Data permission convergence method and device, equipment and storage medium
By constructing a topology graph and marking, notifying, and deleting nodes, the efficiency and security issues of data permission revokement in big data environments are solved, achieving efficient and secure data permission convergence and improving system stability.
Patent Information
- Application Number
- CN202210104973.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-28
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2042-01-28
AI Technical Summary
In the process of big data production and use, when obsolete data is taken offline, existing technologies struggle to efficiently and securely reclaim data access rights, leading to system instability, increased labor costs, and risks.
Construct a topology graph of the data table to be converged, mark relevant nodes, notify and process downstream fields based on the marking information, and delete the successfully processed nodes and their adjacent nodes in the topology graph to achieve data permission convergence.
It improves the efficiency of data access control convergence, saves manpower costs, reduces systemic risks, and ensures the security and stability of the data access control convergence process.
Smart Images

Figure CN114417070B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of cloud storage, in particular to a data permission convergence method and device, equipment and a storage medium. BACKGROUND
[0002] In today's AI (Artificial Intelligence) big data era, each enterprise will produce and process a large amount of high-value data. These data have the characteristics of large scale, long chain and multiple roles. With the explosive growth of enterprise big data, it will inevitably lead to practical problems such as data tracking, data management and data security. Therefore, data governance has become an important work that enterprises must carry out. Data permission governance is an important sub-issue in data governance, which is closely related to the data security and stability of the enterprise.
[0003] The data permission convergence technology refers to a technology that, in the process of big data production and use, when obsolete data is offline, the permissions are reasonably recycled from the downstream system with the help of various statistical information generated by the system, so as to ensure the continuous and normal operation of each system. SUMMARY
[0004] The present disclosure provides a data permission convergence method, device, equipment and storage medium.
[0005] According to a first aspect of the present disclosure, a data permission convergence method is provided, comprising: constructing a topology graph of a to-be-converged data table, wherein the topology graph is used to represent the association relationship between the to-be-converged data table and other data tables and the association information between the fields in the to-be-converged data table and the fields in other data tables, and the other data tables are data tables having a dependency relationship with the to-be-converged data table; marking the related nodes of the to-be-converged fields in the topology graph to obtain marking information, wherein the to-be-converged fields are the fields in the to-be-converged data table; notifying and processing the downstream fields of the to-be-converged fields based on the marking information; and deleting the nodes corresponding to the fields whose processing is successful and the adjacent nodes of the nodes in the topology graph.
[0006] According to a second aspect of the present disclosure, a data authority convergence apparatus is provided, comprising: a construction module configured to construct a topology graph of a data table to be converged, wherein the topology graph is used to represent an association relationship between the data table to be converged and other data tables and association information of fields in the data table to be converged and fields in other data tables, the other data tables being data tables having a dependency relationship with the data table to be converged; a marking module configured to mark relevant nodes of a to-be-converged field in the topology graph to obtain marking information, wherein the to-be-converged field is a field in the data table to be converged; a notification module configured to notify and process a downstream field of the to-be-converged field based on the marking information; and a deletion module configured to delete, in the topology graph, a node corresponding to the field that has passed the processing and adjacent nodes of the node.
[0007] According to a third aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described in any implementation manner of the first aspect.
[0008] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, the computer instructions being used to enable a computer to perform the method described in any implementation manner of the first aspect.
[0009] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, the computer program being used to implement the method described in any implementation manner of the first aspect when executed by a processor.
[0010] It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0011] The accompanying drawings are used to better understand the present scheme, and do not limit the present disclosure. Among them:
[0012] Figure 1 is an exemplary system architecture diagram to which the present disclosure can be applied;
[0013] Figure 2 is a flowchart of one embodiment of a data authority convergence method according to the present disclosure;
[0014] Figure 3 is a flowchart of another embodiment of a data authority convergence method according to the present disclosure;
[0015] Figure 4is a flow chart of still another embodiment of a data permission converging method according to the present disclosure;
[0016] Figure 5 is a structural schematic diagram of one embodiment of a data permission converging apparatus according to the present disclosure;
[0017] Figure 6 is a block diagram of an electronic device for implementing a data permission converging method according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0018] Exemplary embodiments of the present disclosure are described herein below with reference to the accompanying drawings, in which various details of the embodiments of the present disclosure are set forth in order to provide an overall understanding of the embodiments of the present disclosure. It should be noted that these details are merely exemplary. Therefore, one of ordinary skill in the art will recognize that various changes and modifications of the embodiments described herein can be made without departing from the scope and spirit of the present disclosure. Also, in the following description, descriptions of well-known functions and constructions are omitted for clarity and conciseness.
