CO LTD

Systems and methods for managing resource access permissions

ActiveUS12592933B2Securing communicationResource informationPermission system
Systems and methods for managing resource access permissions for users with unknown credentials are disclosed herein. A resource access request may be received. A measure of risk may be determined. In response to determining that a first access level is permitted, the first user identifier may be inserted in a first access control list. Based on information regarding resources accessed by the first user, an updated measure of risk may be determined. In response to determining that a second access level is permitted, the first user identifier may be inserted in a second access control list.
Owner:CAPITAL ONE SERVICES LLC

Charging supervision method of charging cabinet

The invention provides a charging monitoring method for a charging cabinet, and the method comprises the steps: collecting charging process data, and carrying out the source digital signature through a hardware safety module; performing real-time analysis on the data by utilizing an edge intelligent processing unit, and generating a safety state vector containing a risk level; packaging the signed data and the security state vector into a transaction, broadcasting the transaction to a permission system block chain network, and carrying out distributed consensus and non-tampering storage; and when the accident investigation is triggered, automatically performing evidence arrangement and causal chain analysis on the chain data through the law and evidence smart contract deployed on the block chain, and generating a responsibility attribution report. According to the method, a full-link credible channel is constructed, so that tampering resistance and credibility of evidences are ensured, conversion from post-event responsibility investigation to pre-event risk early warning is realized, the responsibility definition process is automatic and transparent by using an intelligent contract, and the problems of difficult evidence collection and difficult responsibility determination of a charging safety accident in a multi-party cooperation scene are solved.
Owner:XIAN AEROSPACE AUTOMATION

A robot extensible permission management method based on an intra-domain role access control model

The application provides a robot extensible permission management method based on a domain role access control model, comprising the following steps: S1, defining basic attributes of a first-level entity; S2, defining basic attributes required by a second-level entity as a sovereign entity; S3, defining basic attributes required by a third-level entity as a resource entity; S4, defining a sovereign object, an authorized object, an authorized permission value and a tenant as columns of a sovereign entity permission table; S5, defining a sovereign object successor, a sovereign object and a tenant as columns of a sovereign entity inheritance relationship table; S6, defining a relationship between the second-level entity and the third-level entity according to requirements; and S7, loading all valid data of the sovereign entity permission table and the sovereign entity inheritance relationship table into the memory in the form of a key-value pair set when the permission system service is started. The application solves the problem of entity management difficulty caused by business requirements when the permission system is designed or after the permission system is put into operation.
Owner:GUANGZHOU YUNDI TECH CO LTD

System and method for automatically updating room card authority through door lock card swiping function

The invention relates to the technical field of hotel room card authority, and discloses a system and method for automatically updating room card authority through a door lock card swiping function, and the system comprises a door lock plate, an applet, a background cloud, a Bluetooth gateway, an authority system, and a room card ID. The authority system is mainly composed of an NFC card-making chip, a signal interaction chip and an NFC card-reading chip, the door lock plate is provided with an induction plate, the induction plate is in signal connection with the NFC card-making chip and the NFC card-reading chip, a Bluetooth module is arranged in the door lock plate, and the Bluetooth module is in signal connection with the NFC card-making chip and the NFC card-reading chip; and the background cloud is in signal connection with the authority system through the Bluetooth gateway and the Bluetooth module. According to the invention, the door lock plate is endowed with a card making function, after a customer completes room renewing operation on a mobile phone, a room renewing work order passes through a gateway, new housing information is transmitted to the door lock plate through a network, and when the customer swipes a card, the door lock plate writes a new housing permission into the room card after identifying the original card, so that non-inductive card renewing is realized.
Owner:SHENZHEN NIKES INTELLIGENT TECHNOLOGY CO LTD +1

