Data access control method and device
By obtaining and querying access control policies, the problem of role management difficulties in complex business systems is solved, the efficiency and maintainability of access control are improved, and fine-grained access control is achieved.
Patent Information
- Application Number
- CN202410497979.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-19
- Filing Date
- 2024-04-22
- Publication Date
- 2025-06-20
AI Technical Summary
In complex business systems, the traditional access control model has difficulty in role management due to the expansion of the number of roles, which in turn reduces the system's access control efficiency and maintainability.
By obtaining access control policies for target data resources, extracting resource identification and user identification in operation requests, querying the target data table based on this information, and determining whether the operation request has access rights, thereby achieving efficient access control.
It improves the efficiency of access control, simplifies role management, enhances the maintainability of the system, and realizes fine-grained access control.
Smart Images

Figure CN120180484A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a data access control method and apparatus. Background Art
[0002] Data permission access control is manifested as the data range that an operating entity can access or operate, and is used to restrict the entity's right to use data. For increasingly complex business systems, the traditional access control model uses the role-based access control (RBAC) model. The RBAC model binds the entity (user) to the roles in the system and pre-sets the access permissions for each role to perform access control. Or use Attribute-Based Access Control (ABAC), and so on.
[0003] As the complexity of the system organization level increases, the number of roles will increase sharply, making it difficult to manage the roles, and thus resulting in low efficiency of the system for access control. The data permission authentication logic and data permission configuration of the interfaces in complex business scenarios are coupled with each other, and there are maintainability problems. Summary of the Invention
[0004] This application provides a data access control method and apparatus to solve the problem of improving the configuration and maintenance efficiency of the authentication system and enhancing the performance of access control.
[0005] This application adopts the following technical solutions.
[0006] In a first aspect, this application provides a data access control method. The data access control method can be applied to a computer system or a computing device that supports the computer system to implement the data access control method. The computing device is such as a server, a terminal, etc. In a possible example, the method includes: obtaining an access control policy for a target data resource, where the access control policy for the target data resource indicates a target data table, and then, in response to an operation request for the target data resource triggered by a user, extracting first feature information including a resource identifier of the target data resource and a user identifier of the user in the operation request. Querying the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user. If the target permission data includes the resource identifier, the authentication passes; if the target permission data does not include the resource identifier, the authentication fails. Among them, the target data table includes access objects for which the user has access permissions to at least one of multiple data in the target data resource; the resource identifier indicates that the operation request is used to request to operate at least one target data among the multiple data in the target data resource.
[0007] In this application, by obtaining in advance the access control policy for the target data resource, and then querying the target permission data mapped to the user identifier from the target data table indicated by the access control policy, and then determining whether the operation request has access permission according to the target access permission data, the access control of the request is realized through the configured access control policy, which improves the efficiency of access control and the maintainability when adjusting the authentication logic later.
[0008] In a possible scenario, multiple access control policies are deployed in the computing device, and each access control policy among the multiple access control policies indicates a data table.
[0009] In a possible scenario, the above data access control method can be applied to access control of an interface. For example, a user accesses the data in system a or program b by calling the interface of system a or program b. Further, before the user accesses the data in system a or program b, it can be determined whether the user has the permission to call the interface of system a or program b to access the data in system a or program b.
[0010] For the content of the target permission data mapped to the user identifier, the following two possible scenarios are provided.
[0011] In a possible scenario, the target permission data mapped to the user identifier can directly be the target permission object, that is, the content or field name that the user has access permission to. For example, if the target permission object is province a and province b, then the target permission data is province a and province b.
[0012] In another possible scenario, the target permission data mapped to the user identifier can be the secondary data under the target permission object. For example, if the target permission object is province a and province b, then the target permission data is the user information within province a and the user information within province b.
[0013] For the specific content of this scenario, reference can be made to the following possible implementation manners, which will not be elaborated here.
[0014] In a possible implementation manner, the above multiple data include multiple first-level data, each first-level data includes multiple second-level data, the target data is the second-level data, the above operation request is used to request to operate the target second-level data among the multiple second-level data, and the target data table includes the permission objects with access permission to the multiple first-level data. Query the target data table based on the operation request to obtain the target permission data mapped to the user identifier of the user in the target data table, including: query the target data table according to the target permission object mapped to the user identifier to obtain at least one target first-level data, and determine that the second-level data included in at least one target first-level data in the target data table is the target permission data.
[0015] In this application, since the target permission data is secondary data, whether the operation request has access permission is determined based on whether the resource identifier is included in the target permission data, achieving fine-grained access control.
[0016] For example, the operation request is used to request the user information with the name xx in the user information within Province A. The user information within Province A includes multiple secondary data, and the user information with the name xx is the target secondary data. The target data table includes permission objects for multiple users to have access permissions to information in different provinces. For example, the permission object of User A is Province A, and the permission object of User B is Province A or Province B. Query the target data table according to the target permission object to obtain the target primary data (Province A), and then determine that the secondary data (user information within Province A) included in the target primary data (Province A) is the target permission data.
[0017] In a possible scenario, the above-mentioned target data table further includes permission objects with access permissions to multiple secondary data.
[0018] In a possible implementation manner, the uniform resource locator (URL) in the operation request indicates the target data resource to be operated by the operation request.
[0019] In a possible scenario, the corresponding access control policy can be determined according to the URL in the operation request. Specifically, the URL in the operation request indicates the business object type, and the access control policy also includes the business object type. When the business object type indicated by the URL in the operation request is the same as the business object type included in Access Control Policy A among multiple access control policies, the access control policy corresponding to the URL in the operation request is Access Control Policy A. Furthermore, the target data resource indicated by Access Control Policy A can be determined.
[0020] In a possible implementation manner, the above-mentioned access policy includes the second feature information of the target data resource, the operation request indicates the second feature information, the first information includes the first feature information and the second feature information, and the second information corresponding to the operation request with authentication passed is stored in the computing device. Before querying the target data table based on the operation request to obtain the target permission data mapped to the user identifier of the user in the target data table, the above method further includes: querying the first information in the second information. If there is information in the second information that is the same as the first information, the authentication passes. If there is no information in the second information that is the same as the first information, then execute querying the target data table based on the operation request to obtain the target permission data mapped to the user identifier of the user in the target data table.
[0021] In this application, by storing the second information corresponding to the operation request that has passed authentication and using the first information corresponding to the operation request to be authenticated currently to query the second information, it is determined whether there is information in the second information that is the same as the first information, so as to achieve the purpose of authenticating the operation request, and only the query operation needs to be performed to complete the authentication of the operation request, avoiding complex authentication operations based on the information in the operation request subsequently, thereby improving the efficiency of access control.
[0022] In a possible scenario, the second characteristic information includes one or more of the following: service object type, operation type, resource type. Among them, the resource type is used to indicate the type of resources in the target data resource, and the operation type is used to indicate the processing means for the data included in the target data resource.
[0023] Exemplarily, the operation type includes one or more of the following: addition, deletion, modification, query.
[0024] Exemplarily, the format of the first information may be: user identifier, operation type, service object type, resource type, resource identifier arranged in sequence. Similarly, the format of the information included in the second information may be: user identifier, operation type, service object type, resource type, resource identifier arranged in sequence.
[0025] For example, the operation request indicates the second characteristic information, including: the URL in the operation request indicates the service object type in the access control policy. Since different access control policies include different service object types, accordingly, based on the URL in the operation request, the corresponding access control policy can be determined, and further the second characteristic information included in the access control policy can be determined.
[0026] In a possible implementation manner, the access control policy includes the second characteristic information indicated by the target data resource, the operation request indicates the second characteristic information, and the computing device stores the corresponding relationship between the second characteristic information and the processing script. A processing script corresponding to a second characteristic information indicates the manner of querying the target permission data from the target data table. Query the target data table based on the operation request to obtain the target permission data in the target data table that has a mapping relationship with the user identifier of the user, including: determining the first processing script corresponding to the second characteristic information in the corresponding relationship, and then adding the target permission object having a mapping relationship with the user identifier to the first processing script to obtain the second processing script. Use the second processing script to query the target data table to obtain the target permission data corresponding to the target permission object in the target data table.
[0027] In the present application, by querying the target permission data corresponding to the target permission object in the target data table in the manner of processing a script, it is possible to quickly filter the target permission data from the target data table, and then determine whether the operation request has access permission according to whether the target permission data includes a resource identifier, thereby improving the efficiency of data access control.
[0028] In a possible scenario, the above-mentioned processing script may be a structured query language (SQL).
[0029] Exemplarily, from the corresponding relationship, the business object type and operation type in the second feature information can be determined, and the corresponding processing script framework (such as an empty SQL statement, for example, SELECT()FROM()WHERE()) can be determined. Further, the target data table corresponding to the resource type and the fields in the target data table can be determined, and then the target data table and the fields in the target data table are filled into the processing script framework to obtain the first processing script (such as SELECT(field name)FROM(target data table)WHERE()).
[0030] In a second aspect, the present application provides a data access control device. The data access control device is applied to a computer system or a computing device that supports the computer system to implement the data access control method. The data access control device includes various modules for executing the data access control method in the first aspect or any optional implementation manner of the first aspect. The data access control device includes: an acquisition module, configured to acquire an access control policy for a target data resource. The target data resource includes a plurality of data, and the access control policy of the target data resource indicates a target data table, and the target data table includes a permission object for which a user has access permission to at least one of the plurality of data in the target data resource.
