Data access control method, apparatus, device, and storage medium

By acquiring data access requests and determining the target object's access template based on the association between the access object information and the template, and configuring permissions, the problem of inflexible control of data access permissions in existing technologies is solved, and flexible data access permission management is achieved.

CN115238291BActive Publication Date: 2026-04-07PING AN TECH (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-29
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies cannot provide flexible data access control methods, especially in the process of cross-organizational or cross-position business data interaction in large enterprises, and cannot meet the needs of various business scenarios.

Method used

By acquiring data access requests, and based on the pre-determined association between access object information and object access templates, the target object access template corresponding to the target access object information is determined. Data access permissions are then configured based on the data information to be accessed, and an access permission control model is established to control data access of the target access object.

Benefits of technology

It improves the flexibility of data access control, enabling flexible management and configuration according to the needs of different business scenarios, and meeting the data access control requirements across organizations or positions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115238291B_ABST
    Figure CN115238291B_ABST
Patent Text Reader

Abstract

The method, device, equipment and storage medium provided by the embodiment of the application can solve the problem that the prior art cannot provide a flexible data access permission control method, and aim to improve the flexibility of data access permission control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a data access control method, apparatus, device, and storage medium. Background Technology

[0002] Data access control, especially row level security, is a feature that almost all data-related products, such as BI tools, data dashboards, and self-service analysis systems, must consider to ensure data security.

[0003] Currently, common data access control methods are designed based on organizational structure (e.g., HR structure), primarily setting access permissions based on whether the user is an internal employee or holds a similar position. However, large enterprises often involve significant restructuring and complex business management processes, frequently requiring cross-organizational or cross-positional data interactions. This poses a significant challenge to existing data access control methods, making them inflexible in meeting the diverse business scenarios of different enterprises. Therefore, providing flexible data access control methods is a pressing technical issue that needs to be addressed. Summary of the Invention

[0004] In view of this, embodiments of this application provide a data access control method, apparatus, device, and storage medium to solve the problem that the prior art cannot provide a flexible data access control method, aiming to improve the flexibility of data access control.

[0005] A first aspect of this application provides a data access control method, the method comprising:

[0006] Obtain a data access request, the data access request carrying target access object information and data information to be accessed;

[0007] Based on the pre-determined association between access object information and object access template, the target object access template corresponding to the target access object information is determined;

[0008] Based on the data information to be accessed, data access permissions are configured for the target object access template to obtain an access permission control model;

[0009] Based on the access control model, the target access object is controlled to access data.

[0010] A second aspect of this application provides a data access control device, the device comprising:

[0011] The acquisition module is used to acquire data access requests, which carry target access object information and data information to be accessed;

[0012] The determination module is used to determine the target object access template corresponding to the target access object information based on the pre-determined association relationship between the access object information and the object access template;

[0013] The configuration module is used to configure data access permissions for the target object access template based on the data information to be accessed, thereby obtaining an access permission control model;

[0014] The control module is used to control the target access object to access data according to the access permission control model.

[0015] A third aspect of this application provides a data access control device, including a memory, a processor, and a computer program stored in the memory and executable on the data access control device. When the processor executes the computer program, it implements the steps of the data access control method provided in the first aspect.

[0016] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the data access control method provided in the first aspect.

[0017] The first aspect of this application provides a data access control method, which, compared with the prior art, includes: acquiring a data access request, the data access request carrying target access object information and data to be accessed; determining a target object access template corresponding to the target access object information based on a pre-determined association between the access object information and the object access template; configuring data access permissions for the target object access template based on the data to be accessed to obtain an access permission control model; and controlling the target access object to access data according to the access permission control model. By determining the target object access template corresponding to the target access object information based on a pre-determined association between the access object information and the object access template, and then configuring data access permissions for the target object access template based on the data to be accessed, the method can improve the flexible management of data access permissions. Furthermore, by controlling the target access object to access data according to the configured access permission control model, it solves the problem that the prior art cannot provide flexible data access permission control methods, aiming to improve the flexibility of data access permission control.

