IP Library Granted Patent US 12683963
Granted Patent B2
US 12683963 · App. 18/598,891 · Granted Jul 14, 2026

Resource access control method, medium and electric device based on an authentication request

Inventor: Shihang Zhong (Beijing, CN)
Assignee: BEIJING VOLCANO ENGINE TECHNOLOGY CO., LTD.
H04L63/10H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683963
App. No.
18/598,891
Granted
Jul 14, 2026
Kind
B2
Abstract

The present disclosure provides a resource access control method, an apparatus, a medium, and an electronic device, the method is to acquire historical resource access information and historical security status information of a target object from a business system according to identity information of the target object, and determine access permission information of the target object for the target resource according to the historical resource access information and the historical security status information, and then send the access permission information to the business system, to enable the business system to determine the operation for the resource access request according to the access permission information.

Claims (64)

1 . A resource access control method, applied to a network control device, comprising:

receiving an authentication request sent by a business system, wherein the authentication request is sent by the business system in a case that the business system determines a first resource to be accessed by a first object belonging to a resource of a first type according to a resource access request sent by the first object, and the authentication request comprises identity information of the first object and the first resource to be accessed by the first object;

acquiring historical resource access information and historical security status information of the first object from the business system according to the identity information of the first object, in response to the authentication request;

determining access permission information of the first object for the first resource according to the historical resource access information and the historical security status information; and

sending the access permission information to the business system, wherein the access permission information is used to enable the business system to determine an operation for the resource access request according to the access permission information;

wherein the determining the access permission information of the first object for the first resource according to the historical resource access information and the historical security status information, comprises:

determining a first risk item triggered by the first object, according to the historical resource access information and the historical security status information and in conjunction with a preset mapping relationship, wherein the mapping relationship comprises a corresponding relationship between different combinations of the historical resource access information and the historical security status information, and different risk items; and

determining the access permission information of the first object for the first resource according to the first risk item.

2 . The method according to claim 1 , further comprising:

in a case that security status information of the first object accessing the business system changes, determining a data access strategy of the target-first object according to the security status information, wherein the data access strategy comprises a resource that the first object is able to access and a resource that the first object is unable to access; and

sending the data access strategy to the business system, wherein the data access strategy is used to enable the business system to determine access permissions of the first object for resources in the business system other than the resource of the first type according to the data access strategy.

3 . The method according to claim 2 , further comprising:

obtaining permission change information according to the data access strategy, wherein the permission change information is used to represent that a resource access permission of the first object for the business system has been changed; and

sending the permission change information to the business system, wherein the permission change information is used to enable the business system to send the permission change information to a terminal device of the first object through a long connection channel between the business system and the terminal device, to display the permission change information on the terminal device.

4 . The method according to claim 1 , further comprising:

in a case that security status information of the first object accessing the business system changes, determining a data access strategy of the first object according to the security status information, wherein the data access strategy comprises a resource that the first object is able to access and a resource that the first object is unable to access; and

sending the data access strategy to the business system, wherein the data access strategy is used to enable the business system to determine access permissions of the first object for resources in the business system other than the resource of the first type according to the data access strategy.

5 . The method according to claim 4 , further comprising:

obtaining permission change information according to the data access strategy, wherein the permission change information is used to represent that a resource access permission of the first object for the business system has been changed; and

sending the permission change information to the business system, wherein the permission change information is used to enable the business system to send the permission change information to a terminal device of the first object through a long connection channel between the business system and the terminal device, to display the permission change information on the terminal device.

6 . A non-transitory computer-readable medium, storing a computer program, wherein in a case that the computer program is executed by a processing apparatus, the resource access control method according to claim 1 is implemented.

7 . A resource access control method, applied to a business system, comprising:

receiving a resource access request sent by a first object, wherein the resource access request is used to request access to a first resource;

in a case that the first resource belongs to a resource of a first type, sending an authentication request to a network control device, wherein the authentication request comprises identity information of the first object and the first resource to be accessed by the first object, and the authentication request is used to enable the network control device to acquire historical resource access information and historical security status information of the first object from the business system according to the identity information of the first object, determine access permission information of the first object for the first resource according to the historical resource access information and the historical security status information, and send the access permission information to the business system; and

upon receiving the access permission information sent by a network security device, determining an operation for the resource access request according to the access permission information;

wherein the authentication request is further used to enable the network control device to determine a first risk item triggered by the first object, according to the historical resource access information and the historical security status information and in conjunction with a preset mapping relationship, and determine the access permission information of the first object for the first resource according to the first risk item; wherein the mapping relationship comprises a corresponding relationship between different combinations of the historical resource access information and the historical security status information, and different risk items.

