Resource access, authority verification, information processing methods, equipment and storage media
By intercepting resource access requests from the user and sending permission verification requests to the permission control device, dynamically adjusting the mapping relationship between resources and permission points, the problem of difficult change in the prior art is solved, and simplified permission management and reduced maintenance costs are achieved.
Patent Information
- Application Number
- CN202010394179.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-11
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2040-05-11
AI Technical Summary
The existing technology needs to statically bind the permission management resources to the permission points during the system development stage, which makes it difficult to change once the permission management relationship is determined, which takes a long time and is costly.
By intercepting resource access requests from the user side, determine whether the target resource is bound with permission points, and send permission verification requests to the permission control device to verify whether the user has the right to use the permission points, and dynamically adjust the mapping relationship between the resources and permission points.
It realizes dynamic mapping of resources and permission points, avoids the need for system redevelopment, simplifies permission management, and reduces maintenance costs and time.
Smart Images

Figure CN113642011B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a resource access, authority verification, information processing method, device and storage medium. Background Art
[0002] Permission management generally refers to the ability of users to access and only access the resources they are authorized to access, no more, no less, according to the security rules or security policies of the system device. For example, after setting permissions for an API (Application Programming Interface), only authorized users can have access to the above API.
[0003] At present, during the system development phase, the permission-controlled resources need to be statically bound to the permission points. After the system is running, the permission-controlled relationship is determined. If the permission-controlled relationship is changed, the system needs to be redeveloped, which is time-consuming and costly. Summary of the invention
[0004] Multiple aspects of the present application provide a resource access, permission verification, information processing method, device and storage medium. The mapping relationship between resources and permission points can be dynamically set, and product maintenance is convenient.
[0005] The present application embodiment provides a resource access method, applicable to a docking party device, including:
[0006] Intercept the access request to the target resource initiated by the user;
[0007] Determine whether the target resource is bound to an authority point according to the existing resource authority data;
[0008] If it is determined that the target resource is bound to a permission point, a permission verification request is sent to the permission management device so that the permission management device verifies whether the user has the right to use the permission point;
[0009] When a verification result sent by the authority management and control device is received, the access request is allowed to access the target resource.
[0010] The embodiment of the present application also provides a permission verification method, which is applicable to a permission management device, including:
[0011] Receiving a permission verification request sent by a docking party device, wherein the permission verification request is sent by the docking party device after determining that the target resource is bound to a permission point based on an access request to the target resource by a user corresponding to the user end;
[0012] Determine whether the user has the right to use the permission point according to the permission verification request;
[0013] In the case that the user has the right to use the authority point, a verification result is sent to the docking device, so that the docking device allows the access request to access the target resource.
[0014] The embodiment of the present application also provides a docking party device, the method comprising: a memory and a processor;
[0015] The memory is used to store one or more computer instructions;
[0016] The processor is used to execute the one or more computer instructions to: execute the steps in the above-mentioned resource access method.
[0017] The embodiment of the present application also provides a computer-readable storage medium storing a computer program, which can implement the steps in the above-mentioned resource access method when executed.
[0018] The embodiment of the present application also provides a permission management device, the method comprising: a memory and a processor;
[0019] The memory is used to store one or more computer instructions;
[0020] The processor is used to execute the one or more computer instructions to: execute the steps in the above-mentioned permission verification method.
[0021] The embodiment of the present application also provides a computer-readable storage medium storing a computer program, which can implement the steps in the above-mentioned permission verification method when executed.
[0022] The embodiment of the present application also provides an information processing method, which is applicable to a permission management device, including:
[0023] Displaying an information interface, wherein the information interface includes at least one authority point;
[0024] In response to a selection operation on at least one permission point, displaying at least one resource data that can be bound to the selected permission point;
[0025] In response to a selection operation on at least one resource data, the selected resource data is bound to the selected permission point to generate resource permission data.
[0026] The embodiment of the present application also provides a permission management device, the method comprising: a memory and a processor;
[0027] The memory is used to store one or more computer instructions;
[0028] The processor is used to execute the one or more computer instructions to: execute the steps in the above-mentioned information processing method.
[0029] The embodiment of the present application also provides a computer-readable storage medium storing a computer program, which can implement the steps in the above-mentioned information processing method when executed.
[0030] The embodiment of the present application also provides a resource access method, applicable to a user terminal, including:
[0031] In response to a resource access operation initiated by a user, an access request for a target resource is sent to a docking device, so that the docking device intercepts the access request, determines whether the target resource is bound to an authority point, and verifies with the authority management device whether the user has the right to use the authority point;
[0032] Receive a result returned by the docking party device that allows access to the target resource, and access the target resource.
[0033] The embodiment of the present application also provides a user terminal, wherein the method comprises: a memory and a processor;
[0034] The memory is used to store one or more computer instructions;
[0035] The processor is used to execute the one or more computer instructions to: execute the steps in the above-mentioned information processing method.
[0036] The embodiment of the present application also provides a computer-readable storage medium storing a computer program, which can implement the steps in the above-mentioned information processing method when executed.
[0037] In some embodiments of the present application, after a user initiates an access request to a target resource, the docking party device first intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; when it is determined that the target resource is bound to permission, a permission verification request is sent to the permission management device to verify whether the user has the right to use the permission point. Only after the permission management device verifies that the user has the right to use the permission point can the docking party device allow the access request to access the target resource; the docking party device interacts with the permission management device for data, providing a permission management method that first determines the resource permission data locally and then verifies the permission. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0039] Figure 1aA schematic diagram of the structure of a permission management system provided for an exemplary embodiment of the present application;
[0040] Figure 1b A schematic diagram of the interaction between a docking party device and a permission management and control platform provided for an exemplary embodiment of the present application;
[0041] Figure 1c A schematic diagram of another interaction between a docking party device and a permission management and control platform provided for an exemplary embodiment of the present application;
[0042] Figure 1d A schematic diagram of another interaction between a docking party device and a permission management and control platform provided for an exemplary embodiment of the present application;
[0043] Figure 2a A flowchart of a resource access method provided from the perspective of a docking party device according to an exemplary embodiment of the present application;
[0044] Figure 2b A flowchart of a permission verification method provided from the perspective of a permission control device in an exemplary embodiment of the present application;
[0045] Figure 2c A flowchart of an information processing method provided from the perspective of a permission control device in an exemplary embodiment of the present application;
[0046] Figure 3 A flowchart of a permission management method provided for an exemplary embodiment of the present application;
[0047] Figure 4 A schematic diagram of the structure of a resource access device provided for an exemplary embodiment of the present application;
[0048] Figure 5 A schematic diagram of the structure of an authority verification device provided for an exemplary embodiment of the present application;
[0049] Figure 6 A schematic diagram of the structure of an information processing device provided for an exemplary embodiment of the present application;
[0050] Figure 7 A schematic diagram of the structure of a docking device provided by an exemplary embodiment of the present application;
[0051] Figure 8 A schematic diagram of the structure of an information processing device provided for an exemplary embodiment of the present application;
[0052] Fig. 9 A schematic diagram of the structure of a user terminal provided for an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0054] The current permission control products only provide static permission binding and control functions. Developers need to connect to permission control products during the system development phase and statically bind the resources that need permission control to the permission points. When the system is running, such permission control relationship is determined. If changes are required, they need to be redeveloped and then released online. This permission control method is relatively rigid. Once some resource permission control changes are required, it will take a very long time, and the redeveloped system release will also increase the probability of errors.