[0018] The beneficial effects provided by the second to fourth aspects of the embodiments of this application are the same as those provided by the first aspect of the embodiments of this application, and will not be repeated here. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating the implementation of a data access control method provided in an embodiment of this application;

[0021] Figure 2 This is a schematic diagram of a scenario illustrating a data access control method provided in an embodiment of this application;

[0022] Figure 3 yes Figure 1 The detailed implementation flowchart of S103 in the middle;

[0023] Figure 4 This is a schematic diagram illustrating the implementation flow of a data access control method provided in another embodiment of this application;

[0024] Figure 5 yes Figure 4 A schematic diagram illustrating the specific implementation process of S403 in China;

[0025] Figure 6 This is a structural block diagram of the data access control device provided in the embodiments of this application;

[0026] Figure 7 This is a structural block diagram of the data access control device provided in the embodiments of this application. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0028] The data access control method involved in the embodiments of this application can be executed by a data access control device. The data access control device includes, but is not limited to, a terminal or a server. The server can be a single server or a cloud server cluster, etc., and the terminal can be a personal digital device, laptop, desktop computer, smart wearable device, or robot, etc. No specific limitations are made here.

[0029] The data access control method involved in this application involves obtaining a data access request, which carries target access object information and data to be accessed; determining a target object access template corresponding to the target access object information based on a pre-determined association between the access object information and the object access template; configuring data access permissions for the target object access template based on the data to be accessed to obtain an access permission control model; and controlling the target access object to access data according to the access permission control model. This method achieves the determination of the target object access template corresponding to the target access object information based on a pre-determined association between the access object information and the object access template, and further improves the flexible management of data access permissions by configuring data access permissions for the target object access template based on the data to be accessed. Furthermore, it controls the target access object to access data according to the configured access permission control model, thereby solving the problem that existing technologies cannot provide flexible data access permission control methods and aiming to improve the flexibility of data access permission control.

[0030] The data access control method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0031] Please see Figure 1 As shown, Figure 1 This is a flowchart illustrating the implementation of a data access control method according to an embodiment of this application. The data access control method provided in this embodiment can be implemented by a data access control device. This data access control device can be a terminal, and / or a server. The terminal includes, but is not limited to, personal laptops, handheld terminals, wearable smartwatches, or robots; the server can be a single server, a server cluster, a cloud server, etc. In other words, the data access control method provided in this embodiment can be applied to any device with data processing capabilities, or it can be completed interactively by multiple devices with data processing capabilities.

[0032] For example, such as Figure 2 As shown, Figure 2 This is a schematic diagram illustrating a scenario of a data access control method provided in an embodiment of this application. Figure 2As can be seen, in this embodiment, the data access control method can be implemented through interaction between the terminal and the server. Specifically, the terminal 202 is used to obtain a data access request and send the data access request to the server 204. The server 204 is used to determine the target object access template corresponding to the target access object information based on the pre-determined association between access object information and object access template; based on the data information to be accessed, it configures data access permissions for the target object access template to obtain an access permission control model; and according to the access permission control model, it controls the target access object to access data. Further, after controlling the target access object to access data, the server 204 returns the data access result to the terminal 202 to achieve flexibility in data access permission control.

[0033] It should be understood that, in practical implementation, if the terminal has strong data processing capabilities, the entire data access control process described above can be directly completed by the terminal device. If the terminal's data processing capabilities are limited, in order to improve the efficiency of data access, the terminal can send the acquired data access requests to the server for processing. Alternatively, the entire data access control process can be directly completed by the server. Specifically, the method needs to be determined based on the actual scenario, and no limitations are made here.

[0034] Depend on Figure 1 As can be seen, the data access control method provided in this embodiment includes steps S101 to S104.

[0035] Details are as follows:

[0036] S101, Obtain a data access request, the data access request carrying target access object information and data information to be accessed.

