Control Method, Device, Electronic Device and Computer Storage Medium for System Permissions
By directly assigning access rights to the target functional module and its lower-level modules to the account, the problem of excessive consumption of the permission control program in the prior art is solved, and more efficient permission control is achieved.
Patent Information
- Application Number
- CN202010960386.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-14
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2040-09-14
AI Technical Summary
In the prior art, the system permission control program needs to detect and authorize the account access rights to multiple underlying functional modules one by one, resulting in excessive consumption of computer resources.
By receiving the access permission request of the target function module, we determine whether the target function module includes the lower-level module. If included, directly allocate the access permissions of the target function module and its lower-level module to the application account, reducing the need for detection and authorization one by one.
It effectively reduces the computer resources consumed by the control program during runtime, and improves the efficiency and user experience of permission control.
Smart Images

Figure CN112069521B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to a method, device, electronic device and computer storage medium for controlling system permissions. Background Art
[0002] A complex business system is often composed of multiple functional modules belonging to different levels. Each level can have multiple functional modules. An upper-layer functional module can be composed of multiple lower-layer functional modules that cooperate with each other. Each account using the business system can use some of the functional modules according to actual needs. In practical applications, in order to ensure the safe operation of each functional module of the business system, it is generally necessary to control the access permissions of the account to each functional module of the system through a control program.
[0003] Existing control programs generally use the access permissions of the underlying functional modules in the system as the permission control granularity. When an account needs to obtain the access permission of an upper-layer functional module, the account needs to submit an application request for each functional module located at the level of the permission control granularity included in the upper-layer functional module, that is, each underlying functional module. The control program needs to detect the application requests of the account for each underlying functional module included in the upper-layer functional module one by one and authorize the account, resulting in excessive consumption of computer resources when the control program runs. Summary of the Invention
[0004] In view of the above-mentioned disadvantages of the prior art, the present application provides a method, device, electronic device and computer storage medium for controlling system permissions to reduce the computer resources consumed by the control program.
[0005] The first aspect of the present application provides a method for controlling system permissions, including:
[0006] Receiving an application request for the access permission of a target functional module, where the level of the target functional module is the level of the permission control granularity;
[0007] If the application request passes, determining whether the target functional module includes at least one lower-layer module; where the lower-layer module refers to a functional module whose own level is lower than the level of the permission control granularity;
[0008] If the target functional module includes at least one lower-layer module, allocating the access permission of the target functional module and the access permission of each lower-layer module included in the target functional module to the account that applies for the access permission of the target functional module.
[0009] Optionally, after allocating the access permission of the target function module and the access permission of each lower-level module included in the target function module to the account applying for the access permission of the target function module, the following steps are further included:
[0010] Count the proportion of accounts among all accounts that send application requests within a preset time period, where the requests are for access permissions of multiple function modules located at the level of the permission control granularity and belonging to the same upper-level module; wherein, the upper-level module refers to a function module whose own level is the upper level of the level of the permission control granularity.
[0011] If the proportion is greater than a preset floating threshold, float the permission control granularity from the current level to the upper level of the current level.
[0012] Optionally, the following steps are further included:
[0013] When a new function module is detected at the lower level of the level where the permission control granularity is located, determine the function module including the new function module at the level where the permission control granularity is located, and allocate the access permission of the new function module to each account that has the access permission of the function module.
[0014] Optionally, the following steps are further included:
[0015] Calculate the difference between the number of function modules at the lower level of the level where the permission control granularity is located and the number of function modules at the level where the permission control granularity is located, and determine whether the difference is less than a preset downward threshold.
[0016] If the difference is less than the downward threshold, lower the permission control granularity from the current level to the lower level of the current level.
[0017] Optionally, after lowering the permission control granularity from the current level to the lower level of the current level, the following steps are included:
[0018] Delete the access permission of each account to the function module at the level before the permission control granularity is lowered.
[0019] The second aspect of the present application provides a control device for system permissions, including:
[0020] A receiving unit, configured to receive an application request for the access permission of a target function module, where the level of the target function module is the level of the permission control granularity.
[0021] A judgment unit, configured to determine whether the target function module includes at least one lower-level module if the application request passes; wherein, the lower-level module refers to a function module whose own level is lower than the level where the permission control granularity is located.
[0022] An allocation unit, configured to, if the target function module includes at least one lower-level module, allocate the access permission of the target function module and the access permission of each lower-level module included in the target function module to an account that applies for the access permission of the target function module.
[0023] Optionally, the control device further includes:
[0024] A statistics unit, configured to count the proportion of accounts among all accounts that send application requests within a preset time period, where the requests are for the access permissions of multiple function modules located at the level where the permission control granularity is located and belonging to the same upper-level module; wherein, the upper-level module refers to a function module whose own level is the upper level of the level where the permission control granularity is located.
