CN114662084A - Method and device for monitoring full life cycle of user account - Google Patents
Method and device for monitoring full life cycle of user account Download PDFInfo
- Publication number
- CN114662084A CN114662084A CN202011533368.6A CN202011533368A CN114662084A CN 114662084 A CN114662084 A CN 114662084A CN 202011533368 A CN202011533368 A CN 202011533368A CN 114662084 A CN114662084 A CN 114662084A
- Authority
- CN
- China
- Prior art keywords
- user account
- information
- identity authentication
- authentication platform
- unified identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/27—Replication, distribution or synchronisation of data between databases or within a distributed database system; Distributed database system architectures therefor
- G06F16/275—Synchronous replication
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Databases & Information Systems (AREA)
- Computing Systems (AREA)
- Data Mining & Analysis (AREA)
- Storage Device Security (AREA)
Abstract
Description
技术领域technical field
本发明涉及信息安全技术领域,更具体的说,涉及一种用户账号全生命周期的监控方法及装置。The invention relates to the technical field of information security, and more particularly, to a monitoring method and device for the full life cycle of a user account.
背景技术Background technique
随着信息技术的发展和信息化建设的不断进步,业务应用、办公系统和商务平台不断推出和投入运行,信息系统在企业运营中全面渗透。由于信息系统包含的设备和服务器众多,管理难度相对较大等因素,越权访问、误操作、操作权限滥用、恶意破坏等情况时有发生,从而导致企业的经济运行能效受到严重影响。With the development of information technology and the continuous progress of informatization construction, business applications, office systems and business platforms have been continuously launched and put into operation, and information systems have fully penetrated into enterprise operations. Due to factors such as the large number of devices and servers included in the information system and the relatively difficult management, unauthorized access, misoperation, abuse of operating authority, and malicious damage often occur, which seriously affects the economic operation and energy efficiency of enterprises.
因此,如何对用户基于用户账户的操作行为进行监控,提高信息系统运维管理水平,成为了本领域技术人员亟需解决的技术问题。Therefore, how to monitor the user's operation behavior based on the user account and improve the operation and maintenance management level of the information system has become an urgent technical problem to be solved by those skilled in the art.
发明内容SUMMARY OF THE INVENTION
有鉴于此,本发明公开一种用户账号全生命周期的监控方法及装置,以实现对用户账户全生命周期所有操作行为进行监控,从而提高信息系统的运维管理水平。In view of this, the present invention discloses a method and device for monitoring the entire life cycle of a user account, so as to monitor all operational behaviors of the user account during the entire life cycle, thereby improving the operation and maintenance management level of the information system.
一种用户账号全生命周期的监控方法,包括:A method for monitoring the entire life cycle of a user account, comprising:
在前端的统一身份认证平台上创建用户账号相关信息,所述用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限;Create user account related information on the front-end unified identity authentication platform, where the user account related information includes: user account and corresponding user account attribute information and access operation authority;
当通过所述统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,其中,所述用户账号属性信息发生变更包括用户职位调用和用户离职;When the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the access operation authority of the target user account whose user account attribute information is changed and/or abnormal operation occurs is modified, wherein , the change of the attribute information of the user account includes the user's position invocation and the user's resignation;
将访问操作权限修改的目标用户账号相关信息同步至与所述统一身份认证平台对接的所有应用中,其中,所述目标用户账号相关信息包括:所述目标用户账号及对应的目标用户账号属性信息和目标用户账号访问操作权限。Synchronize the relevant information of the target user account modified by the access operation authority to all applications docked with the unified identity authentication platform, wherein the relevant information of the target user account includes: the target user account and the corresponding target user account attribute information and target user account access permissions.
可选的,所述在前端的统一身份认证平台上创建用户账号相关信息,具体包括:Optionally, the creation of user account-related information on the front-end unified identity authentication platform specifically includes:
通过同步引擎、事务机制和预设通信协议,从活动目录AD域或办公自动化OA系统同步已有用户账号相关信息至所述统一身份认证平台,实现所述用户账号相关信息的创建。Through the synchronization engine, the transaction mechanism and the preset communication protocol, the existing user account related information is synchronized from the Active Directory AD domain or the office automation OA system to the unified identity authentication platform, so as to realize the creation of the user account related information.
可选的,还包括:Optionally, also include:
对所述用户账号相关信息的同步成功信息和同步失败信息进行多维度记录。Multi-dimensional recording is performed on the synchronization success information and synchronization failure information of the user account related information.
可选的,所述在前端的统一身份认证平台上创建用户账号相关信息,具体还包括:Optionally, the creation of user account-related information on the front-end unified identity authentication platform specifically further includes:
采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号;Using the preset unified account naming specification, create a new user account on the unified identity authentication platform;
为新建的所述用户账号添加对应的用户账号属性信息,并分配对应的访问操作权限。Corresponding user account attribute information is added to the newly created user account, and corresponding access operation authority is assigned.
可选的,所述采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号,具体包括:Optionally, the preset unified account naming specification is used to create a new user account on the unified identity authentication platform, which specifically includes:
将用户姓名拼音中的声母和韵母进行排列组合,同时结合统一码编码表得到初始用户账号;Arrange and combine the initials and finals in the pinyin of the user's name, and obtain the initial user account in combination with the Unicode code table;
将所述初始用户账号发送至服务器端,由所述服务器端校验所述初始用户账号的唯一性及合法性;sending the initial user account to the server, and the server verifies the uniqueness and legitimacy of the initial user account;
接收所述服务器端反馈的校验通过指令,将所述初始用户账号确定为在所述统一身份认证平台上新建的用户账号。Receive the verification passing instruction fed back by the server, and determine the initial user account as a newly created user account on the unified identity authentication platform.
可选的,所述采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号,具体还包括:Optionally, the preset unified account naming specification is used to create a new user account on the unified identity authentication platform, which further includes:
接收所述服务器端反馈的已修改用户账号,将所述已修改用户账号确定为在所述统一身份认证平台上新建的用户账号,其中,所述已修改用户账号为所述服务器端在判定所述初始用户账号存在重复时,在所述初始用户账号后叠加具有唯一性的随机数后生成。Receive the modified user account fed back by the server, and determine the modified user account as a newly created user account on the unified identity authentication platform, wherein the modified user account is determined by the server side. When the initial user account is repeated, a unique random number is superimposed on the initial user account and generated.
可选的,还包括:Optionally, also include:
当系统管理员账号登录所述统一身份认证平台后,接收所述系统管理员账号发送对所述用户账号属性信息的扩展信息;After the system administrator account logs in to the unified identity authentication platform, receiving the extension information sent by the system administrator account to the attribute information of the user account;
将所述扩展信息添加至所述用户账号属性信息中,并将添加所述扩展信息的用户账号属性信息同步至与所述统一身份认证平台所述对接的所有应用中。The extended information is added to the user account attribute information, and the user account attribute information added with the extended information is synchronized to all applications connected to the unified identity authentication platform.