[0019] It should be noted that the embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict. The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0020] Figure 1 An exemplary system architecture 100 to which the embodiments of the data permission converging method or the data permission converging apparatus of the present disclosure can be applied is shown.
[0021] As shown in Figure 1 , the system architecture 100 can include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0022] A user can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send information, etc. Various client applications can be installed on the terminal devices 101, 102, 103.
[0023] The terminal devices 101, 102, 103 can be hardware or software. When the terminal devices 101, 102, 103 are hardware, they can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers, etc. When the terminal devices 101, 102, 103 are software, they can be installed in the above-mentioned electronic devices. They can be implemented as multiple software or software modules, or as a single software or software module. No specific limitation is made herein.
[0024] Server 105 can provide various services. For example, server 105 can analyze and process the converged data obtained from terminal devices 101, 102, and 103, and generate processing results (such as deleting the node corresponding to the successfully processed field and the adjacent nodes of the field in the topology graph).
[0025] It should be noted that server 105 can be either hardware or software. When server 105 is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When server 105 is software, it can be implemented as multiple software programs or software modules (e.g., used to provide distributed services), or as a single software program or software module. No specific limitations are made here.
[0026] It should be noted that the data permission convergence method provided in this embodiment is generally executed by the server 105, and correspondingly, the data permission convergence device is generally set in the server 105.
[0027] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0028] Continue to refer to Figure 2 The document illustrates a flow 200 of an embodiment of a data rights convergence method according to this disclosure. The data rights convergence method includes the following steps:
[0029] Step 201: Construct the topology graph of the data table to be converged.
[0030] In this embodiment, the execution body of the data permission convergence method (e.g.) Figure 1 The server 105 shown constructs a topology graph of the data table to be converged. This topology graph represents the relationships between the data table to be converged and other data tables, as well as the relationships between fields in the data table to be converged and fields in other data tables. The other data tables are those that have dependencies on the data table to be converged. It should be noted that the data permission convergence method in this embodiment refers to a method used during big data production and usage where, when obsolete data is taken offline, permissions are reasonably revoked from downstream systems using various statistical information generated by the system, thereby ensuring the continued normal operation of each system.
[0031] Therefore, the execution subject determines the data table to be converged after the obsolete data is offline, that is, determines the data table for which the permission recovery needs to be performed, and then constructs a topology graph of the data table to be converged. The topology graph includes the association relationship between the data table to be converged and other data tables (downstream data tables), and the association relationship between each field in the data table to be converged and each field in other data tables. The other data tables are other data tables that directly or indirectly depend on the data table to be converged. For example, if a field Filed B1 in a table (Table) B depends on a field Filed A1 in Table A, then Table B is an other data table. For data permissions, the topology graph reflects the divergence of data permissions in the system link. Moreover, in order to trace back in the subsequent recovery phase, the edges in the topology graph generally use bidirectional pointers to implement.
[0032] As an example, the data table to be converged can be taken as a starting vertex of the topology graph, and the topology graph is constructed according to the blood relationship between the fields in the data table to be converged and the fields in other data tables.
[0033] In step 202, the related nodes of the fields to be converged in the topology graph are marked to obtain marking information.
[0034] In this embodiment, the execution subject marks the related nodes of the fields to be converged in the topology graph constructed in step 201, to obtain marking information, wherein the fields to be converged are fields in the data table to be converged. It should be noted that the data table to be converged can include multiple fields, but the fields to be converged can be part of the fields in the data table to be converged. For example, the execution subject can traverse the topology graph based on the topology graph, that is, take the fields to be converged as the starting vertex during traversal, visit the adjacent nodes along the edges from the vertex, mark the adjacent nodes as downstream fields of the fields to be converged, and then repeat the above steps until all the involved fields in the topology graph are marked, to obtain the marking information. For example, if Filed A1 in Table A is a field to be converged, it is marked first. Then, along the edges, the nodes adjacent to Filed A1 are Filed B1, B3, C1, and C3, which are marked. Then, Filed D1 adjacent to Filed B1 and Filed D3 adjacent to Filed C1 are accessed, and then Filed D1 and Filed D3 are marked.
