Data processing method, device, electronic device, medium and product

Through the pre-built permission relationship map, the problem of low authority control efficiency in the existing technology is solved, and efficient authority control and independent authorization between the target access object and business data is achieved.

CN114065254BActive Publication Date: 2025-05-13BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111394869.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-23
Publication Date
2025-05-13
Estimated Expiration
2041-11-23

AI Technical Summary

Technical Problem

The existing permission control mechanism is implemented through a role-based permission access control model, resulting in the correspondence between users and roles, roles and authorized data being many-to-many, which requires manual configuration, resulting in low data processing efficiency.

Method used

Through the pre-constructed permission relationship map, it is determined whether there is an accessible relationship node between the target access object and the target service data. Based on the graph, the target access request is processed to realize the access permission control of the target service data by the target access object.

Benefits of technology

It improves the efficiency of data processing, realizes independent authorization of each access object, flexibly configures the business data of each independent access object, and simplifies the manual configuration process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114065254B_ABST
    Figure CN114065254B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a data processing method, device, electronic device, medium and product, the method comprising: in response to a target access request, obtaining target business data to be accessed by a target access object; based on a pre-constructed permission relationship graph, determining whether there is a reachable relationship node between the target access object and the target business data, the permission relationship graph includes at least one reachable relationship node between a candidate access object and the candidate business data, the candidate business data being the business data that has been authorized by the candidate access object; after determining that there is a reachable relationship node between the target access object and the target business data, processing the target access request based on the target business data. Thus, the business data of each independent access object is flexibly configured based on the permission relationship graph, the target access object's access rights to the target business data are determined through the permission relationship graph, independent authorization of each access object is achieved, and data processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data processing technology, and in particular to a data processing method, device, electronic device, medium and product. Background Art

[0002] Permission control is generally based on security rules or security policies set by the system. Under the set permission control, users can access and can only access the resource data for which they are authorized.

[0003] The current permission control mechanism is mainly implemented through the role-based access control (RBAC) model, that is, users and permissions are indirectly connected through roles. When a user needs to access certain data, the user's access request is processed through the relationship with the role.

[0004] However, the correspondence between users and roles, and between roles and authorization data is many-to-many, and requires manual configuration, resulting in low data processing efficiency. Summary of the invention

[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a data processing method, device, electronic device, medium and product.

[0006] In a first aspect, the present disclosure provides a data processing method, comprising:

[0007] In response to the target access request, obtaining the target business data to be accessed by the target access object;

[0008] Based on a pre-constructed permission relationship graph, determining whether there is a reachable relationship node between the target access object and the target business data, wherein the permission relationship graph includes at least one reachable relationship node between a candidate access object and candidate business data, and the candidate business data is business data that has been authorized by the candidate access object;

[0009] After determining that there is a reachable relationship node between the target access object and the target business data, the target access request is processed based on the target business data.

[0010] In a possible design, before determining whether there is a reachable relationship node between the target access object and the target business data based on the pre-built permission relationship graph, the method further includes:

[0011] Acquire a business information table and an object information table, wherein the business information table is used to describe access objects and business data associated with the access objects, and the object information table is used to describe business relationships between access objects;

[0012] Based on the business information table and the object information table, a permission relationship graph is constructed.

[0013] In a possible design, constructing a permission relationship graph based on the business information table and the object information table includes:

[0014] Establishing relationship nodes of the authority relationship graph based on the business information table;

[0015] Establishing a connection edge between each relationship node based on the object information table;

[0016] Based on each relationship node and the connection edges between each relationship node, a permission relationship graph is determined.

[0017] In a possible design, establishing a connection edge between each relationship node based on the object information table includes:

[0018] Assign a business role to each access object and establish a connection edge between each business role and the access object;

[0019] Based on the approval process of business data, establish a connection edge between each access object and business data.

[0020] In a possible design, determining the permission relationship graph based on each relationship node and the connection edge between each relationship node includes:

[0021] Establishing a permission relationship graph based on each relationship node and each connection edge between the relationship nodes;

[0022] The permission relationship graph is updated according to the point-to-point authorization information associated with each business data, wherein the point-to-point authorization information is used to describe the authorization relationship between the business data and the access object.

[0023] In one possible design, it also includes:

[0024] In response to the permission change event, determine the relationship node where the change subject is located;

[0025] Based on the permission change event, the relationship node is modified, or the connection edge where the relationship node is located is modified.

[0026] In one possible design, it also includes:

[0027] When it is determined that a target relationship node in the permission relationship graph meets a preset trigger condition, the target relationship node is deleted, or a connection edge where the target relationship node is located is deleted, and the target relationship node includes an access object and / or business data;

[0028] The preset trigger condition includes at least one of the following: not exceeding a storage time threshold and not exceeding a connection access times threshold.

