A multi-project permission control method and system
Through the global permission flag flag and application mapping bit methods, the low efficiency of permission query caused by the large number of applications and users in the financial field is solved, and refined permission control and system efficiency improvement are achieved.
Patent Information
- Application Number
- CN202111597067.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-12-24
AI Technical Summary
In the financial field, due to the large number of applications and users and frequent permission queries, it is difficult for the existing technology to achieve efficient permission control.
The global permission flag flag and application mapping bit are used to load user permission information at one time, generate application summary permissions, reduce I/O operations, and realize simplification and dynamic scaling of permission control.
It realizes refined permission control in a small amount of storage space, improves system efficiency, reduces the number of permission queries, and controls system risks.
Smart Images

Figure CN114238896B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular to a multi-project permission control method and system. Background Art
[0002] Nowadays, the content of many software products / platforms is increasing, and the division of product modules is becoming more and more refined. At the same time, there is a trend of more refined division of permission control. Especially in the financial industry, there are many self-operated businesses, intermediate businesses, etc. in the financial industry, and it is imperative to conduct unified and efficient permission control. The access control list (ACL) is one of the access policy options based on resources and can be used to manage access to buckets and objects. Using ACL, basic read, write and other permissions can be granted to other master accounts, sub-accounts and user groups. At present, most systems design fields in the database for permission control. However, in actual applications, especially in application scenarios such as the financial field where there are many applications and many users, frequent permission queries will lead to a rapid decline in efficiency. For tens of millions of users, the technology of database sharding and table partitioning is required to alleviate the problem. The idea of Bitmap is to use a bit to mark the Value corresponding to a certain element, and the Key is the element. Since data is stored in units of bits, a large amount of storage space can be saved. However, in application scenarios such as financial systems where there are many applications and many users (in the millions or tens of millions), the storage volume is quite large. It is unrealistic to load such a large amount of data into memory, and a large number of I / O operations are required.
[0003] However, the existing technology has the technical problem that in the financial field scenario, there are many applications and many users, and frequent permission queries are required, resulting in a relatively fast decline in efficiency. Summary of the Invention
[0004] By providing a multi-project permission control method and system, the present application solves the technical problem in the existing technology that in the financial field scenario, there are many applications and many users, and frequent permission queries are required, resulting in a relatively fast decline in efficiency. It achieves the technical effects of streamlining permission control, realizing dynamic expansion and contraction of permission control, freely adjusting the granularity, completing refined permission control with only a small amount of storage space, greatly improving the processing efficiency, and enabling each person to have the minimum necessary permissions to control system risks.
[0005] In view of the above problems, the present application provides a multi-project permission control method and system.
[0006] In a first aspect, the present application provides a multi-project permission control method, the method comprising: obtaining user information; pulling user permission information according to the user information; obtaining access application information; based on the access application information, checking whether the global permission flag flag of the user permission information allows global access; when global access is not satisfied, obtaining an application mapping bit according to the access application information, and checking the permission marking information in the application mapping bit; generating an application summary permission according to the check result of the permission marking information; and obtaining access feedback information according to the application summary permission.
[0007] In another aspect, the present application provides a multi-project permission control system, the system comprising: a first obtaining unit configured to obtain user information; a first execution unit configured to pull user permission information according to the user information; a second obtaining unit configured to obtain access application information; a second execution unit configured to, based on the access application information, check whether the global permission flag flag of the user permission information allows global access; a third obtaining unit configured to, when global access is not satisfied, obtain an application mapping bit according to the access application information, and check the permission marking information in the application mapping bit; a first generating unit configured to generate an application summary permission according to the check result of the permission marking information; and a fourth obtaining unit configured to obtain access feedback information according to the application summary permission.
[0008] In a third aspect, the present invention provides a multi-project permission control system, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the method in the first aspect are implemented.
[0009] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0010] 1. Since the technical solution of obtaining user information, pulling user permission information, obtaining access application information, checking the global permission flag "flag" of the user permission information to determine whether global access is allowed, when global access is not satisfied, obtaining an application mapping "bit" according to the access application information and checking the permission marking information in the application mapping "bit", generating an application summary permission according to the check result of the permission marking information, and obtaining access feedback information according to the application summary permission is adopted, the present application provides a multi-project permission control method and system, achieving the technical effects of streamlining permission control, realizing dynamic expansion and contraction of permission control, freely adjusting the granularity, completing refined permission control with only a small amount of storage space, greatly improving the processing efficiency, and enabling each person to have the minimum necessary permissions to control system risks.