可选的,还包括:Optionally, also include:
接收已登录所述统一身份认证平台的用户账号发送的针对所述用户账号相关信息的修改内容;Receive the modified content for the relevant information of the user account sent by the user account that has logged in to the unified identity authentication platform;
将所述修改内容发送至系统管理员端进行有效性审核,其中,有效性审核内容至少包括:所述修改内容是否为所述用户账号相关信息中除用户账号唯一身份标识以外的信息;Send the modified content to the system administrator for validity review, wherein the validity review content at least includes: whether the modified content is information other than the user account unique identifier in the user account-related information;
接收所述系统管理员端反馈的有效性审核通过指令,根据所述修改内容对所述用户账号相关信息进行修改,并将修改后的用户账号相关信息同步至与所述统一身份认证平台所述对接的所有应用中。Receive the validity review and pass instruction fed back by the system administrator, modify the user account related information according to the modified content, and synchronize the modified user account related information to the unified identity authentication platform. All docking applications.
一种用户账号全生命周期的监控装置,包括:A monitoring device for the full life cycle of a user account, comprising:
信息创建单元,用于在前端的统一身份认证平台上创建用户账号相关信息,所述用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限;an information creation unit, used for creating user account related information on the front-end unified identity authentication platform, where the user account related information includes: user account and corresponding user account attribute information and access operation authority;
权限修改单元,用于当通过所述统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,其中,所述用户账号属性信息发生变更包括用户职位调用和用户离职;A permission modification unit, used to access the target user account whose attribute information of the user account is changed and/or the abnormal operation occurs when a change in the attribute information of the user account and/or an abnormal operation is detected on the unified identity authentication platform The operation authority is modified, wherein the change of the user account attribute information includes the user's position invocation and the user's resignation;
信息同步单元,用于将访问操作权限修改的目标用户账号相关信息同步至与所述统一身份认证平台对接的所有应用中,其中,所述目标用户账号相关信息包括:所述目标用户账号及对应的目标用户账号属性信息和目标用户账号访问操作权限。an information synchronization unit, used for synchronizing the relevant information of the target user account modified by the access operation authority to all applications connected to the unified identity authentication platform, wherein the relevant information of the target user account includes: the target user account and the corresponding The attribute information of the target user account and the access operation permissions of the target user account.
可选的,所述信息创建单元具体包括:Optionally, the information creation unit specifically includes:
第一信息创建子单元,用于通过同步引擎、事务机制和预设通信协议,从活动目录AD域或办公自动化OA系统同步已有用户账号相关信息至所述统一身份认证平台,实现所述用户账号相关信息的创建。The first information creation subunit is used for synchronizing the relevant information of existing user accounts from the Active Directory AD domain or the office automation OA system to the unified identity authentication platform through the synchronization engine, the transaction mechanism and the preset communication protocol, so as to realize the user Creation of account-related information.
可选的,所述信息创建单元还包括:Optionally, the information creation unit further includes:
信息记录子单元,用于对所述用户账号相关信息的同步成功信息和同步失败信息进行多维度记录。The information recording subunit is used for multi-dimensional recording of the synchronization success information and synchronization failure information of the user account related information.
可选的,所述信息创建单元具体还包括:Optionally, the information creation unit specifically further includes:
第二信息创建子单元,用于采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号;The second information creation subunit is used to create a new user account on the unified identity authentication platform by adopting a preset unified account naming specification;
权限分配子单元,用于为新建的所述用户账号添加对应的用户账号属性信息,并分配对应的访问操作权限。The authority assignment subunit is used for adding corresponding user account attribute information to the newly created user account, and assigning corresponding access operation authority.
可选的,所述第二信息创建子单元具体用于:Optionally, the second information creation subunit is specifically used for:
将用户姓名拼音中的声母和韵母进行排列组合,同时结合统一码编码表得到初始用户账号;Arrange and combine the initials and finals in the pinyin of the user's name, and obtain the initial user account in combination with the Unicode code table;
将所述初始用户账号发送至服务器端,由所述服务器端校验所述初始用户账号的唯一性及合法性;sending the initial user account to the server, and the server verifies the uniqueness and legitimacy of the initial user account;
接收所述服务器端反馈的校验通过指令,将所述初始用户账号确定为在所述统一身份认证平台上新建的用户账号。Receive the verification passing instruction fed back by the server, and determine the initial user account as a newly created user account on the unified identity authentication platform.
可选的,所述第二信息创建子单元具体还用于:Optionally, the second information creation subunit is further used for:
接收所述服务器端反馈的已修改用户账号,将所述已修改用户账号确定为在所述统一身份认证平台上新建的用户账号,其中,所述已修改用户账号为所述服务器端在判定所述初始用户账号存在重复时,在所述初始用户账号后叠加具有唯一性的随机数后生成。Receive the modified user account fed back by the server, and determine the modified user account as a newly created user account on the unified identity authentication platform, wherein the modified user account is determined by the server side. When the initial user account is repeated, a unique random number is superimposed on the initial user account and generated.
可选的,还包括:Optionally, also include:
扩展信息接收单元,用于当系统管理员账号登录所述统一身份认证平台后,接收所述系统管理员账号发送对所述用户账号属性信息的扩展信息;an extension information receiving unit, configured to receive extension information sent by the system administrator account to the attribute information of the user account after the system administrator account logs in to the unified identity authentication platform;
扩展信息添加单元,用于将所述扩展信息添加至所述用户账号属性信息中,并将添加所述扩展信息的用户账号属性信息同步至与所述统一身份认证平台所述对接的所有应用中。An extension information adding unit, configured to add the extension information to the user account attribute information, and synchronize the user account attribute information added with the extension information to all applications connected to the unified identity authentication platform .
可选的,还包括:Optionally, also include:
修改内容接收单元,用于接收已登录所述统一身份认证平台的用户账号发送的针对所述用户账号相关信息的修改内容;a modified content receiving unit, configured to receive the modified content for the relevant information of the user account sent by the user account that has logged in to the unified identity authentication platform;
修改内容审核单元,用于将所述修改内容发送至系统管理员端进行有效性审核,其中,有效性审核内容至少包括:所述修改内容是否为所述用户账号相关信息中除用户账号唯一身份标识以外的信息;A modified content review unit, configured to send the modified content to a system administrator for validity review, wherein the validity review content at least includes: whether the modified content is the unique identity of the user account other than the user account related information Information other than identification;
修改内容同步单元,用于接收所述系统管理员端反馈的有效性审核通过指令,根据所述修改内容对所述用户账号相关信息进行修改,并将修改后的用户账号相关信息同步至与所述统一身份认证平台所述对接的所有应用中。The modification content synchronization unit is used to receive the validity review and approval instruction fed back by the system administrator, modify the user account related information according to the modification content, and synchronize the modified user account related information to the relevant information of the user account. All applications connected to the unified identity authentication platform described above.