[0025] An adjustment unit, configured to, if the proportion is greater than a preset floating threshold, float the permission control granularity from the current level to the upper level of the current level.
[0026] Optionally, the allocation unit is further configured to:
[0027] When it is detected that there is a newly added function module at the lower level of the level where the permission control granularity is located, determine the function module that includes the newly added function module at the level where the permission control granularity is located, and allocate the access permission of the newly added function module to each account that has the access permission of the function module.
[0028] A third aspect of the present application provides an electronic device, including a memory and a processor;
[0029] Wherein, the memory is used to store a computer program;
[0030] The processor is configured to execute the computer program, and specifically configured to implement the system permission control method provided in any item of the first aspect of the present application.
[0031] A fourth aspect of the present application provides a computer storage medium, used to store a computer program, and when the computer program is executed, it is specifically configured to implement the system permission control method provided in any item of the first aspect of the present application.
[0032] The present application provides a method, apparatus, electronic device, and computer storage medium for controlling system permissions. The method includes receiving an application request for access permissions of a target function module, where the level where the target function module is located is the level where the permission control granularity is located; if the application request is approved, determining whether the target function module includes at least one lower-level module; a lower-level module refers to a function module whose own level is lower than the level where the permission control granularity is located; if the target function module includes at least one lower-level module, assign the access permissions of the target function module and the access permissions of each lower-level module included in the target function module to the account that applies for the access permissions of the target function module. After the application request is approved, this solution directly assigns access permissions to the target module and each lower-level module included in the target module, without the need to detect the application requests of the account for multiple lower-level modules one by one, thereby reducing the computer resources consumed during the operation of the control program. Description of the Drawings
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0034] Figure 1 It is a flowchart of a method for controlling system permissions provided by an embodiment of the present application;
[0035] Figure 2 It is a schematic structural diagram of a service system provided by an embodiment of the present application;
[0036] Figure 3 It is a flowchart of a method for increasing the permission control granularity provided by an embodiment of the present application;
[0037] Figure 4 It is a flowchart of a method for decreasing the permission control granularity provided by an embodiment of the present application;
[0038] Figure 5 It is a flowchart of an existing system permission application method;
[0039] Figure 6 It is a flowchart of a permission application method provided by an embodiment of the present application;
[0040] Figure 7 It is a schematic structural diagram of a system permission control device provided by an embodiment of the present application;
[0041] Figure 8 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0043] For a business system adopting a layered architecture, the permission control granularity of the business system can be considered as the minimum level when controlling the access permissions of each functional module in the business system. In the prior art, in order to accurately control the access permissions of each functional module in the business system, the permission control granularity is generally fixed at the lowest level in the business system. Each time an account makes an application request, it can only apply for the access permission of the functional module at the level where the permission control granularity is located, that is, the access permission of the functional module at the lowest level of the business system. This leads to the permission control program of the business system needing to frequently process a large number of application requests for multiple functional modules at the lowest level, resulting in more computing resources consumed by the permission control program.
[0044] The embodiment of the present application provides a method for controlling system permissions, as Figure 1 described, the method may include the following steps:
[0045] The execution subject of any embodiment of the present application can be considered as a permission control program for controlling the permissions of a business system.
[0046] S101. Receive an application request for the access permission of a target functional module.
[0047] The application request in step S101 can be sent by any account of the business system to the permission control program on the terminal device connected to the system (which can be connected through a physical line or through a network connection). Hereinafter, the application account is used to refer to the account that sends the application request in step S101.
[0048] The target functional module refers to the functional module for which the application account requests access permission. Optionally, if the permission control program allows an application account to apply for the access permissions of multiple functional modules at one time, the target functional module in step S101 can refer to the multiple functional modules applied for this time.
[0049] For example, in the business system, there are functional module A and functional module B. The application account needs to obtain the access permissions of these two functional modules, so it sends an application request for the access permissions of these two functional modules to the permission control program. For this application request, functional module A and functional module B are the target functional modules in step S101.
[0050] Further, in a business system, the application requests sent by any account can only apply for the access rights of the function modules at the level where the permission control granularity of the system is located. Therefore, for the above-mentioned target function module, the level where it is located is the current level of the permission control granularity.
[0051] Suppose the function modules of the business system are divided into 5 levels, denoted as level 1 to level 5 in sequence, where level 1 is the highest level in the business system and level 5 is the lowest level. If the current level of the permission control granularity is level 4, then the target function module in step S101 is the function module that has its access rights applied for among the various function modules at level 4.
[0052] In the method for controlling system permissions provided in this application, the permission control granularity of the business system can be adjusted in real time according to the current hierarchical structure of the business system and the application situations of each system account for access rights. The specific adjustment method can refer to the subsequent embodiments.