[0031] An extraction module, configured to extract first feature information in an operation request in response to an operation request triggered by a user for the target data resource. The first feature information includes a resource identifier of the target data resource and a user identifier of the user, and the resource identifier indicates that the operation request is used to request an operation on at least one target data among the plurality of data in the target data resource.
[0032] A first query module, configured to query the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user. If the target permission data includes a resource identifier, the authentication passes. If the target permission data does not include a resource identifier, the authentication fails.
[0033] In a possible implementation, multiple data includes multiple first-level data, each first-level data includes multiple second-level data, the target data is second-level data, the operation request is used to request to operate on the target second-level data among the multiple second-level data, and the target data table includes permission objects that have access permissions to the multiple first-level data. The above-mentioned first query module is specifically configured to query the target data table according to the target permission object mapped to the user identifier, obtain at least one target first-level data, and determine that the second-level data included in at least one target first-level data in the target data table is the target permission data.
[0034] In a possible implementation, the URL in the operation request indicates the target data resource to be operated by the operation request.
[0035] In a possible implementation, the access control policy includes second feature information of the target data resource, the operation request indicates the second feature information, the first information includes the first feature information and the second feature information, and the second information corresponding to the operation request with authenticated authorization is stored in the computing device. The above-mentioned apparatus further includes: a second query module. The second query module is configured to query the first information in the second information; if there is information in the second information that is the same as the first information, the authentication passes; if there is no information in the second information that is the same as the first information, then perform a query on the target data table based on the operation request to obtain the target permission data mapped to the user identifier of the user in the target data table.
[0036] In a possible implementation, the access control policy includes second feature information indicated by the target data resource, the operation request indicates the second feature information, and the computing device stores the correspondence between the second feature information and the processing script. A processing script corresponding to one type of second feature information indicates the method of querying the target permission data from the target data table. The above-mentioned first query module is specifically configured to determine the first processing script corresponding to the feature information in the correspondence; add the target permission object mapped to the user identifier to the first processing script to obtain a second processing script, and use the second processing script to query the target data table to obtain the target permission data of the target permission object in the target table.
[0037] Exemplarily, for the content of the above-mentioned correspondence, reference can be made to the following description of the second correspondence, which will not be elaborated here.
[0038] In a possible implementation, the second feature information includes one or more of the following: business object type, operation type, resource type; the resource type is used to indicate the type of resources in the target data resource, and the operation type is used to indicate the processing means for the data included in the target data resource.
[0039] In a possible implementation, the operation type includes one or more of the following: addition, deletion, modification, and query.
[0040] In a possible implementation, the format of the first information is: user identifier, operation type, service object type, resource type, and resource identifier arranged in sequence.
[0041] In a third aspect, the present application provides a chip. The chip includes an interface circuit and a control circuit. The interface circuit is used to receive the first rule and the second rule configured by the user, and the interface circuit and the control circuit cooperate to execute the method in the first aspect or any possible implementation manner in the first aspect.
[0042] In a fourth aspect, the present application provides a computing device cluster. The computing device cluster includes at least one computing device, and each computing device includes a memory and a processor. The memory of the at least one computing device is used to store computer instructions. When the processor of the at least one computing device executes the computer instructions, the method in the first aspect or any possible implementation manner in the first aspect is implemented.
[0043] In a fifth aspect, the present application provides a computer-readable storage medium. The storage medium stores a computer program or instructions. When the computer program or instructions are executed by a processing device, the method in the first aspect or any possible implementation manner in the first aspect is implemented.
[0044] In a sixth aspect, the present application provides a computer program product. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processing device, the method in the first aspect or any possible implementation manner in the first aspect is implemented.
[0045] The beneficial effects of the second to sixth aspects above can be referred to the first aspect or any possible implementation manner in the first aspect, and will not be elaborated here. Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 It is a schematic diagram of a role-based access control model;
[0047] Figure 2 It is an application scenario diagram of a computer system provided by the present application;
[0048] Figure 3 It is a flowchart of a data access control method provided by the present application Figure 1 ;
[0049] Figure 4 It is a flowchart of a target permission data query method provided by the present application;
[0050] Figure 5 Flow schematic of a data access control method provided for this application Figure 2 ;
[0051] Figure 6 Structure schematic of a data access control device provided for this application Figure 1 ;
[0052] Figure 7 Structure schematic of a data access control device provided for this application Figure 2 ;
[0053] Figure 8 Structure schematic diagram of a computing device provided for this application;
[0054] Figure 9 Structure schematic diagram of a computing device cluster provided for this application;
[0055] Figure 10 Connection schematic diagram between computing devices provided for this application. Detailed implementation manners
[0056] For ease of understanding, first, technical terms involved in this application are introduced.
[0057] Data permission, which is the data scope or business scope that an operation subject (user) can access or operate. For example, within this data scope, the operation subject has the permission to access or operate the data, thus restricting the operation subject's power to use the data.
[0058] Access control refers to, after verifying the identity of the operation subject, restricting the access scope and processing ability of the subject to data according to the identity of the operation subject. This data includes resources in files, databases, servers, etc. The operation subject, object (data), and security access policy are the three elements in access control. The operation subject accesses the object according to the security access policy, and the system gives the result of access control through a series of calculations to determine whether to restrict the subject's access.
[0059] Attribute-based access control (ABAC) model is a model for solving access control of trusted relationships in industry distributed applications. The ABAC model uses the attributes of relevant entities (such as subjects, objects, and environments) as the basis for authorization to study how to perform access control. For example, the ABAC model is usually attribute-based access control. In attribute-based access control, the determination result of access control is calculated based on the attributes of the requester and relevant resources combined with the security access policy. Therefore, the ABAC model can dynamically and flexibly support fine-grained attribute-level authorization management in complex business scenarios.
[0060] A cloud computing platform refers to a platform that provides computing resources and services over the Internet. Based on virtualization technology, the cloud computing platform abstracts and aggregates resources such as computing, storage, and network, enabling users to use these resources on demand without caring about the underlying physical hardware and infrastructure.
[0061] A service module in a cloud computing platform refers to an independent component or module that provides specific functions and services. Each service module is responsible for executing specific operations or providing specific services and interacts with other modules to achieve the overall function.
[0062] The interface of a service module is a set of specifications for communication over the network, used to define the interaction method and data transfer format between the service module and other components or users. The following are some common interface types: application programming interface (API), Webservice (also known as Web) interface, remote procedure calls (RPC) interface, etc.
[0063] Among them, an API is an interface that defines the functions and operation methods provided by a service module externally. By calling the API interface, other applications or developers can interact and integrate with the service module. Common API interfaces include RESTful API, SOAP (simple object access protocol) API, etc.
[0064] A Web interface is an interface implemented through Web technology, usually using the HTTP or HTTPS protocol for communication. The Web interface can be used to display and operate the graphical interface of the service module, such as a management console or dashboard.
[0065] RPC interface, which can allow a program (or service module) to call a subroutine (or sub-service module) or function of another program (or service module) in different address spaces, just like a local call. An RPC interface is an interface for implementing the RPC protocol.
[0066] With the rapid development of global network technology, network information security problems are increasing continuously. In recent years, information security problems have attracted people's attention. The security problems caused by access control technology are becoming increasingly prominent. As one of the core technologies for ensuring network information security, it is also becoming more and more important in the research field of network information security. When enterprises are on the road of informatization construction, they need to analyze access control technology from two perspectives: the perspective of security requirements and the perspective of business requirements. First, from the perspective of security requirements, a large amount of sensitive information data is stored in the informatization system or there are many computing services that need to be protected. Access control technology can add a layer of protection to the system. Based on permission control, it controls system visitors to operate within the reasonable authorization range allowed by the system to protect the security of system information. Second, from the perspective of business requirements, during the healthy development of enterprises, the scale will gradually expand, thus generating a large and complex organizational structure model. When employees are at different organizational levels, their access control permissions, operation permissions, and data permissions in the informatization system are also different, which requires access control technology to meet such business requirements.
[0067] For complex business systems in enterprises, traditional access control models: Discretional Access Control (DAC) model, Mandatory Access Control (MAC) model, RBAC model, Task-based Access Control (TBAC) model are mostly identity-based access controls, which are difficult to meet the fine-grained access control of diverse resources.
[0068] A possible solution is provided for the above-mentioned RBAC model.
[0069] This solution is an interface data permission control method based on the RBAC model, which mainly introduces "roles" between the subject and the object. As Figure 1 shown, Figure 1It is a schematic diagram of a role-based access control model. The role-based access control model binds the subject to the roles in the system and pre-sets the access permissions for each role to perform access control. The basic RBAC model includes four types of entities and two types of relationships. The four types of entities are users, roles, permissions, and sessions. The two types of relationships are the many-to-many assignment relationship between users and roles and the many-to-many assignment relationship between roles and permissions. The system assigns permissions to the corresponding roles, and users obtain the corresponding permissions according to the different roles they are assigned. When a user accesses an object, first a session needs to be established, then a subset of the set of roles to which the user belongs is activated, and finally the activated role permissions are used to perform certain operations.
[0070] Corresponding to the interface data permission control in the business system, the system assigns corresponding roles to users, and through the pre-set association relationship between roles and interfaces, the determination of access control is carried out. Those who have the permission to access the interface are allowed to access the interface, otherwise they are not allowed to access.
