Data permission control method, device and application applicable to multi-institutional data tables
By establishing a mapping relationship between standards and entity agency tags in cross-agency data tables, the complexity of cross-agency data permission management is solved, and refined data permission control and simplified permission management are achieved.
Patent Information
- Application Number
- CN202211398169.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-09
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2042-11-09
AI Technical Summary
Existing technologies make it difficult to effectively manage cross-institutional data permissions, especially when the hierarchical relationships within different institutions are complex, resulting in complex permission management and the inability to achieve fine-grained data permission control.
By setting standard organization tags and entity organization tags, establishing mapping relationships, building an organization mapping table, and controlling access rights to cross-organization data tables based on the user's organization and permission conditions.
It realizes the dynamic identification and refined management of cross-institutional data permissions, simplifies the permission management process, reduces operational difficulty, and improves the efficiency and security of data access.
Smart Images

Figure CN115600234B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data control, and in particular to a data permission control method, device and application applicable to multi-institutional data tables. Background Art
[0002] Data security refers to taking necessary measures to ensure that data is in a state of effective protection and legal use, as well as having the ability to ensure continuous security. Therefore, each unit or organization will control the permissions of its own data. Data permission control means: assigning different permission levels to different users, and returning appropriate data content to the accessing user based on the permission level. A common practice is to integrate the permission settings for all users into a management system, and assign different permissions to different data in the management system. Users access the corresponding data based on their own permission levels.
[0003] With the continuous emergence of cross-institutional collaboration, it is common for personnel from external organizations to access certain data within the organization, making data permission control within the organization very complex. If traditional methods are used, the organization's data permissions need to be known to all external organizations that can be authorized, and the identification information of all external organizations is assigned as authorization fields to the organization's data, thereby achieving permission control for external users. However, this increases the difficulty of management personnel's operations, and when there are a large number of external users or users from other organizations accessing the database, it is impossible to achieve detailed data permission management.
[0004] In particular, for organizations that strictly control access rights according to hierarchy, since the hierarchies within different organizations are different, if the current organization wants to share permissions with other organizations, it needs to know the internal hierarchical relationship of each organization and grant different hierarchical permissions according to the hierarchical relationship, which makes permission management very complicated.
[0005] However, the current mainstream data authorization methods can generally only authorize different data tables and data fields to fixed roles, and cannot dynamically identify the user's organization identity in the data tables provided by different organizations and obtain the data range of different tables for retrieval control. Summary of the Invention
[0006] The present application solution provides a permission control method suitable for cross-institutional data permission control, which can control the institution row-level data access permissions of multiple cross-institutional data tables based on the constructed mapping relationship.
[0007] In a first aspect, the present application provides a permission control method applicable to cross-institutional data permission control, which performs data permission control on partially shared data between multiple institutions, including:
[0008] Establish at least one standard organization label and define a unique entity organization label for each organization;
[0009] A mapping relationship between each standard organization label and at least one entity body label is established based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization labels and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label;
[0010] Obtaining the cross-institutional data table of each institution and constructing an entity institution tag of the corresponding institution for the institution row-level data in each cross-institutional data table;
[0011] Configuring permission conditions for each cross-organization data table, wherein the permission conditions define the organization level interval that can access the cross-organization data table;
[0012] If there is an accessing user, and the accessing user and the cross-institutional data table to be accessed are from the same institution, the accessing user can directly access the cross-institutional data table according to the institutional level interval of the cross-institutional data table to be accessed. If the accessing user and the cross-institutional data table to be accessed are from different institutions, the entity institution tag of the institution to which the accessing user belongs is obtained, and the standard institution tag corresponding to the entity institution tag is obtained based on the institution mapping table, and the permission of the corresponding cross-institutional data table is opened to the accessing user according to the standard institution tag matching the institutional level interval.
