A data authority control method and system
By constructing a multi-level data information tree, the problems of cumbersome data permission configuration and lack of specificity in business data views are solved, realizing personalized business data views for each user and improving data security and configuration efficiency.
Patent Information
- Application Number
- CN202111272410.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-29
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2041-10-29
AI Technical Summary
Existing technologies suffer from cumbersome data permission configuration, inaccurate permission personnel table configuration, and a lack of targeted business data views, resulting in insufficient data security.
By obtaining user information, filtering parent plan codes, acquiring user permissions, and constructing a multi-level data information tree, a personalized business data view is formed, improving the targeting of the data view.
It simplifies data permission configuration, enables separate configuration of permission personnel tables, and improves the relevance of business data views and data security.
Smart Images

Figure CN113971269B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automatic programming technology, specifically to a data access control method and system. Background Technology
[0002] In the software industry, whether traditional or internet-based, methods for controlling business data access are often involved, especially in management projects. Precise matching of user permissions is crucial to ensure data security and flexible control. Without proper business data access control, inexperienced staff may alter settings or perform incorrect operations. Furthermore, even using keys and passwords presents security risks, such as information leakage due to lost keys or forgotten passwords. Adopting data access control allows for permission settings based on company regulations, tiered authorization of personnel according to certain standards, and ensures data security.
[0003] However, in the process of implementing the inventive technical solution in the embodiments of this application, the inventors of this application discovered that the above-mentioned technology has at least the following technical problems:
[0004] There are issues such as cumbersome data permission configuration, inaccurate configuration of the permission personnel table, and a lack of targeted business data views. Summary of the Invention
[0005] This application provides a data access control method and system that solves the technical problems in existing technologies, such as cumbersome data access configuration and access personnel table configuration in specific scenarios, and a lack of targeted business data views. It simplifies data access configuration and allows for separate configuration of the access personnel table, creating personalized business data views and improving the targeting effectiveness of the business data views.
[0006] In view of the above problems, this application provides a data access control method and system.
[0007] In a first aspect, embodiments of this application provide a data access control method, wherein the method includes: obtaining user information; obtaining user plan information based on the user information; filtering the user plan information to obtain a parent plan code; obtaining user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower-level children; obtaining multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; constructing a data information tree based on the multi-level data information, and feeding the data information tree back to the user information.
[0008] On the other hand, embodiments of this application provide a data access control system, wherein the system includes: a first obtaining unit, the first obtaining unit being used to obtain user information; a second obtaining unit, the second obtaining unit being used to obtain user plan information based on the user information; a third obtaining unit, the third obtaining unit being used to filter the user plan information to obtain a parent plan code; a fourth obtaining unit, the fourth obtaining unit being used to obtain user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower-level children; a fifth obtaining unit, the fifth obtaining unit being used to obtain multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; and a first constructing unit, the first constructing unit being used to construct a data information tree based on the multi-level data information, and to feed the data information tree back to the user information.
[0009] Thirdly, embodiments of this application provide a data access control system, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method described in any of the first aspects.
[0010] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0011] By employing the following technical solution: obtaining user information; obtaining user plan information based on the user information; filtering the user plan information to obtain parent plan codes; obtaining user permissions based on the parent plan codes, wherein the user permissions correspond to the parent plan codes and include multi-level data permissions of the parent and its lower-level children; obtaining multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; constructing a data information tree based on the multi-level data information, and feeding the data information tree back to the user information, this application embodiment provides a data permission control method and system, achieving the technical effect of simplifying data permission configuration and configuring permission personnel tables separately, forming a personalized business data view, and improving the targeting of the business data view.
[0012] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0013] Figure 1This is a flowchart illustrating a data access control method according to an embodiment of this application;
[0014] Figure 2 This is a schematic diagram illustrating the process of cyclically filtering plan relationship information in a data access control method according to an embodiment of this application.
[0015] Figure 3 This is a schematic diagram illustrating the process of obtaining multi-level data information using a data access control method according to an embodiment of this application.
[0016] Figure 4 This is a schematic diagram of the process of obtaining Nth sub-level data information in a data access control method according to an embodiment of this application;
[0017] Figure 5 This is a schematic diagram illustrating the process of constructing a data information tree in a data access control method according to an embodiment of this application;
[0018] Figure 6 This is a schematic diagram of the structure of a data access control system according to an embodiment of this application;
[0019] Figure 7 This is a schematic diagram of the structure of an exemplary electronic device according to an embodiment of this application.