[0053] S102. Determine whether to pass the application request.
[0054] If the above application request is passed, then execute step S104; otherwise, if the above application request is not passed, then execute step S103.
[0055] Optionally, the permission control program can detect whether to pass the above application request according to a preset permission configuration file and the account information of the applying account, or can forward the above application request to the terminal of the system permission administrator, and the system permission administrator determines to pass the above application request and feedbacks it to the permission control program through the terminal.
[0056] S103. Prohibit allocating the access rights of the target function module to the applying account.
[0057] If it is determined that the application request is not passed, it means that the applying account is not allowed to access (or call) the requested target function module. Therefore, the access rights of the target function module should be prohibited from being allocated to the applying account.
[0058] S104. Determine whether the target function module includes at least one lower-level module.
[0059] If the target function module includes at least one lower-level module, then execute step S105; if the target function module does not include any lower-level module, then execute step S106.
[0060] Among them, the lower-level module refers to a function module whose own level is lower than the level where the permission control granularity is located.
[0061] Referring to the business system divided into 5 levels in the previous example, assuming that the current level of the permission control granularity is level 3 of the business system, the target function module is a function module at level 3. This target function module includes two function modules at level 4, denoted as function module C and function module D respectively. Further, function module C includes 3 function modules at level 5, denoted as function module C1 to function module C3 in sequence, and function module D includes a function module D1 at level 5.
[0062] For the above example, when performing step S104, it can be determined that the target function module includes 6 lower-level modules, namely function module C and function module D at level 4, and function modules C1 to C3, function module D1 at level 5.
[0063] It should be noted that in the system permission control method provided in any embodiment of the present application, that a function module at a higher level includes multiple function modules at a lower level means that to call the function module at the higher level to implement the function of the function module at the higher level, it is necessary to call the function modules at the lower level included in the function module at the higher level. For example, in the above example, to call the target function module at level 3, it may be necessary to call function module C and function module D at level 4 included in the target function module respectively. In short, that a function module at a higher level includes function modules at a lower level can be considered that the function implemented by the latter is a sub-function of the function implemented by the former.
[0064] Generally, if the current level of the permission control granularity is not the lowest level in the business system, the target function module will include at least one lower-level function module. If the current level of the permission control granularity is the lowest level in the business system, there will be no level lower than the current level of the permission control granularity, and correspondingly, the target function module at the current level of the permission control granularity will not include lower-level modules.
[0065] S105. Assign access permissions for the target function module and access permissions for each lower-level module included in the target function module to the application account.
[0066] As described above, when the target function module includes several lower-level modules, to call the function of the target function module may involve calling the functions of the lower-level modules included in the target function module. To ensure that after the access permission of the target function module is assigned to the application account, the application account can smoothly use all functions of the target function module, it is necessary to assign the access permissions of each lower-level module included in the target function module to the application account together.
[0067] In this way, when the current level of the permission control granularity is higher than the lowest level of the business system, the applying account only needs to apply for the access permission of the target function module at the current level of the permission control granularity, and can access the target function module and call its complete functions after the application request is approved, without applying for the access permissions of multiple lower-level modules included in the target function module one by one, which significantly improves the user experience of the business system.
[0068] On the other hand, it can be understood that in step S102, whether the permission control program directly determines whether to approve the application request according to the permission configuration file, or the permission control program forwards the application request to the terminal of the system permission administrator for the administrator to judge, the permission control program needs to consume certain resources to process the application request put forward by the applying account. Moreover, in a hierarchical business system, the lower the level, the more function modules there are at that level. If a large number of accounts in the business system frequently put forward application requests for multiple function modules at a lower level, the permission control program will consume a large amount of computing resources to process these application requests.
[0069] In this solution, the permission control program only needs to process the application requests of each account in the business system for the function modules at the level of the permission control granularity, and the access permissions of the lower-level modules can be allocated to the applying account together with the access permission of the target function module after the application request for the function module at the level of the permission control granularity is approved. Based on the control method provided in this embodiment, as long as the permission control granularity is set at a higher level, the number of application requests put forward by each account in the business system can be effectively reduced, thereby reducing the computing resources consumed by the permission control program.
[0070] S106. Allocate the access permission of the target function module to the applying account.
[0071] Any user who needs to call the target function module can log in to the account assigned to him / her in the system on the terminal device connected to the corresponding system, and then put forward the application request mentioned in step S101 under this account, so as to apply to the system's permission control program for the access permission of the target function module.
[0072] After the application request is approved, the permission control program allocates the access permission of the target function module and each lower-level module included in the target function module to this account by executing the method provided in the above embodiment, that is, allows this account to directly call (or access) the target function module and each lower-level module included in the target function module.