从上述的技术方案可知,本发明公开了一种用户账号全生命周期的监控方法及装置,在前端的统一身份认证平台上创建用户账号相关信息,用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限,当通过统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,将访问操作权限修改的目标用户账号相关信息同步至与统一身份认证平台对接的所有应用中。本发明从用户入职创建对应的用户账号相关信息,到用户离职用户账号归档的整个过程,都在统一身份认证平台上完成,在用户账户全生命周期中,当统一身份认证平台监测到用户账号属性信息发生变更,比如用户职位调动或用户离职,和/或出现异常操作时,统一身份认证平台会对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,以限制用户的访问操作权限,统一身份认证平台作为对接所有应用的唯一数据源,会将访问操作权限修改的目标用户账号相关信息同步至对接的所有应用中,从而实现统一身份认证平台与对接的所有应用的同步更新,因此,本发明通过统一身份认证平台实现了对用户账户全生命周期所有操作行为进行监控,从而提高了信息系统的运维管理水平。As can be seen from the above technical solutions, the present invention discloses a monitoring method and device for the full life cycle of a user account, creating user account related information on the front-end unified identity authentication platform, and the user account related information includes: the user account and the corresponding user account. Account attribute information and access permissions, when changes in user account attribute information and/or abnormal operations are detected on the unified identity authentication platform, access to the target user account whose user account attribute information changes and/or abnormal operations occur Modify the operation authority, and synchronize the relevant information of the target user account with the modified access operation authority to all applications connected to the unified identity authentication platform. In the present invention, the entire process from the user's entry to create the corresponding user account-related information to the user's resignation and the user account filing is completed on the unified identity authentication platform. When the information changes, such as the user's position transfer or the user's resignation, and/or abnormal operation, the unified identity authentication platform will modify the access operation authority of the target user account whose user account attribute information changes and/or abnormal operation occurs, so as to Restricting the user's access and operation authority, the unified identity authentication platform, as the only data source for connecting all applications, will synchronize the relevant information of the target user account modified by the access operation authority to all the connected applications, so as to realize the unified identity authentication platform and all connected applications. The application is updated synchronously. Therefore, the present invention realizes the monitoring of all operation behaviors in the whole life cycle of the user account through a unified identity authentication platform, thereby improving the operation and maintenance management level of the information system.
附图说明Description of drawings
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据公开的附图获得其他的附图。In order to explain the embodiments of the present invention or the technical solutions in the prior art more clearly, the following briefly introduces the accompanying drawings that need to be used in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only It is an embodiment of the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to the disclosed drawings without creative efforts.
图1为本发明实施例公开的一种用户账号全生命周期的监控方法流程图;1 is a flowchart of a method for monitoring the full life cycle of a user account disclosed in an embodiment of the present invention;
图2为本发明实施例公开的一种用户账号全生命周期的监控装置的结构示意图。FIG. 2 is a schematic structural diagram of a monitoring device for a full life cycle of a user account disclosed in an embodiment of the present invention.
具体实施方式Detailed ways
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
参见图1,本发明实施例公开的一种用户账号全生命周期的监控方法流程图,该方法应用于前端,包括:Referring to FIG. 1 , a flowchart of a method for monitoring the full life cycle of a user account disclosed in an embodiment of the present invention, the method is applied to the front end, and includes:
步骤S101、在前端的统一身份认证平台上创建用户账号相关信息;Step S101, creating user account related information on the front-end unified identity authentication platform;
其中,所述用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限。Wherein, the user account related information includes: user account and corresponding user account attribute information and access operation authority.
统一身份认证平台是一种用户认证数据源以及用户账户全生命周期管理平台。The unified identity authentication platform is a user authentication data source and a user account full life cycle management platform.
本实施例中,统一身份认证平台与多个应用系统对接,其中,对接应用系统包括但不限于AD(Active Directory,活动目录)域、OA(Office Automation,办公自动化)系统和对接的所有应用。In this embodiment, the unified identity authentication platform is interconnected with multiple application systems, wherein the interconnected application systems include but are not limited to AD (Active Directory, Active Directory) domains, OA (Office Automation, Office Automation) systems, and all interconnected applications.
其中,统一身份认证平台与多个应用系统之间采用预设通信协议建立通信连接,预设通信协议可以包括:SCIM(System for Cross-domain Identity Management,跨域身份管理系统)、JNDI(Java Naming and Directory Interface,Java命名和目录接口)和LDAP(Lightweight Directory Access Protocol,轻型目录访问协议)。Wherein, a communication connection is established between the unified identity authentication platform and multiple application systems using a preset communication protocol, and the preset communication protocol may include: SCIM (System for Cross-domain Identity Management, cross-domain identity management system), JNDI (Java Naming and Directory Interface, Java naming and directory interface) and LDAP (Lightweight Directory Access Protocol, Lightweight Directory Access Protocol).
用户账号属性信息可以包括:邮箱、手机号、职位和家庭住址等。The attribute information of the user account may include: email address, mobile phone number, position, and home address, and the like.
步骤S102、当通过所述统一身份认证平台监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改;Step S102, when the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the access operation authority of the target user account whose user account attribute information is changed and/or abnormal operation occurs is modified. ;
其中,所述用户账号属性信息发生变更包括用户职位调用和用户离职。Wherein, the change of the attribute information of the user account includes the invocation of the user's position and the resignation of the user.
用户在统一身份认证平台创建对应的用户账号相关信息,系统管理员为用户账号配置对应的用户账号属性信息和访问操作权限后,用户账号就可以根据具有的访问操作权限访问应用及资源。The user creates the corresponding user account related information on the unified identity authentication platform. After the system administrator configures the corresponding user account attribute information and access operation authority for the user account, the user account can access applications and resources according to the access operation authority.
系统管理员:登录统一身份认证平台后拥有最高权限,能够添加维护用户、用户组织和用户组,分配用户访问操作权限以及对用户整个生命周期的管理维护,还可以负责审批用户自主修改的除账户及姓名外的所有自身属性信息。System administrator: After logging in to the unified identity authentication platform, he has the highest authority, can add and maintain users, user organizations and user groups, assign user access and operation authority, manage and maintain the entire user life cycle, and can also be responsible for approving the user's self-modified removal account and all self-attribute information other than the name.
统一身份认证平台根据自身设置的安全访问策略及风控系统维护整个统一身份认证平台的正常运行。The unified identity authentication platform maintains the normal operation of the entire unified identity authentication platform according to its own security access policy and risk control system.
具体的,用户账号属性信息发生变更,比如,用户离职(用户一旦提交离职流程便会触发系统策略)、用户账号属性变更(如通过非正常渠道对用户属性进行篡改来增大访问权限)。Specifically, the user account attribute information changes, for example, the user resigns (the system policy will be triggered once the user submits the resignation process), and the user account attribute changes (such as tampering with the user attribute through abnormal channels to increase access rights).
异常操作包括:用户账号频繁登录统一身份认证平台、多次异地登录和多终端频繁登录,等等。当出现异常操作时会引起统一身份认证平台的安全风控反应机制。Abnormal operations include: frequent user account logins to the unified identity authentication platform, multiple remote logins and frequent logins from multiple terminals, etc. When an abnormal operation occurs, the security risk control response mechanism of the unified identity authentication platform will be triggered.
当通过统一身份认证平台监测到用户账号属性信息发生变更和/或出现异常操作时,系统便根据已有的任务机制或安全策略,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,并将访问操作权限修改的目标用户账号相关信息同步至与统一身份认证平台对接的所有应用中。也即,在对访问操作权限修改后会第一时间通知对接的所有应用,使修改后的访问操作权限立即生效,以将统一身份认证平台的损失降至最低或防患于未然。整个过程用户是无感知的,完全由系统自动完成。When the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the system will, according to the existing task mechanism or security policy, identify the target user whose user account attribute information is changed and/or abnormal operation occurs. The access operation authority of the account is modified, and the relevant information of the target user account whose access operation authority is modified is synchronized to all applications connected to the unified identity authentication platform. That is, after the access operation authority is modified, all connected applications will be notified as soon as possible, so that the modified access operation authority will take effect immediately, so as to minimize the loss of the unified identity authentication platform or prevent problems before they occur. The entire process is unaware of the user and is completely automated by the system.