[0020] Explanation of reference numerals in the attached drawings: First obtaining unit 11, Second obtaining unit 12, Third obtaining unit 13, Fourth obtaining unit 14, Fifth obtaining unit 15, First building unit 16, Electronic device 300, Memory 301, Processor 302, Communication interface 303, Bus architecture 304. Detailed Implementation
[0021] This application provides a data access control method and system that solves the technical problems in existing technologies, such as cumbersome data access configuration and access personnel table configuration in specific scenarios, and a lack of targeted business data views. It simplifies data access configuration and allows for separate configuration of the access personnel table, creating personalized business data views and improving the targeting effectiveness of the business data views.
[0022] Application Overview
[0023] In the software industry, whether traditional or internet-based, methods for controlling business data permissions are often involved, especially in management projects. Precise matching of user permissions is crucial to ensure data security and flexible control. Without proper business data permission control, inexperienced staff may alter settings or perform incorrect operations. Furthermore, even using keys and passwords presents security risks, such as information leakage due to lost keys or forgotten passwords. Data access control allows for permission settings based on company regulations, tiered authorization of personnel according to certain standards, ensuring data security. However, existing technologies suffer from cumbersome data permission configuration and access control table configuration in specific scenarios, and a lack of targeted technical solutions for business data views.
[0024] To address the aforementioned technical problems, the overall approach of the technical solution provided in this application is as follows:
[0025] This application provides a data access control method, comprising: obtaining user information; obtaining user plan information based on the user information; filtering the user plan information to obtain a parent plan code; obtaining user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower-level children; obtaining multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; constructing a data information tree based on the multi-level data information, and feeding the data information tree back to the user information.
[0026] After introducing the basic principles of this application, various non-limiting embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0027] Example 1
[0028] like Figure 1 As shown in the figure, this application provides a data access control method, wherein the method includes:
[0029] S100: Obtain user information;
[0030] S200: Obtain user plan information based on the user information;
[0031] S300: Filter the user plan information to obtain the parent plan code;
[0032] Specifically, in enterprise management systems, there is often access control where users can generally only view data from their own department, and the system can specify which departments' data a user can view. This type of access control is generally called data access control. The user information includes the user's department, job level, and corresponding code. The user's plan information includes the codes corresponding to all project plans that the user is responsible for or participates in. Due to the differences in user information, user plans can be divided into several levels. The higher the user's job level, the more complex and numerous the user plan levels. The highest-level plan code is called the parent plan code, and the lower levels are child plan codes. By filtering the user plan information, the parent plan code is obtained. The parent level can control all data at the descendant level, thus simplifying data access control configuration and laying the foundation for subsequent separate configuration of the access personnel table.
[0033] S400: Obtain user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower child levels;
[0034] S500: Based on the user permissions, obtain multi-level data information, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions;
[0035] S600: Construct a data information tree based on the multi-level data information, and feed the data information tree back to the user information.
[0036] Specifically, there is a certain correspondence between the user permissions and the parent plan code. Based on the data information of the parent plan code, the user's corresponding permissions, including accessing, processing, and using the parent plan's data information, can be obtained. Based on user permissions, multi-level data information, such as parent and child levels, is obtained. Users have the right to process data at multiple levels below the parent level, and these multi-level data information correspond one-to-one with their multi-level data permissions. By constructing a data information tree, multi-level data information is presented and fed back to the user information. Different users have different data information trees, thereby enabling individual configuration of the permission user table, forming a personalized business data view, and improving the targeted technical effect of the business data view.
[0037] Furthermore, such as Figure 2 As shown, when the user plan information consists of multiple plans, step S200 further includes:
[0038] S210: Obtain plan relationship information based on the user plan information;
[0039] S220: Perform cyclic filtering on the plan relationship information to obtain the parent information set;
[0040] S230: Obtain user permissions based on the parent information set.