[0011] 2. Since the method of generating an access control list ACL (Access Control List) for each user is adopted, the technical effect of loading all the permissions of the user at one time after login and greatly reducing the number of I / O for authentication before accessing different applications and interfaces and improving the system efficiency is achieved.
[0012] The above description is only an overview of the technical solution of the present application. In order to be able to more clearly understand the technical means of the present application, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the specific embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 It is a flowchart of a multi-project permission control method according to an embodiment of the present application;
[0014] Figure 2 It is a flowchart of setting the global permission flag "flag", the array "appArray" and the permission operation "permission" of a multi-project permission control method according to an embodiment of the present application;
[0015] Figure 3 It is a flowchart of obtaining access feedback information of a multi-project permission control method according to an embodiment of the present application;
[0016] Figure 4 It is a schematic diagram of the global access flag of a multi-project permission control method according to an embodiment of the present application;
[0017] Figure 5 It is a schematic diagram of the structure of a multi-project permission control system according to an embodiment of the present application;
[0018] Figure 6 It is a schematic diagram of the structure of an exemplary electronic device according to an embodiment of the present application.
[0019] Explanation of the figure marks: first obtaining unit 11, first executing unit 12, second obtaining unit 13, second executing unit 14, third obtaining unit 15, first generating unit 16, fourth obtaining unit 17, electronic device 300, memory 301, processor 302, communication interface 303, bus architecture 304. DETAILED DESCRIPTION
[0020] This application provides a multi-project permission control method and system to solve the technical problem in the prior art that there are many applications and users in the financial field, and frequent permission queries are required, resulting in a rapid decline in efficiency. The permission control is simplified, and the permission control is dynamically scalable, and the granularity can be freely adjusted. Only a small amount of storage space is required to complete refined permission control. At the same time, the processing efficiency is greatly improved, allowing everyone to have the minimum necessary permissions to control the technical effect of system risks.
[0021] The acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0022] At present, most systems design fields in the database for permission control. However, in actual applications, especially in the financial field where there are many applications and users, frequent permission queries will lead to a rapid decline in efficiency. For tens of millions of users, the database sharding technology is needed to alleviate the problem. In the existing technology, there are many applications and users in the financial field, and frequent permission queries are required, which leads to a rapid decline in efficiency.
[0023] In response to the above technical problems, the overall idea of the technical solution provided by this application is as follows:
[0024] The present application provides a multi-project permission control method, the method comprising: pulling user permission information; based on access application information; checking the global permission flag of the user permission information to determine whether global access is allowed; when global access is not satisfied, obtaining an application mapping bit based on the access application information, and checking the permission marking information in the application mapping bit; generating application summary permissions based on the checking result of the permission marking information; and obtaining access feedback information based on the application summary permissions.
[0025] After introducing the basic principles of the present application, various non-limiting implementation methods of the present application will be specifically described below in conjunction with the drawings in the specification.
[0026] Embodiment 1
[0027] like Figure 1As shown in the figure, an embodiment of the present application provides a multi-project permission control method, where the method includes:
[0028] S100: Obtain user information;
[0029] S200: Pull user permission information according to the user information;
[0030] Specifically, in a financial system, there may be hundreds of independent application systems, where the application systems include but are not limited to human resources systems, R & D systems, test systems, external liaison systems, etc. Obtain user information, which includes but is not limited to user names (e.g., Zhang San, Li Si), user IDs, etc. The permissions of different users are different. Generally speaking, system administrators usually have higher permissions in the system because they need to handle daily maintenance and solve difficult problems that the system may encounter. Pull all the permission information of the user at one time based on the user information. The application permission information includes but is not limited to not allowed to access, read-only, read-write, etc.
[0031] S300: Obtain access application information;
[0032] S400: Based on the access application information, check whether the global permission flag flag of the user permission information allows global access;
[0033] Specifically, the access application information includes the names of the applications accessed by the user, such as: test system, R & D system, human resources system, etc. Based on the access application information, check the global permission flag flag of the user permission information. The global permission flag flag is used to define whether all applications can be accessed, whether all data can be accessed, etc. Among them, the global permission flag flag is of Character type, 2 bytes, and 2x8 = 16 bits of permissions.
[0034] S500: When global access is not satisfied, obtain an application mapping bit according to the access application information, and check the permission marking information in the application mapping bit;
[0035] Furthermore, an embodiment of the present application further includes:
[0036] S510: When the user permission information meets the global access, obtain first execution information, and the first execution information is used to allow access to the access application information.