步骤S103、将访问操作权限修改的目标用户账号相关信息同步至与所述统一身份认证平台对接的所有应用中。Step S103 , synchronizing the relevant information of the target user account modified by the access operation authority to all applications connected to the unified identity authentication platform.
其中,所述目标用户账号相关信息包括:所述目标用户账号及对应的目标用户账号属性信息和目标用户账号访问操作权限。Wherein, the relevant information of the target user account includes: the target user account and corresponding attribute information of the target user account and the access operation authority of the target user account.
综上可知,本发明公开的用户账号全生命周期的监控方法,在前端的统一身份认证平台上创建用户账号相关信息,用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限,当通过统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,将访问操作权限修改的目标用户账号相关信息同步至与统一身份认证平台对接的所有应用中。本发明从用户入职创建对应的用户账号相关信息,到用户离职用户账号归档的整个过程,都在统一身份认证平台上完成,在用户账户全生命周期中,当统一身份认证平台监测到用户账号属性信息发生变更,比如用户职位调动或用户离职,和/或出现异常操作时,统一身份认证平台会对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,以限制用户的访问操作权限,统一身份认证平台作为对接所有应用的唯一数据源,会将访问操作权限修改的目标用户账号相关信息同步至对接的所有应用中,从而实现统一身份认证平台与对接的所有应用的同步更新,因此,本发明通过统一身份认证平台实现了对用户账户全生命周期所有操作行为进行监控,从而提高了信息系统的运维管理水平。To sum up, the monitoring method for the full life cycle of a user account disclosed in the present invention creates user account related information on the front-end unified identity authentication platform, and the user account related information includes: user account and corresponding user account attribute information and access operation authority , when the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the access operation authority of the target user account whose user account attribute information is changed and/or abnormal operation occurs shall be modified, and the access operation authority shall be modified. The relevant information of the target user account modified by the operation authority is synchronized to all applications connected to the unified identity authentication platform. In the present invention, the entire process from the user's entry to create the corresponding user account-related information to the user's resignation and the user account filing is completed on the unified identity authentication platform. When the information changes, such as the user's position transfer or the user's resignation, and/or abnormal operation, the unified identity authentication platform will modify the access operation authority of the target user account whose user account attribute information changes and/or abnormal operation occurs, so as to Restricting the user's access and operation authority, the unified identity authentication platform, as the only data source for connecting all applications, will synchronize the relevant information of the target user account modified by the access operation authority to all the connected applications, so as to realize the unified identity authentication platform and all connected applications. The application is updated synchronously. Therefore, the present invention realizes the monitoring of all operation behaviors in the whole life cycle of the user account through a unified identity authentication platform, thereby improving the operation and maintenance management level of the information system.
在实际应用中,本发明在前端的统一身份认证平台上创建用户账号相关信息主要有两种方式,第一种为同步用户账号相关信息,第二种为在统一身份认证平台上直接创建用户账号相关信息。In practical application, the present invention mainly has two ways to create user account-related information on the front-end unified identity authentication platform, the first is to synchronize user account-related information, and the second is to directly create user accounts on the unified identity authentication platform Related Information.
因此,步骤S101具体可以包括:Therefore, step S101 may specifically include:
通过同步引擎、事务机制和预设通信协议,从AD域或OA系统同步已有用户账号相关信息至所述统一身份认证平台,实现所述用户账号相关信息的创建。Through the synchronization engine, the transaction mechanism and the preset communication protocol, the existing user account related information is synchronized from the AD domain or the OA system to the unified identity authentication platform, so as to realize the creation of the user account related information.
在同步过程中,可以对用户账号相关信息的同步成功信息和同步失败信息进行多维度记录。同步成功信息可以报告形式输出,以方便系统管理员查看,同步失败信息可以通过定时器机制,再次触发同步过程,直至同步成功。During the synchronization process, the synchronization success information and synchronization failure information of the user account related information can be recorded in multiple dimensions. The synchronization success information can be output in the form of a report to facilitate the system administrator to view, and the synchronization failure information can trigger the synchronization process again through the timer mechanism until the synchronization is successful.
步骤S101具体还可以包括:Step S101 may also specifically include:
采用预设统一账户命名规范,在统一身份认证平台上新建用户账号;Use the preset unified account naming specification to create a new user account on the unified identity authentication platform;
为新建的所述用户账号添加对应的用户账号属性信息,并分配对应的访问操作权限。Corresponding user account attribute information is added to the newly created user account, and corresponding access operation authority is assigned.
需要说明的是,新建的用户账号为确定用户身份的唯一信息,因此,为防止出现重名,本发明对用户账号定义了同一账户命名规范。It should be noted that the newly created user account is the only information for determining the user's identity. Therefore, in order to prevent duplicate names, the present invention defines the same account naming specification for the user account.
其中,采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号,具体包括:Wherein, a preset unified account naming specification is adopted to create a new user account on the unified identity authentication platform, which specifically includes:
将用户姓名拼音中的声母和韵母进行排列组合,同时结合统一码(Unicode)编码表得到初始用户账号;Arrange and combine the initials and finals in the pinyin of the user's name, and obtain the initial user account in combination with the Unicode encoding table;
将所述初始用户账号发送至服务器端,由所述服务器端校验所述初始用户账号的唯一性及合法性;sending the initial user account to the server, and the server verifies the uniqueness and legitimacy of the initial user account;
接收所述服务器端反馈的校验通过指令,将所述初始用户账号确定为在所述统一身份认证平台上新建的用户账号。Receive the verification passing instruction fed back by the server, and determine the initial user account as a newly created user account on the unified identity authentication platform.
需要说明的是,当服务器端检测出初始用户账号存在重复用户账号时,为保证用户账号的唯一性,服务器端会在初始用户账号后叠加具有唯一性的随机数对初始用户账号进行修改,并将修改后的初始用户账号反馈给前端。It should be noted that when the server side detects that there are duplicate user accounts in the initial user account, in order to ensure the uniqueness of the user account, the server side will superimpose a unique random number after the initial user account to modify the initial user account, and Feed back the modified initial user account to the front end.
其中,随机数可以为任意具有唯一性的随机数,比如为100以内具有唯一性的随机数,具体依据实际需要而定,本发明在此不做限定。The random number may be any unique random number, for example, a unique random number within 100, which is determined according to actual needs, which is not limited in the present invention.
因此,采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号,具体还可以包括:Therefore, using the preset unified account naming specification, creating a new user account on the unified identity authentication platform may further include:
接收所述服务器端反馈的已修改用户账号,将所述已修改用户账号确定为在所述统一身份认证平台上新建的用户账号,其中,所述已修改用户账号为所述服务器端在判定所述初始用户账号存在重复时,在所述初始用户账号后叠加具有唯一性的随机数后生成。Receive the modified user account fed back by the server, and determine the modified user account as a newly created user account on the unified identity authentication platform, wherein the modified user account is determined by the server side. When the initial user account is repeated, a unique random number is superimposed on the initial user account and generated.