[0055] In addition, resource permission data is stored in the docking system. When the number of resources in the docking system increases, the difficulty of maintaining resource permission data increases. When the permission management user applies for permission on the permission management device, he can only determine whether the permission point is the permission he needs through the permission metadata.
[0056] In response to the above-mentioned technical problems, the embodiments of the present application provide a solution. In some embodiments of the present application, after the user initiates an access request to the target resource, the docking device first intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; when it is determined that the target resource is bound to permission, a permission verification request is sent to the permission management device to verify whether the user has the right to use the permission point. Only after the permission management device verifies that the user has the right to use the permission point can the docking device allow the access request to access the target resource; the docking device interacts with the permission management device for data, providing a permission management method that first determines the resource permission data locally and then verifies the permission.
[0057] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.
[0058] Figure 1a The schematic diagram of the structure of a permission control system 10 provided by the exemplary embodiment of the present application is as follows. Figure 1a As shown, the authority management system 10 includes a user terminal 11a, a docking device 12a and an authority management device 13a.
[0059] In this embodiment, the user initiates a resource access operation on the target resource through the user terminal 11a, and sends an access request for the target resource to the docking device 12a; after receiving the access request from the user terminal, the docking device 12a intercepts the access request, and determines whether the target resource is bound to a permission point in the resource permission data that has been pushed by the permission management device 13a; if it is determined that the target resource is not bound to a permission point, the access request is directly allowed to access the target resource; if it is determined that the target resource is bound to a permission point, the docking device 12a sends a permission verification request to the permission management device 13a. After receiving the permission verification request, the permission management device 13a verifies whether the user has the right to use the permission point; if the permission management device 13 verifies that the user has the right to use the permission point, it sends a verification result of success to the docking device 12a; after receiving the verification result of success sent by the permission management device 13a, the docking device 12a allows the access request to access the target resource; if the permission management device 13a verifies that the user does not have the right to use the permission point, it sends a verification result of failure to the docking device 12a; after receiving the verification result of failure sent by the permission management device 13a, the docking device 12a prohibits the access request from accessing the target resource.
[0060] In this embodiment, the user terminal 11a includes an electronic display screen, and the user interacts with the user terminal 11a through the electronic display screen. The user initiates a resource access operation to the target resource through the electronic display screen and sends an access request to the docking party device 12a. The user terminal 11a can be a computer device or a handheld device, and its implementation form can be various, such as a smart phone, a personal computer, a tablet computer, and a smart wearable device.
[0061] In this embodiment, the docking device 12a can provide resource services for the user terminal 11a. The docking device 12a can be a computer device or a server. When the docking device 12a is a server, the implementation form of the server is not limited. For example, the docking device 12a can be a conventional server, a cloud server, a cloud host, a virtual center, and other server devices. Among them, the composition of the server device mainly includes a processor, a hard disk, a memory, a system bus, etc., and a general computer architecture type. The service provider 10a can include one server or multiple servers.
[0062] In this embodiment, the authority control device 13a is a device for controlling resource authority data. The authority control device 13a is a device for controlling resource authority data and includes an electronic display screen. The user interacts with the authority control device 13a through the electronic display screen. The user establishes resource authority data or changes resource authority data through the electronic display screen. The authority control device 13a can be a server device such as a conventional server, a cloud server, a cloud host, a virtual center, etc. Among them, the composition of the server device mainly includes a processor, a hard disk, a memory, a system bus, etc., and a general computer architecture type. The authority control device 13a can include one server or multiple servers.
[0063] In this embodiment, the docking device 12a establishes a communication connection with the user terminal 11a and the authority control device 13a. Optionally, the docking device 12a can establish a communication connection with the user terminal 11a and the authority control device 13a using WIFI, Bluetooth, infrared or other communication methods, or the docking device 12a can also establish a communication connection with the user terminal 11a and the authority control device 13a through a mobile network. The network standard of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), etc.
[0064] It should be noted that the resource data in the above and following embodiments include web interfaces, common methods and data.
[0065] Figure 1b A schematic diagram of the interaction between a docking device and a permission management platform provided by an exemplary embodiment of the present application. Figure 1b As shown, SDK 121 (Software Development Kit) provided by the authority control device is set in the docking device 12a, and a resource authority management module 131 is set in the authority control device 13a.
[0066] Among them, SDK121 can collect resource data in the docking device 12a and push the resource data to the permission control device 13a; it can also initiate a resource permission data acquisition request to the permission control device 13a to pull the resource permission data from the resource permission management module 131. Furthermore, SDK121 also provides a dynamic proxy function. When a user accesses a target resource, it first determines the permission point corresponding to the target resource, sends a permission verification request to the permission control device 13a, and determines whether the user can access the target resource based on the result of the permission verification, thereby achieving the purpose of permission control.
[0067] Among them, the user can manage resource permission data through the resource permission management module 131 of the permission control device 13a, and send the resource permission data to the SDK 121 for data processing.
[0068] When the docking party device 12a is started, the resource data that requires permission control is obtained, and the resource data that requires permission control is sent to the permission control device 13a; the permission control device 13a receives the resource data that requires permission control, binds the permission point to the resource permission data, and generates resource permission data; after the docking party device 12a is started, the docking party device 12a sends a resource permission data acquisition request to the permission control device 13a, and after receiving the resource permission data acquisition request, the permission control device 13a returns the generated resource permission data to the docking party device 12a.
[0069] In the embodiment of the present application, the mapping relationship between resources and permission points does not need to be determined during the development phase, but can be determined when the device is running. The mapping relationship between resources and permission points can be dynamically changed according to needs without restarting the system or doing additional development. In addition, resource permission data are concentrated on the permission control device side, and these data can be conveniently maintained on the permission control device side.
[0070] Figure 1c This is a schematic diagram of another interaction between a docking device and a permission management platform provided by an exemplary embodiment of the present application. Figure 1c As shown, when the docking device 12a is started, the SDK will obtain all resource data that may require permission control, and send the resource data that requires permission control to the permission control device 13a. After receiving the resource data, the permission control device 13a determines whether there is existing resource permission data in the platform. The existing resource permission data refers to the information of the resources and corresponding permission points that have been bound to the permission points. The binding relationship between resources and permission points can be changed during the startup phase. After the permission control device 13a completes the data processing, it sets the resource permission data to a ready-to-send state. After the docking device 12a is successfully started, the full amount of resource permission data is pulled from the permission control device 13a and saved in the local database. In the embodiment of the present application, each time the docking device is started, the full amount of resource permission data is pulled from the permission control device. The docking device only stores temporary partial data and does not need to persist any data.
[0071] In this embodiment, the docking device 12a does not need to establish a binding relationship between resources and permission points that require permission control during the system development phase, and the above binding relationship can be established during the operation phase. An optional embodiment of establishing a binding relationship between resources and permission points that require permission control is that an information interface is displayed on the electronic display screen of the docking device 12a, and the information interface includes at least one permission point; the docking device 12a responds to the selection operation of at least one permission point and displays at least one resource data that can be bound to the selected permission point; the docking device 12a responds to the selection operation of at least one resource data and binds the selected resource data to the selected permission point to generate resource permission data. For example, the permission control device 13a can display interface information that requires permission control, including interface name, interface annotation and parameter description. When applying for permission, the user can view the interface information to determine whether it is the permission required by the user, thereby improving the user experience.
[0072] In the above embodiment, after the docking device 12a is started, the authority control device 13a can change the existing resource authority data. One achievable method is that the authority control device 13a responds to the resource authority point correction operation, binds the specified resource data that needs authority control and the target authority point to generate incremental resource authority data; the authority control device 13a pushes the incremental resource authority data to the docking device 12a, and stores it in the database or cache of the docking device 12a, so as to minimize the amount of data transmitted.