[0029] In one possible design, it also includes:

[0030] In response to the first query request, searching the permission relationship graph for a first relationship node where the first access object is located;

[0031] Searching the permission relationship graph for a second relationship node that is reachable from the first relationship node, where the second relationship node corresponds to a second business data;

[0032] Respond to the first query request based on the second business data.

[0033] In a possible design, the target access request includes: at least one of data to be added, data to be modified, and data to be deleted;

[0034] The processing of the target access request based on the target service data includes:

[0035] Based on the data to be added included in the target access request, performing an adding operation on the target service data;

[0036] Alternatively, based on the data to be modified included in the target access request, a modification operation is performed on the target business data;

[0037] Alternatively, based on the data to be deleted included in the target access request, a deletion operation is performed on the target business data.

[0038] In a second aspect, the present disclosure provides a data processing device, including:

[0039] An acquisition module, used for acquiring target business data to be accessed by a target access object in response to a target access request;

[0040] A determination module, configured to determine whether there is a reachable relationship node between the target access object and the target business data based on a pre-constructed permission relationship graph, wherein the permission relationship graph includes at least one reachable relationship node between a candidate access object and candidate business data, and the candidate business data is business data that has been authorized by the candidate access object;

[0041] A processing module is used to process the target access request based on the target business data after determining that there is a reachable relationship node between the target access object and the target business data.

[0042] In one possible design, it also includes: building blocks;

[0043] The acquisition module is further used to acquire a business information table and an object information table, wherein the business information table is used to describe the access object and the business data associated with the access object, and the object information table is used to describe the business relationship between the access objects;

[0044] A construction module is used to construct a permission relationship map based on the business information table and the object information table.

[0045] In a possible design, the building module includes: a first building unit, a second building unit, and a determining unit;

[0046] A first establishing unit, configured to establish a relationship node of a permission relationship graph based on the business information table;

[0047] A second establishing unit, configured to establish a connection edge between each relationship node based on the object information table;

[0048] The determination unit is used to determine the permission relationship graph based on each relationship node and the connection edge between each relationship node.

[0049] In a possible design, the second establishing unit is specifically configured to:

[0050] Assign a business role to each access object and establish a connection edge between each business role and the access object;

[0051] Based on the approval process of business data, establish a connection edge between each access object and business data.

[0052] In one possible design, a unit is determined, specifically for:

[0053] Establishing a permission relationship graph based on each relationship node and each connection edge between the relationship nodes;

[0054] The permission relationship graph is updated according to the point-to-point authorization information associated with each business data, wherein the point-to-point authorization information is used to describe the authorization relationship between the business data and the access object.

[0055] In a possible design, it further includes: a modification module;

[0056] The determination module is further used to determine the relationship node where the change subject is located in response to the permission change event;

[0057] A modification module is used to modify the relationship node based on the permission change event, or to modify the connection edge where the relationship node is located.

[0058] In a possible design, the method further includes: deleting a module;

[0059] A deletion module is used to delete the target relationship node in the permission relationship graph when it is determined that the target relationship node meets the preset trigger condition, or delete the connection edge where the target relationship node is located, and the target relationship node includes the access object and / or business data;

[0060] The preset trigger condition includes at least one of the following: not exceeding a storage time threshold and not exceeding a connection access times threshold.

[0061] In a possible design, it further includes: a search module;

[0062] A search module, configured to search, in response to a first query request, a first relationship node where a first access object is located from a permission relationship graph;

[0063] The search module is further used to search the permission relationship graph for a second relationship node that is reachable from the first relationship node, where the second relationship node corresponds to a second business data;

[0064] A response module is used to respond to the first query request based on the second business data.

[0065] In a possible design, the target access request includes: at least one of data to be added, data to be modified, and data to be deleted;

[0066] Processing module, specifically used for:

[0067] Based on the data to be added included in the target access request, performing an adding operation on the target service data;

[0068] Alternatively, based on the data to be modified included in the target access request, a modification operation is performed on the target business data;

[0069] Alternatively, based on the data to be deleted included in the target access request, a deletion operation is performed on the target business data.

[0070] In a third aspect, the present disclosure provides an electronic device comprising: a memory and a processor; the memory is used to store program instructions; the processor is used to call the program instructions in the memory so that the electronic device executes the data processing method in the first aspect and any possible design of the first aspect.

[0071] In a fourth aspect, the present disclosure provides a computer storage medium, including computer instructions, which, when executed on an electronic device, enables the electronic device to execute the data processing method in the first aspect and any possible design of the first aspect.

[0072] In a fifth aspect, the present disclosure provides a computer program product. When the computer program product runs on a computer, it enables the computer to execute the data processing method in the first aspect and any possible design of the first aspect.