[0013] In a second aspect, the present application provides a permission control device suitable for cross-institutional data permission control, comprising:
[0014] Definition module: set at least one standard organization label and define a unique entity organization label for each organization;
[0015] A construction module: establishing a mapping relationship between each standard organization label and at least one entity body label based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization label and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label;
[0016] An acquisition module is configured to acquire a multi-institutional data table consisting of institution row-level data from at least one institution, and to construct an entity institution tag of the corresponding institution for each institution row-level data in the multi-institutional data table;
[0017] Configuration module: configures permission conditions for at least one row-level data of an institution in each of the multi-cross-institution data tables, wherein the permission conditions limit the institution level interval for accessing the row-level data of the institution;
[0018] Access module: If there is an accessing user, obtain the entity institution tag of the institution to which the accessing user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval with the standard institution tag to open the corresponding institution row-level data to the accessing user.
[0019] Compared with the existing technology, this technical solution has the following characteristics and beneficial effects:
[0020] This solution connects multiple databases of an organization and constructs entity organization tags for multiple levels of each organization according to coding rules. The entity organization tags of the same level of different organizations correspond to a standard organization tag. A mapping relationship is established between the entity organization tag and the standard organization tag, and the entity organization code is written into the organization field of the table structure. According to the entity organization code of each user, the data with the same entity organization code in the organization field of the table structure is obtained and returned, thereby completing the row-level permission control of the user during the query process.
[0021] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0023] Figure 1 This is a flowchart of a permission control method applicable to cross-institutional data permission control according to an embodiment of the present application;
[0024] Figure 2 This is a structural block diagram of a permission control device suitable for cross-institutional data permission control according to an embodiment of the present application;
[0025] Figure 3 Schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The implementations described in the following exemplary embodiments are not intended to represent all implementations consistent with one or more embodiments of this specification. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of one or more embodiments of this specification, as detailed in the appended claims.
[0027] It should be noted that in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the method may include more or fewer steps than those described in this specification. In addition, a single step described in this specification may be broken down into multiple steps for description in other embodiments, and multiple steps described in this specification may be combined into a single step for description in other embodiments.
[0028] Example 1
[0029] This application provides a data permission control method applicable to multi-institutional data tables. Figure 1 , the method comprising:
[0030] Establish at least one standard organization label and define a unique entity organization label for each organization;
[0031] A mapping relationship between each standard organization label and at least one entity body label is established based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization labels and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label;
[0032] Obtaining a multi-cross-institution data table consisting of institution row-level data from at least one institution, and constructing an entity institution tag of the corresponding institution for each institution row-level data in the multi-cross-institution data table;
[0033] Configuring permission conditions for at least one row-level data of an institution in each of the multi-cross-institution data tables, wherein the permission conditions limit the institution-level interval for accessing the row-level data of the institution;
[0034] If there is a visiting user, obtain the entity institution tag of the institution to which the visiting user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval according to the standard institution tag to open the corresponding institution row-level data to the visiting user.
[0035] In some embodiments, the standard institution labels are generated according to the same rule logic, the types of the physical institution labels are equal to the number of institutions, and the standard institution labels of each institution level correspond to the physical institution labels of different institutions under the same institution level.
[0036] Specifically, countless types of entity organization labels can be created, and they can be created according to actual needs. For example, to build a data pool based on the databases of 5 institutions, it is necessary to create 5 entity organization labels corresponding to the 5 institutions one by one. The purpose of labeling each entity organization is to identify the data source organization of each data. Only by confirming the source organization of the data can the scope of the institutional row-level data that the user can access be confirmed.
[0037] Furthermore, the standard institution tag is built into the computer system, and user permissions of the corresponding institution level are configured according to the standard institution tag. Users of different institution levels in the institution obtain different institution row-level data according to the corresponding user permissions.
[0038] Specifically, the standard organization tag is built into the computer system, and the administrator (or business object) configures user permissions for all users at each organization level based on the standard structure tag. After the configuration is completed, different users automatically determine the organization row-level data they can access based on the organization level of their organization. If the administrator does not configure user permissions, the user can access all row-level organization data of the corresponding organization level.