[0073] The control method of the system permission provided in this embodiment has the following beneficial effects:
[0074] In the control method provided in this embodiment, when the level where the permission control granularity is located is higher than the lowest level of the business system, the permission control program can allocate the access permissions of the target function module at the level where the permission control granularity is located and the access permissions of each lower-level module included in the target function module to the application account whose corresponding application request has been approved. Therefore, the control method provided in this embodiment allows the permission control granularity to be set at other levels higher than the lowest level of the business system, and does not affect the functions of the target function module used by the application account after the application request is approved.
[0075] In addition, when the level where the permission control granularity is located is higher than the lowest level of the business system, the number of function modules at the level where the permission control granularity is located is less than the number of function modules at the lowest level of the business system. Correspondingly, the number of application requests for the function modules at the level where the permission control granularity is located that the permission control program needs to process is also less. Therefore, the control method provided in this embodiment can reduce the computing resources consumed when the permission control program runs.
[0076] To facilitate the understanding of the control method provided in the embodiments of the present application, the implementation process of the control method for system permissions provided in the embodiments of the present application will be described below with a specific example.
[0077] First, please refer to Figure 2 , a simplified business system including 3 levels may include several function modules as shown in Figure 2 . The levels of each function module are as indicated in the annotation in Figure 2 .
[0078] As shown in Figure 2 , the function module cost analysis at level 1 includes 5 lower-level modules at level 2, namely customer-level cost, cost details, cost parameters, sub-product cost, and user-level cost. Assume that the permission control granularity of this business system is set at level 1, that is, the current level where the permission control granularity is located is level 1. After the application account submits an application request to obtain the access permission of the cost analysis function module, the permission control program determines that the application request is approved. Then, the permission control program allocates the access permission of cost analysis and the access permissions of the 5 lower-level modules, namely customer-level cost, cost details, cost parameters, sub-product cost, and user-level cost, to this application account. In this way, this application account can call the complete functions of the cost analysis function module, and at the same time, the permission control program does not need to process the application requests of the application account for the above 5 lower-level modules, namely customer-level cost, cost details, cost parameters, sub-product cost, and user-level cost, one by one. It can be seen from this that the method provided in this embodiment can effectively reduce the computing resources consumed when the permission control program runs on the premise of meeting the usage requirements of the application account.
[0079] As described above, in the system permission control method provided in the embodiments of the present application, the permission control granularity of the system can be adjusted according to the current hierarchical structure of the system and the application situations of access permissions of each account in the system. Specifically, it can include increasing the permission control granularity, that is, moving the permission control granularity from the current level to the upper level, and decreasing the permission control granularity, that is, moving the permission control granularity from the current level to the lower level. The following will specifically describe the two adjustment methods in combination with the corresponding drawings.
[0080] Please refer to Figure 3 , a method for increasing the permission control granularity provided by the embodiments of the present application may include the following steps:
[0081] S301. Count the proportion of the application accounts that request access permissions for multiple function modules located at the level of the permission control granularity and belonging to the same upper module among all application accounts within a preset time period.
[0082] Among them, the upper module refers to a function module whose own level is the upper level of the level of the permission control granularity.
[0083] The above preset time period can be a past duration with the current moment as the end moment. For example, the preset time period can be the most recent 24 hours or the most recent 12 hours up to the current moment.
[0084] After setting the permission control granularity, if any account needs to obtain the access permission of an upper module, it needs to apply for the access permissions of each function module located at the level of the permission control granularity included in this upper module one by one. For an upper module, if an account has obtained the access permissions of each function module located at the level of the permission control granularity included in this upper module, and the permission control program determines that the access permission of this upper module can be allocated to this account, then the permission control program will allocate the access permission of this upper module to this account.
[0085] For example, assume that the current level of the permission control granularity is level 4. If account A wants to obtain the access permission of an upper module X located at level 3, account A needs to apply for the access permissions of each function module at level 4 included in upper module X one by one. After account A has the access permissions of each function module at level 4 included in upper module X, the permission control program can automatically determine whether to allocate the access permission of upper module X to account A, and allocate the access permission of upper module X to account A after the judgment passes.
[0086] In summary, assume that 1,000 accounts submit application requests to the permission control program within a preset time period. Among them, a relatively large proportion of accounts, for example, 700 accounts, all apply for access rights to each function module at the level where the permission control granularity is located in the same upper module. This indicates that within a recent period of time, many accounts need to use the functions of the corresponding upper module, rather than just using a part of the sub-functions of the upper module.
[0087] S302. Determine whether the above ratio is greater than a preset floating-up threshold.