[0073] The data processing method, device, electronic device, medium and product provided by the embodiments of the present disclosure realize data processing through a pre-established permission relationship graph. After receiving a target access request, the target business data to be accessed by the target access object is obtained, and based on the multiple relationship nodes included in the permission relationship graph, it is found whether there is a reachable relationship node between the target access object and the target business data, so as to determine the direct or indirect relationship connection edge between the target access object and the target business data, thereby determining the access rights of the target access object to the target business data. The permission relationship graph can flexibly configure the business data of each independent access object, realize independent authorization of each access object, and improve data processing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0075] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0076] Figure 1 A flowchart of a data processing method provided by an embodiment of the present disclosure;

[0077] Figure 2 A flowchart of another data processing method provided by an embodiment of the present disclosure;

[0078] Figure 3 A schematic diagram of the architecture of a permission system provided in an embodiment of the present disclosure;

[0079] Figure 4 A schematic diagram of the structure of a permission relationship map provided in an embodiment of the present disclosure;

[0080] Figure 5 A schematic diagram of the structure of another permission relationship map provided in an embodiment of the present disclosure;

[0081] Figure 6 A schematic diagram of the structure of a data processing device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0082] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0083] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0084] Exemplarily, the present disclosure provides a data processing method, device, electronic device, medium and product, which realize data processing through a pre-established permission relationship graph, obtain the target business data to be accessed by the target access object after receiving the target access request, and search whether there are reachable relationship nodes between the target access object and the target business data based on the multiple relationship nodes included in the permission relationship graph, so as to determine the direct or indirect relationship connection edge between the target access object and the target business data, thereby determining the access rights of the target access object to the target business data. The permission relationship graph can flexibly configure the business data of each independent access object, realize independent authorization of each access object, and improve data processing efficiency.

[0085] The data processing method of the present disclosure is executed by a client installed in an electronic device. The electronic device may be a tablet computer, a mobile phone, a wearable device, an in-vehicle device, an augmented reality (AR) / virtual reality (VR) device, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), a smart TV, a smart screen, a high-definition TV, a 4K TV, a smart speaker, a smart projector, and the like. The present disclosure does not impose any restrictions on the specific types of electronic devices.

[0086] The present disclosure does not limit the type of operating system of the electronic device, for example, Android system, Linux system, Windows system, iOS system, etc.

[0087] Please refer to Figure 1 As shown in the example.

[0088] Figure 1 A flowchart of a data processing method provided by an embodiment of the present disclosure is shown in FIG. Figure 1 As shown, the data processing method provided by the present disclosure may include:

[0089] S110 . In response to the target access request, obtain target business data to be accessed by the target access object.

[0090] Among them, a contract life cycle management system can be deployed in electronic devices. In this system, managers can pre-set some configuration rules, such as pre-setting user roles and permissions for accessible business data in the management background or configuration center.

[0091] During the circulation of the contract flowchart, changes in the approval node or the setting of the copy node will affect the change of permissions. The disclosed embodiment can effectively and flexibly independently authorize business data permissions for each target access object (such as independent employees and independent users within the company).

[0092] The target access request is an access request sent by a user when the user wants to access certain business data. The target access request may include the identity of the user and the identifier corresponding to the business data to be accessed.

[0093] It should be noted that since different users have different identity permissions, the business data that a user can access is also different. It is crucial to effectively supervise the business data that different users can access based on their identity permissions.

[0094] S120: Based on the pre-built permission relationship graph, determine whether there is a reachable relationship node between the target access object and the target business data.

[0095] The permission relationship graph includes at least one reachable relationship node between the candidate access object and the candidate business data, and the candidate business data is the business data that the candidate access object has authorized.

[0096] Among them, the permission relationship map is constructed in the contract life cycle management system and can describe the relationship between multiple different users and multiple business data.

[0097] It should be noted that one user can access multiple business data, and one business data page can also be accessed by multiple users.

[0098] Among them, the permission relationship graph contains multiple candidate access objects and multiple candidate business data. There will be multiple connected relationship nodes between each candidate access object and the business data that it can access. The relationship node between a candidate access object and a candidate business data can intuitively identify whether the candidate business data can be accessed by the candidate access object.

[0099] For example, the target access object is object A, and the target business data is data D. In the permission relationship graph, if the relationship node where object A is located is directly connected to the relationship node where data D is located, or there is at least one relationship node with a directed connection between the relationship node where object A is located and the relationship node where data D is located, then it indicates that object A has access rights to access data D.

[0100] S130: After determining that there is a reachable relationship node between the target access object and the target business data, process the target access request based on the target business data.

[0101] The target access request may include data operations that the target access object wants to perform on the target business data, such as data query, data modification, data deletion, data addition, etc.

[0102] The target access request may include at least one of data to be added, data to be modified, and data to be deleted.