[0071] However, with the increase in the complexity of the organizational hierarchy of the business system, the role assignment and management in the interface data permission control method based on the RBAC model will become very complex, resulting in the role explosion problem. When assigning corresponding permissions to users in this model, it can only be based on roles. In fact, various environmental conditions can also be comprehensively considered, but these factors cannot be flexibly implemented in the RBAC model. The definition granularity of objects and permissions is not fine enough, making it difficult to perform fine-grained authorization management.
[0072] In other words, the interface data permission control method based on the RBAC model will generate a large number of roles in complex business situations and assign corresponding roles to the subject. The permission configuration of the aforementioned roles increases geometrically with the complexity of the business, and the configuration and management are difficult, which will further result in low access control efficiency.
[0073] Based on this, the present application provides a data access control method. The method includes: obtaining an access control policy for a target data resource, the access control policy of the target data resource indicating a target data table, and then in response to an operation request for the target data resource triggered by a user, extracting first feature information including a resource identifier of the target data resource and a user identifier of the user in the operation request. Querying the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user. If the target permission data includes the resource identifier, the authentication passes; if the target permission data does not include the resource identifier, the authentication fails. Wherein, the target data table includes access objects for which the user has access permissions to at least one of multiple data in the target data resource; the resource identifier indicates that the operation request is used to request an operation on at least one target data among multiple data in the target data resource.
[0074] In the present application, by querying whether the target permission data includes a resource identifier, it is determined whether the operation request has access permission, that is, by using the attributes (resource identifier and user identifier) in the request, fine-grained access control is implemented. Moreover, by obtaining in advance the access control policy for the target data resource, and then querying the target permission data having a mapping relationship with the user identifier from the target data table indicated by the access control policy, and thus determining whether the operation request has access permission according to the target access permission data, access control of the request is implemented through the configured access control policy, improving the efficiency of access control and the maintainability during the later adjustment of the authentication logic.
[0075] The data access control method provided by the present application can be applied to Figure 2 the computer system shown. As Figure 2 shown, Figure 2 is an application scenario diagram of a computer system provided by the present application. The computer system includes multiple computing devices, such as computing device 310, computing device 320, and computing device 330. The computing device 310, computing device 320, and computing device 330 can be connected through a channel 340. The channel 340 can be a wired channel or a wireless channel. Among them, service modules or other modules for executing services, such as modules for testing, are deployed on the computing device 310, computing device 320, and computing device 330.
[0076] At least one service module is deployed on each of the computing device 310, computing device 320, and computing device 330.
[0077] The above-mentioned wired channel can be: Ethernet, optical fiber, cloud direct connect, and various peripheral component interconnect express (PCIe) buses provided inside the computer system for connecting area a and area b. Cloud direct connect refers to a connection method that directly connects the local network to the data center or other areas of the cloud service provider through a physical dedicated line, realizing a high-speed, low-latency, secure, and reliable connection.
[0078] The above-mentioned wireless channels can be: the Internet, cloud connection, wireless fidelity (WIFI), ultra-wideband (UWB) technology, remote procedure call (RPC), etc. Cloud connection refers to the technology and service of connecting a local network with other cloud service providers or networks in other regions through the Internet. RPC is a technology used to enable communication between different computing devices or processes in a distributed system. RPC allows a program / service to call the process or method of another program / service, just like calling a local process, hiding the details of the underlying communication.
[0079] It should be noted that Figure 2 The architecture of the illustrated computer system is only an example, and the types or quantities of devices inside the system can be configured according to actual needs, which are not limited in the embodiments of the present application. For example, the computer system may further include more computing devices.
[0080] In a possible scenario, a cloud computing platform is running in the computer system.
[0081] In a possible example, the above-mentioned computer system further includes: a terminal 350. The terminal 350 can communicate with the above-mentioned computing device 310, computing device 320, or computing device 330 in a wired or wireless manner.
[0082] For the content that the terminal 350 can communicate with the above-mentioned computing device 310, computing device 320, or computing device 330 in a wired or wireless manner, reference can be made to the content of the above-mentioned wired channels or wireless channels, which will not be elaborated here.
[0083] In a possible example, the above-mentioned computer system may further include: a control device 360, which is used to distribute the requests obtained from the terminal 350 to the computing device 310, computing device 320, or computing device 330, or the control device 360 returns the data of the computing device 310, computing device 320, or computing device 330 to the terminal 350. The control device 360 can communicate with the above-mentioned computing device 310, computing device 320, computing device 330, or terminal 350 in a wired or wireless manner. For example, the control device 360 can be a switch.
[0084] For the content that the control device 360 can communicate with the above-mentioned computing device 310, computing device 320, computing device 330, or terminal 350 in a wired or wireless manner, reference can be made to the content of the above-mentioned wired channels or wireless channels, which will not be elaborated here.
[0085] In a possible scenario, the computing devices in the above computer system are in the same region. For example, computing device 310, computing device 320, and computing device 330 are all in region a.
[0086] In a possible example, computing device 310, computing device 320, and computing device 330 are all in availability zone (AZ) a under region a.
[0087] In another possible example, computing device 310 and computing device 320 are in availability zone (AZ) a under region a, and computing device 330 is in AZ b under region a.
[0088] In another possible scenario, the computing devices in the above computer system are in different regions. For example, computing device 310 and computing device 320 are in region a, and computing device 330 is in region b.
[0089] Exemplarily, the user determines the service to be accessed through the front-end interface (also referred to as the user interface (UI)) of the cloud computing platform provided by the computer system on the terminal 350, and then generates a request to be sent to the service module corresponding to the service to be accessed (such as the service module is deployed on computing device 310). The service module in computing device 310 authenticates the request to determine whether the user has the permission to call the service module. If the authentication passes, the user has the permission to call the service module, and then the service module in computing device 310 executes the business logic indicated by the request (such as adding, deleting, modifying, accessing the target data resources recorded in the service module); if the authentication fails, the user does not have the permission to call the service module, and then the request is intercepted.
[0090] For example, the above computer system can be a browser / server architecture, that is, the terminal 350 sends an operation request to the control device 360 in the server (including the above control device 360, computing device 310, computing device 320, and computing device 330) through the browser. The control device 360 distributes the request to the computing device 310 where the service module a is deployed according to the interface of service module a indicated by the operation request, and the computing device 310 authenticates the request.
[0091] The front-end interface of the above cloud computing platform can be the interface corresponding to the browser on the terminal 350.
[0092] For another example, service module a in computing device 310 sends a request to service module b in computing device 320. Service module b authenticates the request, that is, when service modules in the server call each other, the operation request is authenticated.
[0093] Before an interface call, it is necessary to confirm whether the caller (such as the above-mentioned terminal 350 or service module a) has the permission to access the target data resource indicated by the interface, that is, it is necessary to perform data access control (authenticate the request for the called interface). If the authentication operation is not performed, it will cause a horizontal privilege escalation security problem, resulting in malicious access to resources and reducing the overall security of the system.
[0094] The solution provided in this application can be applied to a microservices architecture, such as a microservices architecture in complex business scenarios.
[0095] Regarding the deployment method of service modules in a computer system, the following provides three possible examples.
[0096] Example 1: Service module a is deployed on computing device 310, service module b is deployed on computing device 320, and service module c is deployed on computing device 330.
[0097] Example 2: Service module a and service module b are deployed on computing device 310, and service module c is deployed on computing device 320.
[0098] Example 3: A part of the sub-modules of service module a is deployed on computing device 310, and another part of the sub-modules of service module a is deployed on computing device 320.
[0099] The above content is only an example and should not be construed as a limitation of this application. In other examples of this application, more or fewer service modules can also be deployed on the same computing device, and more components of the same service module are deployed on multiple computing devices.
[0100] Taking service module a among service module a, service module b, and service module c as an example for illustration, service module a has the ability to execute N types of services, where N is a positive integer. For example, service module a can execute various different service functions, such as one or more of user management service, order management service, product catalog management service, or payment service, etc.
[0101] The user management service is responsible for handling functions such as user registration, login, and personal information management. The order management service is responsible for handling functions such as order establishment and cancellation. The product catalog management service is responsible for handling functions such as product classification, search, and details. The payment service is responsible for handling payment requests and interacting with third-party payment platforms.
[0102] The above content is only an example and should not be construed as a limitation of this application. In other examples of this application, service module a may also perform more or fewer functions.
[0103] Next, a data access control method provided by an embodiment of this application will be described in detail with reference to the accompanying drawings.
[0104] Here, it is described by taking the data access control method provided by an embodiment of this application as Figure 2 executed by the computing device 310 shown as an example. Figure 3 is a flow diagram of a data access control method provided by this application Figure 1 . In this embodiment, service module a is deployed in computing device 310. Taking the case where computing device 310 receives an operation request (also referred to as a call request) for the target data resource recorded by service module a sent by terminal 350 and executes the data access control method as an example for description.
[0105] Figure 3 A data access control method shown may include the following steps S310 - S360.
[0106] S310. The computing device 310 obtains an access control policy for the target data resource.
[0107] Among them, the target data resource includes multiple data, and the access control policy of the target data resource indicates a target data table, and the target data table includes permission objects for which a user has access rights to at least one of the multiple data in the target data resource.
[0108] Exemplarily, the target data resource is business data recorded by service module a, etc. When service module a can execute more services, service module a will record target data resources of different business object types.