[0073] Figure 1d This is a schematic diagram of another interaction between a docking device and a permission management platform provided by an exemplary embodiment of the present application. Figure 1d As shown, the permission control device 13a changes the existing resource permission data, binds the specified resource data that needs permission control and the target permission point, generates incremental resource permission data, and the permission control device 13a pushes the incremental resource permission data to the docking party device 12a.
[0074] The following describes the detailed steps of the receiving device 12a performing permission control in combination with various embodiments.
[0075] In this embodiment, the user sends an access request to the target resource to the docking device 12a through the resource access operation initiated by the user terminal 11a. When the docking device 12a receives the access request to the target resource initiated by the user terminal 11a, it intercepts the access request to the target resource initiated by the user terminal, and determines whether the target resource is bound to a permission point in the resource permission data that has been pushed by the permission control device 13a. If it is determined that the target resource is bound to a permission point, the docking device 12a sends a permission verification request to the permission control device 13a. If it is determined that the target resource is not bound to a permission point, the access request is directly allowed to access the target resource.
[0076] For example, the access request carries the identifier of the target resource, and the resource permission data stores the mapping relationship between the resource and the permission point bound to it; the docking device 12a determines the target resource from the resource permission data based on the identifier of the target resource; if the identifier of the target resource is determined, the target resource is bound to the permission point; if the identifier of the target resource is not determined, the target resource is not bound to the permission point.
[0077] In the above embodiment, when the docking device 12a determines that the target resource is bound to a permission point, the docking device 12a sends a permission verification request to the permission control device 13a to verify whether the user has the right to use the corresponding permission point. The permission control device 13a determines whether the user has the right to use the permission point based on the permission verification request. One achievable method is to query whether the user's identifier exists from the user list of the permission point based on the user's identifier carried in the permission verification request; if it exists, it is determined that the user has the right to use the permission point; if it does not exist, it is determined that the user does not have the right to use the permission point. For example, the permission verification request carries the user's identifier and the identifier of the permission point. The permission control device 13a queries whether the user's identifier exists from the user list of the corresponding permission point based on the identifier of the permission point; if it exists, it is determined that the user has the right to use the permission point, and sends the result of verification passing to the docking device 12a; if it does not exist, it is determined that the user does not have the right to use the permission point, and sends the result of verification failure to the docking device. If the docking device 12a receives the verification result sent by the authority control device 13a, the access request is allowed to access the target resource; if the docking device 12a receives the verification result sent by the authority control device 13a, the access request is prohibited from accessing the target resource.
[0078] In some optional embodiments, the user initiates the operation of changing the user information through the user terminal 11a, and sends a request for changing the user information to the docking device 12a. After receiving the access request, the docking device 12a uses the SDK to intercept the request for changing the user information initiated by the user terminal; the docking device 12a determines whether the user information is bound to a permission point in the resource permission data that has been pushed by the permission management device 13a; if the user information is bound to a permission point for changing the user information, the docking device 12a sends a permission verification request to the permission management device 13a to verify whether the user has the right to use the corresponding permission point; if the user information is not bound to a permission point, the change request to change the user information is directly allowed. The docking device 12a determines the identifier of the user information from the resource permission data according to the identifier of the user information; if the identifier of the user information is determined, the user information is bound to a permission point, and if the identifier of the user information is not determined, the user information is not bound to a permission point. In the case where the docking device 12a determines that the user information is bound to a permission point for changing the user information, the docking device 12a sends a permission verification request to the permission control device 13a. The permission verification request carries the user's ID and the ID of the permission point for changing the user information. The permission control device 13a determines whether the user's ID exists from the user list of the corresponding permission point based on the ID of the permission point; if it exists, it determines that the user has the right to use the permission point, and sends a verification result of passing to the docking device 12a; if it does not exist, it determines that the user does not have the right to use the permission point, and sends a verification result of failing to the docking device. In the case where the docking device 12a receives the verification result sent by the permission control device 13a, the change request to change the user information is allowed; in the case where the docking device 12a receives the verification result sent by the permission control device 13a, the change request to change the user information is prohibited.
[0079] During the normal operation of the docking party device 12a, the permission control device 13a can make changes to the existing resource permission data, wherein the changes made by the permission control device 13a to the existing resource permission data include adding, deleting and modifying the resource permission data. The permission control device 13a responds to the resource permission point correction operation, binds the specified resource data that requires permission control and the target permission point to generate incremental resource permission data; pushes the incremental resource permission data to the docking party device, and stores it in the database or cache of the docking party device. After the permission control device 13a of the embodiment of the present application makes changes to the existing resource permission data of the permission control device 13a, the incremental resource permission data is formed. The permission control device 13a only pushes the incremental resource permission data to the docking party device 12a, and the docking party device 12a updates the incremental resource permission data to the local database or cache, minimizing the amount of data that needs to be transmitted.
[0080] In some optional embodiments, a new permission point can be added through the permission control device 13a. The information interface also includes a permission point addition control, and the permission control device 13a responds to the trigger operation of the permission point addition control to add a new permission point in the information interface. Optionally, in response to the trigger operation of the permission point addition control, a permission point information input page is displayed, and the permission point information input page includes permission point information input items; in response to the operation of inputting permission point information in the permission point information input item, the permission point of information is added in the information interface. For example, the information interface includes a permission point addition control, and the permission control device 13a responds to the trigger operation of the permission point addition control to display the permission point information input page, and the permission point information input page includes permission point information input items, including the permission point name, the permission point binding role and the permission point function description, wherein the permission point input item may include mandatory items and optional items, the mandatory items such as the permission point name, the optional items such as the permission point function description, after the user completes the input of each permission point information input item, the permission control device 13a responds to the user's confirmation operation and adds the information permission point in the information interface.
[0081] In some optional embodiments, the permission point can be deleted by the permission control device 13a. Optionally, the new interface also includes a permission point deletion control corresponding to the permission point, and the permission control device 13a responds to the user's triggering operation on the permission point deletion control and deletes the permission point corresponding to the permission point deletion control. For example, the permission point deletion control can be set around the corresponding permission point to establish a corresponding relationship between the permission point deletion control and the permission point.
[0082] In some optional embodiments, the permission point can be modified by the permission control device 13a. Optionally, the permission control device 13a responds to the trigger operation on the target permission point and displays the resource data bound to the target permission point on the electronic display screen; the permission control device 13a responds to the correction operation on the resource data bound to the target permission point and binds new resource data to the target permission point. For example, new resource data can be bound to the target permission point, or the original resource data of the target permission point can be deleted.
[0083] In the above-mentioned system embodiment of the present application, after the user initiates an access request to the target resource, the docking party device first intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; when it is determined that the target resource is bound to permission, a permission verification request is sent to the permission management device to verify whether the user has the right to use the permission point. Only after the permission management device verifies that the user has the right to use the permission point can the docking party device allow the access request to access the target resource; the docking party device interacts with the permission management device for data, providing a permission management method for locally determining the resource permission data and then verifying the permission.
[0084] In addition to the permission management system provided above, some embodiments of the present application also provide a resource access method and a permission verification method. The resource access method and permission verification method provided by the present application can rely on the above-mentioned permission management system for implementation, but are not limited to the permission management system provided in the above-mentioned embodiments.