[0037] The target access object information includes the identity and affiliation information of the access object initiating the data access request. Specifically, the identity information of the access object includes, but is not limited to, information that can be used to uniquely identify the user, such as ID card information, mobile phone number information, and driver's license information. The affiliation information includes the name of the user's organization, their position within the organization, and their superior-subordinate relationship information. Specifically, the organization name includes the company name or department name, etc.; the position information includes job title information, business line information, and customer type information, etc.; and the superior-subordinate relationship information includes information about the organization's superior.

[0038] The data to be accessed includes the type of data to be accessed, such as database data, memory data, or data specific to a particular business scenario.

[0039] S102, based on the pre-determined association between the access object information and the object access template, determine the target object access template corresponding to the target access object information.

[0040] S103, Based on the data information to be accessed, configure data access permissions for the target object access template to obtain an access permission control model.

[0041] Specifically, the access control model includes access control configuration results and access control scenario configuration results.

[0042] In practice, access control models for the corresponding data to be accessed can be obtained by configuring the target object access template.

[0043] For example, in one embodiment, the target object access template includes an access permission configuration module and an access permission control scenario configuration module.

[0044] Specifically, the access permission configuration module includes a first input box and / or a first selection item. The first input box is used for the user to input an access permission request for the data to be accessed. After the data access control device detects the user's access permission request, it performs corresponding access permission verification and permission configuration, and displays the configured access permission configuration result through the access permission configuration module so that the user can view the access permissions for the data to be accessed.

[0045] The first option includes a dropdown menu, which allows users to select the access permission request for the corresponding data to be accessed.

[0046] The access control scenario configuration module includes a second input box and / or a second selection item. The second input box is used for the user to input the data application scenario information corresponding to the current access request. After the data access control device detects the data application scenario information input by the user, it performs the corresponding access permission verification and control scenario configuration, and displays the configured access control scenario configuration result through the access control scenario configuration module so that the user can view the access permission control scenario for the data to be accessed.

[0047] In the above embodiments, users can configure modules and access control scenarios based on access permissions, configure modules to configure access permissions and access control scenarios for data to be accessed, improve the flexibility of access permission management and adaptability to business scenarios.

[0048] In another embodiment, such as Figure 3 As shown, Figure 3 yes Figure 1 The detailed implementation flowchart of S103. Figure 3As can be seen, in this embodiment, S103 includes S1031 to S1034. Details are as follows:

[0049] S1031, parse the data information to be accessed and determine the first data access permission of the data information to be accessed.

[0050] The first data access request is the preset access permission information corresponding to the data to be accessed. This access permission information is set according to the organization or position to which the access object belongs. When the current access object is in a more complex business scenario, such as when it is conducting legitimate business interactions across organizations, it is not possible to flexibly access the data to be accessed.

[0051] S1032, Based on the first data access permission, configure the second data access permission for the access permission configuration module.

[0052] Specifically, it is necessary to determine whether the first data access permission supports the current data request to be accessed. If not, a second data access permission needs to be configured in the access permission configuration module so that the configured second data access permission supports the current data request to be accessed. This enables flexible configuration of data access permissions according to business scenario needs.

[0053] S1033, Configure the access control scenario for the access control scenario configuration module according to the target access object information and the first data access permission.

[0054] The access control scenarios include access address, access type, and the amount of accessed data.

[0055] Specifically, the access address includes the starting and ending addresses; the access type includes database type, memory type, and other scenario types; and the size of the accessed data includes the percentage of the total data.

[0056] S1034, Based on the configured second data access permission and the access permission control scenario, the access permission control model is obtained.

[0057] S104, according to the access control model, control the target access object to access data.

[0058] In one embodiment, controlling the target access object to access data according to the access permission control model includes: controlling the target access object to access data within the access address that meets the access data size based on the access type, according to the second data access permission.