A dynamic assembly-based permission management method, system and medium

PendingCN122286737ASimplify operation and maintenance workachieve decouplingPermission systemEngineering
This invention discloses a method, system, and medium for permission management based on dynamic assembly, belonging to the field of software security technology. The method includes: defining the attributes and behaviors of all permission nodes through a unified static permission configuration table; responding to permission configuration requests, constructing a static permission tree based on the configuration table, and using reflection to obtain business data instances in real time for data permission nodes configured with dynamic assembly identifiers, generating each instance as a virtual child node, and dynamically assembling them into a complete permission tree; during permission allocation, storing the selected permission key value and permission subject in a completely flattened independent entry format; during authentication, determining whether the target permission key exists in the user's flattened permission set through an efficient set member lookup. This invention achieves unified management of permission configuration, real-time dynamic adaptation of data permissions, and high-performance authentication operations, effectively solving the problems of fragmentation, rigidity, and inefficiency in existing permission systems.
Owner:山东齐鲁壹点传媒有限公司 +1

Data resource permission management method and system, authentication method and change method

The application provides a data resource permission management method and system, an authentication method and a change method. The management method comprises the following steps: after receiving a permission application of a data resource, searching for a data resource ID and a data resource type ID corresponding to the data resource in a permission system, determining whether a permission subject corresponding to the permission application exists and whether the data resource type is registered in the permission system; determining corresponding data resource operation attributes, data resource operation rules and authorization decision rules according to the data resource ID and the data resource type ID; judging whether there is an authorization record belonging to the permission application, and performing permission examination on the permission application according to a judgment result and the data resource operation rules; and granting corresponding permissions to the permission subject according to the authorization decision rules. The application improves the security in the data resource permission management process.
Owner:SHANGHAI SHUHE INFORMATION TECH CO LTD

Rule-based verification and collaborative control-based cable intelligent management method and system

ActiveCN120893808BOffice automationUser PrivilegePermission system
The application relates to the technical field of industrial asset management, and particularly discloses a cable intelligent management method and system based on rule checking and collaborative control, which comprises the following steps: a multi-dimensional basic configuration system containing ship environment parameters, cable basic material attributes, process specifications and user permissions is constructed; a rule checking benchmark library containing design compliance rules, production process constraints and operation and maintenance health threshold values is set; and a cross-role collaborative permission system is implemented for the whole life cycle of cable design, production, laying and operation and maintenance. Through the construction of the multi-dimensional basic configuration system covering the ship environment, material attributes, process specifications and user permissions, and in combination with the checking benchmark library containing the whole-process rules, the information barriers of the design, production, laying and operation and maintenance links are broken, the mistakes and omissions of manual transcription data are avoided, and the unified management and compliance control of the cable whole-life cycle data are realized.
Owner:SHANGHAI COSCO SHIPPING HEAVY IND CO LTD

Bucket wheel machine remote control method based on industrial internet access

PendingCN121887471ASecuring communicationRemote controlPermission system
The invention relates to the technical field of industrial internet and industrial control system safety, and discloses a bucket wheel machine remote control method based on industrial internet access. Establishing a role permission system, mapping a control operation into a permission level, and configuring an operation subset and a permission code; the system receives a permission application containing a remote user identity and authorization duration, generates an authorization time period according to system time, compares the authorization time period with an existing authorization time period of equipment, allocates a token number when no overlapping exists, and generates a dynamic token obtained by processing the identity, the permission, the time period and a token number verification code algorithm. A user carries the dynamic token to initiate a control request within an authorization time period, the equipment performs joint verification according to token information, time conditions and the corresponding relation of authority and operation, and if the verification is passed, a log is executed and recorded, otherwise, the log is rejected and recorded, so that authority control and control traceability are realized.
Owner:LIAONING DATANG INTERNATIONAL SHENDONG THERMAL POWER CO LTD

Computerized security platforms including a role-based permissions system

In an example method, a computer system accessing first natural language user input representing a request to generate security policies for a computerized security platform, and generates the security policies using a computerized large language model (LLM). Generating the one or more security policies includes determining an identity of the computerized security platform, providing at least a portion of the first natural language user input and the identity of the computerized security platform to the LLM, and receiving, from the LLM, first output data representing the security policies. The first output data has a computer language syntax that is compatible with the computerized security platform. Further, the system causes the security policies to be presented to a user and to be stored on a computerized storage device.
Owner:AURADINE INC