[0035] In step 203, the downstream fields of the fields to be converged are notified and processed based on the marking information.
[0036] In the embodiment, the execution subject notifies and processes the downstream field of the field to be converged based on the marking information. That is, the execution triggers the authority convergence notification event, and notifies the downstream field of the field to be converged according to the marking information obtained in step 202. Here, the triggering manner can be divided into two kinds: one is timing triggering, that is, the triggering time is declared in advance, and the execution subject triggers the execution at the agreed triggering time according to the preset authority convergence information; the other is API (Application Programming Interface) triggering, that is, the third-party system calls the API to trigger the event notification when the preset condition is met. Through the notification stage of the data authority, all related nodes can perceive the authority change. Then, the execution subject automatically performs the corresponding processing operation according to the event information, for example, automatically offline the field or hands over to the background processing, and the like.
[0037] In step 204, the node corresponding to the field whose processing is successful and the adjacent nodes of the node are deleted in the topology graph.
[0038] In the embodiment, the execution subject can delete the node corresponding to the field whose processing is successful and the adjacent nodes of the node in the topology graph. After the execution subject processes the field to be converged and the downstream field thereof, the execution subject obtains the processing state, if the processing state is processing success, the execution subject deletes the node corresponding to the field whose processing is successful in the topology graph, and traverses upwards from the node, and deletes the adjacent nodes of the node one by one, and repeatedly performs the above operation until all authorities are recycled. For example, the topology graph is traversed first until the node Filed D1 at the end layer of the topology graph, after the node is deleted, the pointer points to Filed B1, and then the node Filed B1 and the edge of the node Filed B1-D1 are deleted, and the process is repeated until all authorities (nodes and edges) are recycled.
[0039] The data authority convergence method provided by the embodiment of the disclosure first constructs the topology graph of the data table to be converged, then marks the related nodes of the field to be converged in the topology graph to obtain marking information, then notifies and processes the downstream field of the field to be converged based on the marking information, and finally deletes the node corresponding to the field whose processing is successful and the adjacent nodes of the node in the topology graph. The data authority convergence method in the embodiment realizes the convergence of the data authority in a systematic way, improves the efficiency of the data authority convergence, saves a large amount of manpower cost, avoids the systematic risk caused in the convergence process of the data authority, and improves the security of the convergence process of the data authority.
[0040] The collection, storage, use, processing, transmission, provision and disclosure of user personal information in the technical solutions of the present disclosure comply with relevant laws and regulations and do not violate public order and good customs.
[0041] With reference to the foregoing Figure 3 , Figure 3 Figure 300 shows a flow of another embodiment of the data authority convergence method according to the present disclosure. The data authority convergence method includes the following steps:
[0042] Step 301: Taking the data table to be converged as the starting vertex of the topology graph, generating the topology graph according to the blood relationship between the fields in the data table to be converged and the fields in other data tables.
[0043] In this embodiment, the execution subject of the data authority convergence method (for example Figure 1 The server 105 shown in the figure will determine the data table to be converged after the obsolete data is offline, that is, determine the data table that needs to be recycled, and take the data table to be converged as the starting vertex of the topology graph, generate the topology graph according to the blood relationship between the fields in the data table to be converged and the fields in other data tables, and the other data tables are data tables having a dependency relationship with the data table to be converged, thereby completing the construction of the topology graph, and the constructed topology graph contains the association relationship between each data table and the association relationship between each field.
[0044] Step 302: Taking the field to be converged as the starting vertex when traversing the topology graph.
[0045] In this embodiment, the above-mentioned execution subject can take the field to be converged as the starting node when traversing the topology graph. Here, the BFS (Breadth-First-Search, Breadth-First-Search) traversal method is generally used to traverse the constructed topology graph, and the field to be converged is taken as the starting vertex when traversing, and the field to be converged is at least one field in the data table to be converged.