[0088] If the ratio statistically obtained in step S301 is less than or equal to the floating-up threshold, there is no need to float up the permission control granularity, and step S303 is executed. On the contrary, if the ratio statistically obtained in step S301 is greater than the floating-up threshold, it is necessary to float up the permission control granularity, that is, step S304 is executed.
[0089] When the ratio statistically obtained in step S301 is greater than the floating-up threshold, it can be considered that within a recent period of time, the level corresponding to the function requirements of most accounts is higher than the current level where the permission control granularity is located. For example, assume that the current level where the permission control granularity is located is level 4. If it is determined that the ratio statistically obtained in step S301 is greater than the floating-up threshold, it means that the functions required by most accounts within a recent period of time are the functions corresponding to the function modules at level 3. In this case, if the permission control granularity continues to be maintained at the current level, it will cause the subsequent permission control program to frequently process application requests for multiple function modules at level 4. However, if the level where the permission control granularity is located is floated up from level 4 to level 3, the application requests for multiple function modules at level 4 can be merged into application requests for a few function modules at level 3, thereby significantly reducing the number of application requests that the permission control program is expected to process within a future period of time, and further reducing the computer resources consumed by the permission control program.
[0090] S303. Keep the permission control granularity at the current level.
[0091] S304. Float up the permission control granularity from the current level to the upper level of the current level.
[0092] After step S304 is executed, the access rights of the accounts that originally held the access rights to the function modules at the level before the floating-up of the permission control granularity remain unchanged. When other accounts apply for access rights subsequently, they can only apply for the access rights to the function modules at the level after the floating-up of the permission control granularity.
[0093] Combined with the business system divided into 5 levels in the foregoing example, assuming that the current level of the permission control granularity is level 4, then, when performing step S304, it is to change the level where the permission control granularity is located to the upper level of level 4, that is, level 3. After floating up the permission control granularity, when a subsequent account needs to apply for access rights to the function modules of the business system, it is necessary to apply for the function modules at the level where the permission control granularity is located after floating up. In the above example, after performing step S304, the application requests made by subsequent accounts applying for access rights are requests for access rights to the function modules at level 3.
[0094] The method for floating up the permission control granularity provided in this embodiment can be considered as shrinking the permission control granularity of the business system.
[0095] During the operation of the business system, technicians often add new function modules to the business system. Optionally, in the method for controlling system permissions provided in any embodiment of the present application, when the current level where the permission control granularity is located is higher than the lowest level of the business system, it may occur that the level where the newly added function module is located is the lower level of the level where the permission control granularity is located.
[0096] For example, if the level where the permission control granularity is located is level 4, the newly added function module may be a function module at level 5.
[0097] In view of the above situation, the permission control program can detect each newly added function module in the business system in real time. When it detects that there is a newly added function module at the lower level of the level where the permission control granularity is located, it determines the function modules including the newly added function module among the levels where the permission control granularity is located, and allocates the access rights of the newly added function module to each account that has the access rights to the function module.
[0098] Specifically, assuming that the level where the permission control granularity is located is level 4, the newly added function module is a function module at level 5, and the newly added function module belongs to function module Y at level 4. Then, after the permission control program detects this newly added function module, the permission control program can find out each account that has the access rights to function module Y, and then allocate the access rights of this newly added function module to each account that has the access rights to function module Y. In this way, the permission control method provided in this embodiment can ensure that each account can use the newly added sub-functions of each authorized function module in real time.
[0099] The control method provided in this embodiment has the following beneficial effects:
[0100] During the operation of the business system, the requirements of users of the business system at different stages for functions at each level are also different. It is possible that in a certain stage, users generally tend to use functions at a lower level, while in another stage, they tend to use functions at a higher level. In this embodiment, by analyzing the application situation of users' access rights to each function module within a preset time period, the usage tendency of users in a short time is predicted, so as to timely increase the granularity of permission control, and further reduce the computing resources consumed by the permission control program.
[0101] Please refer to Figure 4 , a method for reducing the granularity of permission control provided by an embodiment of the present application may include the following steps:
[0102] S401. Calculate the difference between the number of function modules at the next lower level of the level where the permission control granularity is located and the number of function modules at the level where the permission control granularity is located.
[0103] For example, assume that the current level where the permission control granularity is located is level 3, and the next lower level of level 3 is level 4. Then, step S401 is to calculate the difference between the number of function modules at level 3 and the number of function modules at level 4 in the business system.
[0104] Optionally, step S401 can be executed at regular intervals, or can be executed when it is detected that there are changes in the function modules in the business system. For example, when it is detected that multiple function modules are newly added or deleted at one time in the business system, and when it is detected that the levels of multiple function modules in the business system have changed.
[0105] S402. Determine whether the difference is less than a preset downward adjustment threshold.