[0037] Specifically, check the global permission flag "flag" to determine whether the user permission information meets the global access requirements. When the global access is not satisfied, the user's permissions are insufficient to access all applications and data. Then, according to the accessed application information, check the permission flag information in the application mapping bit, that is, detect the bit corresponding to the application in the appArray, and obtain the application mapping bit, where appArray is a Long-type array. When the user permission information meets the global access requirements, it means that the user's permissions can access all applications and data. Obtain the first execution information, and allow the user to access all application information according to the first execution information.
[0038] S600: Generate the application summary permissions according to the check result of the permission flag information;
[0039] S700: Obtain the access feedback information according to the application summary permissions.
[0040] Specifically, when the global access is not satisfied, detect the bit corresponding to the accessed application in the appArray, obtain the application mapping bit, and determine whether the flag bit is 1. If the flag bit is not 1, access is not allowed and the permission is abnormal. If the flag bit is 1, continue to check the permission flag information in the application mapping bit. Checking the permission flag information in the application mapping bit is to verify all the user permissions included in the permission flag information.
[0041] According to the check result of the permission flag information, the summary permissions of the application can be obtained. After generating the summary permissions, determine whether the summary permission result is 0. If the permission is 0, all applications are not allowed to access. If it is not 0, access is allowed and the application continues. The judgment result of the summary permissions is the access feedback information. It achieves the effect of dynamic scalability and flexible control of permissions, and loads all the user permissions at once after logging in, greatly reducing the number of I / O times for authentication before accessing different applications and interfaces, and improving the technical effect of system efficiency.
[0042] Further, as Figure 2 shown, before obtaining the user information, step S100 includes:
[0043] S110: Obtain the application information set;
[0044] S120: Set the global permission flag "flag" based on the application information set;
[0045] S130: Make a mapping for each application in the application information set, and one bit in the global permission flag "flag" corresponds to the access permission of one application;
[0046] S140: Set an array appArray according to the global permission flag flag, where the length of the array appArray corresponds to the number of applications in the application information set;
[0047] S150: Set a permission operation permission, where the permission operation permission includes the permission marking information, and the permission marking information is associated with the application mapping bit in the array appArray.
[0048] Specifically, obtain the application information set, where the application information set includes all independent applications in the financial system. Based on the application information set, set the global permission flag flag. The global permission flag flag is of the Character type, 2 bytes (one byte is 8 bits), with 2x8 = 16 bits of permissions, which defines whether all applications can be accessed, whether all data can be accessed, etc. For an unrestricted example: Figure 4 As shown, the global permission flag flag corresponds to 16 permissions. Different users have different permissions, and the corresponding bits are different. Assume 0 means non - existent and 1 means existent. The permissions corresponding to the user can be obtained according to the global permission flag.
[0049] Make a mapping for each application in the application information set, that is, one bit in the global permission flag flag corresponds to the access permission of one application. Set an array appArray according to the global permission flag flag, where the length of the array appArray corresponds to the number of applications in the application information set. For example: appArray[0] maps applications 0 - 63, appArray[1] maps applications 64 - 127, appArray[2] maps applications 128 - 191, appArray[3] maps applications 192 - 255... Assume there are 100,000 applications, and each application is assigned one bit. Then, applying for a Long - type array appArray with a length of 100000 / 64 + 1 is sufficient. In this way: it requires (100000 / 64 + 1) x 8 ≈ 12500 Bytes ≈ 13MB.
[0050] After setting the array appArray, the permission operation permission is defined. The type is Character, and 2x8 bits can represent 16 different operation permissions. For example: 0: No access allowed, 1: Read-only, 2: Read-write, etc., a total of 16 permissions. The permission operation permission is composed of the permission marking information, and the permission marking information is associated with the application mapping bit in the array appArray. That is to say, in the array appArray, each application corresponds to a bit, and the bit mapped by the application in the array appArray is associated with each different permission marking information.
[0051] Take an unrestricted example: Suppose Zhang San has the corresponding operation permissions of 1, 2, 4, and 6. If stored in a database (int type), at least 4x4 = 16 bytes are required. For users of products in the financial system with 100,000, millions, or tens of millions of levels, the calculated storage capacity is quite large. If such a large amount of data is to be loaded into memory, it is unrealistic. Either increase the memory or a large number of I / O operations are required. However, suppose there are 100,000 applications, and each application is assigned a bit. Then, applying for a Long type array appArray with a length of 100000 / 64 + 1 is sufficient. In this way, (100000 / 64 + 1) x 8 ≈ 12500 Bytes ≈ 13MB can achieve the goal. It can be seen from this that by setting the array appArray, the technical effect of achieving fine-grained permission control with only a small amount of storage space is achieved.