[0039] Specifically, coding rules are set for the standard organization label and the entity organization label according to different organization levels, and the standard organization code is obtained by encoding according to the coding rules of the standard organization label. The organization level of each entity organization is encoded according to the coding rules of the entity organization label, and the entity organization code is obtained. The entity organization code of the same organization level corresponds to the standard organization code of the same organization level. Therefore, when user authority configuration is performed according to the standard organization code, each member of the organization can obtain the corresponding user authority configuration according to the corresponding entity organization code.
[0040] In some embodiments, in the step of "obtaining a multi-cross-institution data table consisting of institution row-level data from at least one institution, and constructing an entity institution label of the corresponding institution for the institution row-level data in each of the multi-cross-institution data tables", the institution row-level data of each institution is obtained, and the institution row-level data are combined to obtain the multi-cross-institution data table, and the entity institution label of the corresponding institution level is constructed in the institution row-level data with institution fields in the multi-cross-institution data table.
[0041] Specifically, the JDBC method can be used to connect the databases of all organizations, and each cross-organization data table can be classified and managed according to the hierarchical relationship of the organizations.
[0042] Specifically, an organization may include multiple sub-organizations. The organization row-level data of each organization and the row-level data of each sub-organization under the organization are connected to obtain a multi-cross-organization data table, and the organization fields of the organization row-level data and the sub-organization row-level data are marked with the entity organization label of the corresponding organization level.
[0043] Specifically, the relationship between the institutions can be different departments of a hospital, different departments of an enterprise, or between hospitals, enterprises, enterprises and hospitals, etc. This solution does not limit this.
[0044] For example, such as cross-institutional data table A (a1 sub-institution row-level data, a2 sub-institution row-level data, a3 sub-institution row-level data...) / cross-institutional data table B (b1 sub-institution row-level data, b2 sub-institution row-level data, b3 sub-institution row-level data...) / cross-institutional data table C (c1 sub-institution row-level data, c2 sub-institution row-level data, c3 sub-institution row-level data...), etc., where cross-institutional data table A is the first institutional level, a1 sub-institution row-level data is the second institutional level... a11 sub-institution row-level data can also be set up as the third institutional level. The specific situation varies according to the actual scenario, and this solution will not be described in detail here.
[0045] In some embodiments of the present scheme, the first-level organization coding rule of the standard organization label is 00010000, 00020000, 00030000, 00040000, 00050000, 00060000, 00070000, 00080000, 00090000, 00100000, 00110000…, the second-level organization coding rule is 00010100, 00010200, 00010300…, and the third-level organization coding rule is 00010101, 00010102, 00010103…
[0046] In some embodiments of the present solution, the first-level coding rule of the entity organization label in the cross-organization data table A is 29010000, 29020000, 29030000…, the second-level coding rule is 29010100, 29010200, 29010300…, and the third-level coding rule is 29010101, 29010102, 29010103….
[0047] The entity institution label coding rule for the first institution level of the cross-institution data table B is 88010000, 88020000, 88030000…, the second institution level coding rule is 88010100, 88010200, 88010300…, and the third institution level coding rule is 88010101, 88010102, 88010103….
[0048] The entity institution label coding rule for the first institution level of the cross-institution data table C is JJ010000, JJ020000, JJ030000…, the second institution level coding rule is JJ010100, JJ010200, JJ010300…, and the third institution level coding rule is JJ010101, JJ010102, JJ010103….
[0049] This solution establishes a mapping relationship between entity organization labels and standard organization labels at the same organization level and constructs an organization mapping table.
[0050] For example, in this scheme, a mapping relationship is established between the first-level standard institution code 00010000 and the first-level entity institution code 29010000 of entity institution A, the first-level entity institution code 88010000 of entity institution B, and the first-level entity institution code JJ010000 of entity institution C. According to the above method, a mapping relationship is established between the standard institution codes of all levels and entity institution A, entity institution B, entity institution C... respectively.
[0051] Specifically, there may be multiple entity organization tags that establish a mapping relationship with the standard organization tag, and this solution does not limit the number of organizations.