[0109] For example, service module a records business object types such as: user information, laptop computer information under the product type, etc. Hereinafter, taking the business object type of user information as an example for description, Table 1 below shows the target data resource of user information.
[0110] Table 1
[0111] Province Name Age Gender Education Level Number of Activities Intended Vehicle Model Province A Zhang, 45 years old 26 Male Bachelor's Degree 20 Sedan Province A Li, 34 years old 30 Male Ph.D. Candidate 10 SUV Province A Wang, 23 years old 23 Female Master's Degree 25 Sedan Province B Zhang, 12 years old 20 Female Bachelor's Degree 5 Sedan
[0112] It should be noted that the content shown in Table 1 above is only an example and should not be construed as a limitation of this application. In other embodiments of this application, Table 1 may also include more or fewer fields, and Table 1 above only takes user information as an example for description. When the business object type is other types, the above fields may be fields corresponding to the business object type.
[0113] In a possible implementation, the computing device 310 obtains an access control policy for a target data resource, including: the computing device 310 obtains a plurality of access control policies configured by a user, and the plurality of access control policies include the access control policy for the target data resource.
[0114] Exemplarily, for each data resource recorded in the service module a, a corresponding access control policy is configured.
[0115] Exemplarily, the access control policy includes one or more of the following: the business object type of the data resource, the resource type, the operation type, the way to extract the resource identifier in the extraction request, and the way to extract the user identifier in the extraction request.
[0116] Among them, the resource type is used to indicate the type of resources in the target data resource, such as province a, name, age, etc. The operation type is used to indicate the processing means for the data included in the target data resource.
[0117] The above operations include one or more of the following: addition, deletion, modification, and query.
[0118] In a possible example, the target data table may include the primary data in the target data resource, and a plurality of secondary data included in the primary data. For example, when the target data resource is the content shown in Table 1 above, and the access control policy of the target data resource indicates the target data table, the permission objects included in the target data table may be the data recorded under the fields "province" (primary data) and "name" (secondary data) in Table 1, as shown in Table 2 below.
[0119] Table 2
[0120] Province Name Province A Zhang, 45 years old Province A Li, 34 years old Province A Wang, 23 years old Province B Zhang, 12 years old
[0121] Among them, the content shown in Table 2 includes the permission objects corresponding to the user. For example, if the permission object corresponding to the user is "province a, Zhang 45", then the user has access to the data corresponding to "province a, Zhang 45" in Table 1, such as "province a, Zhang 45, 26, male, undergraduate, 20, car".
[0122] Exemplarily, the resource type in the access control policy indicates the target data table. For example, when the resource type is "province a, name" in the target data resource, the target data table is the data included in the field "province a, name" in the target data resource.
[0123] It should be noted that the content shown in Table 2 above is only an example and should not be construed as a limitation to this application. In other embodiments of this application, Table 1 may also include more or less content. For example, the target data table only includes first-level data (such as provinces) in the target data resources, or the target data table includes first-level data (such as provinces) in the target data resources and multiple types of second-level data (such as names and genders), that is, the target data table includes multi-level data.
[0124] S320. The computing device 310 receives an operation request triggered by the user for the target data resource.
[0125] Exemplarily, the computing device 310 receives an operation request triggered by the user for the target data resource recorded by service module a.
[0126] For example, the computing device 310 receives an operation request to call the interface of service module a to request to operate on the target data resource recorded by service module a.
[0127] The interface type of this service module a can be an API interface, a Web interface, an RPC interface, etc. For the descriptions of API interfaces, Web interfaces, and RPC interfaces, reference can be made to the content in the interfaces of the foregoing service modules, which will not be elaborated here.
[0128] The operation request indicates information such as the interface of service module a to be called, request parameters, user identification, resource identification, etc.
[0129] In the case where the interface type of service module a is a Web interface, the interface of service interface a in the operation request can be represented as a URL, and the request parameters can be string parameters carried in the request. The string parameters can be directly appended after the URL corresponding to the interface or can be set separately in the request. The user identification is located in the request header of the operation request, and the resource identification is located in the request parameters.
[0130] In one possible example, the URL in the operation request is http: / / example.com / api / data?feature=xx, where http: / / example.com / api / data represents the interface of service module a, and feature=xx is a query string parameter indicating to query the data corresponding to xx in the feature field. The query string parameter and the URL of the interface are separated by "?".
[0131] In another possible example, part of the content of the operation request is "url='http: / / example.com / api / data'
[0132] params = {'param1': 'value1', 'param2': 'value2'}
[0133] response = requests.get(url, params = params)”
[0134] The above request parameters “'param1': 'value1', 'param2': 'value2'” are set separately in the operation request.
[0135] It should be noted that the above content is only an example and should not be construed as a limitation to this application. In other examples of this application, the operation request may also indicate to delete or modify the data in service module a, or access the sub-services provided by service module a, etc. The request parameters may also be located in the request header, request body, etc.
[0136] In a possible implementation, computing device 310 receives an operation request to call the interface of service module a, including:
[0137] Computing device 310 receives the operation request distributed by control device 360.
[0138] Exemplarily, when terminal 350 initiates an operation request to service module a, the operation request will pass through control device 360 for transit and routing, and finally reach computing device 310.
[0139] Among them, control device 360 is responsible for distributing the request. Based on the path information (such as URL) indicated in the request header (also known as the message header) of the operation request, it determines to distribute the operation request to service module a among multiple service modules.
[0140] In a possible example, terminal 350 accesses the front-end interface of the cloud computing platform through a browser, determines the services or data to be accessed, etc., and then determines the interface of service module a corresponding to the service to be accessed from the corresponding relationship between the service and the service module interface, or determines the interface of service module a corresponding to the data to be processed from the corresponding relationship between the data and the service module interface. Thus, an operation request is generated according to this interface and the processing to be performed on the service or data.
[0141] For example, when the user needs to obtain the data a recorded in service a, terminal 350 determines the interface of service module a corresponding to service a from the above corresponding relationship between the service and the service module interface. And since it is necessary to obtain the data a in service a, the generated operation request will carry the get() method.
[0142] In other embodiments of the present application, the computing device 310 receives an operation request for invoking the interface of service module a, including: the computing device 310 receives an operation request from service module b in the computing device 320 for the interface of service module a.
[0143] In a possible example, if the computing device 310 and the computing device 320 are in the same local area network, the computing device 310 and the computing device 320 communicate directly through the network protocol without passing through a switch for transit. In this case, the service modules can access each other using the Internet Protocol (IP) address.
[0144] In another possible example, if the computing device 310 and the computing device 320 are not in the same local area network, the computing device 310 and the computing device 320 need to communicate through a switch.
[0145] S330. The computing device 310 extracts the first feature information in the operation request in response to the operation request.
[0146] Wherein, the first feature information includes the resource identifier of the target data resource and the user identifier of the user, and the resource identifier indicates that the operation request is used to request at least one target data among multiple data in the target data resource.
[0147] In a possible scenario, the first feature information represents the request parameters carried in the operation request. The request parameters may include the resource identifier and the user identifier.
[0148] The above resource identifier may be the name of the resource, the resource identification number, etc., and the resource identifier indicates that the operation request is used to request at least one target data among multiple data in the target data resource. The user identifier may be the name of the user, the identity identification number, etc.
[0149] For example, the name of the resource may be the above 'param1':'value1', 'param2':'value2', the name of the user may be the above Zhang xx or the identity identification number is 012334, etc.
[0150] It should be noted that the above content is only an example and should not be construed as a limitation to the present application. In other examples of the present application, the request parameters may further include the processing method for the resource (addition, deletion, modification, query, etc.). For example, the processing method for the resource may be the above get(), etc.
[0151] Regarding the content of the computing device 310 obtaining the first feature information of the operation request, the following provides two possible implementation manners.
[0152] In a first possible implementation, the computing device 310 parses the operation requests obtained by the computing device 310 using a fixed parsing method to obtain first feature information.
[0153] In other words, the computing device 310 parses all the operation requests received by the computing device 310 through one or more fixed parsing methods.
[0154] For example, if parameters are passed by adding query parameters after the URL, the computing device 310 obtains the request parameters by parsing the query parameters in the URL, thereby obtaining the first feature information.
[0155] If the placeholder in the URL represents a request parameter, and this placeholder is often located after the URL of the interface, the computing device 310 obtains the request parameters by parsing the placeholder in the URL, thereby obtaining the feature information.
[0156] In a second possible implementation, the computing device 310 maintains an access control policy and a first correspondence between the business object type and the access control policy. The access control policy corresponding to a business object type indicates the method of extracting the first feature information from the operation requests of this business object type. The computing device 310 extracts the first feature information from the operation requests, including: the computing device 310 determines the target access control policy corresponding to the business object type of the operation request in the first correspondence, and then uses the target access control policy to extract the first feature information from the operation requests.
[0157] Exemplarily, the computing device 310 determines the business object type of the operation request from the URL of the operation request, and then determines the target access control policy corresponding to the business object type of the operation request in the first correspondence, and then uses the target access control policy to extract the first feature information from the operation requests.
[0158] In a possible example, the front-end navigation bar of the URL in the operation request indicates the business object type, and the computing device 310 can obtain the business object type of the operation request by parsing the front-end navigation bar of the URL. Furthermore, after the computing device 310 determines the target access control policy according to the business object type of the operation request, it obtains the resource identifier and the user identifier in the operation request according to the methods of extracting the resource identifier and the user identifier included in the target access control policy.