[0106] If the difference is greater than or equal to the downward adjustment threshold, then execute step S403. Conversely, if the difference is less than the downward adjustment threshold, then execute step S404.
[0107] As described above, the key to the control method provided by the present application is to set the permission control granularity at a higher level, so that the permission control program only needs to control the access rights of a small number of function modules at the higher level, reduce the number of application requests that the permission control program needs to process, and achieve the effect of reducing the consumption of computing resources.
[0108] When the number of functional modules at the current hierarchical level of the permission control granularity is close to the number of functional modules at the next hierarchical level of the current hierarchical level, that is, when the above difference is less than the downward adjustment threshold, the impact on the amount of computing resources consumed by adopting the above method is limited, that is, it will not significantly reduce the computing resources consumed by the permission control program. On the contrary, setting a higher permission control granularity will have an adverse impact on the security of the business system. Therefore, after determining that the difference in step S401 is less than the downward adjustment threshold, the permission control granularity can be moved from the current hierarchical level to the next hierarchical level, that is, the permission control granularity is lowered.
[0109] Optionally, in other embodiments of the present application, before increasing or decreasing the permission control granularity, it is also possible to combine Figure 3 the embodiments shown in Figure 4 and the methods of the embodiments shown in
[0110] For example, it is possible to lower the permission control granularity only when it is determined that the ratio obtained by counting in step S301 is not greater than the upward adjustment threshold and the difference in step S401 is less than the downward adjustment threshold. If either of these two conditions is not met, the permission control granularity will not be lowered.
[0111] S403. Keep the permission control granularity at the current hierarchical level.
[0112] S404. Lower the permission control granularity from the current hierarchical level to the next hierarchical level of the current hierarchical level.
[0113] Optionally, after performing step S404, in order to ensure the security of each functional module in the business system, for each functional module at the hierarchical level before the permission control granularity is lowered, the access permissions held by each account for this functional module can be deleted, and only the access permissions of each account for the functional modules at the hierarchical level after the permission control granularity is lowered are retained.
[0114] For example, if the permission control granularity is lowered from level 3 to level 4, then the access permissions originally assigned to each account for the functional modules at level 3 can be deleted, and at the same time, the access permissions of each account for the multiple functional modules at level 4 included in the functional modules at level 3 are retained.
[0115] In combination with the above example, assuming that an account B has access rights to a function module Z at level 3 and the lower modules included in function module Z, after the permission control granularity is lowered to level 4, the access rights of account B to function module Z will be deleted, while the access rights to each function module at level 4 included in function module Z will be retained. After lowering the permission control granularity, if a function module at level 4 subordinate to function module Z is added, the permission control program can automatically assign the access rights of this newly added function module to account B, so that account B always has access rights to each function module at level 4 included in function module Z.
[0116] Setting a higher permission control granularity for the business system can reduce the computing resources consumed by the permission control program, but it will also have a certain impact on the security of the business system. The method provided in this embodiment can reduce the permission control granularity when the reduced computing resource consumption is not obvious, thereby enhancing the security of the business system.
[0117] Optionally, in the permission control method provided in any embodiment of the present application, after determining that the permission control granularity needs to be lowered or the permission control granularity needs to be increased, a request to lower the permission control granularity or to increase the permission control granularity can be sent to the terminal of the permission administrator of the system, and the permission administrator can be prompted to confirm whether to lower or increase the permission control granularity. After the permission administrator confirms, the corresponding operation of lowering or increasing the permission control granularity can be performed.
[0118] In order to better understand the permission control scheme provided in the embodiment of the present application, the existing permission application process and the permission application process implemented based on the permission control scheme provided by the implementation of the present application are introduced below.
[0119] Please refer to Figure 5 , the existing permission application process is:
[0120] S501: A user submits an application for access rights to functional modules at multiple levels in a system.
[0121] S502: Pull the permission information of the applied function module.
[0122] The above permission information can be understood as a series of allocation rules for controlling which accounts the access rights of each functional module can be allocated to. The permission administrator can determine whether to allocate the access rights of the corresponding functional module to the user who initiates the application request based on the permission information.
[0123] S503: Check whether the application request is passed.
[0124] If the application request fails, return to step S501 and prompt the user to initiate the application request again. If the application request is approved, execute step S504.
[0125] S504. Determine whether all the application requests of this user have been verified.
[0126] If not all have been verified, return to step S502 and continue to verify whether another application request of this user is approved. If all the application requests of this user have been verified, execute step S505.
[0127] S505. Allocate access permissions for the function module applied for according to the verification result.
[0128] Steps S502 to S505 can be executed by the system's permission administrator.