[0085] Figure 2a This is a flow chart of a resource access method provided from the perspective of a docking device in an exemplary embodiment of the present application. Figure 2a As shown, the method includes:
[0086] S211: intercepting the access request to the target resource initiated by the user end;
[0087] S212: Determine whether the target resource is bound to a permission point based on the existing resource permission data. If so, execute S213; if not, execute S214;
[0088] S213: Sending a permission verification request to the permission control device, so that the permission control device verifies whether the user has the right to use the permission point; if the verification result sent by the permission control device is received, S214 is executed; if the verification result sent by the permission control device is received, S215 is executed;
[0089] S214: Allow the access request to access the target resource;
[0090] S215: The access request is prohibited from accessing the target resource.
[0091] Figure 2b The following is a flowchart of a permission verification method provided by an exemplary embodiment of the present application from the perspective of a permission control device. Figure 2b As shown, the method includes:
[0092] S221: receiving a permission verification request sent by a docking party device, wherein the permission verification request is sent by the docking party device after determining that the target resource is bound with a permission point according to an access request of a user corresponding to the user end to the target resource;
[0093] S222: Determine whether the user has the right to use the permission point according to the permission verification request; if so, execute S223; if not, execute S224;
[0094] S223: Sending the verification result to the docking device, so that the docking device allows the access request to access the target resource;
[0095] S224: Send a verification failure result to the docking party device, so that the docking party device prohibits the access request from accessing the target resource.
[0096] Figure 2cThe following is a flowchart of an information processing method provided by an exemplary embodiment of the present application from the perspective of a permission control device. Figure 2c As shown, the method includes:
[0097] S231: displaying an information interface, where the information interface includes at least one authority point;
[0098] S232: In response to a selection operation on at least one permission point, display at least one resource data that can be bound to the selected permission point;
[0099] S233: In response to a selection operation on at least one resource data, the selected resource data is bound to a selected permission point to generate resource permission data.
[0100] In this embodiment, the user initiates a resource access operation to the target resource through the user terminal, and sends an access request to the target resource to the docking party device; after receiving the access request from the user terminal, the docking party device intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; if the target resource is not bound to a permission point, the access request is directly allowed to access the target resource; if the target resource is bound to a permission point, the docking party device sends a permission verification request to the permission control device. After receiving the permission verification request, the permission control device verifies whether the user has the right to use the permission point; if the permission control device verifies that the user has the right to use the permission point, it sends a verification result to the docking party device; after receiving the verification result sent by the permission control device, the docking party device allows the access request to access the target resource; if the permission control device verifies that the user does not have the right to use the permission point, it sends a verification failure result to the docking party device; after receiving the verification failure result sent by the permission control device, the docking party device prohibits the access request from accessing the target resource.
[0101] The execution subject of the information processing method of the embodiment of the present application, the user terminal includes an electronic display screen, the user interacts with the user terminal through the electronic display screen, the user initiates a resource access operation to the target resource through the electronic display screen, and sends an access request to the target resource to the docking party device. The user terminal can be a computer device or a handheld device, and its implementation form can be various, such as a smart phone, a personal computer, a tablet computer, and a smart wearable device.
[0102] The execution subject of the resource access method in the embodiment of the present application, the docking party device can provide resource services for the user terminal. The docking party device can be a computer device or a server. When the docking party device is a server, the implementation form of the server is not limited. For example, the docking party device can be a conventional server, a cloud server, a cloud host, a virtual center and other server devices. Among them, the composition of the server device mainly includes a processor, a hard disk, a memory, a system bus, etc., and a general computer architecture type. The service provider can include one server or multiple servers.
[0103] The execution subject of the permission verification method in the embodiment of the present application, the permission control device is a device for controlling resource permission data, and the permission control device is a device for controlling resource permission data, and includes an electronic display screen. The user interacts with the permission control device through the electronic display screen, and the user establishes resource permission data or changes resource permission data through the electronic display screen. The permission control device can be a server device such as a conventional server, a cloud server, a cloud host, a virtual center, etc. Among them, the composition of the server device mainly includes a processor, a hard disk, a memory, a system bus, etc., and a general computer architecture type. The permission control device can include one server or multiple servers.
[0104] It should be noted that the resource data in the above and following embodiments include web interfaces, common methods and data.
[0105] It should be noted that the permission control method of the embodiment of the present application can be applied to any scenario involving permission control, for example, websites, applications, management platforms, and operating systems.
[0106] In some exemplary embodiments, the user initiates a resource access operation to the target website resource through the user terminal, and sends an access request to the target resource to the website server; after receiving the access request from the user terminal, the website server intercepts the access request and determines whether the target website resource is bound to a permission point in the existing resource permission data; if the target website resource is not bound to a permission point, the access request is directly allowed to access the target website resource; if the target website resource is bound to a permission point, the website server sends a permission verification request to the permission control device. After receiving the permission verification request, the permission control device verifies whether the user has the right to use the permission point; if the permission control device verifies that the user has the right to use the permission point, the verification result is sent to the website server; after receiving the verification result sent by the permission control device, the website server allows the access request to access the target website resource; if the permission control device verifies that the user does not have the right to use the permission point, the verification result is sent to the website server; after receiving the verification result sent by the permission control device, the website server prohibits the access request from accessing the target website resource.
[0107] For example, a user initiates an operation to delete the target text content in the website through the user terminal, and sends a request to delete the target text content to the website server; after receiving the request to delete the target text content from the user terminal, the website server intercepts the request and determines whether the target text content to be deleted is bound to a permission point in the existing resource permission data; if the target text content to be deleted is not bound to a permission point, the target text content is directly allowed to be deleted; if the target text content to be deleted is bound to a permission point, the website server sends a permission verification request to the permission management device. After receiving the permission verification request, the permission management device verifies whether the user has the right to use the permission point; if the permission management device verifies that the user has the right to use the permission point, the verification result is sent to the website server; after receiving the verification result sent by the permission management device, the website server allows the target text content to be deleted; if the permission management device verifies that the user does not have the right to use the permission point, the verification result is sent to the website server; after receiving the verification result sent by the permission management device, the website server prohibits the deletion of the target text content.
[0108] The SDK (Software Development Kit) provided by the permission control device is set on the docking device, and a resource permission management module is set in the permission control device.
[0109] Among them, the SDK can collect resource data from the docking device and push the resource data to the permission management device; it can also initiate a resource permission data acquisition request to the permission management device and pull the resource permission data from the resource permission management module. Furthermore, the SDK also provides a dynamic proxy function. When a user accesses a target resource, it first determines the permission point corresponding to the target resource, sends a permission verification request to the permission management device, and determines whether the user can access the target resource based on the result of the permission verification, thereby achieving the purpose of permission control.
[0110] Among them, users can manage resource permission data through the resource permission management module of the permission management device, and send the resource permission data to the SDK for data processing.
[0111] When the docking party device is started, the resource data that requires permission control is obtained, and the resource data that requires permission control is sent to the permission control device; the permission control device receives the resource data that requires permission control, binds the permission point to the resource permission data, and generates resource permission data; after the docking party device is started, the docking party device sends a resource permission data acquisition request to the permission control device, and after receiving the resource permission data acquisition request, the permission control device returns the generated resource permission data to the docking party device.