[0059] As can be seen from the above analysis, the data access control method provided in this application includes: obtaining a data access request, wherein the data access request carries target access object information and data to be accessed; determining a target object access template corresponding to the target access object information based on a predetermined association between the access object information and the object access template; configuring data access permissions for the target object access template based on the data to be accessed to obtain an access permission control model; and controlling the target access object to access data according to the access permission control model. By determining the target object access template corresponding to the target access object information based on a predetermined association between the access object information and the object access template, and then configuring data access permissions for the target object access template based on the data to be accessed, the flexible management of data access permissions can be improved. Furthermore, by controlling the target access object to access data according to the configured access permission control model, the problem of the inability to provide flexible data access permission control methods in the prior art can be solved, aiming to improve the flexibility of data access permission control.

[0060] Please see Figure 4 As shown, Figure 4 This is a schematic diagram illustrating the implementation flow of a data access control method provided in another embodiment of this application. Figure 4 It can be seen that this embodiment is similar to... Figure 1 Compared to the previous embodiment, S401 and S101, as well as S406 to S408 and S102 to S104, are implemented in the same way. The difference lies in the inclusion of S402 to S405 before S406. Details are as follows:

[0061] S401, Obtain a data access request, the data access request carrying target access object information and data information to be accessed.

[0062] S402, obtain the access object information of each pre-determined access object, and determine the access link of each access object to the data and the access permission corresponding to each access link.

[0063] S403, based on the access links and the access permissions of each access link, determine the access permission configuration information and access permission control scenario configuration information of each access object.

[0064] For example, such as Figure 5 As shown, Figure 5 yes Figure 4 A schematic diagram illustrating the specific implementation process of S403. Figure 5 As can be seen, in this embodiment, S403 specifically includes S4031 to S4034. Details are as follows:

[0065] S4031, obtain the access address corresponding to each access link and the access permission description information corresponding to the access address.

[0066] S4032, determine whether the access permission description information corresponding to each access link matches the access permission.

[0067] S4033, if a match is found, then based on the access permissions, determine the access permission configuration information and access permission control scenario configuration information for each access object.

[0068] S4034, if there is no match, then based on the access permission description information, determine the access permission configuration information and access permission control scenario configuration information for each access object.

[0069] S404, Configure the object access template corresponding to each of the access objects according to the access permission configuration information and access permission control scenario configuration information of each access object.

[0070] S405, Based on the object access template and the corresponding access object information corresponding to each access object, establish the association between the access object information and the object access template.

[0071] S406, Based on the association between the access object information and the object access template, determine the target object access template corresponding to the target access object information.

[0072] S407, Based on the data information to be accessed, configure data access permissions for the target object access template to obtain an access permission control model.

[0073] S408, according to the access control model, control the target access object to access data.

[0074] As can be seen from the above analysis, the data access control method provided in this application embodiment determines the association between access object information and object access template, and then determines the target object access template corresponding to the target access object information based on the determined corresponding association. Furthermore, based on the data information to be accessed, data access permissions are configured for the target object access template, which can improve the flexible management of data access permissions. Then, according to the configured access permission control model, the target access object is controlled to access data, so as to solve the problem that the prior art cannot provide a flexible data access permission control method, and aims to improve the flexibility of data access permission control.

[0075] Please see Figure 6 As shown, Figure 6This is a structural block diagram of the data access control device provided in this application embodiment. The data access control device 600 in this embodiment can be deployed in a server or terminal for flexible control of data access. Specifically, the modules included in the data access control device 600 are used to execute the steps in the above method embodiments. Please refer to [link to documentation] for details. Figures 1 to 5 The relevant descriptions in the corresponding embodiments are provided. The functions of the data access control device 600 can be implemented by software or hardware within the server or terminal. Specifically, the functions of the data access control device 600 can be logically divided into different modules. For ease of explanation, only the parts relevant to this embodiment are shown. See also... Figure 6 The data access control device 600 includes:

[0076] Acquisition module 601 is used to acquire data access requests, wherein the data access requests carry target access object information and data information to be accessed;

[0077] The first determining module 602 is used to determine the target object access template corresponding to the target access object information based on the pre-determined association relationship between the access object information and the object access template.