[0159] The front-end navigation bar in the URL, also known as the URL path or URL directory, refers to the part of the URL used to identify the location or business of internal pages of the website.
[0160] For example, the front-end navigation bar in the URL "https: / / www.example.com / products / laptops" is " / products / laptops", and the type of business object indicated by this front-end navigation bar is "laptops under the product type". The method of extracting the resource identifier in the access control policy can be to extract the first feature information from the operation request through a SpringEl expression.
[0161] In a possible scenario, the access control policy further includes second feature information. Furthermore, the computing device 310 determines, in the first correspondence, the target access control policy corresponding to the business object type of the operation request, and then uses the statement information in the target access control policy as the second feature information in the first information.
[0162] In a possible scenario, the statement information of the interface of the service module is used to indicate the usage information or type information publicly disclosed by the interface, etc. The usage information indicates how to call the interface, and the type information is used to indicate the business object type corresponding to the interface (that is, the business type that can be executed by calling this interface, that is, the business object type indicated by the target data resource), the resource type, or the operation type (one or more of addition, deletion, modification, and query), etc.
[0163] This resource type is used to indicate the type of resource indicated by the interface, that is, the type of resource in the target data resource, and the operation type is used to indicate the processing means for the aforementioned target data resource.
[0164] For example, the above usage information includes the interface name, input parameter list, interface method, interface URL, etc. The above type information includes that the interface corresponds to the order business, the order transaction list included in the business data in the order business, and supports addition, deletion, or modification of the data in the order transaction list.
[0165] It should be noted that the above content is only an example and should not be construed as a limitation of this application. In other examples of this application, the second feature information may further include the interface version number, output parameter list, etc.
[0166] In a possible scenario, the first information may include the above first feature information and second feature information.
[0167] For example, the first information includes the resource identifier and user identifier in the operation request, as well as the business object type, resource type, and operation type in the second feature information.
[0168] In a possible example, the content included in the first information is arranged in order. For example, this order is the user identifier, operation type, business object type, resource type, and resource identifier arranged in sequence.
[0169] The above first information can be cached in the computing device 310.
[0170] It should be noted that the above content is only an example and should not be construed as a limitation of this application. In other embodiments of this application, the above first information may further include more or less content, or the arrangement order of the first information is set according to user needs, which is not limited in this application. For example, the first information may also be the operation type, business object type, user identifier, resource type, and resource identifier arranged in sequence.
[0171] It should be noted that the access control policy is the content pre-configured by the user according to the interface or the business object type of the interface, and it is pre-stored in the computing device 310. If an interface involves multiple business object types, there will also be multiple access control policies. In other words, under an interface, one business object type corresponds to one access control policy.
[0172] In this application, the computing device 310 determines the target access control policy corresponding to the business object type of the operation request from the first correspondence according to the business object type determined by the operation request, avoiding the time-consuming caused by traversing all access control policies and obtaining invalid feature information according to all access control policies, as well as the performance loss of the computing device 310, improving the authentication efficiency in complex scenarios (an interface has multiple business object types), and reducing the performance loss of the computing device 310.
[0173] It should be noted that in the second possible implementation manner, the computing device 310 may not store the first correspondence either. After obtaining the business object type of the operation request from the URL of the operation request, it uses a traversal method to determine the configuration information whose business object type is the same as that of the operation request from all configuration information as the target configuration information.
[0174] Please continue to refer to Figure 3 , Figure 3 The data access control method shown also includes the following step S340.
[0175] S340. The computing device 310 queries the target data table based on the operation request to obtain the target permission data in the target data table that has a mapping relationship with the user identifier of the user.
[0176] In a possible scenario, the computing device 310 maintains the correspondence between the user identifier and the permission object.
[0177] In a possible embodiment, multiple data in the target data resource include multiple first-level data, each first-level data includes multiple second-level data, and the above-mentioned target data is second-level data. The operation request is used to request to operate on the target second-level data among the multiple second-level data, and the target data table includes permission objects that have access rights to the multiple first-level data.
[0178] For an example of the target data resource, reference may be made to the content shown in Table 1 above, and for an example of the target data table, reference may be made to the content shown in Table 1 above, which will not be elaborated here.
[0179] In a possible implementation manner, the computing device 310 queries the target data table based on the operation request, and obtains the target permission data in the target data table that has a mapping relationship with the user identification of the user, including:
[0180] The computing device 310 queries the target data table according to the target permission object that has a mapping relationship with the user identification, and obtains at least one target first-level data, and further determines that the second-level data included in at least one target first-level data in the target data table is the target permission data.
[0181] Exemplarily, the computing device 310 queries the target data table shown in Table 2 above according to the target permission object (Province A), and obtains at least one target first-level data (such as Province A), and further determines the second-level data included in Province A (such as Zhang 45, Li 34, Wang 23).
[0182] Regarding the detailed content of S340, reference may be made to the following Figure 4 shown expression, which will not be elaborated here.
[0183] S350: If the target permission data includes a resource identifier, the authentication passes.
[0184] Exemplarily, when the resource identifier indicates "Zhang 45", the computing device 310 determines that the above (Zhang 45, Li 34, Wang 23) includes "Zhang 45", then the authentication passes.
[0185] In a possible situation, the above Figure 3 shown method further includes: If the computing device 310 passes the authentication for the operation request, it allows the execution of the service logic indicated by the operation request. For example, obtaining data, deleting data, etc.
[0186] S360: If the target permission data does not include a resource identifier, the authentication fails.
[0187] Exemplarily, when the resource identifier indicates "Zhang 23", the computing device 310 determines that the above "Zhang 45, Li 34, Wang 23" does not include "Zhang 45", then the authentication passes.
[0188] In a possible situation, the aboveFigure 3 The method shown also includes: if the computing device 310 fails to authenticate the operation request, the computing device 310 issues an alarm and intercepts the operation request.
[0189] In one possible example, the above-mentioned way of giving an alarm can be that the computing device 310 returns a message to the terminal 350, and this message is used to remind the user that they have no right to access. For example, after receiving the message, the terminal 350 can directly display it on the user interface of the terminal 350 to remind the user that they have no right to access.
[0190] In another possible example, the above-mentioned way of giving an alarm can be that the computing device 310 returns a message to the management end of the service module a to remind the operation and maintenance personnel or management personnel that a user has no right to access, and at the same time explain that the operation request of this user has been intercepted.
[0191] For example, the computing device 310 can return a 403 status code.
[0192] In one possible embodiment, the access control policy includes second feature information of the target data resource, the operation request indicates the second feature information, the first information includes the first feature information and the second feature information, and the computing device 310 stores the second information corresponding to the operation request that has passed authentication. Before querying the target data table based on the operation request to obtain the target permission data in the target data table that has a mapping relationship with the user identification of the user, the above-mentioned data access control method includes: the computing device 310 queries the first information in the second information; if there is information in the second information that is the same as the first information, the authentication passes. If there is no information in the second information that is the same as the first information, the content of the above-mentioned S340 is executed.
[0193] Exemplarily, multiple second information that has passed authentication is stored in the memory or hard disk of the computing device 310. The computing device 310 queries the second information in the memory or hard disk. If there is information in the second information that is the same as the first information, the authentication passes. Otherwise, the content of the above-mentioned S340 is executed.
[0194] For example, the second information includes: user identification, operation type, business object type, resource type, resource identification. For the detailed content of the second information, reference can be made to the description of the above-mentioned first information.
[0195] In this application, the computing device 310 queries the first information in the second information that has passed authentication in history. If there is information in the second information that is the same as the first information, it avoids performing the subsequent complex authentication logic on the same information multiple times, reduces the time consumption of performing the subsequent complex authentication logic, and moreover, the computing device 310 can implement the authentication of the first information only by querying, improving the authentication efficiency of the first information.
[0196] Regarding the content of S340 above, a possible implementation is shown below.
[0197] The access control policy includes second feature information. The operation request indicates the second feature information. In the computing device 310, a second correspondence between the second feature information and a processing script is stored. A processing script corresponding to one type of second feature information indicates a method for querying target permission data from a target data table indicated by the second feature information. As Figure 4 shown, Figure 4 is a schematic flowchart of the method for querying target permission data provided by this application. As Figure 3 in S340 may include the following steps S410 - S430.
[0198] S410. The computing device 310 determines the first processing script corresponding to the second feature information in the second correspondence.
[0199] In a possible implementation, the computing device 310 determines the processing script corresponding to the second feature information according to the business object type and operation type in the second correspondence and the resource type in the second feature information, and determines to query in the target data table, thereby obtaining the first processing script.
[0200] The determined processing script corresponding to the second feature information is an empty processing script, that is, there are only processing means but no specific fields, so it is not known who to process.
[0201] When the processing script is used to indicate SQL, an example of a processing template is provided below: SELECT ${column}
[0202] FROM table_name
[0203] ${tableJoinSql}
[0204] WHERE(${permissionSql})
[0205] The above ${column}, ${tableJoinSql}, and ${permissionSql} are all content to be filled.
[0206] In a possible example, the computing device 310 determines the field name of the target data table where the resource type is located (i.e., the above-mentioned column) and the target data table where the resource type is located and the associated table of the target data table where the resource type is located (i.e., the above-mentioned tableJoinSql) according to the resource type. Furthermore, it replaces "${column}" in the processing template with "the field name of the target data table where the resource type is located", and replaces "${tableJoinSql}" in the processing template with "the target data table where the resource type is located and the associated table of the target data table where the resource type is located" to obtain the first processing script.