[0052] In some embodiments, in the step of "obtaining the entity institution label of the institution to which the accessing user belongs, and obtaining the standard institution label corresponding to the entity institution label based on the institution mapping table", if the entity institution label of the institution row-level data to be accessed is the same as the entity institution label of the accessing user, then the accessing user directly accesses the institution row-level data according to the institution level interval of the institution row-level data; if the entity institution label of the accessing user is different from the entity institution label of the institution row-level data to be accessed, then the standard institution label corresponding to the accessing user is obtained according to the institution mapping table, and the user authority of the accessing user is judged according to the standard institution label whether it has the right to access the institution row-level data. If it has the right to access, then the institution row-level data is accessed according to the institution level interval of the institution row-level data. If it does not have the right to access, then a failure result is returned.
[0053] In some embodiments, in the step of "configuring permission conditions for at least one institution row-level data in each of the multi-institution data tables, wherein the permission conditions limit the institution level interval for accessing the institution row-level data", the permission conditions for the cross-institution data table are specifically:
[0054] (1) When the row-level data of the institution is queried, only the row-level data of the institution in the multi-cross-institution data table is returned;
[0055] (2) When the organization row-level data is queried, the organization row-level data and the organization row-level data below the level of the organization row-level data in the multi-cross organization data table are returned.
[0056] Specifically, returning the row-level data of the institution in the cross-institution data table means only returning the row-level receipts of the institution in the cross-institution data table; returning the row-level data of the institution and its sub-institution data in the cross-institution data table means not only returning the row-level data of the institution in the cross-institution data table, but also returning the row-level data of the subordinate sub-institutions of the institution row-level data.
[0057] For example, when a user performs a cross-institutional data query, the user's identity information is first obtained. The identity information includes the user's full path information and the entity organization code corresponding to the organizational level. Taking the above coding rules as an example, the user is a second-level department staff member of organization A, then the entity organization code to which the user belongs is 29010100. Through the mapping relationship, the standard organization code of the user is 00010100.
[0058] If the user wants to access the cross-institution data table a1 of institution A and the cross-institution data table b1 of institution B, and the permission condition for the cross-institution data table a1 is to return only the row-level data of the institution in the cross-institution data table, and the permission condition for the cross-institution data table b1 is to return the row-level data of the institution and its sub-institutions in the cross-institution data table, the user's acquisition logic is as follows:
[0059] First, obtain the row-level data of institution a1. Since the user is a member of institution A, he can directly access the cross-institution data table of a1. The cross-institution data table then returns row-level data for all institutions whose institution field is 29010100.
[0060] When obtaining the row-level data of institution B1, since the user is a member of institution A, the entity institution code 29010100 described by the user must be converted into the standard institution code 00010100 according to the mapping relationship. The standard institution code 00010100 is then converted into the entity institution code 88010100 of institution B at the same level. Since the permission condition for the row-level data of institution B1 is to return the row-level data of the current institution level and its sub-institutions, the sub-level codes 88010101, 88010102, 88010103... of the entity institution code 88010100 are obtained, and then the row-level data of all institutions whose institution fields in the row-level institution data of B1 are the entity institution code 88010100 and its sub-level codes are returned.
[0061] Example 2
[0062] Based on the same idea, refer to Figure 2This application also proposes a data authority control method and device applicable to multi-institutional data tables, including:
[0063] Definition module: set at least one standard organization label and define a unique entity organization label for each organization;
[0064] A construction module: establishing a mapping relationship between each standard organization label and at least one entity body label based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization label and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label;
[0065] An acquisition module is configured to acquire a multi-institutional data table consisting of institution row-level data from at least one institution, and to construct an entity institution tag of the corresponding institution for each institution row-level data in the multi-institutional data table;
[0066] Configuration module: configures permission conditions for at least one row-level data of an institution in each of the multi-cross-institution data tables, wherein the permission conditions define the institution level intervals for accessing the row-level data of the institution;
[0067] Access module: If there is an accessing user, obtain the entity institution tag of the institution to which the accessing user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval with the standard institution tag to open the corresponding institution row-level data to the accessing user.
[0068] Example 3
[0069] This embodiment also provides an electronic device, referring to Figure 3 , including a memory 404 and a processor 402, wherein the memory 404 stores a computer program, and the processor 402 is configured to run the computer program to execute the steps in any one of the above-mentioned data authority control method embodiments applicable to multi-cross-institutional data tables.