[0041] Specifically, when the user's plan information comprises multiple plans—that is, when the user is responsible for multiple plans within a system—the plan relationship information is obtained, which represents a hierarchical relationship among the plans. In this case, the user has multiple project plan codes. By iteratively filtering the plan relationship information, a set of parent information for multiple plans is obtained, containing the parent code for each plan. Since the user's permissions correspond to the parent plan codes, all of the user's plan permissions can be obtained. This provides the user with complete permission data.
[0042] Furthermore, when the user plan information is a single plan, step S200 further includes:
[0043] S240: Obtain the user permissions based on the user plan information.
[0044] Specifically, when a user is only responsible for a single plan, the code of that user plan is obtained, and the data permissions for that single plan are output according to computer coding rules. Furthermore, the corresponding user data view is output.
[0045] Furthermore, such as Figure 4 As shown, step S500, which involves obtaining multi-level data information based on the user permissions, further includes:
[0046] S510: Obtain the first sub-level plan code based on the user permissions;
[0047] S520: Establish a first connection based on the parent plan code and the first child plan code;
[0048] S530: Based on the first connection, obtain the first child data information according to the parent plan code;
[0049] S540: Obtain parent data information based on the parent plan code;
[0050] S550: Obtain the multi-level data information based on the parent data information and the first child data information.
[0051] Specifically, due to the complexity and large volume of user plan data, the data is hierarchically divided. Based on user permissions, the first child-level plan code is obtained. The first child-level plan is a lower-level child of its parent, and a connection is established between them, known as the first connection. Based on this first connection, the first child-level data information is obtained according to the parent plan code. This first child-level data information is a portion of the parent data information, and it is connected to its lower-level child through a specific connection relationship. According to the parent plan code, the parent data information, i.e., the entire user plan data, is obtained through encoding rules. Based on the parent data information, the first child-level data information, and the connection methods between levels, the multi-level data information is obtained. Each multi-level data information corresponds one-to-one with a multi-level data permission, thus granting the user multi-level data permissions. In this hierarchical scenario, each level has a corresponding responsible person. Users are only allowed to view and operate the level they are responsible for and its sub-levels, thereby avoiding role configuration and enabling individual configuration of permissions for specific personnel.
[0052] Furthermore, such as Figure 5 As shown, embodiments of this application also include:
[0053] S551: Obtain a second sub-level plan code based on the first sub-level plan code, wherein the second sub-level plan code is a lower-level sub-level of the first sub-level plan code;
[0054] S552: Establish a second connection based on the first sub-level plan code and the second sub-level plan code;
[0055] S553: Based on the second connection, obtain the second sub-level data information according to the first sub-level plan code; and so on, repeatedly obtain the third sub-level data information until the Nth sub-level data information is obtained, where N is a natural number;
[0056] S554: Obtain the multi-level data information based on the parent data information, the first child data information, and up to the Nth child data information.
[0057] Specifically, the multi-level data information is connected through planning codes between adjacent levels. Data information for the current level is obtained based on the connections between adjacent levels and the planning code of the previous level, and so on, resulting in N child-level data information. This multi-level data information consists of parent data information, first child-level data information, second child-level data information, third child-level data information, ..., N-1th child-level data information, and Nth child-level data information, where N is a natural number determined by the user's planning information. Adjacent levels are connected, and each level's data is encompassed by the level above it. As the number of levels increases, the amount of data at each level gradually decreases. This multi-level data information structure uses hierarchical coding data to control user data permissions. This ensures that each user's responsible level or data is initialized correctly, and that data permission control is uniformly performed using a single data filtering engine, simplifying data permission configuration.
[0058] Furthermore, such as Figure 6 As shown, the step S554 of constructing a data information tree based on the multi-level data information further includes:
[0059] S5541: Obtain the parent data information and the first child data information based on the multi-level data information;
[0060] S5542: Based on the first connection, construct a first-level information tree according to the parent data information and the first child data information;
[0061] S5543: Obtain the second sub-level data information based on the multi-layer data information;
[0062] S5544: Based on the second connection, construct a secondary information tree according to the first sub-level data information and the second sub-level data information; and so on, based on the Nth connection, construct an Nth-level information tree according to the (N-1)th sub-level data information and the Nth sub-level data information;
[0063] 5545: Construct the data information tree based on the first-level information tree, the second-level information tree, and so on up to the Nth-level information tree.