[0207] The following provides an example of the first processing script: SELECT Name
[0208] FROM table_name
[0209] Table a, Table b
[0210] WHERE (${permissionSql})
[0211] In the above example, "Name" is the field name of the target data table where the resource type is located, and "Table a, Table b" is the target data table where the resource type is located and the associated table of the target data table where the resource type is located.
[0212] S420. The computing device 310 adds the target permission object to the first processing script to obtain the second processing script.
[0213] The permission object refers to an entity or resource that needs to be subject to permission control in the system or business, that is, it represents an entity or resource that has access permission in the system or business. Therefore, the permission object indicated by the user identifier represents an entity or resource that the user indicated by the user identifier has access permission to in the system or business.
[0214] Exemplarily, a system includes a customer identity table, a customer order table, and a customer transaction volume table. User a only has the access permission to query the customer identity table and the customer order table, then the customer identity table and the customer order table are the permission objects of user a.
[0215] Or, a system includes user information from various regions, such as Province a and Province b. The user only has the permission to query the user information of Province a, then the permission object of the user is Province a or the user information of Province a.
[0216] In a possible implementation manner, the computing device 310 adds the target permission object to the filtering condition part in the first processing script, thereby obtaining the second processing script.
[0217] Exemplarily, the computing device 310 adds the target permission object after "where" in the first processing script, thereby obtaining the second processing script.
[0218] For example, if the existing target permission object is the permission object "Province A", the computing device 310 replaces "${permissionSql}" in the SQL statement of the above first processing script with "Province A", thereby obtaining the following second processing script:
[0219] SELECT Name
[0220] FROM table_name
[0221] Table a, Table b
[0222] WHERE (Province A)
[0223] For the content of obtaining the target permission object having a mapping relationship with the user identifier, reference may be made to the description of the permission object shown below, which will not be elaborated here. Figure 5 shown, and will not be elaborated here.
[0224] S430. The computing device 310 uses the second processing script to query the target data table, and obtains the target permission data corresponding to the target permission object in the target data table.
[0225] In a possible scenario, various types of data of the service module a are stored in the database system set by the computing device 310. Further, the computing device 310 executes the second processing script to query the target data table in the database system, and obtains the target permission data corresponding to the target permission object in the target data table.
[0226] Exemplarily, the computing device 310 executes the SQL statement indicated by the second processing script to implement the target permission data corresponding to the target permission object in the target data table (such as Table a, Table b) or the specified fields in the target data table (such as Name in Table a, Name in Table b) (such as Name within Province A).
[0227] In a possible example, specifically, the database management system in the computing device 310 may execute the second processing script, and the database management system is used to manage the above database system.
[0228] In this application, the computing device 310 queries the target data matching the target permission object in the target data table through the processing script. The query granularity is the specific specified data in the data table. If the queried target permission data includes the resource identifier, the authentication passes; if the queried target permission data does not include the resource identifier, the authentication fails, realizing fine-grained access control management.
[0229] Regarding the aboveFigure 3 and Figure 4 For the content shown below, a complete embodiment of a data access control method is provided as follows. As Figure 5 shown Figure 5 is a schematic flowchart of a data access control method provided by this application Figure 2 . Figure 5 The method shown can be executed by a computing device 310. A service module a is deployed in the computing device 310, and the data recorded in the service module a can be the target data resource. Figure 5 A data access control method shown may include the following steps ①-⑩.
[0230] Step ①: The computing device 310 obtains an operation request.
[0231] In a possible scenario, after obtaining the operation request, the computing device 310 queries all access control policies of the interface according to the request method of the interface and the URL in the operation request.
[0232] The request method of the above interface, that is, the request method in the operation request, such as get, post, put, delete or patch.
[0233] Step ②: The computing device 310 determines the business object type of the service module a to be called by the operation request according to the front-end navigation bar information of the URL in the operation request.
[0234] Step ③: The computing device 310 determines an access control policy a corresponding to the business object type from multiple access control policies. The business object type included in the access control policy a is consistent with the business object type of the service module a to be called by the operation request.
[0235] The multiple access control policies are N of the above all access control policies, and N is a positive integer.
[0236] The access control policy includes second feature information and a way to extract first feature information from the operation request. For example, the access control policy includes: the business object type involved in the interface, the operation type, the resource type, and the way to extract the resource identifier and user identifier from the request parameters of the operation request.
[0237] Since the input parameter names and data types of each interface are different, in this embodiment, the resource identifier is extracted from the request parameters of the operation request through the SpringEL expression. If an interface involves multiple complex business scenarios (that is, multiple business object types), multiple access control policies will also be configured.
[0238] Exemplarily, the computing device 310 defines an access control policy through a YAML (YAML Ain't Markup Language) file. The following gives a possible example of YAML:
[0239] configs:
[0240] -method: Interface type (POST / DELETE / PUT / GET) # Interface type (POST / DELETE / PUT / GET)
[0241] url: 'Interface URL' # Interface URL
[0242] configs:
[0243] -el: 'SpringEl expression' # SpringEl expression, used to extract the resource id in the interface request parameters
[0244] objType: Resource type # Resource type in the authentication configuration
[0245] boType: Business object type # Business object type in the authentication configuration
[0246] operateType: Operation type # Operation type in the authentication configuration
[0247] conditionEl:'springEl expression' # This springEl expression must be true for this configuration to take effect
[0248] passConditionEl:'springEl expression' # When it is true, the authentication passes directly without executing the authentication logic
[0249] sites: [cn, hk, eur] # Site information, the configurations of the interfaces may be different for different sites
[0250] In a possible implementation, the computing device 310 determines the business object type corresponding to the front-end navigation bar URL in the operation request from the mapping relationship between the URL and the business object type, so as to determine an access control policy a with a business object type consistent with the business object type indicated by the operation request from multiple access control policies.
[0251] In this application, according to the mapping relationship between the URL and the business object type, the computing device 310 can accurately and quickly determine the access control policy a that is consistent with the business object type indicated by the operation request, avoiding the time-consuming caused by traversing all access control policies and obtaining invalid first information according to all access control policies, as well as the performance loss of the computing device 310. This improves the efficiency of authenticating operation requests in complex scenarios (where one interface has multiple business object types) and reduces the performance loss of the computing device 310.
[0252] Step ④: The computing device 310 uses the access control policy a to obtain the first feature information and the second feature information of the operation request, and obtains the first information.
[0253] The first information includes the first feature information and the second feature information. Among them, the second feature information is pre-configured in the access control policy.
[0254] In a possible example, the first information includes the operation type, business object type, resource identifier, resource type, and user identifier.
[0255] Exemplarily, the user identifier, operation type, business object type, resource type, and resource identifier are arranged in sequence.
[0256] Step ⑤: The computing device 310 uses the first information to perform cache data verification, that is, uses the first information to query the second information. If there is information in the second information that is consistent with the first information, the authentication passes, and the following step ⑨ is executed. If there is no information in the second information that is consistent with the first information, the following step ⑥ is executed.
[0257] Among them, the second information is the information that passes the authentication, and the second information can be stored in the cache or hard disk. For example, the second information is stored in a data storage system (such as redis (Remote Dictionary Server)).
[0258] Step ⑥: The computing device 310 determines the first processing script according to the operation type and business object type in the first information.
[0259] In a possible example, the computing device 310 determines the authentication executor a from multiple authentication executors according to the operation type and business object type. The authentication executor is used to execute the first processing script. A YAML file is pre-configured in one authentication executor, and the processing script is defined in the YAML file.
[0260] The operation type and business object type in the YAML file pre-configured in the above authentication executor a are consistent with the operation type and business object type in the first information.
[0261] For example, the computing device 310 defines the mapping relationships among business object types, operation types, and resource types through a YAML file. Among them, in the YAML file, it is defined that through the business object type and operation type, a template SQL (i.e., the above-mentioned processing script) can be determined. Furthermore, the computing device 310 determines the field names of the table where the resource type is located, the table where the resource type is located, and the associated tables associated with the table where the resource type is located according to the resource type defined in the YAML file, adds the field names of the table where the resource type is located after SELECT in the template SQL, and adds the table where the resource type is located and the associated tables associated with the table where the resource type is located after FROM in the template SQL to obtain the first processing script.
[0262] For a service module that uses a relational database (such as MySql), the computing device 310 can fully perform authentication by configuring the SQL statement query method.
[0263] The following shows a possible YAML file:
[0264] boType: business object type # business object type
[0265] navigationUrls: [url1, url2] # page navigation bar URL, used to quickly identify business objects
[0266] sites: [site1, site2] # site information
[0267] operateConfigs:
[0268] - operateType: operation type # operation type, not allowed to have the same name under the same business object
[0269] baseSqlTemplate: |- # template SQL, which should contain the column names corresponding to the resources and the association relationships of the tables
[0270] SELECT ${column}
[0271] FROM table_name # operation type in the authentication configuration
[0272] ${tableJoinSql}
[0273] WHERE (${permissionSql})
[0274] conditions: |- # need to implement the PermissionConditionService interface in the service
[0275] - fieldname: privilegeSql # The scheduler obtains the permission object and uses reflection to obtain the fields in the permission object
[0276] placeholder: permissionSql # The placeholder name of the permission SQL in the template SQL
[0277] objTypes:
[0278] - objType: resource type # The resource type, which cannot have the same name under the same business object and operation type
[0279] relations:
[0280] - tableAlias: The alias of the table where the resource type is located
[0281] column: The field name of the table where the resource type is located
[0282] tableJoinSql: The association SQL between the table where the resource type is located and the base table in the template SQL
[0283] customized: true / false # Indicates whether it is a customized verification and requires implementing the DataAuthExecutor interface
[0284] Step ⑦: The computing device 310 adds the target permission object to the first processing script to obtain the second processing script.