[0070] Specifically, the processor 402 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0071] Among them, the memory 404 may include a large-capacity memory 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid-state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 404 may include a removable or non-removable (or fixed) medium. Where appropriate, the memory 404 may be inside or outside the data processing device. In a specific embodiment, the memory 404 is a non-volatile memory. In a specific embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (Programmable Read-Only Memory, abbreviated as PROM), an erasable PROM (Erasable Programmable Read-Only Memory, abbreviated as EPROM), an electrically erasable PROM (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), an electrically alterable ROM (Electrically Alterable Read-Only Memory, abbreviated as EAROM) or a flash memory (FLASH) or a combination of two or more of these. In appropriate circumstances, the RAM can be a static random access memory (SRAM) or a dynamic random access memory (DRAM), wherein the DRAM can be a fast page mode dynamic random access memory 404 (FPMDRAM), an extended data output dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0072] The memory 404 may be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402 .
[0073] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement the implementation process of any one of the data permission control methods applicable to multi-cross-institutional data tables in the above embodiments.
[0074] Optionally, the electronic device may further include a transmission device 406 and an input / output device 408 , wherein the transmission device 406 is connected to the processor 402 , and the input / output device 408 is connected to the processor 402 .
[0075] Transmission device 406 can be used to receive or send data via a network. Specific examples of the aforementioned network may include a wired or wireless network provided by a communications provider of the electronic device. In one embodiment, the transmission device includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In one embodiment, transmission device 406 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0076] The input and output devices 408 are used to input or output information. In this embodiment, the input information may be the organization field of the cross-organization data table, the mapping relationship between the standard organization code and the entity organization code, etc. The output information may be the user's query results, etc.
[0077] Optionally, in this embodiment, the processor 402 may be configured to execute the following steps through a computer program:
[0078] S101. Set at least one standard organization label and define a unique entity organization label for each organization;
[0079] S102: Establishing a mapping relationship between each standard organization label and at least one entity label based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table defines the organization hierarchy of the standard organization labels and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label;
[0080] S103: Obtain a multi-institution data table consisting of institution row-level data from at least one institution, and construct an entity institution tag for the corresponding institution for each institution row-level data in the multi-institution data table;
[0081] S104: Configure permission conditions for at least one row-level data of an institution in each of the multi-institution data tables, wherein the permission conditions define the institution level intervals for accessing the row-level data of the institution;
[0082] S105. If there is a visiting user, obtain the entity institution tag of the institution to which the visiting user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval with the standard institution tag to open the corresponding institution row-level data to the visiting user.
[0083] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and this embodiment will not be repeated here.
[0084] In general, various embodiments may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects of the invention may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the invention may be shown and described as block diagrams, flow charts, or using some other graphical representation, it should be understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or a controller or other computing device, or some combination thereof.
[0085] The embodiments of the present invention may be implemented by computer software that is executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. Computer software or programs (also referred to as program products) including software routines, applets and / or macros may be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. A computer program product may include one or more computer executable components that are configured to perform an embodiment when the program is run. One or more computer executable components may be at least one software code or a portion thereof. In addition, it should be noted at this point that, for example, Figure 3 Any block of the logic flow in the program may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on physical media such as memory chips or memory blocks implemented within the processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs, etc. Physical media are non-transitory media.
[0086] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0087] The above embodiments merely illustrate several embodiments of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A data authority control method applicable to multi-institutional data tables, characterized in that: include, Establish at least one standard organization label and define a unique entity organization label for each organization; A mapping relationship between each standard organization label and at least one entity body label is established based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization labels and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label; Obtaining a multi-cross-institution data table consisting of institution row-level data from at least one institution, and constructing an entity institution tag of the corresponding institution for each institution row-level data in the multi-cross-institution data table; Configuring permission conditions for at least one row-level data of an institution in each of the multi-cross-institution data tables, wherein the permission conditions define an institution-level interval for accessing the row-level data of the institution; If there is a visiting user, obtain the entity institution tag of the institution to which the visiting user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval according to the standard institution tag to open the corresponding institution row-level data to the visiting user.