当在统一身份认证平台上创建完用户账号相关信息后,便可以通过统一身份认证平台来维护用户账号相关信息,除了用户账号、姓名等可以用来确定用户身份信息的唯一性和不可更改性,统一身份认证平台可以针对其他用户信息进行自定义扩展,如邮箱、手机号、职位、住址等信息,以完善用户账号信息。系统管理员拥有对统一身份认证平台的最高操作权限,在实际应用中,可以由系统管理员根据实际需求在统一身份认证平台上对用户账号属性信息进行扩展。After the user account related information is created on the unified identity authentication platform, the user account related information can be maintained through the unified identity authentication platform, except that the user account number and name can be used to determine the uniqueness and immutability of the user identity information. The unified identity authentication platform can customize and expand other user information, such as email, mobile phone number, position, address and other information to improve user account information. The system administrator has the highest operating authority on the unified identity authentication platform. In practical applications, the system administrator can expand the user account attribute information on the unified identity authentication platform according to actual needs.
因此,为进一步优化上述实施例,监控方法还可以包括:Therefore, in order to further optimize the above embodiment, the monitoring method may further include:
当系统管理员账号登录所述统一身份认证平台后,接收所述系统管理员账号发送对所述用户账号属性信息的扩展信息;After the system administrator account logs in to the unified identity authentication platform, receiving the extension information sent by the system administrator account to the attribute information of the user account;
将所述扩展信息添加至所述用户账号属性信息中,并将添加所述扩展信息的用户账号属性信息同步至与统一身份认证平台对接的所有应用中。The extended information is added to the user account attribute information, and the user account attribute information added with the extended information is synchronized to all applications connected to the unified identity authentication platform.
在实际应用中,还可以通过统一身份认证平台实现用户账号全生命周期管理,可以根据现有的人员部门、组信息、类别,进行组织机构建立或同步工作,选择组织机构,获取组织机构的所有成员列表,在成员列表界面可以添加、修改、删除公司部门信息、人员信息以及同步人员信息到统一身份认证平台对接的所有应用中。In practical applications, the whole life cycle management of user accounts can also be realized through a unified identity authentication platform, and organizations can be established or synchronized according to the existing personnel department, group information, and categories, select an organization, and obtain all the organization's information Member list, in the member list interface, you can add, modify, delete company department information, personnel information, and synchronize personnel information to all applications connected to the unified identity authentication platform.
系统管理员在统一身份认证平台上定义好用户账号属性信息(属性字段)后,不仅可以通过已有用户账号相关信息维护,还可以由用户通过PC端、移动端用户自主修改除用户账号、姓名等唯一确定用户身份信息以外的所有信息,如职务、住址等。当职务、住址等其他信息发生变更后,用户可以不通知系统管理员去修改,用户自己登陆统一身份认证平台后进行修改,修改信息发送至系统管理员进行审核,审核内容可以包括:修改内容是否有效,修改格式是否正确,职位信息调用是否正确,等等。当用户修改内容审核通过后便立即生效。修改内容若与统一身份认证平台对接的所有应用存在关联,则统一身份认证平台将修改后的用户账号相关信息同步至对接的所有应用中。After the system administrator defines the user account attribute information (attribute field) on the unified identity authentication platform, not only can it be maintained through the relevant information of the existing user account, but also the user can independently modify the user account and name through the PC terminal and mobile terminal. and so on to uniquely identify all information other than user identity information, such as job title, address, etc. When other information such as job title and address is changed, the user can modify it without notifying the system administrator. The user can modify it after logging in to the unified identity authentication platform. The modified information is sent to the system administrator for review. The review content can include: whether the modified content is Valid, whether the modification format is correct, whether the job information call is correct, and so on. When the user's modification content is approved, it will take effect immediately. If the modified content is associated with all applications connected to the unified identity authentication platform, the unified identity authentication platform will synchronize the modified user account related information to all connected applications.
因此,为进一步优化上述实施例,监控方法还可以包括:Therefore, in order to further optimize the above embodiment, the monitoring method may further include:
接收已登录所述统一身份认证平台的用户账号发送的针对所述用户账号相关信息的修改内容;Receive the modified content for the relevant information of the user account sent by the user account that has logged in to the unified identity authentication platform;
将所述修改内容发送至系统管理员端进行有效性审核,其中,有效性审核内容至少包括:所述修改内容是否为所述用户账号相关信息中除用户账号唯一身份标识以外的信息;Send the modified content to the system administrator for validity review, wherein the validity review content at least includes: whether the modified content is information other than the user account unique identifier in the user account-related information;
接收所述系统管理员端反馈的有效性审核通过指令,根据所述修改内容对所述用户账号相关信息进行修改,并将修改后的用户账号相关信息同步至与统一身份认证平台对接的所有应用中。Receive the validity review instruction fed back by the system administrator, modify the user account related information according to the modified content, and synchronize the modified user account related information to all applications connected to the unified identity authentication platform middle.
需要说明的是,如果系统管理员发现修改内容有误或者不正确,将不予审核通过,此时,系统管理员通过统一身份认证平台发送邮件给用户告知审核不通过,且说明审核不通过原因。待用户修改后重新提交,系统管理员再次进行审核,直至修改内容审核通过或用户放弃修改。针对修改内容,系统可以提供完善的修改记录及用户操作行为信息。It should be noted that if the system administrator finds that the modified content is wrong or incorrect, the review will not be approved. At this time, the system administrator will send an email to the user through the unified identity authentication platform to inform the user that the review is not approved, and explain the reason for the failure to pass the review. . After the user has modified it and resubmitted it, the system administrator will review it again until the modified content is approved or the user abandons the modification. For the modified content, the system can provide complete modification records and user operation behavior information.
与上述方法实施例相对应,本发明还公开了一种用户账号全生命周期的监控装置。Corresponding to the above method embodiments, the present invention also discloses a monitoring device for the full life cycle of a user account.
参见图2,本发明实施例公开的一种用户账号全生命周期监控装置的结构示意图,该装置包括:Referring to FIG. 2, a schematic structural diagram of a user account full life cycle monitoring device disclosed in an embodiment of the present invention, the device includes:
信息创建单元201,用于在前端的统一身份认证平台上创建用户账号相关信息,所述用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限;The
本实施例中,统一身份认证平台与多个应用系统对接,其中,对接应用系统包括但不限于AD(Active Directory,活动目录)域、OA(Office Automation,办公自动化)系统和对接的所有应用。In this embodiment, the unified identity authentication platform is interconnected with multiple application systems, wherein the interconnected application systems include but are not limited to AD (Active Directory, Active Directory) domains, OA (Office Automation, Office Automation) systems, and all interconnected applications.
其中,统一身份认证平台与多个应用系统之间采用预设通信协议建立通信连接,预设通信协议可以包括:SCIM(System for Cross-domain Identity Management,跨域身份管理系统)、JNDI(Java Naming and Directory Interface,Java命名和目录接口)和LDAP(Lightweight Directory Access Protocol,轻型目录访问协议)。Wherein, a communication connection is established between the unified identity authentication platform and multiple application systems using a preset communication protocol, and the preset communication protocol may include: SCIM (System for Cross-domain Identity Management, cross-domain identity management system), JNDI (Java Naming and Directory Interface, Java naming and directory interface) and LDAP (Lightweight Directory Access Protocol, Lightweight Directory Access Protocol).
