Method and system for permission management
The present disclosure proposes methods, devices, systems, and computer programs for creating a permit. In more details, the method comprising the steps of receiving a request comprising a first permit identifier, wherein the first permit identifier identifies a first permit, and obtaining a first permit data based on the first permit identifier wherein the first permit data comprises data indicative of at least one permission and wherein the at least one permission provides an indication of one or more actions a holder of the first permit can take and/or what the holder of the first permit is allowed to do, wherein the request is a request to create a further permit and the request comprises data indicative of a further permit.
1 . A computer-implemented method for creating a permit, the method performed by a permit computing module, the method comprising the steps:
receiving a request message, a header of the request message comprising:
a first permit identifier, wherein the first permit identifier identifies a first permit;
in response to receiving the request message, obtaining, from a memory of the permit computing module or from a database, a first permit data associated with the first permit identifier, wherein the first permit data comprises data indicative of at least one permission and wherein the at least one permission provides an indication of one or more actions a holder of the first permit can take and what the holder of the first permit is allowed to do,
validating the first permit;
wherein:
the request message further comprises data specifying attributes of a child permit to be created;
the child permit is a further permit that is to be recorded as a child of the first permit; and
the child permit comprises at least one child permission that provides an indication of one or more actions a holder of the child permit can take and what the holder of the child permit is allowed to do, and the method further comprises:
creating the child permit based on the data specifying attributes of the child permit; and
recording a reference to the child permit in the first permit data such that the child permit is recorded as a child of the first permit.
2 . The computer-implemented method according to claim 1 , wherein the step of validating the first permit data comprises determining whether the first permit has been revoked.
3 . The computer-implemented method according to claim 1 , further comprising the step of validating that the first permit is able to create child permits.
4 . The computer-implemented method according to claim 3 , wherein the step of validating the first permit is able to create child permits comprises any one or more of the following steps:
validating that a maximum number of child permits associated with the first permit has not been exceeded; and/or
validating that a maximum depth of child permits associated with the first permit has not been exceeded.
5 . The computer-implemented method according to claim 1 , wherein the method further comprises the step of verifying the data specifying attributes of the child permit.
6 . The computer-implemented method according to claim 1 , wherein the step of creating the child permit comprises:
creating a child permit data instance based on the child permit, wherein the child permit data instance comprises a parent permit value that is set to the first permit identifier.
7 . The computer-implemented method according to claim 1 , wherein the method further comprises the step of providing a child permit identifier to a sender of the request.
8 . The computer-implemented method according to claim 1 , wherein data indicative of the at least one permission is an object comprising at least one name-value pair.
9 . The computer-implemented method according to claim 1 , wherein the request message is received via an API that is only provided to computing modules belonging to a secure computing environment.
10 . The computer-implemented method according to claim 1 , wherein the first permit data comprises an indication as to whether further permits may be generated that are children of the first permit.
11 . The computer-implemented method according to claim 1 , wherein the first permit data comprises at least one namespace, wherein each namespace defines part of a permission a child of the first permit can have.
12 . The computer-implemented method according to claim 1 , wherein the first permit data comprises at least one of:
an indication as to a maximum depth of descendants that the first permit can have;
a maximum number of children permits that the first permit can have; or
an array to indicate a maximum number of descendant permits that the first permit can have at different depths.
13 . The computer-implemented method according to claim 1 , wherein the first permit data comprises a maximum number of children permits that the first permit can have.
14 . The computer-implemented method according to claim 1 , wherein the first permit identifier obliviates the identity of the holder of the first permit.
15 . The computer-implemented method according to claim 1 , wherein the first permit identifier is a pseudo-randomly generated string of characters.
16 . A non-transitory computer-readable storage medium comprising computer program code instructions, being executable by a computer, to conduct the computer- implemented method as claimed in claim 1 .
17 . A computer program stored on a non-transitory computer-readable storage medium, the computer program comprising instructions that, when the program is executed by a computer, cause the computer to carry out the computer-implemented method as claimed in claim 1 .