[0103] Optionally, the target access request is processed based on the target business data, including:

[0104] Based on the data to be added included in the target access request, perform an adding operation on the target business data;

[0105] Alternatively, based on the data to be modified included in the target access request, a modification operation is performed on the target business data;

[0106] Alternatively, based on the data to be deleted included in the target access request, a deletion operation is performed on the target business data.

[0107] In addition, on this basis, based on the data to be added included in the target access request, an addition operation can be performed on the target business data, based on the data to be modified included in the target access request, a modification operation can be performed on the target business data, and based on the data to be deleted included in the target access request, a deletion operation can be performed on the target business data.

[0108] Alternatively, perform at least one of the above operations.

[0109] Therefore, after determining that the target access object has access rights to the target business data, the target access request can be effectively responded to based on the required operation of the target access object.

[0110] At the same time, it provides good performance of adding, deleting and modifying permission subject nodes and business data. In traditional permission control schemes, when a permission subject node or business data is changed, it is necessary to involve changes in multiple tables at the same time. However, in the embodiment of the present disclosure, only a single modification of a relationship node or a connection edge is required.

[0111] In addition, the permission relationship graph provided by the embodiment of the present disclosure can also enable a department or leader in an enterprise-level application to inherit the data and functional permissions owned by their subordinates by setting the relationship type of the connecting edge.

[0112] The data processing method provided by the embodiment of the present disclosure realizes data processing through a pre-established permission relationship graph. After receiving a target access request, the target business data to be accessed by the target access object is obtained, and based on the multiple relationship nodes included in the permission relationship graph, it is found whether there is a reachable relationship node between the target access object and the target business data, so as to determine the direct or indirect relationship connection edge between the target access object and the target business data, thereby determining the access rights of the target access object to the target business data. The permission relationship graph can flexibly configure the business data of each independent access object, realize independent authorization of each access object, and improve data processing efficiency.

[0113] Figure 2 A flowchart of another data processing method provided by an embodiment of the present disclosure. This embodiment is based on the above embodiment. Further, before S120, the method of this embodiment may also include:

[0114] S111. Obtain a business information table and an object information table.

[0115] The business information table can be used to describe the access object and the business data associated with the access object, and the object information table can be used to describe the business relationship between the access objects.

[0116] The business information table may include: all business data that can be accessed by an access object, and / or all access objects that can be accessed by a business data.

[0117] In addition, the business information table may also include: the usage relationship between the access object and the department to which it belongs and the business data, the access relationship / modification relationship between the access object and the department to which it belongs and the business data, etc.

[0118] The object information table may include: the management relationship between the first access object and the second access object, such as the first access object can manage the second access object, and / or the belonging relationship between the first access object / the second access object and the department, such as the first access object / the second access object belongs to an employee in a certain department, etc.

[0119] It should be noted that some of the relationship information in the business information table and the object information table mentioned above can be obtained from a data source (which may be a component in a storage system developed independently) or other sources.

[0120] S112. Construct a permission relationship map based on the business information table and the object information table.

[0121] Among them, based on the business information table and the object information table, each relationship node is constructed, and then based on the authority subject node in the relationship node and the business relationship / management relationship / belonging relationship between each relationship node, a connecting edge composed of the authority subject node and each relationship node is constructed to obtain a permission relationship graph, thereby obtaining a permission relationship graph containing multiple relationship nodes and the relationship between each relationship node.

[0122] It should be noted that the authority subject node may be a relationship node for constructing a business data, and may include an access object or a department to which an access object belongs.

[0123] For example, Figure 3 It is a schematic diagram of the architecture of a permission system.

[0124] Among them, some information tables obtained, such as employee tables, department tables, business data tables and business function tables, can be imported into the storage system. The storage system is a graph database, which can construct permission relationship graph nodes and connection edges, so that permission access can be granted to certain business data in the business system.

[0125] It should be noted that graph databases support directed attribute graph data modeling and some common graph database languages ​​(such as Gremlin). The read and write throughput can be extended to tens of millions of GPS, and the latency is at the millimeter level. It can be widely used in the storage and query of user information and user relationships, and the connection between users and the content they follow.

[0126] Optionally, building a permission relationship graph based on the business information table and the object information table may include:

[0127] Establish relationship nodes of the permission relationship graph based on the business information table;

[0128] Establish connection edges between each relationship node based on the object information table;

[0129] Based on each relationship node and the connection edges between each relationship node, a permission relationship graph is determined.

[0130] Among them, the relationship nodes of the permission relationship map may include: business documents (such as business data), personnel (such as access objects), departments, roles, product lines, transaction parties, business document types, etc.

[0131] Among them, in the construction of the business document node, it can be achieved by setting its label (such as label) to contract, and the node data (such as data) can include the business document identifier (identity document, id), business document name, tenant id and business document number, etc. The node data example can be seen as follows.