8 . The method according to claim 7 , further comprising:

upon receiving a data access strategy of the first object sent by the network control device, determining access permissions of the first object for resources in the business system other than the resource of the first type according to the data access strategy,

wherein the data access strategy is determined by the network control device according to security status information of the first object accessing the business system in a case that the security status information of the first object changes, and the data access strategy comprises a resource that the first object is able to access and a resource that the first object is unable to access.

9 . The method according to claim 8 , further comprising:

upon receiving permission change information sent by the network control device, sending the permission change information to a terminal device of the first object through a long connection channel between the business system and the terminal device to display the permission change information on the terminal device,

wherein the permission change information is generated by the network control device according to the data access strategy, and the permission change information is used to represent that a resource access permission of the first object for the business system has been changed.

10 . An electronic device, comprising:

a storage apparatus, storing a computer program; and

a processing apparatus for executing the computer program in the storage apparatus to implement the resource access control method according to claim 9 .

11 . An electronic device, comprising:

a storage apparatus, storing a computer program; and

a processing apparatus for executing the computer program in the storage apparatus to implement the resource access control method according to claim 8 .

12 . A non-transitory computer-readable medium, storing a computer program, wherein in a case that the computer program is executed by a processing apparatus, the resource access control method according to claim 7 is implemented.

13 . An electronic device, comprising:

a storage apparatus, storing a computer program; and

a processing apparatus for executing the computer program in the storage apparatus to implement the resource access control method according to claim 7 .

14 . An electronic device, comprising:

a storage apparatus, storing a computer program; and

a processing apparatus for executing the computer program in the storage apparatus to implement a resource access control method, wherein the resource access control method is applied to a network control device, and comprises:

receiving an authentication request sent by a business system, wherein the authentication request is sent by the business system in a case that the business system determines a first resource to be accessed by a first object belonging to a resource of a first type according to a resource access request sent by the first object, and the authentication request comprises identity information of the first object and the first resource to be accessed by the first object;

acquiring historical resource access information and historical security status information of the first object from the business system according to the identity information of the first object, in response to the authentication request;

determining access permission information of the first object for the first resource according to the historical resource access information and the historical security status information; and

sending the access permission information to the business system, wherein the access permission information is used to enable the business system to determine an operation for the resource access request according to the access permission information;

wherein the determining the access permission information of the first object for the first resource according to the historical resource access information and the historical security status information, comprises:

determining a first risk item triggered by the first object, according to the historical resource access information and the historical security status information and in conjunction with a preset mapping relationship, wherein the mapping relationship comprises a corresponding relationship between different combinations of the historical resource access information and the historical security status information, and different risk items; and

determining the access permission information of the first object for the first resource according to the first risk item.

15 . The electronic device according to claim 14 , wherein the resource access control method further comprises:

in a case that security status information of the first object accessing the business system changes, determining a data access strategy of the first object according to the security status information, wherein the data access strategy comprises a resource that the first object is able to access and a resource that the first object is unable to access; and

sending the data access strategy to the business system, wherein the data access strategy is used to enable the business system to determine access permissions of the first object for resources in the business system other than the resource of the first type according to the data access strategy.

16 . The electronic device according to claim 15 , wherein the resource access control method further comprises:

obtaining permission change information according to the data access strategy, wherein the permission change information is used to represent that a resource access permission of the first object for the business system has been changed; and

sending the permission change information to the business system, wherein the permission change information is used to enable the business system to send the permission change information to a terminal device of the first object through a long connection channel between the business system and the terminal device, to display the permission change information on the terminal device.

17 . The electronic device according to claim 14 , wherein the resource access control method further comprises:

in a case that security status information of the first object accessing the business system changes, determining a data access strategy of the first object according to the security status information, wherein the data access strategy comprises a resource that the first object is able to access and a resource that the first object is unable to access; and

sending the data access strategy to the business system, wherein the data access strategy is used to enable the business system to determine access permissions of the first object for resources in the business system other than the resource of the first type according to the data access strategy.

18 . The electronic device according to claim 17 , wherein the resource access control method further comprises:

obtaining permission change information according to the data access strategy, wherein the permission change information is used to represent that a resource access permission of the first object for the business system has been changed; and

sending the permission change information to the business system, wherein the permission change information is used to enable the business system to send the permission change information to a terminal device of the first object through a long connection channel between the business system and the terminal device, to display the permission change information on the terminal device.