[0078] The first configuration module 603 is used to configure data access permissions for the target object access template based on the data information to be accessed, so as to obtain an access permission control model.

[0079] The control module 604 is used to control the target access object to access data according to the access permission control model.

[0080] In one embodiment, the target object access template includes an access permission configuration module and an access permission control scenario configuration module.

[0081] In one embodiment, the first configuration module 603 includes:

[0082] The parsing unit is used to parse the data information to be accessed and determine the first data access permission of the data information to be accessed;

[0083] The first configuration unit is used to configure the second data access permission for the access permission configuration module according to the first data access permission;

[0084] The second configuration unit is used to configure the access control scenario for the access control scenario configuration module according to the target access object information and the first data access permission;

[0085] The obtaining unit is used to obtain the access control model based on the configured second data access permission and the access control scenario.

[0086] In one embodiment, the access control scenario includes access address, access type, and the amount of accessed data.

[0087] In one embodiment, the control module 604 is specifically used for:

[0088] Based on the second data access permission, the target access object is controlled to access data within the access address that meets the access data size requirement, according to the access type.

[0089] In one embodiment, the data access control device 600 further includes:

[0090] The second determining module is used to obtain the access object information of each pre-determined access object, determine the access link of each access object to the data and the access permission corresponding to each access link;

[0091] The third determining module is used to determine the access permission configuration information and access permission control scenario configuration information of each access object based on the access link and the access permissions of each access link;

[0092] The second configuration module is used to configure the object access template corresponding to each of the access objects according to the access permission configuration information and access permission control scenario configuration information of each of the access objects;

[0093] The module is used to establish the association between the access object information and the object access template based on the object access template and the corresponding access object information for each access object.

[0094] In one embodiment, the third determining module includes:

[0095] The acquisition unit is used to acquire the access address corresponding to each access link and the access permission description information corresponding to the access address;

[0096] The fourth determining unit is used to determine whether the access permission description information corresponding to each access link matches the access permission;

[0097] The fifth determining unit is used to determine, if a match is found, the access permission configuration information and access permission control scenario configuration information of each access object based on the access permissions.

[0098] The sixth determining unit is used to determine the access permission configuration information and access permission control scenario configuration information of each access object based on the access permission description information if there is no match.

[0099] It should be understood that, Figure 6In the structural block diagram of the data access control device 600 shown, each module is used to perform... Figures 1 to 5 The steps in the corresponding embodiments, and for Figures 1 to 5 The steps in the corresponding embodiments have been explained in detail in the above embodiments. Please refer to them for details. Figures 1 to 5 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0100] Please see Figure 7 As shown, Figure 7 This is a structural block diagram of the data access control device provided in an embodiment of this application. For example... Figure 7 As shown, the data access control device 700 of this embodiment includes: a processor 710, a memory 720, and a computer program 730, such as a data access control program, stored in the memory 720 and executable on the processor 710. When the processor 710 executes the computer program 730, it implements the steps of the various embodiments of the data access control methods described above, for example... Figures 1 to 5 The steps shown. Alternatively, the processor 710 may implement the above when executing the computer program 730. Figure 6 The functions of each module or unit in the corresponding embodiments, for example, Figure 6 For details on the functions of modules 601 to 604 shown, please refer to [link / reference]. Figure 6 The relevant descriptions in the corresponding embodiments are not repeated here.

[0101] For example, the computer program 730 can be divided into one or more units, which are stored in the memory 720 and executed by the processor 710 to complete this application. The one or more units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program 730 in the data access control device 700. For example, the computer program 730 can be divided into: an acquisition module, a first determination module, a first configuration module, and a control module; the specific functions of each module are as follows: Figure 6 As stated above.

[0102] The data access control device 700 may include, but is not limited to, a processor 710 and a memory 720. Those skilled in the art will understand that... Figure 7 This is merely an example of a data access control device 700 and does not constitute a limitation on the data access control device 700. It may include more or fewer components than shown, or combine certain components, or different components. For example, the data access control device 700 may also include input / output devices, network access devices, buses, etc.