[0064] Specifically, based on the first connection, the parent data information, and the first child data information, a first-level information tree is constructed. This first-level information tree corresponds one-to-one with the first connection, the parent data information, and the first child data information. Based on the second connection, a second-level information tree is constructed based on the first child data information and the second child data information. This process continues until an N-level information tree, or data information tree, is constructed. This tree corresponds to all data information at the current (parent) level and below (child) levels for which the user has permissions, and is then fed back to the user. To further improve the security of information data storage, this application embodiment utilizes blockchain for distributed storage of multi-level data. Blockchain technology, also known as distributed ledger technology, is an emerging technology where several computing devices jointly participate in "accounting" and maintain a complete distributed database. Due to its decentralized, transparent, and database recording capabilities, and the ability for each computing device to quickly synchronize data, blockchain technology has been widely applied in numerous fields. Based on the parent data information, a first verification code is generated. Based on the first child data information and the first verification code, a second verification code is generated. Based on the second child data information and the second verification code, a third verification code is generated, and so on. Based on the (N-1)th child data information and the (N-1)th verification code, an Nth verification code is generated. All connections, all levels of data information, and the information tree are copied and stored on M electronic devices, where M is a natural number greater than 1. When the multi-layer data information needs to be accessed, each subsequent node receives the data stored by the previous node, verifies it through a consensus mechanism, and then saves it. A hash function is used to concatenate each storage unit, making the multi-layer data information less prone to loss and corruption. The multi-layer data information is encrypted using blockchain logic, ensuring its security. Furthermore, based on the first-level information tree, the second-level information tree, and so on up to the Nth-level information tree, the data information tree is constructed, enabling the formation of personalized business data views and improving the targeting effectiveness of the business data view.
[0065] In summary, the data access control method and system provided in this application have the following technical effects:
[0066] 1. By employing the following technical solution: obtaining user information; obtaining user plan information based on the user information; filtering the user plan information to obtain parent plan codes; obtaining user permissions based on the parent plan codes, wherein the user permissions correspond to the parent plan codes and include multi-level data permissions of the parent and its lower-level children; obtaining multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; constructing a data information tree based on the multi-level data information, and feeding the data information tree back to the user information, this application embodiment provides a data permission control method and system, achieving the technical effect of simplifying data permission configuration and configuring permission personnel tables separately, forming a personalized business data view, and improving the targeting of the business data view.
[0067] 2. By adopting the method of constructing a data information tree, it is possible to create a personalized business data view, thereby improving the technical effectiveness of the business data view in terms of targeting.
[0068] Example 2
[0069] Based on the same inventive concept as the data access control method in the foregoing embodiments, such as Figure 6 As shown in the figure, this application embodiment provides a data access control system, wherein the system includes:
[0070] The first obtaining unit 11 is used to obtain user information;
[0071] The second obtaining unit 12 is used to obtain user plan information based on the user information;
[0072] The third obtaining unit 13 is used to filter the user plan information and obtain the parent plan code;
[0073] The fourth obtaining unit 14 is used to obtain user permissions according to the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower child levels.
[0074] The fifth obtaining unit 15 is used to obtain multi-level data information according to the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions;
[0075] The first construction unit 16 is configured to construct a data information tree based on the multi-level data information and feed the data information tree back to the user information.
[0076] Furthermore, the system includes:
[0077] The sixth obtaining unit is used to obtain plan relationship information based on the user plan information;
[0078] The seventh obtaining unit is used to perform cyclic filtering on the plan relationship information to obtain the parent information set;
[0079] The eighth obtaining unit is used to obtain user permissions based on the parent information set.
[0080] Furthermore, the system includes:
[0081] The ninth obtaining unit is used to obtain the user permissions based on the user plan information.
[0082] Furthermore, the system includes:
[0083] The tenth obtaining unit is used to obtain the first sub-level plan code according to the user's permissions;
[0084] The first execution unit is configured to establish a first connection based on the parent plan code and the first child plan code;
[0085] The eleventh obtaining unit is used to obtain first child-level data information based on the first connection and the parent-level plan code;
[0086] The twelfth obtaining unit is used to obtain parent data information based on the parent plan code;
[0087] The thirteenth obtaining unit is used to obtain the multi-level data information based on the parent data information and the first child data information.