[0046] Step 303: Based on the edges in the topology graph starting from the field to be converged, accessing the adjacent nodes of the field to be converged, and marking the adjacent nodes to obtain the marking information.
[0047] In the embodiment, the execution subject can access the adjacent nodes of the field to be converged and mark the adjacent nodes based on the edges in the topology graph starting from the field to be converged, so as to obtain the marking information. That is, the field to be converged is taken as the starting vertex, the adjacent nodes are accessed along the edges of the vertex in the topology graph, the adjacent nodes are taken as the downstream nodes of the field to be converged, the adjacent nodes are marked, and the above operation is repeated until all the fields involved in the topology graph are marked, so as to obtain the marking information. Moreover, in order to improve the access speed, a mapping table is usually used to cache the marked node information. The related nodes of the field to be converged in the topology graph are marked through the above steps, so that the discovery phase of the data authority is completed, and the field-level authority divergence positioning is realized.
[0048] In step 304, the downstream field of the field to be converged is notified and processed based on the marking information.
[0049] In step 305, the nodes corresponding to the fields processed successfully and the adjacent nodes of the fields are deleted in the topology graph.
[0050] Steps 304-305 are basically the same as steps 203-204 in the foregoing embodiment, and the specific implementation mode can be referred to the description of steps 203-204, which will not be described here.
[0051] As can be seen from Figure 3 , compared with Figure 2 the corresponding embodiment, the data authority convergence method in the embodiment highlights the steps of constructing the topology graph and marking the topology graph, so that more accurate construction of the topology graph is realized, the field-level authority divergence positioning is realized, and the convergence efficiency and accuracy of the data authority are improved.
[0052] Continuing to refer to Figure 4 , Figure 4 Fig. 4 shows a flow 400 of still another embodiment of the data authority convergence method according to the present disclosure. The data authority convergence method comprises the following steps:
[0053] In step 401, a data table to be converged is taken as a starting vertex of a topology graph, and the topology graph is generated according to the blood relationship between the fields in the data table to be converged and the fields in other data tables.
[0054] In step 402, a field to be converged is taken as a starting vertex when traversing the topology graph.
[0055] In step 403, adjacent nodes of the field to be converged are accessed and marked based on the edges in the topology graph starting from the field to be converged, so as to obtain marking information.
[0056] Steps 401-403 are substantially identical to steps 301-303 of the foregoing embodiment, and the specific implementation can refer to the foregoing description of steps 301-303, which will not be described here again.
[0057] Step 404, record the topological depth information of each marked node in the topological graph from the field to be converged.
[0058] In the present embodiment, the execution subject of the data authority convergence method (for example Figure 1 The server 105 shown in the figure records the topological depth information of each marked node in the topological graph from the field to be converged. When marking the field to be converged, the execution subject records the topological depth of the field to be converged as 0. If the adjacent node of the field to be converged node Filed A1 is Filed B2, then the topological depth of Filed B2 is 1. If the node Filed C3 is the adjacent node of the node Filed B2, then the topological depth of Filed C3 is 2. By recording the topological depth information of the marked node, necessary information can be provided for the subsequent convergence process.
[0059] Step 405, obtain the pre-registered meta information of each data table.
[0060] In the present embodiment, the execution subject obtains the pre-registered meta information of each data table. Each data table pre-registers meta information in the system, which can include table responsible person, associated system, associated account, etc. Similarly, the fields in the data table can also pre-register information, and the priority of the meta information in the present embodiment is field level > table level.
[0061] Step 406, based on the marking information and the blood relationship between the fields in the data table to be converged and the fields in other data tables, match the meta information with each field.
[0062] In the present embodiment, after obtaining the meta information in batches, the execution subject matches the obtained meta information with each field based on the marking information and the blood relationship between the fields in the data table to be converged and the fields in other data tables, thereby providing necessary information for the subsequent convergence process.
[0063] Step 407, notify and process each field based on the topological depth information and the meta information.
[0064] In the present embodiment, the execution subject can notify and process each field based on the topological depth information and the meta information. That is, after completing the matching, the execution subject triggers the authority convergence notification event, thereby notifying each field based on the topological depth information. The event notification order is: according to the topological depth information of each field, the notification is performed in order from high to low, thereby completing the triggering process.