[0132]

[0133] Among them, when constructing the personnel node, it can be achieved by setting its label to employee, and the node data data can include employee id, employee name, tenant id, etc.

[0134] Among them, when constructing a department node, its label can be set to department, and the node data data can include department id, department name, tenant id, etc.

[0135] Among them, when constructing a role node, its label can be set to role, and the node data data can include role id, role name, tenant id, etc.

[0136] Among them, when constructing a product line node, its label can be set to productLine, and the node data data can include product line id, product line name, tenant id, etc.

[0137] Among them, in the construction of the transaction party entity node, it can be achieved by setting its label to legalEntity, and the node data data can include the transaction party entity id, transaction party entity name, tenant id, etc.

[0138] In the construction of the business document type node, the label can be set to contractCategory, and the node data data can include the business document type id, the business document type name, the tenant id, and the like.

[0139] Therefore, by determining each relationship node, the connection edges between the relationship nodes are constructed to completely determine the permission relationship graph.

[0140] Among them, building a business data corresponding to the authority relationship map can be seen in Figure 4 As shown in the example.

[0141] Figure 4 In the example, user C creates a business data 1, then user C has the permission to modify and view all the data in business data 1.

[0142] User C belongs to department A_A, department A_A is managed by user G, user G is led by user H, user H's leader is user B, and user G belongs to department B, which is managed by user I. Then user B, user G, user H, and user I all have the permission to modify and view business data 1.

[0143] User D obtains the permission to view business data 1 through independent authorization.

[0144] User E is the approval user in the business approval flow and automatically obtains the permission to view business data 1.

[0145] Business data 1 belongs to the procurement type, and user K is authorized to view all business data under the procurement type. Therefore, user K obtains the permission to view business data 1.

[0146] Optionally, establishing a connection edge between each relationship node based on the object information table includes:

[0147] Assign a business role to each access object and establish a connection edge between each business role and the access object;

[0148] Based on the approval process of business data, establish a connection edge between each access object and business data.

[0149] The connection edge between each relationship node can be controlled based on at least two control permissions, such as control permissions based on roles and rules and control permissions based on approval flows of business documents.

[0150] Among them, the rules can be understood as the associated attributes of the business documents configured at the role level. For example, role A configures the business document with transaction party 1 and transaction party 2, and the transaction party can be abstracted as the associated attributes of the business document.

[0151] The relationship between roles and personnel or departments is to establish an edge with the employee or department as the starting point and the role as the end point. The relationship between roles and rules is to establish an edge with the role as the starting point and the relevant associated attributes as the end point.

[0152] Among them, the model is built based on the approval flow of the business document, such as the business document submitter, approver, copy recipient, etc., and an edge is established with the person as the starting point and the business document as the end point.

[0153] Thus, by establishing a connection edge between each business role and the access object, and establishing a connection edge between each access object and the business data, it is effectively possible to establish connection edges between relationship nodes from different control granularities of permissions.

[0154] For example, the connection edges may include: departments and departments, personnel and personnel, personnel and departments, personnel / department and roles, rule-related edges, and business-related edges.

[0155] Among them, the parent department of the business task sub-department's permissions are included. With the parent department as the starting point and the sub-department as the end point, a directed edge is established. The label can be set to departmentRelate. The edge data mainly stores the tenant id. The node data example is as follows:

[0156]

[0157] Among them, similar to departments, there will also be reporting relationships in the corporate organizational structure, with the superior as the starting point and the subordinate as the end point, establishing a directed edge, the label can be set to employeeRelate, and the edge data is mainly used to store the tenant ID.

[0158] Among them, the personnel will belong to the department. With the department as the starting point and the employee as the end point, a directed edge is established. The label can be set to departmentEmployeeRelate. The edge data is mainly used to store the tenant ID.

[0159] Among them, the role can be bound to a person or department. A directed edge is established with the person or department as the starting point and the role as the end point. The label can be set to departmentRoleRelate or employeeRoleRelate. The edge data is mainly used to store the tenant ID.

[0160] Among them, the rule type edge is modeled around the business document association attributes and can be divided into the following two categories.

[0161] Category 1: The relationship between roles and associated attributes. A directed edge is established with the role as the starting point and the associated attribute as the end point. The label can be set to roleAttributeRelate. The edge data is mainly used to store the tenant ID.

[0162] Category 2: Establish a directed edge with the associated attribute as the starting point and the business document as the end point. The label can be set to attributeContractRelate. The edge data is mainly used to store the tenant ID.

[0163] Among them, according to the process participants, a directed edge is established with the employee as the starting point and the business document as the end point. The label can be set to processParticipant, and the edge data is mainly used to store the tenant ID.