[0052] Furthermore, the step S700 of obtaining the access feedback information according to the application aggregated permissions further includes:
[0053] S710: Determine whether the application aggregated permissions meet the preset restricted access format;
[0054] S720: When it is satisfied, obtain the permission exception feedback information;
[0055] S730: When it is not satisfied, obtain the first execution information.
[0056] Specifically, the preset restricted access format is preferably whether the permission is 0. Assume that 0 means non-existent and 1 means existent. Determine whether the application aggregated permissions meet the preset restricted access format. If the permission is 0, obtain the permission exception feedback information and do not allow access. If the permission is not 0, that is, when it does not meet the preset restricted access format, obtain the first execution information and allow access, and the application continues.
[0057] Furthermore, the embodiments of the present application include:
[0058] S151: Obtain the permission operation permission corresponding to the application according to the application mapping bit;
[0059] S152: Check the permission marking information in the permission operation permission to obtain the application operation permission;
[0060] S153: Based on the application operation permission, perform permission summarization to generate the application summary permission.
[0061] Specifically, since the permission operation permission includes the permission marking information, and the permission marking information is associated with the application mapping bit in the array appArray. Therefore, the permission operation permission corresponding to the application can be obtained according to the application mapping bit, and the permission marking information in the permission operation permission is checked, that is, different operation permissions owned by the application are checked. After obtaining the corresponding operation permissions, permission summarization is performed. After checking and summarizing through the permission marking information, the application summary permission is obtained. It achieves the technical effect of laying a foundation for the user not to need to perform frequent authentication operations after logging in.
[0062] Further, as Figure 3 shown, the embodiments of the present application further include:
[0063] S810: Obtain the global permission flag flag, the array appArray, and the permission operation permission of the user according to the user information;
[0064] S820: Based on the global permission flag flag, the array appArray, and the permission operation permission of the user, generate the user access control list ACL;
[0065] S830: Perform bit calculation on the user access control list ACL to obtain the user permission information;
[0066] S840: Obtain the access feedback information according to the access application information and the user permission information.
[0067] Specifically, the user access control list ACL (Access Control List) is one of the access policy options based on resources and can be used to manage access to buckets and objects. Using the ACL, basic read, write, and other permissions can be granted to other master accounts, sub-accounts, and user groups. In practical applications, after obtaining three pieces of user information, namely the global permission flag flag, the array appArray, and the permission operation permission, based on these three pieces of information, the user's access control list ACL is generated. Through bitwise calculation using the user access control list ACL, the user permission information is obtained. Thus, based on the access application information and the user permission information, the access feedback information is obtained. It achieves the technical effect that each user has its own access control list ACL, and when judging user permissions, only bitwise calculation and operations are required, enabling each person to have the minimum necessary permissions to control system risks.
[0068] Embodiment 2
[0069] Based on the same inventive concept as a multi-project permission control method in the foregoing embodiment, as Figure 5 shown, an embodiment of the present application provides a multi-project permission control system, wherein the system includes:
[0070] The first acquisition unit 11, which is used to acquire user information;
[0071] The first execution unit 12, which is used to pull user permission information according to the user information;
[0072] The second acquisition unit 13, which is used to acquire access application information;
[0073] The second execution unit 14, which is used to check whether the global permission flag flag of the user permission information allows global access based on the access application information;
[0074] The third acquisition unit 15, which is used to, when global access is not satisfied, acquire an application mapping bit according to the access application information and check the permission marking information in the application mapping bit;
[0075] The first generation unit 16, which is used to generate an application summary permission according to the check result of the permission marking information;
[0076] The fourth acquisition unit 17, which is used to acquire access feedback information according to the application summary permission.
[0077] Furthermore, the system includes:
[0078] A fifth acquisition unit, which is configured to acquire an application information set;
[0079] A third execution unit, which is configured to set a global permission flag flag based on the application information set;
[0080] A fourth execution unit, which is configured to map each application in the application information set, and one bit in the global permission flag flag corresponds to the access permission of one application;
[0081] A fifth execution unit, which is configured to set an array appArray according to the global permission flag flag, and the length of the array appArray corresponds to the number of applications in the application information set;
[0082] A sixth execution unit, which is configured to set a permission operation permission, and the permission operation permission includes the permission marking information, wherein the permission marking information is associated with the application mapping bit in the array appArray.