[0065] For the notification of the field association system, the notification source is a callback API provided by the business system, through which the entire system can receive an event and automatically perform a corresponding processing operation according to the event information, for example, automatically offline a field or hand over to a background processing, and finally the processing state is fed back through the callback API. For the notification of the field association responsible person, the notification source can be a short message, an email, a communication software, and the like.
[0066] Regardless of the notification, after the above execution subject notifies each field, the above execution subject automatically processes each field.
[0067] Step 408, obtaining the processing state of each field.
[0068] In the embodiment, the above execution subject can obtain the processing state of each field. After the above execution subject notifies and processes each field, the above execution subject also obtains the processing state of each field. Specifically, the above execution subject can return the processing state through the callback API and perform a corresponding operation according to the processing state, wherein the processing state can include processing, processing completed, and processing failed.
[0069] In some optional embodiments of the embodiment, in response to the processing state being processing, the processing flow stops at the node until the processing state becomes processing success or processing failure; in response to the processing state being processing failure, the node is notified and processed again.
[0070] In the implementation, if the returned processing state is processing, the recycling process of the system will be blocked at the node until the processing state of the node flows to a terminal value, that is, processing success or processing failure. However, in order to improve the processing efficiency, nodes with the same topology depth can be executed in parallel. If the returned processing state is processing failure, the above execution subject will trigger the notification and processing again. Thus, the nodes with different processing states are operated.
[0071] Step 409, in response to the processing state being processing success, deleting the node corresponding to the field with processing success in the topology graph.
[0072] In the embodiment, if the processing state is processing success, the above execution subject will delete the node corresponding to the field with processing success in the topology graph, thereby indicating that the processing of the node is completed.
[0073] Step 410, deleting the adjacent nodes of the node based on the marking information.
[0074] In the embodiment, the execution subject can delete the adjacent nodes of the node whose processing is successful based on the marking information. After a certain node is deleted, the execution subject traces upwards according to the marking information, deletes the adjacent nodes after caching the adjacent nodes, deletes the edges of the two nodes, and repeatedly executes the above operations until all the permissions (nodes and edges) are recycled, thereby completing the recycling phase of the data permissions and recycling all the associated data fields.
[0075] As can be seen from Figure 4 , compared with the embodiment corresponding to Figure 3 , the convergence method of the data permissions in the embodiment highlights the steps of notifying and processing the downstream fields of the field to be converged and deleting the nodes corresponding to the field whose processing is successful and the adjacent nodes of the field in the topology graph, thereby automatically notifying and processing in combination with the blood relationship of the field, further improving the convergence efficiency of the data permissions, ensuring the effective convergence of the data permissions, and improving the stability of the data business system.
[0076] Further referring to Figure 5 , as an implementation of the method shown in the above figures, the disclosure provides an embodiment of a data permission convergence device, which corresponds to the method embodiment shown in Figure 2 . The device can be applied to various electronic devices.
[0077] As shown in Figure 5 , the data permission convergence device 500 of the embodiment includes a construction module 501, a marking module 502, a notification module 503, and a deletion module 504. The construction module 501 is configured to construct a topology graph of a data table to be converged, wherein the topology graph is used to represent the association relationship between the data table to be converged and other data tables and the association information between the fields in the data table to be converged and the fields in other data tables, and the other data tables are data tables having a dependency relationship with the data table to be converged; the marking module 502 is configured to mark the related nodes of the field to be converged in the topology graph to obtain marking information, wherein the field to be converged is a field in the data table to be converged; the notification module 503 is configured to notify and process the downstream fields of the field to be converged based on the marking information; and the deletion module 504 is configured to delete the nodes corresponding to the field whose processing is successful and the adjacent nodes of the node in the topology graph.
[0078] In the embodiment, the data permission convergence device 500 includes the construction module 501, the marking module 502, the notification module 503, and the deletion module 504, and the specific processing and the technical effects brought by the modules can be respectively referred to the related descriptions of steps 201-204 in the corresponding embodiment, which will not be described herein again. Figure 2 In the embodiment, the data permission convergence device 500 includes the construction module 501, the marking module 502, the notification module 503, and the deletion module 504, and the specific processing and the technical effects brought by the modules can be respectively referred to the related descriptions of steps 201-204 in the corresponding embodiment, which will not be described herein again.