2. A data authority control method applicable to multi-institutional data tables according to claim 1, characterized in that: The standard organization labels are generated according to the same rule logic, the types of the physical organization labels are equal to the number of organizations, and the standard organization labels of each organization level correspond to the physical organization labels of different organizations under the same organization level.
3. A data authority control method applicable to multi-institutional data tables according to claim 2, characterized in that: User permissions of corresponding institutional levels are configured according to the standard institutional labels, and users of different institutional levels in the institution obtain different institutional row-level data according to the corresponding user permissions.
4. A data authority control method applicable to multi-institutional data tables according to claim 1, characterized in that: In the step of "obtaining a multi-cross-institution data table consisting of institution row-level data from at least one institution, and constructing an entity institution label of the corresponding institution for the institution row-level data in each of the multi-cross-institution data tables", the institution row-level data of each institution is obtained, and the institution row-level data are combined to obtain the multi-cross-institution data table, and the entity institution label of the corresponding institution level is constructed in the institution row-level data with institution fields in the multi-cross-institution data table.
5. According to claim 1, a data permission control method suitable for multi-cross-institutional data tables, in the step of "obtaining the entity institution label of the institution to which the accessing user belongs, and obtaining the standard institution label corresponding to the entity institution label based on the institution mapping table", if the entity institution label of the institution row-level data to be accessed is the same as the entity institution label of the accessing user, then the accessing user directly accesses the institution row-level data according to the institution level interval of the institution row-level data; if the entity institution label of the accessing user is different from the entity institution label of the institution row-level data to be accessed, then the standard institution label corresponding to the accessing user is obtained according to the institution mapping table, and the user authority of the accessing user is judged according to the standard institution label whether it has the right to access the institution row-level data; if it has the right to access, then the institution row-level data is accessed according to the institution level interval of the institution row-level data; if it does not have the right to access, a failure result is returned.
6. A data authority control method applicable to multi-institutional data tables according to claim 1, characterized in that: In the step of "configuring permission conditions for at least one row-level data of an institution in each of the multi-institution data tables, wherein the permission conditions limit the institution-level interval for accessing the row-level data of the institution", the permission conditions for the cross-institution data table are specifically as follows: (1) When the row-level data of the institution is queried, only the row-level data of the institution in the multi-cross-institution data table is returned; (2) When the organization row-level data is queried, the organization row-level data and the organization row-level data below the level of the organization row-level data in the multi-cross organization data table are returned.
7. A data authority control device applicable to multi-institutional data tables, characterized in that: include: Definition module: set at least one standard organization label and define a unique entity organization label for each organization; A construction module: establishing a mapping relationship between each standard organization label and at least one entity body label based on the organization relationship of each organization to obtain an organization mapping table; wherein the organization mapping table sets the organization hierarchy of the standard organization label and the association relationship between different standard organization labels, and each standard organization label is mapped to at least one related entity organization label; An acquisition module is configured to acquire a multi-institutional data table consisting of institution row-level data from at least one institution, and to construct an entity institution tag of the corresponding institution for each institution row-level data in the multi-institutional data table; Configuration module: configures permission conditions for at least one row-level data of an institution in each of the multi-cross-institution data tables, wherein the permission conditions define the institution level intervals for accessing the row-level data of the institution; Access module: If there is an accessing user, obtain the entity institution tag of the institution to which the accessing user belongs, obtain the standard institution tag corresponding to the entity institution tag based on the institution mapping table, and match the institution level interval with the standard institution tag to open the corresponding institution row-level data to the accessing user.
8. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute a data authority control method applicable to multi-institutional data tables as described in claims 1 to 6.
9. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which includes a program code for controlling a process to execute a process, and the process includes a data authority control method applicable to multi-cross-institutional data tables according to claims 1 to 6.
Citation Information
Patent Citations
Data query permission control method and device
CN110427775A
Method for realizing row-level authority control based on domestic database
CN113656827A