[0083] Further, the system includes:
[0084] A sixth acquisition unit, which is configured to acquire first execution information when the user permission information meets the global access, and the first execution information is used to allow access to the access application information.
[0085] Further, the system includes:
[0086] A seventh acquisition unit, which is configured to acquire the corresponding permission operation permission of the application according to the application mapping bit;
[0087] An eighth acquisition unit, which is configured to check the permission marking information in the permission operation permission to obtain the application operation permission;
[0088] A second generation unit, which is configured to perform permission summarization based on the application operation permission to generate the application summary permission.
[0089] Further, the system includes:
[0090] A first judgment unit, which is configured to judge whether the application summary permission meets a preset restricted access format;
[0091] A ninth acquisition unit, which is configured to acquire permission exception feedback information when it is satisfied;
[0092] A tenth acquisition unit, which is configured to acquire the first execution information when the condition is not met.
[0093] Furthermore, the system includes:
[0094] An eleventh acquisition unit, which is configured to acquire a global permission flag flag, an array appArray, and a permission operation permission of the user according to the user information;
[0095] A third generation unit, which is configured to generate a user access control list ACL based on the global permission flag flag, the array appArray, and the permission operation permission of the user;
[0096] A twelfth acquisition unit, which is configured to perform bitwise calculation on the user access control list ACL to obtain user permission information;
[0097] A thirteenth acquisition unit, which is configured to acquire the access feedback information according to the access application information and the user permission information.
[0098] Exemplary electronic device
[0099] Next, reference is made to Figure 6 to describe the electronic device according to an embodiment of the present application.
[0100] Based on the same inventive concept as the multi-project permission control method in the foregoing embodiment, an embodiment of the present application further provides a multi-project permission control system, including: a processor, the processor is coupled to a memory, and the memory is used to store a program. When the program is executed by the processor, the system is enabled to execute the method according to any one of the first aspect.
[0101] The electronic device 300 includes: a processor 302, a communication interface 303, and a memory 301. Optionally, the electronic device 300 may further include a bus architecture 304. Among them, the communication interface 303, the processor 302, and the memory 301 may be interconnected through the bus architecture 304; the bus architecture 304 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus architecture 304 may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6It is represented by only one thick line, but it does not mean that there is only one bus or one type of bus.
[0102] The processor 302 can be a CPU, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application solution.
[0103] The communication interface 303 uses any device such as a transceiver to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), wired access networks, etc.
[0104] The memory 301 can be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor through the bus architecture 304. The memory can also be integrated with the processor.
[0105] Among them, the memory 301 is used to store the computer execution instructions for executing the present application solution, and is controlled by the processor 302 to execute. The processor 302 is used to execute the computer execution instructions stored in the memory 301, so as to implement a multi-project permission control method provided by the above embodiments of the present application.
[0106] Optionally, the computer execution instructions in the embodiments of the present application can also be referred to as application program codes, and the embodiments of the present application do not make specific limitations thereto.
[0107] An embodiment of the present application provides a multi-project permission control method, where the method includes: obtaining user information and pulling user permission information; obtaining access application information; checking a global permission flag flag in the user permission information to determine whether global access is allowed; when global access is not satisfied, obtaining an application mapping bit according to the access application information and checking permission marking information in the application mapping bit; generating an application summary permission according to the check result of the permission marking information; and obtaining access feedback information according to the application summary permission.
[0108] Those of ordinary skill in the art can understand that the various digital numbers such as the first and second involved in this application are only for convenient distinction in description, and are not used to limit the scope of the embodiments of this application, nor do they represent the order of precedence. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one" means one or more. At least two means two or more. "At least one", "any one" or similar expressions refer to any combination of these items, including any combination of single item (s) or plural item (s). For example, at least one (piece, kind) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c can be single or multiple.
[0109] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media integrated. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0110] In the embodiments of the present application, the various illustrative logical units and circuits described can be implemented or operate the described functions through a design of a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination of the above. The general-purpose processor may be a microprocessor. Optionally, the general-purpose processor may also be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented by a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.
[0111] The steps of the methods or algorithms described in the embodiments of the present application may be directly embedded in hardware, software units executed by a processor, or a combination of both. The software units may be stored in a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium may be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium may also be integrated into the processor. The processor and the storage medium may be provided in an ASIC, and the ASIC may be provided in a terminal. Optionally, the processor and the storage medium may also be provided in different components of the terminal. These computer program instructions may also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 the steps of the functions specified in one block or multiple blocks.