[0079] In some optional implementation forms of the embodiment, the constructing module comprises a constructing submodule configured to take the data table to be converged as a starting vertex of the topological graph, and generate the topological graph according to the blood relationship between the fields in the data table to be converged and the fields in other data tables.
[0080] In some optional implementation forms of the embodiment, the marking module comprises a marking submodule configured to take the field to be converged as a starting vertex when traversing the topological graph, and access the adjacent nodes of the field to be converged based on the edges in the topological graph starting from the field to be converged, and mark the adjacent nodes to obtain the marking information.
[0081] In some optional implementation forms of the embodiment, the data permission converging apparatus 500 further comprises a recording module configured to record the topological depth information of each marked node in the topological graph from the field to be converged.
[0082] In some optional implementation forms of the embodiment, the notifying module comprises an obtaining submodule configured to obtain the pre-registered meta information of each data table, a matching submodule configured to match the meta information with each field based on the marking information and the blood relationship between the fields in the data table to be converged and the fields in other data tables, and a notifying submodule configured to notify and process each field based on the topological depth information and the meta information.
[0083] In some optional implementation forms of the embodiment, the data permission converging apparatus 500 further comprises an obtaining module configured to obtain the processing state of each field, a first processing module configured to, in response to the processing state being in processing, stop the processing flow at the node until the processing state changes to processing success or processing failure, and a second processing module configured to, in response to the processing state being processing failure, re-notify and process the node.
[0084] In some optional implementation forms of the embodiment, the deleting module comprises a first deleting submodule configured to, in response to the processing state being processing success, delete the node corresponding to the field with processing success in the topological graph, and a second deleting submodule configured to delete the adjacent nodes of the node based on the marking information.
[0085] According to the embodiments of the present disclosure, the present disclosure further provides an electronic device, a readable storage medium and a computer program product.
[0086] Figure 6A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present disclosure described and / or claimed in this document.
[0087] As shown in Figure 6 The device 600 includes a computing unit 601 that can perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 602 or a computer program loaded into a random access memory (RAM) 603 from a storage unit 608. Various programs and data required for the operation of the device 600 can also be stored in the RAM 603. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0088] Various components in the device 600 are connected to the I / O interface 605, including an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; the storage unit 608, such as a magnetic disk, an optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the device 600 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0089] The computing unit 601 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs various methods and processes described above, such as the convergence method of data authority. For example, in some embodiments, the convergence method of data authority can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded onto the RAM 603 and executed by the computing unit 601, one or more steps of the convergence method of data authority described above can be performed. Alternatively, in other embodiments, the computing unit 601 can be configured to perform the convergence method of data authority by any other suitable means, such as by means of firmware.
[0090] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0091] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces the functions / operations specified in the flowcharts and / or the block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0092] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0093] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0094] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0095] Cloud computer refers to a technology system that accesses elastic and scalable shared physical or virtual resource pools through a network, the resources can include servers, operating systems, networks, software, applications or storage devices, etc., and the resources can be deployed and managed in a demand-based and self-service manner. Through cloud computing technology, efficient and powerful data processing capabilities can be provided for artificial intelligence, blockchain and other technical applications and model training.
[0096] The computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, or a server of a distributed system, or a server combined with a blockchain.
[0097] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, the steps described in the present disclosure can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present disclosure can be achieved, which is not limited herein.
[0098] The above detailed description does not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements within the spirit and principles of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. A method for converging data permissions, comprising: constructing a topology graph of a data table to be converged, wherein the topology graph is used to represent an association between the data table to be converged and other data tables and association information between fields in the data table to be converged and fields in the other data tables, the other data tables being data tables having a dependency relationship with the data table to be converged; labeling relevant nodes of a field to be converged in the topology graph, to obtain label information, wherein the field to be converged is a field in the data table to be converged; recording topology depth information of each labeled node in the topology graph from the field to be converged; notifying and processing downstream fields of the field to be converged based on the label information, including: notifying and processing the downstream fields in order from high to low according to topology depth information of each of the downstream fields; deleting nodes corresponding to the fields for which processing is successful and adjacent nodes of the nodes in the topology graph.