[0112] In the embodiment of the present application, the mapping relationship between resources and permission points does not need to be determined in the development stage, but can be determined when the device is running. The mapping relationship between resources and permission points can be dynamically changed according to the needs, without restarting the system and doing additional development. In addition, the resource permission data is concentrated on the side of the permission control device, and the permission control device can conveniently maintain these data. For example, when the docking device is started, the SDK will obtain all resource data that may require permission control, and send the resource data that requires permission control to the permission control device. After receiving the resource data, the permission control device determines whether there is existing resource permission data in the platform. The existing resource permission data refers to the information of the resources and corresponding permission points that have been bound to the permission points. The binding relationship between resources and permission points can be changed in the startup stage. After the permission control device completes the data processing, the resource permission data is set to the ready-to-send state. After the docking device is successfully started, the full amount of resource permission data is pulled from the permission control device and saved in the local database. In the embodiment of the present application, the full amount of resource permission data is pulled from the permission control device every time the docking device is started. The docking device only stores temporary partial data without persisting any data.
[0113] In this embodiment, the docking device does not need to establish a binding relationship between resources and permission points that require permission control during the system development phase, and the above binding relationship can be established during the operation phase. An optional embodiment of establishing a binding relationship between resources and permission points that require permission control is that an information interface is displayed on the electronic display screen of the docking device, and the information interface includes at least one permission point; the docking device responds to the selection operation of at least one permission point and displays at least one resource data that can be bound to the selected permission point; the docking device responds to the selection operation of at least one resource data and binds the selected resource data to the selected permission point to generate resource permission data. For example, the permission control device can display interface information that requires permission control, including interface name, interface annotation and parameter description. When applying for permission, the user can check the interface information to determine whether it is the permission required by the user, thereby improving the user experience.
[0114] In the above embodiment, after the docking party device is started, the permission management device can change the existing resource permission data. One achievable way is that the permission management device responds to the resource permission point correction operation, binds the specified resource data that needs permission management and the target permission point to generate incremental resource permission data; the permission management device pushes the incremental resource permission data to the docking party device to minimize the amount of data transmitted. For example, the permission management device changes the existing resource permission data, binds the specified resource data that needs permission management and the target permission point to generate incremental resource permission data, and the permission management device pushes the incremental resource permission data to the docking party device.
[0115] The following describes the detailed steps of performing permission management on the receiving device in combination with various embodiments.
[0116] In this embodiment, the user sends an access request to the target resource to the docking device through a resource access operation initiated by the user end. When the docking device receives the access request to the target resource initiated by the user end, it intercepts the access request to the target resource initiated by the user end, and determines whether the target resource is bound to a permission point in the existing resource permission data. If the target resource is bound to a permission point, the docking device sends a permission verification request to the permission management device. If the target resource is not bound to a permission point, the access request is directly allowed to access the target resource.
[0117] For example, the access request carries the identifier of the target resource, and the resource permission data stores the mapping relationship between the resource and the permission point bound to it; the docking device determines the target resource from the resource permission data based on the identifier of the target resource; if the identifier of the target resource is determined, the target resource is bound to the permission point; if the identifier of the target resource is not determined, the target resource is not bound to the permission point.
[0118] In the above embodiment, when the docking device determines that the target resource is bound to a permission point, the docking device sends a permission verification request to the permission control device to verify whether the user has the right to use the corresponding permission point. The permission control device determines whether the user has the right to use the permission point according to the permission verification request. One achievable method is to query whether the user's identity exists from the user list of the permission point according to the user's identity carried in the permission verification request; if it exists, it is determined that the user has the right to use the permission point; if it does not exist, it is determined that the user does not have the right to use the permission point. For example, the permission verification request carries the user's identity and the identity of the permission point. The permission control device queries whether the user's identity exists from the user list of the corresponding permission point according to the identity of the permission point; if it exists, it is determined that the user has the right to use the permission point, and sends the result of verification passing to the docking device; if it does not exist, it is determined that the user does not have the right to use the permission point, and sends the result of verification failure to the docking device. When the docking device receives the result of verification passing sent by the permission control device, the access request is allowed to access the target resource; when the docking device receives the result of verification failure sent by the permission control device, the access request is prohibited from accessing the target resource.
[0119] In some optional embodiments, the user initiates the operation of changing user information through the user terminal, and sends a request to change the user information to the docking party device. After receiving the access request, the docking party device uses the SDK to intercept the request to change the user information initiated by the user terminal; the docking party device determines whether the user information is bound to a permission point in the existing resource permission data; if the user information is bound to a permission point for changing the user information, the docking party device sends a permission verification request to the permission management device to verify whether the user has the right to use the corresponding permission point; if the user information is not bound to a permission point, the change request to change the user information is directly allowed. The docking party device determines the identifier of the user information from the resource permission data based on the identifier of the user information; if the identifier of the user information is determined, the user information is bound to a permission point; if the identifier of the user information is not determined, the user information is not bound to a permission point. In the case where the docking device determines that the user information is bound to a permission point for changing the user information, the docking device sends a permission verification request to the permission management device. The permission verification request carries the user's ID and the ID of the permission point for changing the user information. The permission management device queries the user list of the corresponding permission point based on the ID of the permission point to see whether the user's ID exists; if it exists, it determines that the user has the right to use the permission point, and sends a verification success result to the docking device; if it does not exist, it determines that the user does not have the right to use the permission point, and sends a verification failure result to the docking device. In the case where the docking device receives the verification success result sent by the permission management device, the change request to change the user information is allowed; in the case where the docking device receives the verification failure result sent by the permission management device, the change request to change the user information is prohibited.
[0120] During the normal operation of the docking party device, the permission control device can make changes to the existing resource permission data, wherein the changes made by the permission control device to the existing resource permission data include adding, deleting and modifying the resource permission data. The permission control device responds to the resource permission point correction operation, binds the specified resource data that requires permission control and the target permission point to generate incremental resource permission data; and pushes the incremental resource permission data to the docking party device. After the permission control device of the embodiment of the present application makes changes to the existing resource permission data of the permission control device, incremental resource permission data is formed. The permission control device only pushes the incremental resource permission data to the docking party device, and the docking party device updates the incremental resource permission data to the local database, minimizing the amount of data that needs to be transmitted.
[0121] In some optional embodiments, a new permission point can be added through the permission control device. The information interface also includes a permission point addition control, and the permission control device responds to the trigger operation of adding the permission point control to add the new permission point in the information interface. Optionally, in response to the trigger operation of adding the permission point control, a permission point information input page is displayed, and the permission point information input page includes permission point information input items; in response to the operation of inputting permission point information in the permission point information input items, the permission point of information is added in the information interface. For example, the information interface includes a permission point addition control, and the permission control device responds to the trigger operation of adding the permission point control to display the permission point information input page, and the permission point information input page includes permission point information input items, including the permission point name, the permission point binding role and the permission point function description, wherein the permission point input items may include mandatory items and optional items, such as the permission point name, and the optional items such as the permission point function description. After the user completes the input of each permission point information input item, the permission control device responds to the user's confirmation operation and adds the permission point of information in the information interface.
[0122] In some optional embodiments, the permission point can be deleted by the permission control device. Optionally, the new interface also includes a permission point deletion control corresponding to the permission point, and the permission control device responds to the user's triggering operation on the permission point deletion control and deletes the permission point corresponding to the permission point deletion control. For example, the permission point deletion control can be set around the corresponding permission point to establish a corresponding relationship between the permission point deletion control and the permission point.
[0123] In some optional embodiments, the permission point can be modified by the permission control device. Optionally, the permission control device responds to the trigger operation on the target permission point and displays the resource data bound to the target permission point on the electronic display screen; the permission control device responds to the correction operation on the resource data bound to the target permission point and binds new resource data to the target permission point. For example, new resource data can be bound to the target permission point, or the original resource data of the target permission point can be deleted.