用户账号属性信息可以包括:邮箱、手机号、职位和家庭住址等。The attribute information of the user account may include: email address, mobile phone number, position, and home address, and the like.
权限修改单元202,用于当通过所述统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,其中,所述用户账号属性信息发生变更包括用户职位调用和用户离职;The
用户在统一身份认证平台创建对应的用户账号相关信息,系统管理员为用户账号配置对应的用户账号属性信息和访问操作权限后,用户账号就可以根据具有的访问操作权限访问应用及资源。The user creates the corresponding user account related information on the unified identity authentication platform. After the system administrator configures the corresponding user account attribute information and access operation authority for the user account, the user account can access applications and resources according to the access operation authority.
系统管理员:登录统一身份认证平台后拥有最高权限,能够添加维护用户、用户组织和用户组,分配用户访问操作权限以及对用户整个生命周期的管理维护,还可以负责审批用户自主修改的除账户及姓名外的所有自身属性信息。System administrator: After logging in to the unified identity authentication platform, he has the highest authority, can add and maintain users, user organizations and user groups, assign user access and operation authority, manage and maintain the entire user life cycle, and can also be responsible for approving the user's self-modified removal account and all self-attribute information other than the name.
统一身份认证平台根据自身设置的安全访问策略及风控系统维护整个统一身份认证平台的正常运行。The unified identity authentication platform maintains the normal operation of the entire unified identity authentication platform according to its own security access policy and risk control system.
具体的,用户账号属性信息发生变更,比如,用户离职(用户一旦提交离职流程便会触发系统策略)、用户账号属性变更(如通过非正常渠道对用户属性进行篡改来增大访问权限)。Specifically, the user account attribute information changes, for example, the user resigns (the system policy will be triggered once the user submits the resignation process), and the user account attribute changes (such as tampering with the user attribute through abnormal channels to increase access rights).
异常操作包括:用户账号频繁登录统一身份认证平台、多次异地登录和多终端频繁登录,等等。当出现异常操作时会引起统一身份认证平台的安全风控反应机制。Abnormal operations include: frequent user account logins to the unified identity authentication platform, multiple remote logins and frequent logins from multiple terminals, etc. When an abnormal operation occurs, the security risk control response mechanism of the unified identity authentication platform will be triggered.
当通过统一身份认证平台监测到用户账号属性信息发生变更和/或出现异常操作时,系统便根据已有的任务机制或安全策略,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,并将访问操作权限修改的目标用户账号相关信息同步至与统一身份认证平台对接的所有应用中。也即,在对访问操作权限修改后会第一时间通知对接的所有应用,使修改后的访问操作权限立即生效,以将统一身份认证平台的损失降至最低或防患于未然。整个过程用户是无感知的,完全由系统自动完成。When the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the system will, according to the existing task mechanism or security policy, identify the target user whose user account attribute information is changed and/or abnormal operation occurs. The access operation authority of the account is modified, and the relevant information of the target user account whose access operation authority is modified is synchronized to all applications connected to the unified identity authentication platform. That is, after the access operation authority is modified, all connected applications will be notified as soon as possible, so that the modified access operation authority will take effect immediately, so as to minimize the loss of the unified identity authentication platform or prevent problems before they occur. The entire process is unaware of the user and is completely automated by the system.
信息同步单元203,用于将访问操作权限修改的目标用户账号相关信息同步至与所述统一身份认证平台对接的所有应用中,其中,所述目标用户账号相关信息包括:所述目标用户账号及对应的目标用户账号属性信息和目标用户账号访问操作权限。The
综上可知,本发明公开的用户账号全生命周期的监控装置,在前端的统一身份认证平台上创建用户账号相关信息,用户账号相关信息包括:用户账号及对应的用户账号属性信息和访问操作权限,当通过统一身份认证平台上监测到用户账号属性信息发生变更和/或出现异常操作时,对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,将访问操作权限修改的目标用户账号相关信息同步至与统一身份认证平台对接的所有应用中。本发明从用户入职创建对应的用户账号相关信息,到用户离职用户账号归档的整个过程,都在统一身份认证平台上完成,在用户账户全生命周期中,当统一身份认证平台监测到用户账号属性信息发生变更,比如用户职位调动或用户离职,和/或出现异常操作时,统一身份认证平台会对用户账号属性信息发生变更和/或出现异常操作的目标用户账号的访问操作权限进行修改,以限制用户的访问操作权限,统一身份认证平台作为对接所有应用的唯一数据源,会将访问操作权限修改的目标用户账号相关信息同步至对接的所有应用中,从而实现统一身份认证平台与对接的所有应用的同步更新,因此,本发明通过统一身份认证平台实现了对用户账户全生命周期所有操作行为进行监控,从而提高了信息系统的运维管理水平。To sum up, the monitoring device for the full life cycle of a user account disclosed in the present invention creates user account related information on the front-end unified identity authentication platform, and the user account related information includes: user account and corresponding user account attribute information and access operation authority , when the user account attribute information is changed and/or abnormal operation is detected through the unified identity authentication platform, the access operation authority of the target user account whose user account attribute information is changed and/or abnormal operation occurs shall be modified, and the access operation authority shall be modified. The relevant information of the target user account modified by the operation authority is synchronized to all applications connected to the unified identity authentication platform. In the present invention, the entire process from the user's entry to create the corresponding user account-related information to the user's resignation and the user account filing is completed on the unified identity authentication platform. When the information changes, such as the user's position transfer or the user's resignation, and/or abnormal operation, the unified identity authentication platform will modify the access operation authority of the target user account whose user account attribute information changes and/or abnormal operation occurs, so as to Restricting the user's access and operation authority, the unified identity authentication platform, as the only data source for connecting all applications, will synchronize the relevant information of the target user account modified by the access operation authority to all the connected applications, so as to realize the unified identity authentication platform and all connected applications. The application is updated synchronously. Therefore, the present invention realizes the monitoring of all operation behaviors in the whole life cycle of the user account through a unified identity authentication platform, thereby improving the operation and maintenance management level of the information system.
在实际应用中,本发明在前端的统一身份认证平台上创建用户账号相关信息主要有两种方式,第一种为同步用户账号相关信息,第二种为在统一身份认证平台上直接创建用户账号相关信息。In practical application, the present invention mainly has two ways to create user account-related information on the front-end unified identity authentication platform, the first is to synchronize user account-related information, and the second is to directly create user accounts on the unified identity authentication platform Related Information.
因此信息创建单元201具体可以包括:Therefore, the
第一信息创建子单元,用于通过同步引擎、事务机制和预设通信协议,从活动目录AD域或办公自动化OA系统同步已有用户账号相关信息至所述统一身份认证平台,实现所述用户账号相关信息的创建。The first information creation subunit is used for synchronizing the relevant information of existing user accounts from the Active Directory AD domain or the office automation OA system to the unified identity authentication platform through the synchronization engine, the transaction mechanism and the preset communication protocol, so as to realize the user Creation of account-related information.