2. The method of claim 1, wherein, The constructing of the topology graph of the data table to be converged comprises: taking the data table to be converged as a starting vertex of the topology graph, and generating the topology graph according to blood relationship between fields in the data table to be converged and fields in other data tables.
3. The method of claim 1, wherein, The labeling of the relevant nodes of the field to be converged in the topology graph to obtain label information comprises: taking the field to be converged as a starting vertex when traversing the topology graph; based on edges from the field to be converged in the topology graph, accessing adjacent nodes of the field to be converged, and labeling the adjacent nodes to obtain label information.
4. The method of claim 3, wherein, The notifying and processing of the downstream fields of the field to be converged based on the label information further comprises: obtaining pre-registered meta information of each data table; matching the meta information with each field based on the label information and the blood relationship between the fields in the data table to be converged and the fields in other data tables; notifying and processing each field based on the topology depth information and the meta information. 5.The method of any one of claims 1-4, further comprising: obtaining a processing state of each field; in response to the processing state being in processing, stopping the processing flow at the node until the processing state changes to processing success or processing failure; in response to the processing state being processing failure, re-notifying and processing the node.
6. The method of claim 5, wherein, The deleting of the nodes corresponding to the fields for which processing is successful and the adjacent nodes of the nodes in the topology graph comprises: in response to the processing state being processing success, deleting the nodes corresponding to the fields for which processing is successful in the topology graph; deleting the adjacent nodes of the nodes based on the label information. 7.A device for converging data permissions, comprising: a constructing module configured to construct a topology graph of a data table to be converged, wherein the topology graph is used to represent an association between the data table to be converged and other data tables and association information between fields in the data table to be converged and fields in the other data tables, the other data tables being data tables having a dependency relationship with the data table to be converged; a marking module, configured to mark relevant nodes of a to-be-converged field in the topology graph to obtain marking information, wherein the to-be-converged field is a field in the to-be-converged data table; a recording module, configured to record topology depth information of each marked node in the topology graph from the to-be-converged field; a notification module, configured to notify and process downstream fields of the to-be-converged field based on the marking information, including: notifying in turn according to topology depth information of each downstream field in descending order; a deletion module, configured to delete nodes corresponding to fields for which processing is successful and adjacent nodes of the nodes in the topology graph.
8. The apparatus of claim 7, wherein, The construction module includes: a construction submodule, configured to take the to-be-converged data table as a starting vertex of a topology graph, and generate the topology graph according to blood relationship between fields in the to-be-converged data table and fields in other data tables.
9. The apparatus of claim 7, wherein, The marking module includes: a starting vertex submodule, configured to take the to-be-converged field as a starting vertex when traversing the topology graph; a marking submodule, configured to access adjacent nodes of the to-be-converged field based on edges in the topology graph from the to-be-converged field, and mark the adjacent nodes to obtain marking information.
10. The apparatus of claim 9, wherein, The notification module includes: an acquisition submodule, configured to acquire pre-registered meta information of each data table; a matching submodule, configured to match the meta information with each field based on the marking information and blood relationship between fields in the to-be-converged data table and fields in other data tables; a notification submodule, configured to notify and process each field based on the topology depth information and the meta information.
11. The apparatus according to any one of claims 7-10, further comprising: an acquisition module, configured to acquire a processing state of each field; a first processing module, configured to, in response to the processing state being processing, stop the processing flow at the node until the processing state changes to processing success or processing failure; a second processing module, configured to, in response to the processing state being processing failure, renotify and process the node.
12. The apparatus of claim 11, wherein, The deletion module includes: a first deletion submodule, configured to, in response to the processing state being processing success, delete nodes corresponding to fields for which processing is successful in the topology graph; a second deletion submodule, configured to delete adjacent nodes of the nodes based on the marking information.
13. An electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method in any one of claims 1-6.
14. A non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method in any one of claims 1-6.
15. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-6.
Citation Information
Patent Citations
Data offline method and system based on tasks and fields
CN111930734A
Data topology generation method and device, electronic equipment and storage medium
CN113656407A