[0124] Based on the method embodiments provided in the above embodiments, Figure 3 The following is a flowchart of a permission control method provided by an exemplary embodiment of the present application. Figure 3 As shown, the method includes:
[0125] S301: The docking device intercepts the access request to the target resource initiated by the user terminal;
[0126] S302: The docking device determines whether the target resource is bound to an authority point according to the existing resource authority data. If so, S303 is executed; if the target resource is not bound to an authority point, S307 is executed;
[0127] S303: The docking device sends a permission verification request to the permission control device;
[0128] S304: The permission control device receives the permission verification request, and determines whether the user has the right to use the permission point according to the permission verification request; if so, execute S305; if not, execute S306;
[0129] S305: the authority control device sends a verification result to the docking device, and the docking device receives the verification result sent by the authority control device, and then executes S306;
[0130] S306: the authority control device sends a verification failure result to the docking device, and the docking device receives the verification failure result sent by the authority control device, and then executes S307;
[0131] S307: The docking device allows the access request to access the target resource;
[0132] S308: The docking device prohibits the access request from accessing the target resource.
[0133] In the above-mentioned method embodiment of the present application, after the user initiates an access request to the target resource, the docking party device first intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; when it is determined that the target resource is bound to permission, a permission verification request is sent to the permission management device to verify whether the user has the right to use the permission point. Only after the permission management device verifies that the user has the right to use the permission point can the docking party device allow the access request to access the target resource; the docking party device interacts with the permission management device for data, providing a permission management method for locally determining the resource permission data by a posteriori permissions.
[0134] It should be noted that the execution subject of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 301 to 303 can be device A; for another example, the execution subject of steps 301 and 302 can be device A, and the execution subject of step 303 can be device B; and so on.
[0135] In addition, in some of the processes described in the above embodiments and the accompanying drawings, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or executed in parallel, and the sequence numbers of the operations, such as 301, 302, etc., are only used to distinguish between different operations, and the sequence numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., do not represent the order of precedence, and do not limit the "first" and "second" to be different types.
[0136] Figure 4 A schematic diagram of a resource access device provided by an exemplary embodiment of the present application is shown in FIG. Figure 4 As shown, the resource access device includes a determination module 41, a sending module 42 and an access module 43. It also includes a receiving module 44 and a resource acquisition module 45.
[0137] The determination module 41 is used to intercept the access request to the target resource initiated by the user end, and determine whether the target resource is bound with a permission point in the existing resource permission data;
[0138] The sending module 42 is used to send a permission verification request to the permission control device when it is determined that the target resource is bound to a permission point, so that the permission control device verifies whether the user has the right to use the permission point;
[0139] The access module 43 is used to allow the access request to access the target resource when receiving the verification result sent by the permission management and control device.
[0140] Optionally, the access module 43 is further configured to directly allow the access request to access the target resource when it is determined that the target resource is not bound to a permission point.
[0141] Optionally, the receiving module 44 is used to receive incremental resource permission data pushed by the permission management device, wherein the incremental resource permission data includes the specified resource data that the permission management device needs to control and its bound permission point information; and update the incremental resource permission data into the existing resource permission data.
[0142] Optionally, the resource acquisition module 45 is used to acquire at least one resource data that requires permission control; send at least one resource data that requires permission control to a permission control device so that the permission control device binds a permission point to at least one resource data; and receive resource permission data pushed by the permission control device, the resource permission data including at least one resource data and its bound permission point information.
[0143] Figure 5 A schematic diagram of a structure of a permission verification device provided by an exemplary embodiment of the present application is shown in FIG. Figure 5 As shown, the authority verification device includes a receiving module 51, a determining module 52 and a sending module 53. It also includes a binding module 54, a correcting module 55 and an adding module 56.
[0144] The receiving module 51 is used to receive the permission verification request sent by the docking party device, wherein the permission verification request is sent by the docking party device after determining that the target resource is bound with a permission point according to the access request of the user corresponding to the user end to the target resource;
[0145] A determination module 52, used to determine whether the user has the right to use the permission point according to the permission verification request;
[0146] The sending module 53 is used to send the verification result to the docking device if the user has the right to use the permission point, so that the docking device allows the access request to access the target resource.
[0147] Optionally, the sending module 53 is further used for: when the user does not have the right to use the permission point, sending a verification failure result to the docking device, so that the docking device is prohibited from accessing the target resource.
[0148] Optionally, the binding module 54 is used to receive at least one resource data that requires permission control sent by the docking party device; bind a permission point to at least one resource data to generate resource permission data; respond to a resource permission data acquisition request sent by the docking party device, and send the resource permission data to the docking party device.
[0149] Optionally, the determination module 52 is specifically used to query whether the user's identifier exists in the user list of the permission point according to the user identifier carried in the permission verification request; if so, it is determined that the user has the right to use the permission point; if not, it is determined that the user does not have the right to use the permission point.
[0150] Optionally, the correction module 55 is used to respond to the resource permission point correction operation, bind the specified resource data requiring permission control and the target permission point to generate incremental resource permission data; and push the incremental resource permission data to the docking party device.
[0151] Optionally, the correction module 55 is specifically used to: display an information interface, which includes at least one permission point; in response to a selection operation on at least one permission point, display at least one resource data corresponding to the selected target permission point; in response to a selection operation on at least one resource data, use the selected resource data as designated resource data to be bound to the target permission point; in response to a confirmation operation, bind the designated resource data and the target permission point.
[0152] Optionally, add module 56, which is used to display an information interface, which includes a permission point addition control; in response to a trigger operation on the permission point addition control, display a permission point information page, which includes a permission point information input item; in response to an operation of entering permission point information in the permission point information input item, add a new permission point in the information interface.
[0153] Figure 6 A schematic diagram of the structure of an information processing device provided by an exemplary embodiment of the present application is shown in FIG. Figure 6 As shown, the information processing device includes: a first display module 61, a second display module 62 and a generating module 63. It also includes: a sending module 64, an adding module 65 and a deleting module 66.
[0154] Wherein, the first display module 61 is used to display an information interface, and the information interface includes at least one authority point;
[0155] A second display module 62, configured to respond to a selection operation of at least one permission point and display at least one resource data that can be bound to the selected permission point;
[0156] The generating module 63 is used to respond to the selection operation of at least one resource data and bind the selected resource data with the selected permission point to generate resource permission data.
[0157] Optionally, the sending module 64 is used to respond to the resource authority data acquisition request sent by the docking party device and send the resource authority data to the docking party device.
[0158] Optionally, the adding module 65 is used to respond to the triggering operation of adding a control to the permission point and add a new permission point in the information interface.
[0159] Optionally, the adding module 65 can also be used to: respond to a trigger operation of adding a control to a permission point, display a permission point information input page, the permission point information input page includes a permission point information input item; respond to an operation of inputting permission point information in the permission point information input item, and add a permission point of information to the information interface.
[0160] Optionally, the deleting module 66 is configured to respond to a triggering operation on the permission point deletion control and delete the permission point corresponding to the permission point deletion control.
[0161] Optionally, the generation module 63 is further used to: respond to a trigger operation on the target authority point, and display the resource data bound to the target authority point; respond to a correction operation on the resource data bound to the target authority point, and bind new resource data to the target authority point.
[0162] Figure 7The following is a schematic diagram of a docking device provided by an exemplary embodiment of the present application. Figure 7 As shown, the docking device includes: a memory 701 and a processor 702. In addition, the docking device also includes necessary components such as a power supply component 703 and a communication component 704.
[0163] The memory 701 is used to store computer programs and can be configured to store various other data to support operations on the docking device. Examples of such data include instructions for any application or method operating on the docking device.
[0164] Memory 701 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0165] The communication component 704 is used for data transmission with other devices.
[0166] Processor 702 can execute computer instructions stored in memory 701 to: intercept access requests to target resources initiated by the user end; determine whether the target resource is bound to a permission point based on existing resource permission data; if it is determined that the target resource is bound to a permission point, send a permission verification request to the permission management device so that the permission management device can verify whether the user has the right to use the permission point; if a verification result sent by the permission management device is received, allow the access request to access the target resource.
[0167] Optionally, the processor 702 may be further configured to: directly allow the access request to access the target resource when it is determined that the target resource is not bound to an authority point.
[0168] Optionally, processor 702 can also be used to: receive incremental resource permission data pushed by the permission management device, wherein the incremental resource permission data includes the specified resource data that the permission management device needs to control and its bound permission point information; and update the incremental resource permission data into the existing resource permission data.
[0169] Optionally, before intercepting an access request to a target resource initiated by a user terminal, the processor 702 can also be used to: obtain at least one resource data requiring permission control; send at least one resource data requiring permission control to a permission control device so that the permission control device can bind a permission point to at least one resource data; and receive resource permission data pushed by the permission control device, the resource permission data including at least one resource data and its bound permission point information.
[0170] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer-readable storage medium stores the computer program and the computer program is executed by one or more processors, the one or more processors execute Figure 2a Each step in the method embodiment.
[0171] Figure 8 The following is a schematic diagram of the structure of an information processing device provided by an exemplary embodiment of the present application. Figure 8 As shown, the information processing device includes: a memory 801 and a processor 802. In addition, the information processing device also includes necessary components such as a power supply component 803 and a communication component 804.
[0172] The memory 801 is used to store computer programs and can be configured to store various other data to support operations on the information processing device. Examples of such data include instructions for any application program or method operating on the information processing device.
[0173] Memory 801 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0174] The communication component 804 is used for data transmission with other devices.
[0175] Processor 802 can execute computer instructions stored in memory 801, so as to: receive a permission verification request sent by a docking party device, wherein the permission verification request is issued by the docking party device after determining that the target resource is bound with a permission point based on an access request to the target resource by a user corresponding to the user end; determine whether the user has the right to use the permission point based on the permission verification request; and if the user has the right to use the permission point, send a verification result to the docking party device so that the docking party device allows the access request to access the target resource.
[0176] Optionally, the processor 802 may be further configured to: when the user does not have the right to use the permission point, send a verification failure result to the docking party device, so that the docking party device is prohibited from accessing the target resource.
[0177] Optionally, before receiving a permission verification request sent by a docking party device, the processor 802 can also be used to: receive at least one resource data that requires permission control sent by the docking party device; bind a permission point to at least one resource data to generate resource permission data; and respond to a resource permission data acquisition request sent by the docking party device, and send the resource permission data to the docking party device.
[0178] Optionally, when the processor 802 determines whether the user has the right to use the permission point based on the permission verification request, it is specifically used to: query whether the user's identifier exists in the user list of the permission point based on the user's identifier carried in the permission verification request; if so, determine that the user has the right to use the permission point; if not, determine that the user does not have the right to use the permission point.
[0179] Optionally, the processor 802 may also be used to: respond to a resource permission point correction operation, bind the specified resource data requiring permission control and the target permission point to generate incremental resource permission data; and push the incremental resource permission data to the docking party device.
[0180] Optionally, when the processor 802 binds the designated resource data requiring permission control and the target permission point to generate incremental resource permission data in response to a resource permission point correction operation, it is specifically used to: display an information interface, the information interface including at least one permission point; in response to a selection operation of at least one permission point, display at least one resource data corresponding to the selected target permission point; in response to a selection operation of at least one resource data, use the selected resource data as the designated resource data to be bound to the target permission point; and in response to a confirmation operation, bind the designated resource data and the target permission point.
[0181] Optionally, processor 802 may also be used to: display an information interface, the information interface including a permission point adding control; in response to a triggering operation on the permission point adding control, display a permission point information page, the permission point information page including a permission point information input item; in response to an operation of inputting permission point information in the permission point information input item, add a new permission point in the information interface.
[0182] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer-readable storage medium stores the computer program and the computer program is executed by one or more processors, the one or more processors execute Figure 2b Each step in the method embodiment.
[0183] Fig. 9 A schematic diagram of the structure of a user terminal provided by an exemplary embodiment of the present application. Fig. 9As shown, the user terminal includes: a memory 901 and a processor 902. In addition, the user terminal also includes necessary components such as a power supply component 903, a communication component 904 and an electronic display screen 905.
[0184] The memory 901 is used to store computer programs and can be configured to store various other data to support operations on the user end. Examples of such data include instructions for any application program or method used to operate on the user end.
[0185] Memory 901 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0186] The communication component 904 is used for data transmission with other devices.
[0187] Processor 902 can execute computer instructions stored in memory 901 to: display an information interface, the information interface includes at least one permission point; in response to a selection operation on at least one permission point, display at least one resource data that can be bound to the selected permission point; in response to a selection operation on at least one resource data, bind the selected resource data to the selected permission point to generate resource permission data.
[0188] Optionally, after generating the resource permission data, the processor 902 may also be configured to: respond to a resource permission data acquisition request sent by the docking party device, and send the resource permission data to the docking party device.
[0189] Optionally, the information interface further includes a permission point adding control, and the processor 902 may be further configured to: respond to a triggering operation on the permission point adding control, and add a new permission point in the information interface.
[0190] Optionally, when processor 902 responds to a trigger operation for adding a control to a permission point and adds a new permission point in the information interface, it is specifically used to: respond to a trigger operation for adding a control to the permission point and display a permission point information input page, the permission point information input page including a permission point information input item; respond to an operation for entering permission point information in the permission point information input item and add the permission point of information in the information interface.
[0191] Optionally, the information interface further includes a permission point deletion control corresponding to the permission point, and the processor 902 may be further configured to: respond to a triggering operation on the permission point deletion control, and delete the permission point corresponding to the permission point deletion control.
[0192] Optionally, the processor 902 may also be used to: respond to a trigger operation on a target authority point, and display resource data bound to the target authority point; respond to a correction operation on resource data bound to the target authority point, and bind new resource data to the target authority point.
[0193] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer-readable storage medium stores the computer program and the computer program is executed by one or more processors, the one or more processors execute Figure 2c Each step in the method embodiment.
[0194] Above Figure 7-Figure 9 The communication component in is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0195] Above Figure 7-Figure 9 The power supply component in the device provides power to various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device where the power supply component is located.
[0196] In an embodiment of the device method of the present application, after a user initiates an access request to a target resource, the docking party device first intercepts the access request and determines whether the target resource is bound to a permission point in the existing resource permission data; when it is determined that the target resource is bound to permission, a permission verification request is sent to a permission management device to verify whether the user has the right to use the permission point. Only after the permission management device verifies that the user has the right to use the permission point can the docking party device allow the access request to access the target resource; the docking party device interacts with the permission management device for data, providing a permission management method for locally determining the post-authorization of resource permission data.
[0197] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0198] The present invention is described with reference to the flowchart and / or block diagram of the method, device (system), and computer program product according to the embodiment of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the process and / or box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0199] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0200] These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0201] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0202] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0203] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0204] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0205] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A resource access method, applicable to a docking party device, comprising: When the docking system is started, resource data that needs permission control is obtained, and the resource data that needs permission control is sent to the permission control device, so that the permission control device generates resource permission data for the resource data that needs permission control. The resource permission data refers to the binding relationship between the resource that has been bound to the permission point and the corresponding permission point; After the docking system is started, the resource permission data is pulled from the permission control device; Intercept the access request to the target resource initiated by the user; Determining whether the target resource is bound to an authority point according to the resource authority data; If it is determined that the target resource is bound to a permission point, a permission verification request is sent to a permission control device so that the permission control device verifies whether the user has the right to use the permission point bound to the target resource; When a verification result sent by the authority management and control device is received, the access request is allowed to access the target resource.
2. The method according to claim 1, further comprising: When it is determined that the target resource is not bound to an authority point, the access request is directly allowed to access the target resource.
3. The method according to claim 1, further comprising: Receive incremental resource permission data pushed by the permission control device, wherein the incremental resource permission data includes the specified resource data that the permission control device needs to control and the permission point information bound thereto; The incremental resource permission data is updated into the resource permission data.
4. According to the method of claim 1, the step of pulling the resource permission data from the permission management device comprises: Send a resource permission data acquisition request to the permission control device; The resource permission data sent by the receiving permission management device according to the resource permission data acquisition request.
5. A permission verification method, applicable to a permission management device, comprising: Receiving resource data that needs permission control sent by the docking party device, the docking party device obtains the resource data that needs permission control when the docking party system is started, and sends the resource data that needs permission control to the permission control device; Generate resource permission data for the resource data that needs permission control, where the resource permission data refers to the binding relationship between the resource that has been bound to the permission point and the corresponding permission point, so that the docking party device can pull the resource permission data from the permission control device after the docking party system is started; Sending the resource permission data to the docking party device so that the docking party device intercepts the access request to the target resource initiated by the user terminal, determines whether the target resource is bound to a permission point according to the resource permission data, and sends a permission verification request to the permission control device if it is determined that the target resource is bound to a permission point; Receive the permission verification request sent by the docking device; Determine, according to the permission verification request, whether the user has the right to use the permission point bound to the target resource; In the case where it is determined that the user has the right to use the permission point, a verification result is sent to the docking device so that the docking device allows the access request to access the target resource.
6. The method according to claim 5, further comprising: In the case where it is determined that the user does not have the right to use the authority point, a verification failure result is sent to the docking device so that the docking device is prohibited from accessing the target resource.
7. The method according to claim 5, wherein sending the resource permission data to the docking party device comprises: In response to the resource authority data acquisition request sent by the docking party device, the resource authority data is sent to the docking party device.
8. The method according to claim 5, determining whether the user has the right to use the permission point according to the permission verification request, comprises: According to the user identifier carried in the permission verification request, query whether the user identifier exists in the user list of the permission point; If so, it is determined that the user has the right to use the permission point; If not, it is determined that the user does not have the right to use the permission point.
9. The method according to claim 5, further comprising: In response to the resource permission point correction operation, the designated resource data requiring permission control and the target permission point are bound to generate incremental resource permission data; The incremental resource permission data is pushed to the docking party device.
10. The method according to claim 9, in response to the resource permission point correction operation, binding the specified resource data requiring permission control and the target permission point to generate incremental resource permission data, comprising: Displaying an information interface, wherein the information interface includes at least one authority point; In response to a selection operation on at least one permission point, display at least one resource data corresponding to the selected target permission point; In response to a selection operation on at least one resource data, the selected resource data is used as designated resource data to be bound to the target authority point; In response to the determination operation, the specified resource data and the target authority point are bound.
11. The method according to claim 5, further comprising: Displaying an information interface, wherein the information interface includes a permission point adding control; In response to a triggering operation of adding a control to a permission point, displaying a permission point information page, the permission point information page including permission point information input items; In response to the operation of inputting permission point information in the permission point information input item, a new permission point is added to the information interface.
12. A docking device, the method comprising: Memory and processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions to: execute the steps in the resource access method described in any one of claims 1-4.
13. A computer-readable storage medium storing a computer program, which can implement the steps of the resource access method according to any one of claims 1 to 4 when the computer program is executed.
14. A permission management device, the method comprising: Memory and processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions to: execute the steps in the permission verification method described in any one of claims 5-11.
15. A computer-readable storage medium storing a computer program, which, when executed, can implement the steps of the permission verification method described in any one of claims 5 to 11.
16. An information processing method, applicable to a permission management device, comprising: Displaying an information interface, wherein the information interface includes at least one authority point; In response to a selection operation on at least one permission point, displaying at least one resource data that can be bound to the selected permission point; In response to a selection operation on at least one resource data, the selected resource data is bound to the selected permission point, so that after receiving the resource data that needs permission control sent by the docking party device, resource permission data is generated for the resource data that needs permission control. The resource permission data refers to the binding relationship between the resource that has been bound to the permission point and the corresponding permission point. The docking party device obtains the resource data that needs permission control when the docking party system is started, and sends the resource data that needs permission control to the permission control device. The docking party device pulls the resource permission data from the permission control device after the docking party system is started. It intercepts the access request to the target resource initiated by the user end, determines whether the target resource is bound to the permission point according to the resource permission data, and sends a permission verification request to the permission control device when it is determined that the target resource is bound to the permission point, so that the permission control device verifies whether the user has the right to use the permission point bound to the target resource.
17. The method according to claim 16, wherein the information interface further comprises a permission point adding control, and the method further comprises: In response to the triggering operation of adding a control to a permission point, a new permission point is added to the information interface.
18. The method according to claim 17, in response to a triggering operation of adding a control to a permission point, adding a new permission point in the information interface, comprises: In response to a triggering operation of adding a control to a permission point, a permission point information input page is displayed, wherein the permission point information input page includes permission point information input items; In response to the operation of inputting permission point information in the permission point information input item, the permission point of the information is added in the information interface.
19. The method according to claim 16, wherein the information interface further comprises a permission point deletion control corresponding to the permission point, and the method further comprises: In response to the triggering operation of the permission point deletion control, the permission point corresponding to the permission point deletion control is deleted.
20. The method according to claim 16, further comprising: Respond to the triggering operation on the target permission point and display the resource data bound to the target permission point; In response to a correction operation on the resource data bound to the target authority point, new resource data is bound to the target authority point.
21. A permission management device, the method comprising: Memory and processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions to: execute the steps in the information processing method described in any one of claims 16-20.
22. A computer-readable storage medium storing a computer program, which can implement the steps of the information processing method according to any one of claims 16 to 20 when the computer program is executed.
23. A resource access method, applicable to a user terminal, comprising: In response to a resource access operation initiated by a user, an access request for a target resource is sent to a docking party device, so that the docking party device intercepts the access request, determines whether the target resource is bound to a permission point according to the resource permission data, and verifies with the permission control device whether the user has the right to use the permission point bound to the target resource if it is determined that the target resource is bound to a permission point, wherein the resource permission data refers to the binding relationship between the resource that has been bound to the permission point and the corresponding permission point; wherein the docking party device obtains the resource data that needs permission control when the docking party system is started, and sends the resource data that needs permission control to the permission control device, so that the permission control device generates resource permission data for the resource data that needs permission control, and pulls the resource permission data from the permission control device after the docking party system is started; Receive a result returned by the docking party device that allows access to the target resource, and access the target resource.
24. A user terminal, the method comprising: Memory and processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions to: execute the steps in the resource access method described in claim 23.
25. A computer-readable storage medium storing a computer program, which can implement the steps in the resource access method according to claim 23 when the computer program is executed.
Citation Information
Patent Citations
Maintenance authority management system
CN103853984A
Authority processing method, apparatus, application-side apparatus, and storage medium
CN109472127A
Authority control method, device and equipment and storage medium
CN111079104A