[0164] Optionally, determining a permission relationship graph based on each relationship node and the connection edge between each relationship node includes:

[0165] Based on each relationship node and the connection edges between each relationship node, a permission relationship graph is established;

[0166] The permission relationship map is updated according to the point-to-point authorization information associated with each business data. The point-to-point authorization information is used to describe the authorization relationship between business data and access objects.

[0167] Among them, the specific business scenario corresponding to point-to-point authorization is to authorize a business document to a certain employee, and to establish a connection edge with the employee as the starting point and the business document as the end point, that is, a data-related edge.

[0168] For example, a directed edge is created with the employee as the starting point and the business document as the end point. The label can be set to employeeContractRelate, and the edge data is mainly used to store the tenant ID.

[0169] Therefore, on the basis of the initially constructed permission relationship graph, connection edges between point-to-point authorized employees and business documents are added to further enrich the connection edges in the permission relationship graph.

[0170] Based on the description of the above embodiment, after the permission relationship graph is constructed, a change operation may be performed on a certain relationship node in the permission relationship graph, wherein the change operation may include data change and personnel change.

[0171] Optionally, the method of this embodiment may further include:

[0172] In response to the permission change event, determine the relationship node where the change subject is located;

[0173] Based on the permission change event, modify the relationship node, or modify the connection edge where the relationship node is located.

[0174] Among them, by monitoring binlog or asynchronous events, permission change events can be effectively identified.

[0175] Permission change events may include: organizational structure change events, role change events, business document process flow events, business document associated attribute change events, business document additions and deletions, point-to-point authorization and other events.

[0176] Among them, the organizational structure change events are monitored, and the personnel nodes (relationship nodes), department nodes (relationship nodes), personnel-personnel relationships (connection edges), department-department relationships (connection edges), personnel-department relationships (connection edges), and personnel or department-role relationships (connection edges) are updated and adjusted.

[0177] Among them, the role change event is listened to, and the role node (connection edge), the relationship between personnel or department and role (connection edge), and the rule type edge (connection edge) are updated and adjusted.

[0178] Among them, by monitoring the business document process flow events, it is possible to add, delete, modify and adjust business-related edges (connection edges).

[0179] Among them, the business document related attribute change events are monitored, and the product lines (relationship nodes), transaction parties (relationship nodes), and business document types (relationship nodes) are added, deleted, modified, and adjusted.

[0180] Among them, it monitors events such as the addition and deletion of business documents, point-to-point authorization, and adds, deletes, and modifies business documents (relationship nodes), rule-related edges (connection edges), and data-related edges (connection edges).

[0181] In addition, after the permission relationship graph is constructed, the deletion rules of a certain relationship node can be set periodically based on the needs of business data. When the pre-set deletion rules are met, the relevant information of the relationship node is automatically deleted.

[0182] Optionally, the method of this embodiment may further include:

[0183] When it is determined that a target relationship node in the permission relationship graph meets a preset trigger condition, the target relationship node is deleted, or a connection edge where the target relationship node is located is deleted, and the target relationship node includes an access object and / or business data;

[0184] Among them, the preset trigger condition includes at least one of the following: not exceeding a storage time threshold and not exceeding a connection access number threshold.

[0185] Among them, the expiration and invalidation processing mechanism of the relationship nodes can be set in the permission relationship graph, so that the relationship nodes will perform automatic invalidation processing when the preset trigger conditions are met, which is convenient for effectively maintaining the real-time data of the relationship nodes and connection edges in the permission relationship graph.

[0186] It should be noted that, in addition to being able to find out whether a certain access object has access rights to a certain business data, the permission relationship map can also find all business data that an access object can access, or all access objects that can access a certain business data.

[0187] Optionally, the method of this embodiment may further include:

[0188] In response to the first query request, searching the permission relationship graph for a first relationship node where the first access object is located;

[0189] Searching the permission relationship graph for a second relationship node that is reachable from the first relationship node, where the second relationship node corresponds to a second business data;

[0190] Based on the second business data, respond to the first query request.

[0191] After receiving the first query request, the first relationship node is taken as the starting point in the permission relationship graph, and all reachable second relationship nodes are traversed in the graph.

[0192] It should be noted that the second relationship node may correspond to one or more second business data.

[0193] Therefore, in the constructed permission relationship graph, all business data that a certain access object can access can be directly obtained at one time, effectively improving the efficiency of business data search.

[0194] For example, Figure 5 A schematic diagram of the structure of the permission relationship graph is provided. Assume that the first relationship node is person D. Figure 5 In the example, person D is the copy recipient of business document 1, the approver of business document 2, and the authorizer of business document 3. The second relationship nodes corresponding to person D are the relationship node of business document 1, the relationship node of business document 2, and the relationship node of business document 3. The second business data corresponding to person D are business document 1, business document 2, and business document 3.