[0285] In a possible example, the computing device 310 adds the target permission object indicated by the user identifier to the first processing script to obtain the second processing script.
[0286] The computing device 310 finds the Java implementation class of the defined interface PermissionConditionService in the YAML file, then calls this implementation class to obtain the permission object indicated by the user identifier, and uses Java's reflection mechanism to obtain the field information in the permission object, so as to add the field information in this permission object after the WHERE in the above template SQL to obtain the second processing script. This second processing script is a complete SQL, with specific fields after SELECT, FROM, and WHERE.
[0287] Step ⑧: The computing device 310 executes the second processing script to query the target permission data in the target data table that matches the target permission object.
[0288] If the target permission data includes the resource identifier, the authentication passes; if the target permission data does not include the resource identifier, the authentication fails.
[0289] In a possible example, the computing device 310 executes a second processing script through an authentication executor to query the target data in the target data table that matches the target right object.
[0290] Exemplarily, the computing device 310 defines various business object types, operation types, and resource types through a YAML file, and presents the processing script relationship through SQL in a relational database. The specific permission is represented as a permission SQL. The computing device 310 obtains a query result (target permission data) by executing an SQL with a filtering condition (such as including the target permission object), and then determines whether the operation request has the permission to call the service module a according to whether the target permission data includes a resource identifier.
[0291] Regarding the content of the above steps ⑥ - ⑧, a possible example is provided below. In this example, taking the query in the operation types including addition, deletion, modification, or query as an example, taking the order business as the business object type, and taking "name" in the resource type as an example for description.
[0292] The computing device 310 determines the authentication executor a from multiple authentication executors according to "addition" and "order business" in the first information. The operation type is defined as "addition" and the business object type is defined as "order business" in the YAML file that can be pre-configured in the authentication executor a, which is consistent with the first information. Furthermore, the computing device 310 calls the Java implementation class of the interface PermissionConditionService defined in the YAML file to obtain the permission object indicated by the user identifier, and then obtains the field information in the permission object, such as "Province A", through the reflection mechanism of Java. The computing device 310 combines the processing template in the YAML file pre-configured in the authentication executor a, the field name of the target data table where the resource type indicated by the resource type is located, the target data table where the resource type is located, and the associated table associated with the target data table where the resource type is located to obtain a first processing script.
[0293] Thus, the computing device 310 adds the above "Province A" to the first processing script according to the pre-configured YAML file to obtain a second processing script; the authentication executor a executes the second processing script to query the target permission data that meets "Province A" in the table where the resource type is "name" and the associated table of the table where the resource type is "name". If the target permission data includes a resource identifier, the authentication passes. If the target permission data does not include a resource identifier, the authentication fails.
[0294] Step ⑨: If the authentication passes, the computing device 310 executes the business logic indicated by the operation request.
[0295] In a possible scenario, the computing device 310 stores the information that the authentication passes in a cache or a hard disk.
[0296] Step ⑩: If the authentication fails, the computing device 310 intercepts the request and issues an alarm.
[0297] In other embodiments of the present application, during the authentication process based on the first information, in addition to using the configured YAML method for authentication, the code method can be used for authentication. For example, public interface DataAuthExecutor extends PermissionType
[0298]
[0299] The content indicated by the above code is Figure 5 the content shown in steps ⑤ and ⑥ in , which will not be elaborated here.
[0300] It can be understood that in order to implement the functions in the above embodiments, the computing device 310 includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combining the units and method steps of each example described in the embodiments disclosed in the present application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application scenarios and design constraints of the technical solution.
[0301] In the above text, in combination with Figures 2 to 5 the data access control method provided according to the present application has been described in detail. Next, in combination with Figure 6 , Figure 6 a structural schematic diagram of a data access control device provided by the present application Figure 1 the data access control device provided by the present application will be described. The data access control device 600 can be used to implement the functions of the computing device 310 in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0302] As Figure 6 shown, the data access control device 600 includes an acquisition module 610, an extraction module 620, and a first query module 630. In a possible example, the specific process for the data access control device 600 to implement the above data access control method includes the following process:
[0303] The acquisition module 610 is used to acquire the access control policy for the target data resource. The target data resource includes multiple data, and the access control policy of the target data resource indicates the target data table, and the target data table includes the permission objects for which the user has access permissions to at least one of the multiple data in the target data resource.
[0304] An extraction module 620, configured to extract first feature information in an operation request in response to an operation request triggered by a user for a target data resource, where the first feature information includes a resource identifier of the target data resource and a user identifier of the user, and the resource identifier indicates that the operation request is used to request an operation on at least one target data among a plurality of data in the target data resource.
[0305] A first query module 630, configured to query a target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user; if the target permission data includes the resource identifier, the authentication passes; if the target permission data does not include the resource identifier, the authentication fails.
[0306] To further implement the functions in the method embodiments shown above Figures 2 to 5 in this application, a data access control device is further provided. As shown in Figure 7 the following, Figure 7 is a structural schematic diagram of a data access control device provided by this application Figure 2 . The data access control device 600 further includes: a second query module 640.
[0307] Among them, the second query module 640 is configured to query for first information in the second information; if there is information in the second information that is the same as the first information, the authentication passes; if there is no information in the second information that is the same as the first information, perform a query of the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user. Among them, the access control policy includes second feature information of the target data resource, the operation request indicates the second feature information, the first information includes the first feature information and the second feature information, and the second information corresponding to the operation request with passed authentication is stored in the computing device.
[0308] Among them, the acquisition module 610, the extraction module 620, the first query module 630, and the second query module 640 can all be implemented by software or can be implemented by hardware. Exemplarily, next, taking the acquisition module 610 as an example, the implementation manner of the acquisition module 610 is introduced. Similarly, the implementation manners of the extraction module 620, the first query module 630, and the second query module 640 can refer to the implementation manner of the acquisition module 610.
[0309] As an example of a software functional unit, the acquisition module 610 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the acquisition module 610 may include code running on multiple hosts / virtual machines / containers.
[0310] It should be noted that the multiple hosts / virtual machines / containers for running the code can be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code can be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Generally, one region can include multiple AZs.
[0311] Similarly, the multiple hosts / virtual machines / containers for running the code can be distributed in the same VPC or in multiple VPCs. Generally, one VPC is set up within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set up within each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0312] As an example of a hardware functional unit, the acquisition module 610 can include at least one computing device, such as a server. Alternatively, the acquisition module 610 can also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD can be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0313] The multiple computing devices included in the acquisition module 610 can be distributed in the same region or in different regions. The multiple computing devices included in the acquisition module 610 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the acquisition module 610 can be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0314] It should be noted that in other embodiments, the obtaining module 610 can be used to perform any step in the data access control method, the extraction module 620 can be used to perform any step in the data access control method, and the first query module 630 can be used to perform any step in the data access control method. The steps to be implemented by the obtaining module 610, the extraction module 620, and the first query module 630 can be specified as needed. By respectively implementing different steps in the data access control method through the obtaining module 610, the extraction module 620, and the first query module 630, all functions of the computing device 310 are realized.
[0315] It should be noted that the computing device 310 in the foregoing embodiment can correspond to the data access control device 600 and can correspond to the corresponding subject that executes the method according to the embodiment of the present application. Figures 2 to 5 And the operations and / or functions of each module in the data access control device 600 are respectively for implementing Figures 2 to 5 the corresponding processes of the respective methods in the corresponding embodiments. For the sake of brevity, they will not be described in detail here.
[0316] In addition, Figure 6 or Figure 7 the data access control device 600 shown can also be implemented by a communication device. Here, the communication device can refer to the computing device 310 in the foregoing embodiment. When the communication device is a chip or a chip system applied to a processing device, the data access control device 600 can also be implemented by the chip or the chip system.
[0317] An embodiment of the present application further provides a chip system, which includes a control circuit and an interface circuit. The interface circuit is used to obtain an access control policy and an operation request, and the control circuit is used to implement the functions of the computing device 310 in the foregoing method according to the obtained access control policy and operation request.
[0318] In a possible design, the foregoing chip system further includes a memory for storing program instructions and / or data. The chip system can be composed of chips or can include chips and other discrete devices.
[0319] An embodiment of the present application further provides a computing device. Please refer to Figure 8 , Figure 8A structural schematic diagram of a computing device provided by this application. The computing device 800 includes a bus 802, a processor 804, a memory 806, and a communication interface 808. Among them, the processor 804, the memory 806, and the communication interface 808 are communicatively connected to each other through the bus 802. The computing device 800 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 800. For example, the computing device 800 can be the above-mentioned computing device 310.
[0320] The bus 802 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, Figure 8 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus. The bus 802 can include a path for transmitting information between various components of the computing device 800 (for example, the processor 804, the memory 806, the communication interface 808).
[0321] The processor 804 can include any one or more of a CPU, a GPU, a microprocessor (MP), or a DSP, etc.