[0103] The processor 710 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0104] In one embodiment, the processor is configured to run a computer program stored in memory to perform the following steps:

[0105] Obtain a data access request, the data access request carrying target access object information and data information to be accessed;

[0106] Based on the pre-determined association between access object information and object access template, the target object access template corresponding to the target access object information is determined;

[0107] Based on the data information to be accessed, data access permissions are configured for the target object access template to obtain an access permission control model;

[0108] Based on the access control model, the target access object is controlled to access data.

[0109] In one embodiment, the target object access template includes an access permission configuration module and an access permission control scenario configuration module.

[0110] In one embodiment, configuring data access permissions for the target object access template based on the data to be accessed, to obtain an access permission control model, includes:

[0111] Parse the data information to be accessed and determine the first data access permission of the data information to be accessed;

[0112] Based on the first data access permission, configure the second data access permission for the access permission configuration module;

[0113] Based on the target access object information and the first data access permission, configure the access permission control scenario for the access permission control scenario configuration module;

[0114] The access control model is obtained based on the configured second data access permission and the access control scenario.

[0115] In one embodiment, the access control scenario includes access address, access type, and the amount of accessed data.

[0116] In one embodiment, controlling the target access object to access data according to the access control model includes:

[0117] Based on the second data access permission, the target access object is controlled to access data within the access address that meets the access data size requirement, according to the access type.

[0118] In one embodiment, before determining the target object access template corresponding to the target access object information based on the predetermined association between access object information and object access templates, the method further includes:

[0119] Obtain the access object information of each pre-determined access object, determine the access link of each access object to the data and the access permissions corresponding to each access link;

[0120] Based on the access links and the access permissions of each access link, determine the access permission configuration information and access permission control scenario configuration information of each access object;

[0121] Configure the object access template corresponding to each of the access objects based on the access permission configuration information and access permission control scenario configuration information of each access object;

[0122] Based on the object access template and the corresponding access object information for each access object, establish the association between the access object information and the object access template.

[0123] In one embodiment, determining the access permission configuration information and access permission control scenario configuration information for each access object based on the access link and the access permissions of each access link includes:

[0124] Obtain the access address corresponding to each access step and the access permission description information corresponding to the access address;

[0125] Determine whether the access permission description information corresponding to each access step matches the access permission;

[0126] If a match is found, then based on the access permissions, determine the access permission configuration information and access permission control scenario configuration information for each access object;

[0127] If there is a mismatch, then based on the access permission description information, determine the access permission configuration information and access permission control scenario configuration information for each access object.

[0128] The memory 720 can be an internal storage unit of the data access control device 700, such as a hard disk or memory of the data access control device 700. The memory 720 can also be an external storage device of the data access control device 700, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the data access control device 700. Furthermore, the memory 720 can include both internal storage units and external storage devices of the data access control device 700. The memory 720 is used to store the computer program and other programs and data required by the data access control device 700. The memory 720 can also be used to temporarily store data that has been output or will be output.

[0129] The embodiments of this application also provide a computer-readable storage medium storing a computer program, the computer program including program instructions, and the processor executing the program instructions to implement the steps of the data access control method provided in the above embodiments of this application.

[0130] The computer-readable storage medium can be an internal storage unit of the data access control device described in the foregoing embodiments, such as the hard disk or memory of the data access control device. Alternatively, the computer-readable storage medium can be an external storage device of the data access control device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the data access control device.