[0195] Similarly, if you want to find out whether person B has the authority to access business document 3, you can Figure 5 It is concluded that there is no reachable relationship node between the relationship node where person B is located and the relationship node where business document 3 is located, and it is determined that person B does not have access rights to access business document 3.

[0196] Figure 6 A structural diagram of a data processing device provided by the present disclosure is shown in FIG. Figure 6 As shown, the data processing device 600 of this embodiment includes: an acquisition module 610, a determination module 620 and a processing module 630, wherein:

[0197] An acquisition module 610 is used to acquire target business data to be accessed by a target access object in response to a target access request;

[0198] A determination module 620 is used to determine whether there is a reachable relationship node between the target access object and the target business data based on a pre-constructed permission relationship graph, wherein the permission relationship graph includes at least one reachable relationship node between a candidate access object and candidate business data, and the candidate business data is business data that has been authorized by the candidate access object;

[0199] The processing module 630 is used to process the target access request based on the target business data after determining that there is a reachable relationship node between the target access object and the target business data.

[0200] In this embodiment, optionally, the device of this embodiment further includes: a construction module;

[0201] The acquisition module 610 is further used to acquire a business information table and an object information table, wherein the business information table is used to describe the access object and the business data associated with the access object, and the object information table is used to describe the business relationship between the access objects;

[0202] A construction module is used to construct a permission relationship map based on the business information table and the object information table.

[0203] In this embodiment, optionally, the construction module includes: a first establishing unit, a second establishing unit and a determining unit;

[0204] A first establishing unit, configured to establish a relationship node of a permission relationship graph based on the business information table;

[0205] A second establishing unit, configured to establish a connection edge between each relationship node based on the object information table;

[0206] The determination unit is used to determine the permission relationship graph based on each relationship node and the connection edge between each relationship node.

[0207] In this embodiment, optionally, the second establishing unit is specifically configured to:

[0208] Assign a business role to each access object and establish a connection edge between each business role and the access object;

[0209] Based on the approval process of business data, establish a connection edge between each access object and business data.

[0210] In this embodiment, optionally, the determining unit is specifically configured to:

[0211] Establishing a permission relationship graph based on each relationship node and each connection edge between the relationship nodes;

[0212] The permission relationship graph is updated according to the point-to-point authorization information associated with each business data, wherein the point-to-point authorization information is used to describe the authorization relationship between the business data and the access object.

[0213] In this embodiment, optionally, the device of this embodiment further includes: a modification module;

[0214] The determination module 620 is further used to determine the relationship node where the change subject is located in response to the permission change event;

[0215] A modification module is used to modify the relationship node based on the permission change event, or to modify the connection edge where the relationship node is located.

[0216] In this embodiment, optionally, the device of this embodiment further includes: a deletion module;

[0217] A deletion module is used to delete the target relationship node in the permission relationship graph when it is determined that the target relationship node meets the preset trigger condition, or delete the connection edge where the target relationship node is located, and the target relationship node includes the access object and / or business data;

[0218] The preset trigger condition includes at least one of the following: not exceeding a storage time threshold and not exceeding a connection access times threshold.

[0219] In this embodiment, optionally, it further includes: a search module;

[0220] A search module, configured to search, in response to a first query request, a first relationship node where a first access object is located from a permission relationship graph;

[0221] The search module is further used to search the permission relationship graph for a second relationship node that is reachable from the first relationship node, where the second relationship node corresponds to a second business data;

[0222] A response module is used to respond to the first query request based on the second business data.

[0223] In this embodiment, optionally, the target access request includes: at least one of data to be added, data to be modified, and data to be deleted;

[0224] The processing module 620 is specifically configured to:

[0225] Based on the data to be added included in the target access request, performing an adding operation on the target service data;

[0226] Alternatively, based on the data to be modified included in the target access request, a modification operation is performed on the target business data;

[0227] Alternatively, based on the data to be deleted included in the target access request, a deletion operation is performed on the target business data.

[0228] The data processing device provided by the present disclosure can execute the above method embodiments. Its specific implementation principles and technical effects can be found in the above method embodiments, and the present disclosure will not repeat them here.

[0229] Exemplarily, the present disclosure provides an electronic device, comprising: one or more processors; a memory; and one or more computer programs; wherein the one or more computer programs are stored in the memory; when the one or more processors execute the one or more computer programs, the electronic device implements the data processing method of the foregoing embodiments.

[0230] Illustratively, the present disclosure provides a chip system, which is applied to an electronic device including a memory and a sensor; the chip system includes: a processor; when the processor executes the data processing method of the above embodiment.

[0231] Exemplarily, the present disclosure provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor in an electronic device, the data processing method of the foregoing embodiment is implemented.