在同步过程中,可以对用户账号相关信息的同步成功信息和同步失败信息进行多维度记录。同步成功信息可以报告形式输出,以方便系统管理员查看,同步失败信息可以通过定时器机制,再次触发同步过程,直至同步成功。During the synchronization process, the synchronization success information and synchronization failure information of the user account related information can be recorded in multiple dimensions. The synchronization success information can be output in the form of a report to facilitate the system administrator to view, and the synchronization failure information can be triggered again through the timer mechanism until the synchronization is successful.
因此,信息创建单元还可以包括:Therefore, the information creation unit may also include:
信息记录子单元,用于对所述用户账号相关信息的同步成功信息和同步失败信息进行多维度记录。The information recording subunit is used for multi-dimensional recording of the synchronization success information and synchronization failure information of the user account related information.
在统一身份认证平台上直接创建用户账号相关信息时,信息创建单元201具体还包括:When directly creating user account related information on the unified identity authentication platform, the
第二信息创建子单元,用于采用预设统一账户命名规范,在所述统一身份认证平台上新建用户账号;The second information creation subunit is used to create a new user account on the unified identity authentication platform by adopting a preset unified account naming specification;
权限分配子单元,用于为新建的所述用户账号添加对应的用户账号属性信息,并分配对应的访问操作权限。The authority assignment subunit is used for adding corresponding user account attribute information to the newly created user account, and assigning corresponding access operation authority.
需要说明的是,新建的用户账号为确定用户身份的唯一信息,因此,为防止出现重名,本发明对用户账号定义了同一账户命名规范。It should be noted that the newly created user account is the only information for determining the user's identity. Therefore, in order to prevent duplicate names, the present invention defines the same account naming specification for the user account.
因此,第二信息创建子单元具体用于:Therefore, the second information creation subunit is specifically used for:
将用户姓名拼音中的声母和韵母进行排列组合,同时结合统一码编码表得到初始用户账号;Arrange and combine the initials and finals in the pinyin of the user's name, and obtain the initial user account in combination with the Unicode code table;
将所述初始用户账号发送至服务器端,由所述服务器端校验所述初始用户账号的唯一性及合法性;sending the initial user account to the server, and the server verifies the uniqueness and legitimacy of the initial user account;
接收所述服务器端反馈的校验通过指令,将所述初始用户账号确定为在所述统一身份认证平台上新建的用户账号。Receive the verification passing instruction fed back by the server, and determine the initial user account as a newly created user account on the unified identity authentication platform.
需要说明的是,当服务器端检测出初始用户账号存在重复用户账号时,为保证用户账号的唯一性,服务器端会在初始用户账号后叠加具有唯一性的随机数对初始用户账号进行修改,并将修改后的初始用户账号反馈给前端。It should be noted that when the server side detects that there is a duplicate user account in the initial user account, in order to ensure the uniqueness of the user account, the server side will superimpose a unique random number after the initial user account to modify the initial user account, and Feedback the modified initial user account to the front end.
其中,随机数可以为任意具有唯一性的随机数,比如为100以内具有唯一性的随机数,具体依据实际需要而定,本发明在此不做限定。The random number may be any unique random number, such as a unique random number within 100, which is determined according to actual needs, and is not limited in the present invention.
因此,第二信息创建子单元具体还用于:Therefore, the second information creation subunit is specifically also used for:
接收所述服务器端反馈的已修改用户账号,将所述已修改用户账号确定为在所述统一身份认证平台上新建的用户账号,其中,所述已修改用户账号为所述服务器端在判定所述初始用户账号存在重复时,在所述初始用户账号后叠加具有唯一性的随机数后生成。Receive the modified user account fed back by the server, and determine the modified user account as a newly created user account on the unified identity authentication platform, wherein the modified user account is determined by the server side. When the initial user account is repeated, a unique random number is superimposed on the initial user account and generated.
当在统一身份认证平台上创建完用户账号相关信息后,便可以通过统一身份认证平台来维护用户账号相关信息,除了用户账号、姓名等可以用来确定用户身份信息的唯一性和不可更改性,统一身份认证平台可以针对其他用户信息进行自定义扩展,如邮箱、手机号、职位、住址等信息,以完善用户账号信息。系统管理员拥有对统一身份认证平台的最高操作权限,在实际应用中,可以由系统管理员根据实际需求在统一身份认证平台上对用户账号属性信息进行扩展。After the user account related information is created on the unified identity authentication platform, the user account related information can be maintained through the unified identity authentication platform, except that the user account number, name, etc. can be used to determine the uniqueness and immutability of the user identity information. The unified identity authentication platform can customize and expand other user information, such as email, mobile phone number, position, address and other information to improve user account information. The system administrator has the highest operating authority on the unified identity authentication platform. In practical applications, the system administrator can expand the user account attribute information on the unified identity authentication platform according to actual needs.
因此,为进一步优化上述实施例,监控装置还可以包括:Therefore, in order to further optimize the above embodiment, the monitoring device may further include:
扩展信息接收单元,用于当系统管理员账号登录所述统一身份认证平台后,接收所述系统管理员账号发送对所述用户账号属性信息的扩展信息;an extension information receiving unit, configured to receive extension information sent by the system administrator account to the attribute information of the user account after the system administrator account logs in to the unified identity authentication platform;
扩展信息添加单元,用于将所述扩展信息添加至所述用户账号属性信息中,并将添加所述扩展信息的用户账号属性信息同步至与所述统一身份认证平台所述对接的所有应用中。An extension information adding unit, configured to add the extension information to the user account attribute information, and synchronize the user account attribute information added with the extension information to all applications connected to the unified identity authentication platform .
在实际应用中,还可以通过统一身份认证平台实现用户账号全生命周期管理,可以根据现有的人员部门、组信息、类别,进行组织机构建立或同步工作,选择组织机构,获取组织机构的所有成员列表,在成员列表界面可以添加、修改、删除公司部门信息、人员信息以及同步人员信息到统一身份认证平台对接的所有应用中。In practical applications, the whole life cycle management of user accounts can also be realized through a unified identity authentication platform, and organizations can be established or synchronized according to the existing personnel department, group information, and categories, select an organization, and obtain all the organization's information Member list, in the member list interface, you can add, modify, delete company department information, personnel information, and synchronize personnel information to all applications connected to the unified identity authentication platform.
系统管理员在统一身份认证平台上定义好用户账号属性信息(属性字段)后,不仅可以通过已有用户账号相关信息维护,还可以由用户通过PC端、移动端用户自主修改除用户账号、姓名等唯一确定用户身份信息以外的所有信息,如职务、住址等。当职务、住址等其他信息发生变更后,用户可以不通知系统管理员去修改,用户自己登陆统一身份认证平台后进行修改,修改信息发送至系统管理员进行审核,审核内容可以包括:修改内容是否有效,修改格式是否正确,职位信息调用是否正确,等等。当用户修改内容审核通过后便立即生效。修改内容若与统一身份认证平台对接的所有应用存在关联,则统一身份认证平台将修改后的用户账号相关信息同步至对接的所有应用中。After the system administrator defines the user account attribute information (attribute field) on the unified identity authentication platform, not only can it be maintained through the relevant information of the existing user account, but also the user can independently modify the user account and name through the PC terminal and mobile terminal. and so on to uniquely identify all information other than user identity information, such as job title, address, etc. When other information such as job title and address is changed, the user can modify it without notifying the system administrator. The user can modify it after logging in to the unified identity authentication platform. The modified information is sent to the system administrator for review. The review content can include: whether the modified content is Valid, whether the modification format is correct, whether the job information call is correct, and so on. When the user's modification content is approved, it will take effect immediately. If the modified content is associated with all applications connected to the unified identity authentication platform, the unified identity authentication platform will synchronize the modified user account related information to all connected applications.