[0088] Furthermore, the system includes:
[0089] The fourteenth obtaining unit is used to obtain a second sub-level plan code based on the first sub-level plan code, wherein the second sub-level plan code is a lower sub-level of the first sub-level plan code;
[0090] The second execution unit is configured to establish a second connection based on the first sub-level plan code and the second sub-level plan code.
[0091] The fifteenth obtaining unit is used to obtain second sub-level data information based on the second connection and the first sub-level plan code; and so on to repeatedly obtain third sub-level data information until Nth sub-level data information is obtained, where N is a natural number;
[0092] The sixteenth obtaining unit is used to obtain the multi-level data information based on the parent data information, the first child data information, and up to the Nth child data information.
[0093] Furthermore, the system includes:
[0094] The seventeenth obtaining unit is used to obtain the parent data information and the first child data information based on the multi-level data information.
[0095] The second construction unit is used to construct a first-level information tree based on the first connection, according to the parent data information and the first child data information;
[0096] The eighteenth obtaining unit is used to obtain the second sub-level data information based on the multi-layer data information;
[0097] The third construction unit is used to construct a second-level information tree based on the second connection and according to the first sub-level data information and the second sub-level data information; and so on, based on the Nth connection, constructing an N-level information tree according to the (N-1)th sub-level data information and the Nth sub-level data information;
[0098] The fourth construction unit is used to construct the data information tree based on the first-level information tree, the second-level information tree, and so on up to the N-level information tree.
[0099] Exemplary electronic devices
[0100] The following is for reference. Figure 7 To describe the electronic device in the embodiments of this application,
[0101] Based on the same inventive concept as the data access control method in the foregoing embodiments, this application also provides a data access control system, including: a processor coupled to a memory for storing a program, wherein when the program is executed by the processor, the system performs the method described in any of the first aspects.
[0102] The electronic device 300 includes a processor 302, a communication interface 303, and a memory 301. Optionally, the electronic device 300 may also include a bus architecture 304. The communication interface 303, processor 302, and memory 301 can be interconnected via the bus architecture 304; the bus architecture 304 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus architecture 304 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0103] Processor 302 may be a CPU, microprocessor, ASIC, or one or more integrated circuits used to control the execution of programs according to the present application.
[0104] Communication interface 303 is used in any transceiver system for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), wired access network, etc.
[0105] Memory 301 can be ROM or other types of static storage devices capable of storing static information and instructions, RAM or other types of dynamic storage devices capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory can exist independently and be connected to the processor via bus architecture 304. Memory can also be integrated with the processor.
[0106] The memory 301 stores computer execution instructions for implementing the scheme of this application, and the processor 302 controls the execution. The processor 302 executes the computer execution instructions stored in the memory 301, thereby implementing the data access control method provided in the above embodiments of this application.
[0107] Optionally, the computer execution instructions in the embodiments of this application may also be referred to as application code, and the embodiments of this application do not specifically limit this.
[0108] This application provides a data access control method, comprising: obtaining user information; obtaining user plan information based on the user information; filtering the user plan information to obtain a parent plan code; obtaining user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower-level children; obtaining multi-level data information based on the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; constructing a data information tree based on the multi-level data information, and feeding the data information tree back to the user information.
[0109] Those skilled in the art will understand that the various numerical designations, such as "first" and "second," used in this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application, nor do they indicate a sequential order. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one" refers to one or more. "At least two" refers to two or more. "At least one," "any one," or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0110] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable system. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0111] The various illustrative logic units and circuits described in the embodiments of this application can be implemented or operate the described functions using a general-purpose processor, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic system, discrete gate or transistor logic, discrete hardware components, or any combination thereof. The general-purpose processor can be a microprocessor; alternatively, it can also be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented using a combination of computing systems, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.
[0112] The steps of the methods or algorithms described in the embodiments of this application can be directly embedded in hardware, software units executed by a processor, or a combination of both. The software units can be stored in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and storage medium can be disposed in an ASIC, which can be disposed in a terminal. Optionally, the processor and storage medium can also be disposed in different components of the terminal. These computer program instructions can also be loaded onto a computer or other programmable data processing device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0113] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Thus, if such modifications and modifications fall within the scope of the claims and their equivalents, this application intends to include such modifications and modifications.