[0232] Illustratively, the present disclosure provides a computer program product. When the computer program product is run on a computer, the computer is enabled to execute the data processing method of the foregoing embodiment.

[0233] In the above embodiments, all or part of the functions can be implemented by software, hardware, or a combination of software and hardware. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present disclosure is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or a data center that includes one or more available media integrated. Available media can be magnetic media, (e.g., floppy disks, hard disks, tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid state disks (SSDs)), etc.

[0234] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0235] The above description is only a specific embodiment of the present disclosure, so that those skilled in the art can understand or implement the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data processing method, characterized in that: include: In response to the target access request, obtaining the target business data to be accessed by the target access object; Based on a pre-constructed permission relationship graph, determine whether there is a reachable relationship node between the target access object and the target business data, the permission relationship graph includes at least one reachable relationship node between a candidate access object and candidate business data, the candidate business data is the business data that the candidate access object has authorized, the permission relationship graph is constructed based on a business information table and an object information table, the business information table is used to describe an access object and the business data associated with the access object, and the object information table is used to describe the business relationship between each access object; After determining that there is a reachable relationship node between the target access object and the target business data, the target access request is processed based on the target business data.

2. The method according to claim 1, characterized in that The constructing a permission relationship graph based on the business information table and the object information table includes: Establishing relationship nodes of the authority relationship graph based on the business information table; Establishing a connection edge between each relationship node based on the object information table; Based on each relationship node and the connection edges between each relationship node, a permission relationship graph is determined.

3. The method according to claim 2, characterized in that The establishing of a connection edge between each relationship node based on the object information table includes: Assign a business role to each access object and establish a connection edge between each business role and the access object; Based on the approval process of business data, establish a connection edge between each access object and business data.

4. The method according to claim 2, characterized in that: The determining of the permission relationship graph based on each relationship node and the connection edge between each relationship node includes: Establishing a permission relationship graph based on each relationship node and each connection edge between the relationship nodes; The permission relationship graph is updated according to the point-to-point authorization information associated with each business data, wherein the point-to-point authorization information is used to describe the authorization relationship between the business data and the access object.

5. The method according to any one of claims 2 to 4, characterized in that: Also includes: In response to the permission change event, determine the relationship node where the change subject is located; Based on the permission change event, the relationship node is modified, or the connection edge where the relationship node is located is modified.

6. The method according to any one of claims 2 to 4, characterized in that: Also includes: When it is determined that a target relationship node in the permission relationship graph meets a preset trigger condition, the target relationship node is deleted, or a connection edge where the target relationship node is located is deleted, and the target relationship node includes an access object and / or business data; The preset trigger condition includes at least one of the following: not exceeding a storage time threshold and not exceeding a connection access times threshold.

7. The method according to any one of claims 1 to 4, characterized in that Also includes: In response to the first query request, searching the permission relationship graph for a first relationship node where the first access object is located; Searching the permission relationship graph for a second relationship node that is reachable from the first relationship node, where the second relationship node corresponds to a second business data; Respond to the first query request based on the second business data.

8. The method according to claim 1, characterized in that The target access request includes: at least one of data to be added, data to be modified, and data to be deleted; The processing of the target access request based on the target service data includes: Based on the data to be added included in the target access request, performing an adding operation on the target service data; Alternatively, based on the data to be modified included in the target access request, a modification operation is performed on the target business data; Alternatively, based on the data to be deleted included in the target access request, a deletion operation is performed on the target business data.

9. A data processing device, characterized in that: include: An acquisition module, used for acquiring target business data to be accessed by a target access object in response to a target access request; A determination module, for determining whether there is a reachable relationship node between the target access object and the target business data based on a pre-constructed permission relationship graph, wherein the permission relationship graph includes at least one reachable relationship node between a candidate access object and candidate business data, wherein the candidate business data is business data that has been authorized by the candidate access object, and wherein the permission relationship graph is constructed based on a business information table and an object information table, wherein the business information table is used to describe an access object and business data associated with the access object, and the object information table is used to describe business relationships between access objects; A processing module is used to process the target access request based on the target business data after determining that there is a reachable relationship node between the target access object and the target business data.

10. An electronic device comprising: one or more processors; Memory; and one or more computer programs; wherein the one or more computer programs are stored in the memory; characterized in that when the one or more processors execute the one or more computer programs, the electronic device implements the data processing method as described in any one of claims 1-8.

11. A computer storage medium, characterized in that: The method comprises computer instructions, which, when executed on an electronic device, enable the electronic device to execute the data processing method according to any one of claims 1 to 8.

12. A computer program product, characterized in that When the computer program product is run on a computer, the computer is enabled to execute the data processing method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Authority management method and device based on graph database and electronic equipment

    CN112328712A