[0129] It can be seen from the above application process that in the existing solution, if a user needs to obtain complete access permissions for a higher-level function module, application requests need to be made for this higher-level function module and each of its lower-level function modules included. Correspondingly, the permission control program needs to forward each of the multiple application requests made by the user to the permission administrator one by one for verification. Obviously, this process will consume more computer resources.
[0130] Please refer to Figure 6 , and the permission application process based on the permission control solution provided in this application can be:
[0131] S601. The user makes an application request for the function module at the level where the permission granularity is located.
[0132] S602. Pull the permission information of the function module applied for.
[0133] S603. Verify whether the application request is approved.
[0134] If the application request is not approved, return to step S601 and prompt the user to make a new application request. If the verification is approved, execute step S604.
[0135] S604. Allocate access permissions for the function module applied for by the user and all its lower-level modules included.
[0136] Steps S602 to S604 can be executed by the system's permission administrator.
[0137] In a system applying the permission control method of the present application, when the permission control granularity is at a higher level, the user only needs to apply for the function modules at the level where the permission control granularity is located. After the application request is approved, the user can automatically obtain the access permissions of the function modules at the level where the permission control granularity is located, as well as all the lower-level modules included in the function module. That is to say, the user only needs to submit an application request for a small number of function modules at the level where the permission control granularity is located, and can automatically obtain the complete access permissions of the applied function modules. Correspondingly, the number of application requests that the permission control program needs to forward is obviously less than that in the application process as shown in Figure 5 Therefore, applying the permission control method provided by the present application can reduce the computer resources consumed by the permission control program.
[0138] Combined with the system permission control method provided in the embodiments of the present application, the embodiments of the present application also provide a system permission control device for controlling the access permissions of function modules at each level of the system and adjusting the system permission control granularity according to the actual situation. Please refer to Figure 7 This device may include the following units:
[0139] A receiving unit 701, configured to receive an application request for the access permission of a target function module.
[0140] Wherein, the level where the target function module is located is the level where the permission control granularity is located.
[0141] A judging unit 702, configured to judge whether the target function module includes at least one lower-level module if the application request is approved.
[0142] Wherein, the lower-level module refers to a function module whose own level is lower than the level where the permission control granularity is located.
[0143] An allocating unit 703, configured to allocate the access permission of the target function module and the access permission of each lower-level module included in the target function module to the account that applies for the access permission of the target function module if the target function module includes at least one lower-level module.
[0144] Optionally, the control device further includes:
[0145] A statistical unit 704, configured to count the proportion of accounts that request the access permissions of multiple function modules located at the level where the permission control granularity is located and belonging to the same upper-level module among all the accounts that send application requests within a preset time period.
[0146] Wherein, the upper-level module refers to a function module whose own level is the upper level of the level where the permission control granularity is located.
[0147] An adjustment unit 705, configured to, if the ratio is greater than a preset floating threshold, float the permission control granularity from the current level to the upper level of the current level.
[0148] Optionally, the allocation unit 703 is further configured to:
[0149] When it is detected that there is a newly added function module in the lower level of the level where the permission control granularity is located, determine, in the level where the permission control granularity is located, the function modules including the newly added function module, and allocate the access permission of the newly added function module to each account having the access permission to the function module.
[0150] Optionally, the control device may further include:
[0151] A calculation unit 706, configured to calculate the difference between the number of function modules in the lower level of the level where the permission control granularity is located and the number of function modules in the level where the permission control granularity is located, and determine whether the difference is less than a preset downward adjustment threshold.
[0152] The adjustment unit 705 is further configured to, if the difference is less than the downward adjustment threshold, lower the permission control granularity from the current level to the lower level of the current level.
[0153] The allocation unit 703 is further configured to:
[0154] Delete the access permission of each account to the function modules in the level before the downward adjustment of the permission control granularity.
[0155] The present application provides a control device for system permissions. The device includes a receiving unit 701, configured to receive an application request for the access permission of a target function module, where the level where the target function module is located is the level where the permission control granularity is located; a judgment unit 702, configured to, if the application request passes, determine whether the target function module includes at least one lower-level module; a lower-level module refers to a function module whose own level is lower than the level where the permission control granularity is located; an allocation unit 703, configured to, if the target function module includes at least one lower-level module, allocate the access permission of the target function module and the access permission of each lower-level module included in the target function module to the account applying for the access permission of the target function module. After the application request passes, the present solution directly allocates the access permission to the target module and each lower-level module included in the target module, without the need to detect the application requests of the account for multiple lower-level modules one by one, thereby reducing the computer resources consumed during the operation of the control program.
[0156] An embodiment of the present application further provides an electronic device. Please refer to Figure 8 , and the electronic device may include a memory 801 and a processor 802.
[0157] Among them, the memory 801 is used to store computer programs;
[0158] The processor 802 is used to execute the computer program, and specifically used to implement the system privilege control method provided by any embodiment of the present application.