因此,为进一步优化上述实施例,监控装置还可以包括:Therefore, in order to further optimize the above embodiment, the monitoring device may further include:
修改内容接收单元,用于接收已登录所述统一身份认证平台的用户账号发送的针对所述用户账号相关信息的修改内容;a modified content receiving unit, configured to receive the modified content for the relevant information of the user account sent by the user account that has logged in to the unified identity authentication platform;
修改内容审核单元,用于将所述修改内容发送至系统管理员端进行有效性审核,其中,有效性审核内容至少包括:所述修改内容是否为所述用户账号相关信息中除用户账号唯一身份标识以外的信息;A modified content review unit, configured to send the modified content to a system administrator for validity review, wherein the validity review content at least includes: whether the modified content is the unique identity of the user account other than the user account related information Information other than identification;
修改内容同步单元,用于接收所述系统管理员端反馈的有效性审核通过指令,根据所述修改内容对所述用户账号相关信息进行修改,并将修改后的用户账号相关信息同步至与所述统一身份认证平台所述对接的所有应用中。The modification content synchronization unit is used to receive the validity review and approval instruction fed back by the system administrator, modify the user account related information according to the modification content, and synchronize the modified user account related information to the relevant information of the user account. All applications connected to the unified identity authentication platform described above.
需要说明的是,如果系统管理员发现修改内容有误或者不正确,将不予审核通过,此时,系统管理员通过统一身份认证平台发送邮件给用户告知审核不通过,且说明审核不通过原因。待用户修改后重新提交,系统管理员再次进行审核,直至修改内容审核通过或用户放弃修改。针对修改内容,系统可以提供完善的修改记录及用户操作行为信息。It should be noted that if the system administrator finds that the modified content is wrong or incorrect, the review will not be approved. At this time, the system administrator will send an email to the user through the unified identity authentication platform to inform the user that the review is not approved, and explain the reason for the failure to pass the review. . After the user has modified it and resubmitted it, the system administrator will review it again until the modified content is approved or the user abandons the modification. For the modified content, the system can provide complete modification records and user operation behavior information.
最后,还需要说明的是,在本文中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。Finally, it should also be noted that in this document, relational terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply these entities or that there is any such actual relationship or sequence between operations. Moreover, the terms "comprising", "comprising" or any other variation thereof are intended to encompass a non-exclusive inclusion such that a process, method, article or device that includes a list of elements includes not only those elements, but also includes not explicitly listed or other elements inherent to such a process, method, article or apparatus. Without further limitation, an element qualified by the phrase "comprising a..." does not preclude the presence of additional identical elements in a process, method, article or apparatus that includes the element.
本说明书中各个实施例采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似部分互相参见即可。The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same and similar parts between the various embodiments can be referred to each other.
对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本发明。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本发明的精神或范围的情况下,在其它实施例中实现。因此,本发明将不会被限制于本文所示的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。The above description of the disclosed embodiments enables any person skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the generic principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Thus, the present invention is not intended to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims (16)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011533368.6A CN114662084A (en) | 2020-12-23 | 2020-12-23 | Method and device for monitoring full life cycle of user account |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011533368.6A CN114662084A (en) | 2020-12-23 | 2020-12-23 | Method and device for monitoring full life cycle of user account |
Publications (1)
Publication Number | Publication Date |
---|---|
CN114662084A true CN114662084A (en) | 2022-06-24 |
Family
ID=82024504
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011533368.6A Pending CN114662084A (en) | 2020-12-23 | 2020-12-23 | Method and device for monitoring full life cycle of user account |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN114662084A (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN114745203A (en) * | 2022-05-13 | 2022-07-12 | 长扬科技(北京)有限公司 | Method and device for monitoring full life cycle of user account |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109388921A (en) * | 2017-08-10 | 2019-02-26 | 顺丰科技有限公司 | A kind of unification user rights management platform and operation method |
CN110070285A (en) * | 2019-04-19 | 2019-07-30 | 成都飞机工业(集团)有限责任公司 | A kind of application system user (asu) administrative center system and its working method |
CN110175439A (en) * | 2019-05-29 | 2019-08-27 | 深圳前海微众银行股份有限公司 | User management method, device, equipment and computer readable storage medium |
-
2020
- 2020-12-23 CN CN202011533368.6A patent/CN114662084A/en active Pending
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109388921A (en) * | 2017-08-10 | 2019-02-26 | 顺丰科技有限公司 | A kind of unification user rights management platform and operation method |
CN110070285A (en) * | 2019-04-19 | 2019-07-30 | 成都飞机工业(集团)有限责任公司 | A kind of application system user (asu) administrative center system and its working method |
CN110175439A (en) * | 2019-05-29 | 2019-08-27 | 深圳前海微众银行股份有限公司 | User management method, device, equipment and computer readable storage medium |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN114745203A (en) * | 2022-05-13 | 2022-07-12 | 长扬科技(北京)有限公司 | Method and device for monitoring full life cycle of user account |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11381572B2 (en) | Pervasive intermediate network attached storage application | |
US11522850B2 (en) | Cluster claim | |
US10917408B2 (en) | Secure document management through verification of security states of information processing apparatuses in peer-to-peer transmission of encrypted documents | |
US10003458B2 (en) | User key management for the secure shell (SSH) | |
US7577689B1 (en) | Method and system to archive data | |
CN103098070B (en) | For the methods, devices and systems of Data Position in monitoring network service | |
US20200145427A1 (en) | Reducing risks associated with recertification of dormant accounts | |
CN103875211B (en) | A kind of internet account number management method, manager, server and system | |
US10715502B2 (en) | Systems and methods for automating client-side synchronization of public keys of external contacts | |
CN101753313A (en) | Password management method, password management system and password management server | |
JP2006510991A (en) | Distributed content management system | |
JP6819748B2 (en) | Information processing equipment, information processing systems and programs | |
CN108289074B (en) | User account login method and device | |
USRE45046E1 (en) | Media device access control mechanism | |
CN114662084A (en) | Method and device for monitoring full life cycle of user account | |
WO2020212784A1 (en) | Destination addressing associated with a distributed ledger | |
CN110210192A (en) | Approaches to IM, device, equipment and readable storage medium storing program for executing | |
CN114065183A (en) | Authority control method and device, electronic equipment and storage medium | |
CN110741371A (en) | Information processing apparatus, protection processing apparatus, and usage terminal | |
CN113612865A (en) | Method, device and equipment for managing cloud platform LDAP domain account and readable medium | |
WO2014084981A1 (en) | Assigning electronically purchased items of content to users | |
CN114745203A (en) | Method and device for monitoring full life cycle of user account | |
WO2013111532A1 (en) | Administration system, administration method, and program | |
US9424405B2 (en) | Using receipts to control assignments of items of content to users | |
CN115150191A (en) | Cross-region cloud management platform information interaction method and related components |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination |