An information management method, management system, and storage medium
Patent Information
- Application Number
- CN202111150577.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-29
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2041-09-29
AI Technical Summary
[0004]本申请实施例提供一种信息管理方法、管理系统和存储介质,以解决相关技术对于不同的调用方而言,对多个所有标签都有读写权限,至少存在数据冗余、定位性差的问题
[0019]By receiving request information from the caller, including the caller's account identifier, user identifier, tag identifier to be invoked, and operation type corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user requesting tag management; if the request information is verified, the permission verification result of the caller's permission to perform the operation type corresponding to the tag identifier to be invoked is obtained; based on the permission verification result, the user profile associated with the user identifier of the tag identifier to be invoked is managed. Thus, this application solves the problem of data redundancy and poor localization in related technologies where different callers have read and write permissions to multiple tags; it achieves filtering and screening of tag data based on the caller's permission to perform the operation type corresponding to the tag identifier to be invoked, reducing data redundancy while accurately locating the tag information contained in the user profile.
Smart Images

Figure CN113792274B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology in financial technology (Fintech), and includes, but is not limited to, an information management method, a management system, and a storage medium. Background Technology
[0002] With the development of computer computing, more and more technologies are being applied in the financial field, and the traditional financial industry is gradually transforming into financial technology (Fintech). However, due to the security and real-time requirements of the financial industry, Fintech also places higher demands on technology.
[0003] In the fintech field, various financial systems (such as management systems of commercial banks and securities companies) offer customer profiling functions, or functions for tagging, de-tagging, or querying tags for customers within the system. Currently, when a financial system receives a request from a user requesting customer profiling, it directly responds to the request by reading and writing all tags in the customer's profile based on the customer identifier, tag identifier, and the operation type corresponding to the tag identifier. If multiple products create personalized customer profiles for the same customer, querying the customer's personalized tags will yield the customer's tags across all products, rather than specifically retrieving the tags from the customer profile in the product highly relevant to the user. Therefore, the above method, where different users have read and write permissions to multiple tags, suffers from data redundancy and poor localization. Summary of the Invention
[0004] This application provides an information management method, management system, and storage medium to address the problems of data redundancy and poor location accuracy in related technologies where different callers have read and write permissions for multiple tags.
[0005] The technical solution of this application embodiment is implemented as follows:
[0006] This application provides an information management method, including:
[0007] The system receives request information sent by the caller, wherein the request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and operation type for the tag corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management.
[0008] If the request information is verified, the caller pointed to by the account identifier is obtained, and the permission verification result of the permission to perform the operation of the operation type corresponding to the tag to be called is obtained.
[0009] Based on the permission verification result, the user profile of the user identifier associated with the tag identifier to be invoked is managed.
[0010] This application provides an information management device, including:
[0011] The receiving module is used to receive request information sent by the caller, wherein the request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and operation type of the tag corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management;
[0012] The acquisition module is used to, if the request information is verified, acquire the caller pointed to by the account identifier, and the permission verification result of the permission to execute the operation of the operation type corresponding to the tag to be invoked tag identifier;
[0013] The processing module is used to manage the user profile of the user identifier associated with the tag identifier to be invoked, based on the permission verification result.
[0014] This application provides a management system, including:
[0015] Memory, used to store executable instructions;
[0016] The processor implements the above method when executing executable instructions stored in memory.
[0017] This application provides a storage medium storing executable instructions for inducing a processor to execute the above-described method.
[0018] The embodiments of this application have the following beneficial effects:
[0019] By receiving request information from the caller, including the caller's account identifier, user identifier, tag identifier to be invoked, and operation type corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user requesting tag management; if the request information is verified, the permission verification result of the caller's permission to perform the operation type corresponding to the tag identifier to be invoked is obtained; based on the permission verification result, the user profile associated with the user identifier of the tag identifier to be invoked is managed. Thus, this application solves the problem of data redundancy and poor localization in related technologies where different callers have read and write permissions to multiple tags; it achieves filtering and screening of tag data based on the caller's permission to perform the operation type corresponding to the tag identifier to be invoked, reducing data redundancy while accurately locating the tag information contained in the user profile. Attached Figure Description
[0020] Figure 1 This is an optional architecture diagram of the management system provided in an embodiment of this application;
[0021] Figure 2 This is an optional flowchart illustrating the information management method provided in an embodiment of this application;
[0022] Figure 3 This is an optional flowchart illustrating the information management method provided in an embodiment of this application;
[0023] Figure 4 This is an optional structural block diagram of the management system provided in the embodiments of this application;
[0024] Figure 5 This is an optional flowchart illustrating the information management method provided in an embodiment of this application;
[0025] Figure 6 This is an optional flowchart illustrating the information management method provided in an embodiment of this application;
[0026] Figure 7 This is an optional flowchart illustrating the information management method provided in an embodiment of this application;
[0027] Figure 8 This is an optional flowchart illustrating the information management method provided in the embodiments of this application. Detailed Implementation
[0028] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0029] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. However, it is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments of this application pertain. The terminology used in the embodiments of this application is for the purpose of describing the embodiments of this application only and is not intended to limit the application.
[0030] The following describes exemplary applications provided by embodiments of this application, which can be implemented as servers. Exemplary applications implemented as servers will be described below.
[0031] See Figure 1 , Figure 1 This is a schematic diagram of the structure of the management system 100 provided in the embodiments of this application. Figure 1 The management system 100 shown includes at least one processor 110, at least one network interface 120, a user interface 130, and a memory 150. The various components in the management system 100 are coupled together via a bus system 140. It is understood that the bus system 140 is used to implement communication between these components. In addition to a data bus, the bus system 140 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 1 The general labeled all buses as Bus System 140.
[0032] The processor 110 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0033] User interface 130 includes one or more output devices 131 that enable the presentation of media content, including one or more speakers and / or one or more visual displays. User interface 130 also includes one or more input devices 132, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.
[0034] Memory 150 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, etc. Memory 150 may optionally include one or more storage devices physically located remote from processor 110. Memory 150 may include volatile memory or non-volatile memory, or both. Non-volatile memory may be read-only memory (ROM), and volatile memory may be random access memory (RAM). The memory 150 described in this application embodiment is intended to include any suitable type of memory. In some embodiments, memory 150 is capable of storing data to support various operations, examples of which include programs, modules, and data structures, or subsets or supersets thereof, as exemplified below.
[0035] Operating system 151 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;
[0036] The network communication module 152 is used to reach other computing devices via one or more (wired or wireless) network interfaces 120, such as Bluetooth, WiFi, and Universal Serial Bus (USB).
[0037] The input processing module 153 is used to detect and translate one or more user inputs or interactions from one or more input devices 132.
[0038] In some embodiments, the apparatus provided in this application can be implemented in software. Figure 1 An information management device 154 stored in memory 150 is shown. This information management device 154 can be an information management device within management system 100. It can be software in the form of programs and plug-ins, including the following software modules: a receiving module 1541, an acquisition module 1542, and a processing module 1543. These modules are logically connected and can therefore be arbitrarily combined or further divided according to their implemented functions. The functions of each module will be described below.
[0039] In other embodiments, the apparatus provided in this application can be implemented in hardware. As an example, the apparatus provided in this application can be a processor in the form of a hardware decoding processor, which is programmed to execute the information management method provided in this application. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0040] The information management method provided in this application will be described below with reference to exemplary applications and implementations of the management system 100 provided in the embodiments of this application. See also Figure 2 , Figure 2 This is an optional flowchart illustrating the information management method provided in this application embodiment, which will be combined with... Figure 2 The steps shown are explained below.
[0041] Step 201: Receive the request information sent by the caller.
[0042] The request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and the operation type of the tag corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management.
[0043] In this embodiment, the caller is an electronic device used to call the tag. Here, electronic devices include, but are not limited to, mobile terminal devices such as smartphones, tablets, laptops, smart TVs, drawing tablets, personal digital assistants (PDAs), cameras, and wearable devices, as well as fixed terminal devices such as desktop computers.
[0044] In this embodiment, the caller's account identifier is a unique identifier assigned to the caller by the management system. Here, before each caller accesses the profiling function in the management system, the management system generates an account identifier for the caller. It should be noted that when generating the account identifier for the caller, the management system sets the tags that the account identifier can operate on, as well as the permissions for the operations that can be performed on those tags.
[0045] In this embodiment, the user identifier is the identifier possessed by the user who requests tag management from the calling party. The user identifier can also be understood as the customer number of each customer in the management system, and this customer number is unique.
[0046] In this embodiment, the tag identifier to be invoked is the identifier information of the tag that the caller wants to operate on. There can be one or more tag identifiers to be invoked, and this application does not impose any specific restrictions.
[0047] In this embodiment of the application, the operation type of the tag corresponding to the tag identifier to be called includes the tag query operation type and the tag update operation type; wherein, the tag update operation type includes the tag addition operation type or the tag removal operation type.
[0048] In this embodiment of the application, when the management system receives the request information sent by the caller, it parses the relevant parameters in the request information to obtain the caller's account identifier, user identifier, tag identifier to be called, and the operation type of the tag corresponding to the tag identifier to be called carried in the request information.
[0049] Step 202: If the request information verification passes, obtain the permission verification result of the caller pointed to by the account identifier, the tag corresponding to the tag identifier to be called, and the permission of the operation type to be executed.
[0050] In this embodiment of the application, the permission verification is whether the caller, as indicated by the account identifier, has the permission to perform an operation of the type of operation corresponding to the tag identifier to be called; the permission verification result includes whether the caller has the permission to perform an operation of the type of operation corresponding to the tag identifier to be called, or whether the caller does not have the permission to perform an operation of the type of operation corresponding to the tag identifier to be called.
[0051] In this embodiment of the application, after the management system receives the request information sent by the caller, it verifies the request message. If the request message passes the verification, the management system obtains the permission verification result of the caller pointed to by the account identifier, the tag corresponding to the tag to be called, and the permission to perform the operation type. This enables the management system to manage the user profile of the user identifier associated with the tag to be called based on the permission verification result.
[0052] Step 203: Based on the permission verification results, manage the user profile of the user identifier associated with the tag identifier to be invoked.
[0053] In this embodiment of the application, the electronic device displays a user profile of the user identifier associated with the tag identifier to be invoked on the display module of the electronic device based on the permission verification result.
[0054] This application provides an information management method that receives request information from a caller, including the caller's account identifier, user identifier, tag identifier to be invoked, and operation type of the tag corresponding to the tag identifier to be invoked. The user identifier is the identifier possessed by the user requesting tag management. If the request information is verified, the method obtains the permission verification result of the caller's permission to perform the operation type of the tag corresponding to the tag identifier to be invoked, as indicated by the account identifier. Based on the permission verification result, the method manages the user profile associated with the user identifier of the tag identifier to be invoked. Thus, this application solves the problems of data redundancy and poor localization in related technologies where different callers have read and write permissions to multiple tags. It achieves filtering and screening of tag data based on the caller's permission to perform the operation type of the tag corresponding to the tag identifier to be invoked, reducing data redundancy while accurately locating the tag information contained in the user profile.
[0055] See Figure 3 , Figure 3 This is an optional flowchart illustrating the information management method provided in this application embodiment, which will be combined with... Figure 3 The steps shown are explained below.
[0056] Step 301: Receive the request information sent by the caller.
[0057] The request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and the operation type of the tag corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management.
[0058] In other embodiments of this application, see Figure 4 , Figure 4 This is an optional structural block diagram of the management system provided in this application embodiment. The management system is a distributed management system, and the distributed management system includes multiple nodes. A load balancing server, such as an NGINX server, is deployed at the front end of the management system, and the management system sets up a liveness detection interface for each node. Every target time interval, such as 3 seconds, the load balancing server calls the liveness detection interface of each node to forward the request information received through the load balancing server in the management system.
[0059] In one scenario, when all nodes in the management system are functioning normally, the load balancer server receives a success message from each node via the liveness detection interface. When a caller sends a request to the management system, it first receives the request through the load balancer server. Then, the load balancer server forwards the received requests sequentially to each node according to a round-robin principle. For example, if the management system has 6 nodes, the load balancer server will forward the received requests sequentially to node 1, node 2, ..., node 6, and so on, according to the round-robin principle.
[0060] In another scenario, when some nodes in the management system are providing normal service, the load balancer server receives success messages from these nodes via the liveness detection interface. The load balancer then forwards each received request to these normal service nodes sequentially according to a round-robin principle. For example, if the management system has 6 nodes, the load balancer server calls the liveness detection interface of each node every target interval, such as 3 seconds. If the load balancer server does not receive a success message from node 1 via the liveness detection interface, it indicates that node 1 is experiencing a service failure. In this case, the load balancer server removes node 1 from the round-robin node list. That is, the load balancer server continues to forward each received request to the normal service nodes sequentially according to the round-robin principle, i.e., node 2, ..., node 6, and so on. When node 1 successfully returns a success message via the liveness detection interface, the load balancer server adds node 1 back to the round-robin node list.
[0061] As described above, in this embodiment, the management system can be a distributed management system. By setting a liveness detection interface for each node in the distributed management system, the failure of a single node will not affect the normal service provided by the management system. Furthermore, the management system's front end is connected to a load balancing server to perform balanced forwarding of received request information and to detect the liveness of system nodes. When a node fails, the load balancing server in the management system can promptly remove the node from the node cluster. This avoids the problem of system downtime caused by some nodes in the management system due to hardware aging or other issues, improves the stable operation of the customer profiling function in the management system, and enhances the robustness of the management system.
[0062] In this embodiment of the application, before receiving the request information sent by the caller, the management system may also perform the following steps:
[0063] Step 1: Generate at least one authorization message at a preset rate.
[0064] In this embodiment of the application, authorization information is used to grant the right to perform certain operations. For example, authorization information includes, but is not limited to, tokens.
[0065] Step 2: If the available storage space in the distributed cache pool meets the caching conditions for authorization information, store at least one piece of authorization information in the distributed cache pool.
[0066] In this embodiment of the application, the distributed cache pool is used to store authorization information. For example, the distributed cache pool can be a Remote Dictionary Server (Redis) cache pool.
[0067] In this embodiment of the application, the authorization information caching conditions include that the distributed storage pool has remaining storage space or the size of the available storage space meets a preset size.
[0068] In this embodiment, firstly, the management system generates at least one authorization message at a preset rate, i.e., a constant rate; secondly, the management system determines whether the available storage space of the distributed cache pool meets the authorization message caching conditions. If the management system determines that the available storage space of the distributed cache pool meets the authorization message caching conditions, i.e., the management system determines that there is available storage space in the distributed cache pool, then at least one authorization message is stored in the distributed cache pool; if the management system determines that the available storage space of the distributed cache pool does not meet the authorization message caching conditions, i.e., the management system determines that there is no available storage space in the distributed cache pool, then the authorization message generated by the management system at the current moment is discarded.
[0069] Accordingly, after receiving the request information sent by the caller, the management system can also perform the following steps:
[0070] Step 3: Retrieve authorization information from the distributed cache pool for the request information and obtain the retrieval result.
[0071] Step 4: If the retrieved result indicates that the requested information has been retrieved and an authorization information has been retrieved, then the requested information is verified.
[0072] In this embodiment, the management system retrieves authorization information from the distributed cache pool for the request information at a preset retrieval rate. For example, the retrieval rate is the same as the preset rate.
[0073] In this embodiment, the fetch result can be characterized as either the request information fetching authorization information or the request information not fetching authorization information. It should be noted that since the generation rate of authorization information is pre-set, the higher the frequency of requests sent by the caller within a certain period, the less authorization information is stored in the distributed cache pool. Therefore, the probability of fetching authorization information for requests sent later by the caller is lower. Furthermore, only when authorization information is fetched for requests sent later by the caller will the subsequent request information verification stage begin; conversely, if authorization information is not fetched for requests sent later by the caller, the subsequent request information verification stage cannot begin, and the later-sent request information is discarded. Thus, regardless of the frequency of the caller's request information, since the management system's fetch rate for authorization information is constant, only requests within the management system's authorization information generation rate can be processed normally. This avoids system crashes due to a surge in request information volume, ensuring the stability and robustness of the management system, while also protecting its security.
[0074] In one feasible application scenario, see Figure 4 The management system is a distributed system, which deploys a distributed rate limiting tool (distributedRateLimiter). This tool is implemented using Redis, and taking authorization information as tokens as an example, its underlying algorithm is the token bucket algorithm. Here, the management system generates tokens at a constant rate and places them in a Redis cache pool. If the Redis cache pool is not full, a token is added; if the cache pool is full, the newly generated token is discarded. When the management system receives a request, it needs to retrieve a token from the Redis cache pool. Only after successfully retrieving the token can subsequent processing operations be performed. Thus, regardless of the rate at which the caller sends requests, because the rate at which the management system retrieves tokens for requests is constant, only requests within the rate at which the management system generates tokens can be processed normally. This avoids system crashes due to a surge in request volume, ensuring the stability and robustness of the management system, while also protecting its security.
[0075] Step 302: If the request information is verified, look up the configuration value corresponding to the account identifier using the account identifier as the key.
[0076] Among them, the configuration value corresponding to the account identifier represents the set of permissions for the tags that the account identifier can operate on.
[0077] In this embodiment, the management system and the configuration center system establish a communication connection. The configuration center system pre-sets configuration information containing key-value pairs with the account identifier as the key and the configuration value as the value. The configuration value corresponding to the account identifier represents the set of permissions for the tags that the account identifier can operate on, i.e., the permission protocol content corresponding to the account identifier. For example, the configuration value corresponding to the account identifier is “tagId-1|W; tagId-2|RW; tagId-3|R”. Here, tagId-1 represents the tag identifier of tag 1, tagId-2 represents the tag identifier of tag 2, tagId-3 represents the tag identifier of tag 3, W represents write permission, R represents read permission, and RW represents read and write permission. Here, the configuration value "tagId-1|W;tagId-2|RW;tagId-3|R" corresponding to the account identifier can be interpreted as the caller indicated by the account identifier having write permissions for the tag identified by tagId-1, read and write permissions for the tag identified by tagId-2, and read permissions for the tag identified by tagId-3. It should be noted that having write permissions for the tags corresponding to the tag identifier can also be interpreted as having the permission to tag or remove tags; having read permissions for the tags corresponding to the tag identifier can also be interpreted as having the permission to query tags. Furthermore, each account identifier can have operation permissions for multiple tags, each tag has corresponding configuration content, and the configuration content is separated by preset separators such as semicolons, commas, etc.
[0078] In one feasible application scenario, after the management system receives the request information sent by the caller, it verifies the request message. If the request message passes the verification, it generates a query request with the account identifier as the key and sends the query request to the configuration center system. The configuration center system searches for the configuration value corresponding to the account identifier as the key in the configuration information. The configuration center system sends the query information with the account identifier as the key and the corresponding configuration value to the management system, thereby the management system obtains the set of permissions for the tags that the account identifier can operate on.
[0079] In another implementation scenario, the configuration center system is a distributed configuration center system, and the management system is a distributed management system. Each node in the configuration center system stores configuration information. When the configuration information in a node is updated, the configuration center system updates the updated configuration information to all nodes in the configuration center. Simultaneously, the configuration center system updates the updated configuration information to every node in the management system in real time, enabling the management system to back up the configuration information corresponding to each account identifier to the local disk of each node. When the configuration center system crashes, the management system can query the locally backed-up configuration information to ensure the normal operation of existing functions. That is, after receiving a request from a caller, the management system verifies the request message. If the request message passes verification, it uses the account identifier as the key to look up the configuration value corresponding to the account identifier in the configuration information, thereby obtaining the set of permissions for the tags that the account identifier can operate on.
[0080] As can be seen from the above, in this embodiment of the application, when a provider of a new product or application accesses the management system through a caller, the system administrator of the management system needs to agree, and then the management system generates a unique account identifier and grants the account identifier specific permissions for specific tags; in this way, the generation and acquisition of redundant data are reduced, unnecessary data management troubles are reduced, and accurate and personalized user profile services are achieved.
[0081] In other embodiments of this application, the management system stores a set of permissions—using account identifiers as keys and corresponding configuration values (i.e., the permissions of the tags that can be operated)—in a configuration center system. These permissions are configured and take effect in real time. When a new product or application provider accesses the management system through a caller, the permission set only needs to be modified in the configuration information of the configuration center system for immediate effect. Simultaneously, the configuration center system updates the updated configuration information to the local disks of each node in the management system in real time. This avoids the impact of configuration center failures on new product or application providers accessing the management system through callers, improving convenience without compromising system robustness and ensuring high availability.
[0082] Here, combined Figure 5 The process of verifying the request information in step 302 is further explained.
[0083] Step A1: Use the account identifier as the key to search for a configuration value corresponding to the account identifier, and verify the validity of the account identifier based on the search results.
[0084] In this embodiment, the management system uses the account identifier as the key to search for a configuration value corresponding to the account identifier in the configuration information. If the search result indicates that a configuration value corresponding to the account identifier exists, the validity of the account identifier is verified.
[0085] Step A2: Perform format validation on the user identifier and verify the association between the user identifier and the product identifier of the caller.
[0086] In this embodiment, the management system performs format validation on the user identifier. If the user identifier's format meets the requirements and there is a high correlation between the user identifier and the caller's product identifier, the correlation validation is deemed successful. For example, the management system verifies whether the user identifier's format is correct and whether the user corresponding to the user identifier is a real user of the management system. If it is a real user, then a high correlation between the user identifier and the caller's product identifier is determined.
[0087] Step A3: Validate the validity of the tag identifier to be called.
[0088] In this embodiment, the management system determines whether the tag identifier to be called is stored in the database. If it is determined that the tag identifier to be called is stored in the database, the management system determines that the validity verification of the tag identifier to be called has passed.
[0089] Step A4: Perform an executability check on the operation type.
[0090] In this embodiment, the operation types include tag query operation types and tag update operation types; wherein, the tag update operation type includes tag addition operation types or tag removal operation types. The management system verifies whether the operation type conforms to the preset operation type. If it is determined that the operation type conforms to the preset operation type, the management system passes the executability verification of the operation type.
[0091] Step A5: If the validity of the account identifier, the format and relevance of the user identifier, the validity of the tag identifier to be called, and the executability of the operation type are all verified, then the request information is confirmed to be verified.
[0092] In this embodiment, the management system uses the account identifier as the key to search for the existence of a configuration value corresponding to the account identifier, and performs a validity check on the account identifier based on the search results; it performs a format check on the user identifier, and a correlation check on the user identifier and the product identifier of the caller; it performs a validity check on the tag identifier to be called; and it performs an executability check on the operation type. If the validity check of the account identifier, the format check and correlation check of the user identifier, the validity check of the tag identifier to be called, and the executability check of the operation type pass, the request information is determined to have passed the verification. At this time, the management system performs subsequent operations based on the account identifier, user identifier, tag identifier to be called, and the operation type of the tag corresponding to the tag identifier to be called. In this way, by performing security checks on the parameters carried in the request information, access to unauthorized request information is avoided, ensuring the security of the system and data.
[0093] Step 303: Based on the permission set, verify the caller's permission to perform the operation type corresponding to the tag identifier to be called, and obtain the permission verification result.
[0094] In this embodiment of the application, the permission verification is whether the caller, as indicated by the account identifier, has the permission to perform an operation of the type of operation corresponding to the tag to be called; the permission verification result includes whether the caller has the permission to perform an operation of the type of operation corresponding to the tag to be called, or whether the caller has the permission not to perform an operation of the type of operation corresponding to the tag to be called.
[0095] In this embodiment of the application, if the management system verifies the request information, it looks up the configuration value corresponding to the account identifier using the account identifier as the key, and then verifies the caller's permission to perform the operation type operation corresponding to the tag to be called based on the permission set, so as to obtain the permission verification result. This allows the management system to manage the user profile of the user identifier associated with the tag to be called based on the permission verification result.
[0096] Step 304: Based on the permission verification results, manage the user profile of the user identifier associated with the tag identifier to be invoked.
[0097] In other embodiments of this application, when the permission verification result indicates that the permission set does not include the permission for the operation type corresponding to the tag to be called, a prompt message is generated to remind the caller that the permission is limited, and the prompt message is output.
[0098] In this embodiment of the application, after the management system determines the list of tag identifiers of the tags of the operation permissions that the caller can execute based on the permission set, when the permission verification result indicates that the permission set does not include the permission to execute the operation type of the tag corresponding to the tag identifier to be called, that is, it indicates that the caller does not have read permission or write permission for the tag identifier to be called, a prompt message is generated to remind the caller that the permission is restricted, and the prompt message is output.
[0099] In this embodiment of the application, combined with Figure 6 If the operation type includes querying tags, the process of managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result in step 304 will be further explained.
[0100] Step B1: Based on the permission set, determine the list of tag identifiers for the tags that the caller can use to perform the operation of querying tags.
[0101] The tag identifier list includes reference tags corresponding to reference tag identifiers, which are tags that the caller can use to perform tag query operations.
[0102] In this embodiment of the application, if the operation type includes the operation of querying tags, the management system obtains a list of reference tag identifiers corresponding to the reference tags for which the caller can perform the operation of querying tags, based on the permission set.
[0103] Step B2: When the permission verification result indicates that there is a tag identifier to be called in the reference tag identifiers included in the tag identifier list, filter out the tag identifier sublist that includes the tag identifier to be called from the tag identifier list.
[0104] In this embodiment, after the management system determines the list of tag identifiers for which the caller can perform the operation of querying tags based on the permission set, when the permission verification result indicates that there is a tag identifier to be called in the reference tag identifiers included in the tag identifier list, it indicates that the caller has read permission for the tag identifier to be called; further, the management system filters out a sub-list of tag identifiers with read permission, including the tag identifier to be called.
[0105] Step B3: Obtain the reference tags corresponding to all the tag identifiers to be called in the tag identifier sublist, and filter out the tags included in the user profile associated with the user identifier from all the reference tags.
[0106] In this embodiment, when the permission verification result indicates that the reference tag identifiers included in the tag identifier list contain a tag identifier to be invoked, the management system filters out a sub-list of tag identifiers containing the tag identifier to be invoked from the tag identifier list. Then, the management system obtains the reference tags corresponding to all the tag identifiers to be invoked in the sub-list of tag identifiers, and filters out the tags included in the user profile associated with the user identifier from all the reference tags. In this way, based on the permission set and permission verification result, and knowing that permissions have been allocated or granted to the caller, the management system filters and selects the tag identifier list based on the tag identifier to be invoked to obtain the tags included in the user profile associated with the user identifier. This reduces data redundancy while accurately locating the tag information contained in the user profile.
[0107] In a feasible application scenario, taking the configuration value corresponding to the account identifier, i.e., the permission set as "tagId-1|W; tagId-2|RW; tagId-3|R", as an example, if the tag identifier to be called is tagId-1, and the operation type of the tag corresponding to the tag identifier to be called is a tag query operation, the management system, based on the permission set, determines that the list of tag identifiers of the tags for which the caller can perform the tag query operation is "tagId-1 and tagId-2". Further, the management system verifies the tag corresponding to the tag identifier to be called by the caller and executes... The permission verification result of the operation type is used to determine if there is a tag identifier tagId-1 to be called in the reference tag identifiers included in the tag identifier list "tagId-1 and tagId-2". The tag identifier sublist "tagId-1" that includes the tag identifier tagId-1 to be called is filtered out from the tag identifier list "tagId-1 and tagId-2", and the tags corresponding to all the tag identifiers to be called in the tag identifier sublist are obtained. The tags included in the user profile associated with the user identifier are then filtered out from the tags corresponding to all the tag identifiers to be called.
[0108] As described above, in this embodiment, when the operation type carried in the request information is a query tag operation type, the management system, based on the obtained permission set corresponding to the account identifier using the account identifier as the key, achieves preliminary filtering of the tags that the caller can operate on. Further, based on the permission set, the management system determines a list of tag identifiers composed of reference tag identifiers corresponding to reference tags for which the caller can perform query tag operations, achieving further filtering of the tags that the caller can operate on. Finally, the management system filters out a sub-list of tag identifiers with read permissions, including the tag identifier to be called, and obtains the reference tags corresponding to all the tag identifiers to be called in the sub-list. It then filters out the tags included in the user profile associated with the user identifier from all the reference tags. Thus, it achieves the query and organization of tags included in the user profile associated with the user.
[0109] In this embodiment of the application, combined with Figure 7 If the operation type includes querying tags, the process of managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result in step 304 will be further explained.
[0110] Step C1: Based on the permission set, determine the list of tag identifiers for the tags that the caller can use to perform the operation of querying tags.
[0111] The tag identifier list includes reference tags corresponding to reference tag identifiers, which are tags that the caller can use to perform tag query operations.
[0112] Step C2: When the permission verification result indicates that the reference label identifier included in the label identifier list does not contain the label identifier to be called, generate a prompt message to inform the caller that the permission is restricted, and output the prompt message.
[0113] In this embodiment, after the management system determines the list of tag identifiers for which the caller can perform tag query operations based on the permission set, if the permission verification result indicates that the tag identifier to be called is not present in the reference tag identifiers included in the tag identifier list, that is, it indicates that the caller does not have read permission for the tag identifier to be called; furthermore, the management system generates and outputs a prompt message to remind the caller that their permissions are restricted; thus, based on the permission set and permission verification result, when it is determined that the caller's permissions are restricted or unauthorized, the system prompts the caller that they cannot operate on the user profile of the user identifier associated with the tag identifier to be called.
[0114] In a feasible application scenario, taking the configuration value corresponding to the account identifier, i.e., the permission set as "tagId-1|W; tagId-2|RW; tagId-3|R", as an example, if the tag identifier to be called is tagId-3, and the operation type of the tag corresponding to the tag identifier to be called is a query tag operation type, the management system determines, based on the permission set, the list of tag identifiers of the tags that the caller can execute the query tag operation as "tagId-1 and tagId-2". Further, the management system verifies the permission verification result of the caller's permission to execute the operation type of the tag corresponding to the tag identifier to be called, and the permission verification result indicates that the tag identifier to be called tagId-3 is not among the reference tag identifiers included in the tag identifier list "tagId-1 and tagId-2", that is, it indicates that the caller does not have read permission for the tag identifier to be called tagId-3. Further, the management system generates a prompt message to remind the caller that the permission is restricted, and outputs the prompt message.
[0115] In other embodiments of this application, the management system may first perform a filter on the permission set based on the tag identifier to be invoked, to obtain a tag permission list of tags that the caller can operate on; then, the management system may perform a permission verification result to verify the caller's permission to perform operations of the type of operation in the tag permission list.
[0116] In other embodiments of this application, before generating the prompt message to inform the caller of restricted permissions in step C2, the management system may also generate a rejection instruction to reject the caller's request and respond to the rejection instruction.
[0117] In other embodiments of this application, the management system receives request information sent by the caller; wherein, the request information includes the caller's account identifier, user identifier, and operation type; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management. If the request information is verified, the system looks up the configuration value corresponding to the account identifier using the account identifier as the key; wherein, the configuration value corresponding to the account identifier represents the permission set of tags that the account identifier can operate on. Based on the permission set, the management system determines a list of tag identifiers for tags that the caller can use to perform tag query operations. The management system obtains the tags corresponding to all tag identifiers in the tag identifier list and filters out the tags included in the user profile associated with the user identifier from all tags. Thus, even if the request information sent by the caller does not carry the tag identifier to be invoked, the management system only filters the tags that the caller can operate on based on the tag query operation type, obtaining a filtered list of tag identifiers, thereby realizing the query of tags included in the customer profile associated with the user identifier.
[0118] In other embodiments of this application, if the operation type includes updating tags, the process of managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result in step 304 is further explained.
[0119] When the permission verification result indicates that the permission set includes the permission to perform the operation of updating the label corresponding to the label to be called, the label corresponding to the label to be called is added or deleted in the user profile of the user identifier to obtain the updated user profile.
[0120] In this embodiment, when the operation type carried in the request information is an update tag operation type, i.e., a tagging operation type or a tag removal operation type, the management system searches for the permission set corresponding to the account identifier based on the obtained account identifier as the key. Further, based on the permission set, the management system determines a list of reference tag identifiers consisting of reference tag identifiers corresponding to reference tags for which the caller can perform tagging or tag removal operations. When the permission verification result indicates that the permission set includes the tag corresponding to the tag to be called, and the permission to perform tagging or tag removal operations, the tag corresponding to the tag to be called is added or deleted from the user profile of the user identifier, resulting in an updated user profile.
[0121] It should be noted that in the current profiling function solution, since the tag ID is hard-coded into the code or stored in the database, when a new tag ID needs to be used, the system needs to be developed and a version released, or the database script needs to be executed to change the data. This is time-consuming and labor-intensive, and the complicated operation increases the probability of production failures.
[0122] In other embodiments of this application, the management system and the configuration center system establish a communication connection. The configuration center system pre-sets configuration information, and the management system stores all tag-related configurations in the configuration center system. When a new tag is used, the corresponding permission protocol only needs to be modified in the configuration information of the configuration center system for it to take effect immediately. This avoids the need for the management system to undergo further development and version releases, or to execute database scripts to change data, which is time-consuming and labor-intensive. It also avoids increasing the probability of management system failures due to complex operations, improving system convenience while ensuring system security and robustness.
[0123] In one feasible application scenario, see Figure 8 , Figure 8 This is an optional flowchart illustrating the information management method provided in this application embodiment, which will be combined with... Figure 8 The diagram shows S1-S3; or S1-S2 and S4-S6; or S1-S2, S4-S5 and S7.
[0124] S1. Receive the request information sent by the caller. If the request information is verified, obtain and parse the permission control protocol corresponding to the account identifier using the account identifier as the key to obtain the permission set.
[0125] In this embodiment, the management system parses the access control protocol to obtain the configuration value corresponding to the account identifier. The configuration value corresponding to the account identifier represents the set of permissions for the tags that the account identifier can operate on.
[0126] S2. Based on the permission set, determine the operation type of the tag corresponding to the tag to be invoked.
[0127] In this embodiment of the application, the management system determines, based on the permission set, that the operation type of the tag corresponding to the tag identifier to be called is an update operation type, and then executes S3; if the management system determines that the operation type of the tag corresponding to the tag identifier to be called is a query operation type, then executes S4.
[0128] S3. If the operation type is an update operation, verify the account identifier's write permission to the tag identifier to be called. If the verification result indicates that the permission set includes the tag corresponding to the tag identifier to be called, and the permission to perform the update tag operation is granted, the management system adds or deletes the tag corresponding to the tag identifier to be called in the user profile of the user identifier to obtain the updated user profile.
[0129] S4. If the operation type is a query operation, retrieve the list of tags with read permissions from the permission set.
[0130] S5. Determine whether the request information contains a tag identifier to be invoked.
[0131] In this embodiment of the application, if the management system determines that the request information carries a tag identifier to be called, then S6 is executed; if the management system determines that the request information does not carry a tag identifier to be called, then S7 is executed.
[0132] S6. Verify that the tag identifier is in the permission identifier list. If the verification result indicates that the permission set includes the tag corresponding to the tag identifier to be called, and has the permission to perform the tag query operation, the management system filters out the tag identifier sublist that includes the tag identifier to be called from the tag identifier list, obtains the reference tags corresponding to all the tag identifiers to be called in the tag identifier sublist, and filters out the tags included in the user profile associated with the user identifier from all the reference tags.
[0133] S7. Obtain the reference tags corresponding to all tag identifiers in the tag identifier list, and filter out the tags included in the user profile associated with the user identifier from all reference tags.
[0134] Step 305: Based on the operation time of managing the user profile, generate the operation record of the caller managing the user profile indicated by the account identifier.
[0135] The operation record includes account identifier, user identifier, operation type, tag identifier to be invoked, system identifier of the caller, product identifier of the caller associated with the user identifier, and operation time.
[0136] In this embodiment, the management system can also generate operation records for the user profile management performed by the caller indicated by the account identifier based on the operation time of the user profile management operation. These operation records include at least the account identifier, user identifier, operation type, tag identifier to be invoked, caller's system identifier, the product identifier of the caller associated with the user identifier, and the operation time. In other words, the management system records all operations performed by the caller indicated by the account identifier on the user corresponding to the user identifier, with each operation recorded as a data operation record and stored in the database. For example, the caller, indicated by the account identifier, tagged user 1 (user identifier 1) and user 2 (user identifier 2) with tag 1. Then, a tag query operation was performed on user 2. At this time, the system will add three operation contents. Each operation contents contains the following main information: account identifier, user identifier, operation type, tag identifier to be called (can be empty when querying), calling system, product party, and operation time. At this time, the three operation contents are (APPID, ecifNo-1, W, tagId-1, systemA, productId, 2021-07-21 19:00:00), (APPID, ecifNo-2, W, tagId-1, systemA, productId, 2021-07-21 19:00:01), and (APPID, ecifNo-2, R, null, systemA, productId, 2021-07-21 19:00:02). After the operation content is added, the system automatically generates a timeline of the caller's operation history for the user and exposes an interface. The input parameters for this interface can be the start time, end time, and user identifier, and the output parameter can be the customer's operation history data within the time range specified by the parameters. Thus, for complex individual customer profile histories, the management system supports tracing back the operation history data of all user profiles within a historical period, enabling clear and concise acquisition of the tag data contained in a specific user's profile, facilitating the processing of production requirements and the tracking of customer information.
[0137] It should be noted that the descriptions of the same steps and contents as in other embodiments in this embodiment can be found in the descriptions in other embodiments, and will not be repeated here.
[0138] The following continues to describe the exemplary structure of the information management device 154 provided in the embodiments of this application as a software module. In some embodiments, such as Figure 1 As shown, the software module stored in the information management device 154 of the memory 150 can be the information management device in the management system 100, including:
[0139] The receiving module 1541 is used to receive request information sent by the caller. The request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and operation type of the tag corresponding to the tag identifier to be invoked. The user identifier is the identifier of the user who requests the execution of tag management by the caller.
[0140] The module 1542 is used to obtain the permission verification result of the caller pointed to by the account identifier, the tag corresponding to the tag identifier to be called, and the permission of the operation type to be executed if the request information is verified.
[0141] Processing module 1543 is used to manage the user profile of the user identifier associated with the tag identifier to be called based on the permission verification result.
[0142] In other embodiments of this application, the acquisition module 1542 is further configured to, if the request information is verified, look up the configuration value corresponding to the account identifier using the account identifier as the key, wherein the configuration value corresponding to the account identifier represents the permission set of the tags that the account identifier can operate on; the processing module 1543 is further configured to, based on the permission set, verify the caller's permission to perform an operation of the operation type corresponding to the tag to be called tag identifier, and obtain the permission verification result.
[0143] In other embodiments of this application, the processing module 1543 is further configured to determine a list of tag identifiers for tags on which the caller can perform a query tag operation based on a set of permissions, wherein the reference tags corresponding to the reference tag identifiers included in the tag identifier list are tags on which the caller can perform a query tag operation; when the permission verification result indicates that there is a tag identifier to be called among the reference tag identifiers included in the tag identifier list, a sublist of tag identifiers including the tag identifier to be called is filtered from the tag identifier list; the acquisition module 1542 is further configured to acquire the reference tags corresponding to all the tag identifiers to be called in the sublist of tag identifiers; the processing module 1543 is further configured to filter out the tags included in the user profile associated with the user identifier from all the reference tags.
[0144] In other embodiments of this application, the processing module 1543 is further configured to generate a prompt message to indicate that the caller's permissions are restricted when the permission verification result indicates that there is no tag identifier to be called in the reference tag identifiers included in the tag identifier list; the output module is configured to output the prompt message.
[0145] In other embodiments of this application, the processing module 1543 is further configured to add or delete the label corresponding to the label to be called in the user profile of the user identifier when the permission verification result indicates that the permission set includes the permission to perform the operation of updating the label corresponding to the label to be called.
[0146] In other embodiments of this application, the processing module 1543 is further configured to generate at least one authorization information at a preset rate; if the available storage space of the distributed cache pool meets the authorization information caching conditions, store the at least one authorization information in the distributed cache pool; retrieve authorization information for the request information from the distributed cache pool to obtain a retrieval result; if the retrieval result indicates that the request information has retrieved authorization information, verify the request information.
[0147] In other embodiments of this application, the processing module 1543 is further configured to generate an operation record of the caller managing the user profile based on the operation time of the user profile management, wherein the operation record includes the account identifier, user identifier, operation type, tag identifier to be called, system identifier of the caller, product identifier of the caller associated with the user identifier, and operation time.
[0148] In other embodiments of this application, the processing module 1543 is further configured to: search for the existence of a configuration value corresponding to the account identifier using the account identifier as the key; perform a validity check on the account identifier based on the search result; perform a format check on the user identifier; and perform an association check between the user identifier and the product identifier of the caller; perform a validity check on the tag identifier to be called; and perform an executable check on the operation type; if the validity check of the account identifier, the format check and association check of the user identifier, the validity check of the tag identifier to be called, and the executable check of the operation type are all passed, then the verification of the request information is determined to be successful.
[0149] This application provides a storage medium storing executable instructions. When these executable instructions are executed by a processor, they cause the processor to perform the method provided in this application, for example... Figures 2-3 , Figures 5-8 The method shown.
[0150] In some embodiments, the storage medium may be a computer-readable storage medium, such as a ferromagnetic random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic surface memory, optical disc, or a compact disk-read-only memory (CD-ROM); or it may be a device that includes one or any combination of the above-mentioned memories.
[0151] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0152] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file containing other programs or data, for example, in one or more scripts within a Hyper Text Markup Language (HTL) document, in a single file dedicated to the program in question, or in multiple co-located files (e.g., files storing one or more modules, subroutines, or code sections). As an example, executable instructions may be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.
[0153] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.
Claims
1. An information management method, characterized in that, include: The system receives request information sent by the caller, wherein the request information includes the caller's account identifier, user identifier, tag identifier to be invoked, and operation type for the tag corresponding to the tag identifier to be invoked; the user identifier is the identifier possessed by the user to whom the caller requests to perform tag management. The system searches for the existence of a configuration value corresponding to the account identifier using the account identifier as the key, and performs a validity check on the account identifier based on the search result; it performs a format check on the user identifier, and a correlation check on the user identifier and the product identifier of the caller; it performs a validity check on the tag identifier to be called; it performs an executability check on the operation type; if the validity check of the account identifier, the format check and the correlation check of the user identifier, the validity check of the tag identifier to be called, and the executability check of the operation type pass, then the verification of the request information is deemed successful. If the request information is verified, the configuration value corresponding to the account identifier is found using the account identifier as the key. The configuration value corresponding to the account identifier represents the set of permissions for the tags that the account identifier can operate. Based on the permission set, the permission of the caller to execute the operation type corresponding to the tag to be invoked is verified to obtain the permission verification result; the permission verification result includes the permission of the caller to execute the operation type corresponding to the tag to be invoked, or the permission of the caller not to execute the operation type corresponding to the tag to be invoked. Based on the permission verification result, the user profile of the user identifier associated with the tag identifier to be invoked is managed.
2. The method according to claim 1, characterized in that, The operation type includes querying tags, and managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result, including: Based on the permission set, a list of tag identifiers for tags for which the caller can perform the operation of querying tags is determined, wherein the reference tags corresponding to the reference tag identifiers in the tag identifier list are the tags for which the caller can perform the operation of querying tags; When the permission verification result indicates that the tag identifier to be invoked exists in the reference tag identifiers included in the tag identifier list, a sublist of tag identifiers including the tag identifier to be invoked is filtered out from the tag identifier list; Obtain the reference tags corresponding to all the tag identifiers to be called in the tag identifier sublist, and filter out the tags included in the user profile associated with the user identifier from all the reference tags.
3. The method according to claim 2, characterized in that, The method further includes: When the permission verification result indicates that the tag to be called does not exist in the reference tag tags included in the tag tag list, a prompt message is generated to indicate that the caller's permissions are restricted, and the prompt message is output.
4. The method according to claim 1, characterized in that, The operation type includes updating tags, and managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result, including: When the permission verification result indicates that the permission set includes the permission to perform the operation of updating the tag corresponding to the tag identifier to be invoked, the tag corresponding to the tag identifier to be invoked is added or deleted in the user profile of the user identifier to obtain the updated user profile.
5. The method according to claim 1, characterized in that, Before receiving the request information sent by the caller, the method includes: At least one authorization message is generated at a preset rate; If the available storage space of the distributed cache pool meets the caching conditions for authorization information, the at least one piece of authorization information is stored in the distributed cache pool; After receiving the request information sent by the caller, the method further includes: The authorization information is retrieved from the distributed cache pool for the request information, and the retrieval result is obtained. If the fetch result indicates that the requested information has fetched authorization information, the requested information is verified.
6. The method according to any one of claims 1 to 5, characterized in that, After managing the user profile of the user identifier associated with the tag identifier to be invoked based on the permission verification result, the method includes: Based on the operation time of managing the user profile, an operation record of the caller managing the user profile is generated, as indicated by the account identifier. The operation record includes the account identifier, the user identifier, the operation type, the tag identifier to be invoked, the system identifier of the caller, the product identifier of the caller associated with the user identifier, and the operation time.
7. A management system, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the method according to any one of claims 1 to 6.
8. A storage medium, characterized in that, It stores executable instructions for causing a processor to execute, thereby implementing the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Permission management method and apparatus for user portrait, server, and storage medium
WO2021097717A1