[0159] The embodiment of the present application also provides a computer storage medium for storing a computer program. When the computer program is executed, it is specifically used for the system privilege control method provided by any embodiment of the present application.
[0160] According to one aspect of the present application, there is provided a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the system privilege control method and the corresponding method for adjusting the privilege control granularity provided by any one of the above embodiments.
[0161] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the presence of additional identical elements in the process, method, article or device including the element.
[0162] It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions executed by these devices, modules or units.
[0163] Those skilled in the art can implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for controlling system permissions, characterized in that, Including: Receiving an application request for access rights to a target function module, where the level where the target function module is located is the level where the access control granularity is located; If the application request passes, determining whether the target function module includes at least one lower-level module; where the lower-level module refers to a function module whose own level is lower than the level where the access control granularity is located; If the target function module includes at least one lower-level module, allocating the access rights to the target function module and the access rights to each lower-level module included in the target function module to the account applying for the access rights to the target function module; Calculating the difference between the number of function modules at the next level below the level where the access control granularity is located and the number of function modules at the level where the access control granularity is located, and determining whether the difference is less than a preset downward adjustment threshold; If the difference is less than the downward adjustment threshold, lowering the access control granularity from the current level to the next level below the current level.
2. The control method according to claim 1, characterized in that, After allocating the access rights to the target function module and the access rights to each lower-level module included in the target function module to the account applying for the access rights to the target function module, further including: Counting the proportion of accounts among all accounts that send application requests within a preset time period and request access rights to multiple function modules located at the level where the access control granularity is located and belonging to the same upper-level module; where the upper-level module refers to a function module whose own level is the level above the level where the access control granularity is located; If the proportion is greater than a preset upward adjustment threshold, raising the access control granularity from the current level to the level above the current level.
3. The control method according to claim 1 or 2, characterized in that, Also including: When it is detected that there is a newly added function module at the next level below the level where the access control granularity is located, determining the function module that includes the newly added function module at the level where the access control granularity is located, and allocating the access rights to the newly added function module to each account that has the access rights to the function module.
4. The control method according to claim 1, characterized in that, After lowering the access control granularity from the current level to the next level below the current level, including: Deleting the access rights of each account to the function modules at the level before the access control granularity is lowered.
5. A control device for system permissions, characterized in that, Including: A receiving unit, configured to receive an application request for access rights to a target function module, where the level where the target function module is located is the level where the access control granularity is located; A judging unit, configured to determine whether the target function module includes at least one lower-level module if the application request passes; where the lower-level module refers to a function module whose own level is lower than the level where the access control granularity is located; An allocating unit, configured to, if the target function module includes at least one lower-level module, allocate the access rights to the target function module and the access rights to each lower-level module included in the target function module to the account applying for the access rights to the target function module; A calculation unit for calculating the difference between the number of function modules in the next level below the level where the permission control granularity is located and the number of function modules in the function module at the level where the permission control granularity is located, and determining whether the difference is less than a preset downward adjustment threshold; An adjustment unit for, if the difference is less than the downward adjustment threshold, lowering the permission control granularity from the current level where it is located to the next level below the current level where it is located.
6. The control device according to claim 5, characterized in that, The control device further includes: A statistics unit for statistically calculating the proportion of accounts among all accounts that send application requests within a preset time period and request access permissions for multiple function modules that are at the level where the permission control granularity is located and belong to the same upper-level module; wherein, the upper-level module refers to a function module whose own level is the upper level of the level where the permission control granularity is located; The adjustment unit is further used for, if the proportion is greater than a preset upward adjustment threshold, raising the permission control granularity from the current level where it is located to the upper level of the current level where it is located.
7. The control device according to claim 5 or 6, characterized in that, The allocation unit is further used for: When a new function module is detected in the next level below the level where the permission control granularity is located, determining the function modules including the new function module at the level where the permission control granularity is located, and allocating access permissions for the new function module to each account that has access permissions for the function module.
8. The control device according to claim 5, characterized in that, The allocation unit is further used for: Deleting the access permissions of each account for the function modules at the level before the permission control granularity is lowered.
9. An electronic device, characterized in that, It includes a memory and a processor; Wherein, the memory is used to store a computer program; The processor is used to execute the computer program, specifically for implementing the system permission control method as described in any one of claims 1 to 4.
10. A computer storage medium, characterized in that, For storing a computer program, when the computer program is executed, it is specifically used to implement the system permission control method as described in any one of claims 1 to 4.
11. A computer program product, characterized in that, The computer program product includes computer instructions, and the processor of the computer device executes the computer instructions, so that the computer device executes the system permission control method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Management interface having fine-grain access control using regular expressions
US7647318B1