Claims
1. A data access control method, wherein, The method includes: Obtain user information; Based on the user information, obtain the user plan information; The user plan information is filtered to obtain the parent plan code; User permissions are obtained based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower child levels, and there is a correspondence between the user permissions and the parent plan code; Based on the user permissions, multi-level data information is obtained, and the multi-level data information corresponds one-to-one with the multi-level data permissions; Based on the multi-level data information, a data information tree is constructed, and the data information tree is fed back to the user information. Different users have different data information trees, forming a targeted business data view. The step of obtaining multi-level data information based on the user permissions includes: Based on the user permissions, obtain the first sub-level plan code; Establish a first connection based on the parent plan code and the first child plan code; Based on the first connection, according to the parent plan code, the first child data information is obtained. The first child data information is part of the parent data information. The first child and the lower child are connected in a certain connection relationship. Based on the parent plan code, obtain the parent data information, which is the complete data of the user plan; Based on the parent data information, the first child data information, and the connection method between levels, the multi-level data information is obtained, and the multi-level data information corresponds one-to-one with the multi-level data permissions.
2. The method as described in claim 1, wherein, When the user plan information comprises multiple plans, the method includes: Based on the user's plan information, plan relationship information is obtained; The plan relationship information is filtered cyclically to obtain the parent information set; Based on the parent information set, obtain user permissions.
3. The method as described in claim 1, wherein, When the user plan information is a single plan, the method includes: Based on the user plan information, obtain the user permissions.
4. The method of claim 1, wherein, The method includes: Based on the first sub-level plan code, a second sub-level plan code is obtained, wherein the second sub-level plan code is a lower-level sub-level of the first sub-level plan code; Establish a second connection based on the first sub-level plan code and the second sub-level plan code; Based on the second connection, the second sub-level data information is obtained according to the first sub-level plan code; the third sub-level data information is obtained repeatedly in this way until the Nth sub-level data information is obtained, where N is a natural number; The multi-level data information is obtained based on the parent data information, the first child data information, and up to the Nth child data information.
5. The method of claim 4, wherein, The step of constructing a data information tree based on the multi-level data information includes: Based on the multi-level data information, the parent level data information and the first child level data information are obtained; Based on the first connection, a first-level information tree is constructed according to the parent data information and the first child data information; Based on the multi-level data information, the second sub-level data information is obtained; Based on the second connection, a second-level information tree is constructed according to the first sub-level data information and the second sub-level data information; and so on, based on the Nth connection, an N-level information tree is constructed according to the (N-1)th sub-level data information and the Nth sub-level data information. The data information tree is constructed based on the first-level information tree, the second-level information tree, and so on up to the Nth-level information tree.
6. A data access control system, wherein, The system includes: A first obtaining unit, the first obtaining unit being used to obtain user information; The second obtaining unit is used to obtain user plan information based on the user information; The third obtaining unit is used to filter the user plan information and obtain the parent plan code; The fourth obtaining unit is used to obtain user permissions based on the parent plan code, wherein the user permissions correspond to the parent plan code, and the user permissions include multi-level data permissions of the parent and its lower child levels, and the user permissions have a corresponding relationship with the parent plan code; The fifth obtaining unit is used to obtain multi-level data information according to the user permissions, wherein the multi-level data information corresponds one-to-one with the multi-level data permissions; The first construction unit is used to construct a data information tree based on the multi-level data information and feed the data information tree back to the user information. Different users have different data information trees, forming a targeted business data view. The system includes: The tenth obtaining unit is used to obtain the first sub-level plan code according to the user's permissions; The first execution unit is configured to establish a first connection based on the parent plan code and the first child plan code; The eleventh obtaining unit is used to obtain first child data information based on the first connection and according to the parent plan code. The first child data information is part of the parent data information, and the first child and the lower child are connected in a certain connection relationship. The twelfth obtaining unit is used to obtain parent data information based on the parent plan code, wherein the parent data information is the full data of the user plan; The thirteenth obtaining unit is used to obtain the multi-level data information based on the parent data information, the first child data information, and the connection method between levels. The multi-level data information corresponds one-to-one with the multi-level data permissions.
7. A data access control system, comprising: A processor coupled to a memory for storing a program that, when executed by the processor, causes the system to perform the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Project plan permission control method based on classification
CN112465477A