[0131] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A data access control method, characterized in that, The method includes: Obtain a data access request, the data access request carrying target access object information and data information to be accessed; Based on the pre-determined association between access object information and object access template, the target object access template corresponding to the target access object information is determined; Based on the data information to be accessed, data access permissions are configured for the target object access template to obtain an access permission control model; The target object access template includes an access permission configuration module and an access permission control scenario configuration module, and the access permission control model includes access permission configuration results and access permission control scenario configuration results. Based on the access control model, control the data access of the target access object; The access permission configuration module includes a first input box, which is used for users to input access permission requests for the data to be accessed. After the data access control device detects the access permission requests input by the user, it performs corresponding access permission verification and permission configuration, and displays the configured access permission configuration results through the access permission configuration module so that users can view the access permissions to the data to be accessed. The access control scenario configuration module includes a second input box, which is used for the user to input the data application scenario information corresponding to the current access request. After the data access control device detects the data application scenario information input by the user, it performs the corresponding access permission verification and control scenario configuration, and displays the configured access control scenario configuration result through the access control scenario configuration module so that the user can view the access permission control scenario for the data to be accessed. The access control scenarios include access address, access type, and the amount of data accessed.

2. The data access control method as described in claim 1, characterized in that, The step of configuring data access permissions for the target object access template based on the data information to be accessed, to obtain an access permission control model, includes: Parse the data information to be accessed and determine the first data access permission of the data information to be accessed; Based on the first data access permission, configure the second data access permission for the access permission configuration module; Based on the target access object information and the first data access permission, configure the access permission control scenario for the access permission control scenario configuration module; The access control model is obtained based on the configured second data access permission and the access control scenario.

3. The data access control method according to claim 2, characterized in that, The step of controlling the target access object to access data according to the access control model includes: Based on the second data access permission, the target access object is controlled to access data within the access address that meets the access data size requirement, according to the access type.

4. The data access control method as described in claim 1, characterized in that, Before determining the target object access template corresponding to the target access object information based on the predetermined association between the access object information and the object access template, the method further includes: Obtain the access object information of each pre-determined access object, determine the access link of each access object to the data and the access permissions corresponding to each access link; Based on the access links and the access permissions of each access link, determine the access permission configuration information and access permission control scenario configuration information of each access object; Configure the object access template corresponding to each of the access objects based on the access permission configuration information and access permission control scenario configuration information of each access object; Based on the object access template and the corresponding access object information for each access object, establish the association between the access object information and the object access template.

5. The data access control method as described in claim 4, characterized in that, The determination of access permission configuration information and access permission control scenario configuration information for each access object based on the access links and the access permissions of each access link includes: Obtain the access address corresponding to each access step and the access permission description information corresponding to the access address; Determine whether the access permission description information corresponding to each access step matches the access permission; If a match is found, then based on the access permissions, determine the access permission configuration information and access permission control scenario configuration information for each access object; If there is a mismatch, then based on the access permission description information, determine the access permission configuration information and access permission control scenario configuration information for each access object.

6. A data access control device, characterized in that, The device includes: The acquisition module is used to acquire data access requests, which carry target access object information and data information to be accessed; The determination module is used to determine the target object access template corresponding to the target access object information based on the pre-determined association relationship between the access object information and the object access template; The configuration module is used to configure data access permissions for the target object access template based on the data information to be accessed, thereby obtaining an access permission control model; The target object access template includes an access permission configuration module and an access permission control scenario configuration module, and the access permission control model includes access permission configuration results and access permission control scenario configuration results. The control module is used to control the target access object to access data according to the access permission control model; The access permission configuration module includes a first input box, which is used for users to input access permission requests for the data to be accessed. After the data access control device detects the access permission requests input by the user, it performs corresponding access permission verification and permission configuration, and displays the configured access permission configuration results through the access permission configuration module so that users can view the access permissions to the data to be accessed. The access control scenario configuration module includes a second input box, which is used for the user to input the data application scenario information corresponding to the current access request. After the data access control device detects the data application scenario information input by the user, it performs the corresponding access permission verification and control scenario configuration, and displays the configured access control scenario configuration result through the access control scenario configuration module so that the user can view the access permission control scenario for the data to be accessed. The access control scenarios include access address, access type, and the amount of data accessed.

7. An apparatus comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the data access control method as described in any one of claims 1 to 5.

8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the data access control method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Database access method, apparatus and device

    CN110795485A

  • Permission configuration and data processing method and device, electronic equipment and medium

    CN113923023A