[0322] The memory 806 can include a volatile memory, such as a Random Access Memory (RAM). The processor 804 can also include a non-volatile memory, such as a Read-Only Memory (ROM), a flash memory, a Hard Disk Drive (HDD), or a Solid State Drive (SSD).
[0323] The memory 806 stores executable program code, and the processor 804 executes the executable program code to respectively implement the functions of the aforementioned acquisition module 610, extraction module 620, and first query module 630, thereby implementing the data access control method. That is, the memory 806 stores instructions for executing the data access control method.
[0324] The communication interface 808 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 800 and other devices or communication networks. The computing device 800 can be a computer (e.g., a server) in a cloud data center, or a computer in an edge data center, or a terminal.
[0325] For the functions of the computing device 310 and the computing device 320 deployed within the same computing device 800, the computing device 310 can communicate with the computing device 320 via the bus 802.
[0326] For the functions of the computing device 310 and the computing device 320 deployed in different computing devices 800, the computing device 320 can communicate with the computing device 310 via a communication network.
[0327] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device, which can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0328] As Figure 9 shown, Figure 9 is a schematic structural diagram of a computing device cluster provided by the present application. The computing device cluster includes at least one computing device 800. Instructions for executing a data access control method can be stored in the same manner in the memories 806 of one or more of the computing devices 800 in the computing device cluster.
[0329] In some possible implementation manners, partial instructions for executing the data access control method can also be stored separately in the memories 806 of one or more of the computing devices 800 in the computing device cluster. In other words, a combination of one or more computing devices 800 can jointly execute the instructions for executing the data access control method.
[0330] It should be noted that the memories 806 in different computing devices 800 in the computing device cluster can store different instructions, which are respectively used to execute partial functions of the data access control method. That is, the instructions stored in the memories 806 of different computing devices 800 can implement the functions of one or more of the acquisition module 610, the extraction module 620, and the first query module 630.
[0331] In some possible implementation manners, one or more computing devices in the computing device cluster can be connected via a network. Among them, the network can be a wide area network or a local area network, etc. Figure 10 shows a possible implementation manner. As Figure 10 shown,Figure 10 A connection schematic diagram between computing devices provided for this application. Two computing devices 800A and 800B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this possible implementation, the instructions for executing the functions of the acquisition module 610 are stored in the memory 806 of the computing device 800A. At the same time, the instructions for executing the functions of the extraction module 620 and the first query module 630 are stored in the memory 806 of the computing device 800B.
[0332] It should be understood that Figure 10 the functions of the computing device 800A shown in can also be completed by multiple computing devices 800. Similarly, the functions of the computing device 800B can also be completed by multiple computing devices 800.
[0333] The embodiments of this application also provide a computer program product containing instructions. This computer program product can be software or a program product that contains instructions and can run on a computing device or be stored in any available medium. When this computer program product runs on at least one computing device, it causes at least one computing device to execute the above data access control method.
[0334] The embodiments of this application also provide a computer-readable storage medium. This computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc. This computer-readable storage medium includes instructions that direct the computing device to execute the data access control method.
[0335] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid state drive (SSD).
[0336] As described above, the above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A data access control method, characterized in that: The method is applied to a computing device, and the method comprises: Acquire an access control policy for a target data resource, the target data resource comprising a plurality of data, the access control policy of the target data resource indicating a target data table, the target data table comprising a permission object for which a user has access rights to at least one of the plurality of data in the target data resource; In response to an operation request for the target data resource triggered by a user, extracting first characteristic information in the operation request, the first characteristic information including a resource identifier of the target data resource and a user identifier of the user, the resource identifier indicating that the operation request is used to request an operation on at least one target data among a plurality of data in the target data resource; Querying the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user; If the target authority data includes the resource identifier, the authentication is successful; if the target authority data does not include the resource identifier, the authentication is unsuccessful.
2. The method according to claim 1, characterized in that The multiple data include multiple primary data, each of the primary data includes multiple secondary data, the target data is secondary data, the operation request is used to request an operation on target secondary data among the multiple secondary data, and the target data table includes a permission object having access rights to the multiple primary data; The querying of the target data table based on the operation request to obtain the target permission data in the target data table that has a mapping relationship with the user identifier of the user includes: Query the target data table according to the target permission object having a mapping relationship with the user identifier to obtain at least one target first-level data; Determine that the secondary data included in the at least one target primary data in the target data table is the target authority data.
3. The method according to claim 1 or 2, characterized in that: The uniform resource locator URL in the operation request indicates the target data resource to be operated by the operation request.
4. The method according to any one of claims 1 to 3, characterized in that The access control policy includes second characteristic information of the target data resource, the operation request indicates the second characteristic information, the first information includes first characteristic information and second characteristic information, the computing device stores second information corresponding to the operation request that has passed authentication, and before querying the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user, the method further includes: searching the second information for the first information; If the second information contains information that is identical to the first information, the authentication is successful; if the second information does not contain information that is identical to the first information, the target data table is queried based on the operation request to obtain target authority data in the target data table that has a mapping relationship with the user identifier of the user.
5. The method according to any one of claims 1 to 4, characterized in that The access control policy includes second characteristic information indicated by the target data resource, the operation request indicates the second characteristic information, the computing device stores a correspondence between the second characteristic information and a processing script, a processing script corresponding to the second characteristic information, indicating a method for querying target permission data from a target data table, and querying the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user, including: In determining the corresponding relationship, the first processing script corresponding to the second feature information; Adding a target permission object having a mapping relationship with the user identifier to the first processing script to obtain a second processing script; The target data table is queried by using the second processing script to obtain the target permission data corresponding to the target permission object in the target data table.
6. The method according to claim 4 or 5, characterized in that: The second characteristic information includes one or more of the following: business object type, operation type, resource type; the resource type is used to indicate the resource type in the target data resource, and the operation type is used to indicate the processing method for the data included in the target data resource.
7. The method according to claim 6, characterized in that The operation type includes one or more of the following: add, delete, modify, and query.
8. The method according to claim 6 or 7, characterized in that: The format of the first information is: the user identifier, the operation type, the business object type, the resource type, and the resource identifier arranged in sequence.
9. A data access control device, characterized in that: The device is applied to a computing device, and comprises: an acquisition module, configured to acquire an access control policy for a target data resource, the target data resource comprising a plurality of data, the access control policy of the target data resource indicating a target data table, the target data table comprising a permission object for which a user has access rights to at least one of the plurality of data in the target data resource; an extraction module, configured to extract, in response to an operation request for the target data resource triggered by a user, first characteristic information in the operation request, wherein the first characteristic information includes a resource identifier of the target data resource and a user identifier of the user, and the resource identifier indicates that the operation request is used to request an operation on at least one target data among a plurality of data in the target data resource; The first query module is used to query the target data table based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user; if the target permission data includes the resource identifier, the authentication is successful; if the target permission data does not include the resource identifier, the authentication fails.
10. The device according to claim 9, characterized in that The multiple data include multiple primary data, each of the primary data includes multiple secondary data, the target data is secondary data, the operation request is used to request an operation on target secondary data among the multiple secondary data, and the target data table includes a permission object having access rights to the multiple primary data; The first query module is specifically used to query the target data table according to the target permission object having a mapping relationship with the user identifier, obtain at least one target first-level data, and determine that the second-level data included in the at least one target first-level data in the target data table is the target permission data.
11. The device according to claim 9 or 10, characterized in that The uniform resource locator URL in the operation request indicates the target data resource to be operated by the operation request.
12. The device according to any one of claims 9 to 11, characterized in that The access control policy includes the second characteristic information of the target data resource, the operation request indicates the second characteristic information, the first information includes the first characteristic information and the second characteristic information, and the computing device stores the second information corresponding to the operation request that has passed the authentication; the apparatus further includes: a second query module; The second query module is used to query the first information in the second information; if the second information contains information that is identical to the first information, the authentication is passed; if the second information does not contain information that is identical to the first information, the target data table is queried based on the operation request to obtain target permission data in the target data table that has a mapping relationship with the user identifier of the user.
13. The device according to any one of claims 9 to 12, characterized in that The access control policy includes second characteristic information indicated by the target data resource, the operation request indicates the second characteristic information, the computing device stores a correspondence between the second characteristic information and a processing script, and a processing script corresponding to the second characteristic information, indicating a method for querying target permission data from a target data table; The first query module is specifically used to determine a first processing script corresponding to the feature information in the corresponding relationship; The target permission object having a mapping relationship with the user identifier is added to the first processing script to obtain a second processing script, and the target data table is queried using the second processing script to obtain the target permission data in the target data table corresponding to the target permission object.
14. The device according to claim 12 or 13, characterized in that The second characteristic information includes one or more of the following: business object type, operation type, resource type; the resource type is used to indicate the resource type in the target data resource, and the operation type is used to indicate the processing method for the data included in the target data resource.
15. The device according to claim 14, characterized in that The operation type includes one or more of the following: add, delete, modify, and query.
16. The device according to claim 14 or 15, characterized in that The format of the first information is: the user identifier, the operation type, the business object type, the resource type, and the resource identifier arranged in sequence.
17. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 8.
18. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 8.
19. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method according to any one of claims 1 to 8.
Citation Information
Cited By
Management of object metadata across data sources and storage systems
US12670289B2
Management of object metadata across data sources and storage systems
WO2026096048A1