[0112] Although the present application has been described in conjunction with specific features and their embodiments, it is obvious that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present application defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.
Claims
1. A multi-project permission control method, characterized in that, The method includes: Obtain user information; Pull user permission information according to the user information; Obtain access application information; Based on the access application information, check whether the global permission flag "flag" in the user permission information allows global access; When global access is not satisfied, detect the bit corresponding to the access application in the appArray, and determine whether the flag bit is 1. If the flag bit is not 1, access is not allowed and there is a permission exception. If the flag bit is 1, continue to check the permission marking information in the application mapping bit; according to the check result of the permission marking information, generate the application summary permission; after generating the summary permission, determine whether the summary permission result is 0. If the permission is 0, access to all applications is not allowed. If it is not 0, access is allowed and the application continues; Obtain access feedback information according to the application summary permission; Before obtaining the user information, the method further includes: Obtain an application information set; Set the global permission flag "flag" based on the application information set; Make a mapping for each application in the application information set, and one bit in the global permission flag "flag" corresponds to the access permission of one application; Set the array appArray according to the global permission flag "flag", and the length of the array appArray corresponds to the number of applications in the application information set; Set the permission operation "permission", and the permission operation "permission" includes the permission marking information, where the permission marking information is associated with the application mapping bit in the array appArray; Obtain the user's global permission flag "flag", array appArray, and permission operation "permission" according to the user information; Generate a user access control list ACL based on the user's global permission flag "flag", array appArray, and permission operation "permission"; Perform bitwise calculation on the user access control list ACL to obtain user permission information; Obtain the access feedback information according to the access application information and the user permission information.
2. The method according to claim 1, characterized in that, The method further includes: When the user permission information satisfies the global access, obtain first execution information, and the first execution information is used to allow access to the access application information.
3. The method according to claim 1, characterized in that, The method further includes: Obtain the permission operation "permission" corresponding to the application according to the application mapping bit; Check the permission marking information in the permission operation "permission" to obtain the application operation permission; Perform permission summarization based on the application operation permission to generate the application summary permission.
4. The method according to claim 2, wherein The obtaining the access feedback information according to the application summary permission includes: Determine whether the application summary permission meets a preset restricted access format; When it is satisfied, obtain a permission exception feedback information; When it is not satisfied, obtain the first execution information.
5. A multi-project permission control system, characterized in that, The system includes: A first obtaining unit, and the first obtaining unit is used to obtain user information; A first execution unit, and the first execution unit is used to pull user permission information according to the user information; A second acquisition unit configured to acquire access application information; A second execution unit configured to check whether the global permission flag "flag" of the user permission information allows global access based on the access application information; A third acquisition unit configured to, when global access is not satisfied, detect the corresponding bit of the access application in the appArray, determine whether the flag bit is 1. If the flag bit is not 1, access is not allowed and a permission exception occurs; if the flag bit is 1, continue to check the permission marking information in the application mapping bit; A first generation unit configured to generate an application summary permission according to the check result of the permission marking information; after generating the summary permission, determine whether the summary permission result is 0. If the permission is 0, all applications are not allowed to access; if it is not 0, access is allowed and the application continues; A fourth acquisition unit configured to acquire access feedback information according to the application summary permission; Before acquiring the user information, the system further includes: Acquire an application information set; Set a global permission flag "flag" based on the application information set; Map each application in the application information set, and one bit in the global permission flag "flag" corresponds to the access permission of one application; Set an array appArray according to the global permission flag "flag", and the length of the array appArray corresponds to the number of applications in the application information set; Set a permission operation "permission", where the permission operation "permission" includes the permission marking information, and the permission marking information is associated with the application mapping bit in the array appArray; Acquire the user's global permission flag "flag", array appArray, and permission operation "permission" according to the user information; Generate a user access control list "ACL" based on the user's global permission flag "flag", array appArray, and permission operation "permission"; Perform bit calculation on the user access control list "ACL" to obtain user permission information; Obtain the access feedback information according to the access application information and the user permission information.
6. A computer-readable storage medium, characterized in that A computer program is stored on the storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1-4 is implemented.
7. An electronic device, characterized in that, Including a processor and a memory: The memory is used for storage; The processor is configured to execute the method according to any one of claims 1-4 by calling.
8. A computer program product comprising a computer program and / or instructions, characterized in that, When the computing program and / or instruction is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
User access authorization management method and system
CN101060407A