A method, apparatus, server, distributed system and storage medium for managing permissions
By managing permissions based on location relationships in a distributed system, the problem of user data not being shared across regions is solved, enabling fast and accurate dynamic authorization, improving efficiency and reducing the risk of information leakage.
Patent Information
- Application Number
- CN202211444396.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-18
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2042-11-18
AI Technical Summary
The lack of data sharing between provinces makes it cumbersome and inefficient for migrant workers to access information, especially when accessing information across regions, which poses a risk of information leakage.
By determining the location relationship, dynamic authorization for cross-regional access is achieved. The first node and child nodes in the distributed system manage permissions, and permission management is carried out according to the location of the target object and the location relationship of the associated region, and dynamic access permissions are granted.
It improves the efficiency of cross-regional access, reduces the risk of information leakage, and enables fast and accurate access control, adapting to the access needs of different organizations.
Smart Images

Figure CN115809478B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of big data, and in particular to a permission management method and device, a server, a distributed system and a storage medium. BACKGROUND
[0002] With the continuous advancement and deepening of informationization construction in China, more and more scenarios need to obtain personal information of users. The current situation in China is that each province establishes a database to manage and operate user data within the province, and there is a problem of non-interoperability of user data among provinces. However, the size of the floating population in China has reached 376 million, accounting for more than 1 / 4 of the total population. When managing the population in the jurisdiction, each province and city needs to frequently apply for access to information bases of other provinces to obtain relevant information of the floating population, and obtaining data of other provinces needs to be authorized, which is a relatively cumbersome and inefficient process. SUMMARY
[0003] The present application aims to at least partly solve one of the technical problems in the related art.
[0004] To this end, the present application proposes a permission management method and device, a server, a distributed system and a storage medium, which realize dynamic authorization of cross-regional access through determination of the location relationship, thereby improving the efficiency.
[0005] An embodiment of the present application provides a permission management method, comprising:
[0006] receiving an authorization request, wherein the authorization request is used to request to grant a first node a right to access information related to a target object;
[0007] in response to the authorization request, querying a target location where the target object is located;
[0008] managing the permission of the first node according to a location relationship between the target location and a target region associated with the first node.
[0009] Another embodiment of the present application provides a permission management device, comprising:
[0010] a receiving module configured to receive an authorization request, wherein the authorization request is used to request to grant a first node a right to access information related to a target object;
[0011] a querying module configured to, in response to the authorization request, query a target location where the target object is located;
[0012] a processing module configured to manage the permission of the first node according to a location relationship between the target location and a target region associated with the first node.
[0013] Another aspect of the present application provides a server, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to implement the method of the preceding aspect.
[0014] Another aspect of the present application provides a distributed system, comprising: a plurality of first nodes, each of the first nodes maintaining a database; wherein at least one of the first nodes is configured with a sub-node; and the sub-node is configured to implement the method of the preceding aspect.
[0015] Another aspect of the present application provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method of the preceding aspect.
[0016] Another aspect of the present application provides a computer program product, characterized in that comprising a computer program, the computer program is executed by a processor to implement the method of the preceding aspect.
[0017] The technical scheme provided by the embodiments of the present application comprises the following technical effects:
[0018] The authorization request is received, wherein the authorization request is used to request to grant the first node the right to access the information related to the target object, the target location where the target object is located is queried in response to the authorization request, the permission of the first node is managed according to the location relationship between the target location and the target area associated with the first node, the permission management of the first node is based on the determination of the location relationship between the target object location and the target area associated with the first node, the dynamic authorization of cross-region access is realized, and the efficiency is improved.
[0019] Additional aspects and advantages of the present application will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS
[0020] The above and / or additional aspects and advantages of the present application will become apparent and be readily appreciated from the following description, taken in conjunction with the accompanying drawings, in which:
[0021] Figure 1 A flowchart of a permission management method provided by an embodiment of the present application;
[0022] Figure 2 A flowchart of another permission management method provided by an embodiment of the present application;
[0023] Figure 3Another flowchart of a permission management method provided by an embodiment of the present application is shown in FIG. 6.
[0024] Figure 4 A schematic diagram of a permission management provided by an embodiment of the present application is shown in FIG. 7.
[0025] Figure 5 Another flowchart of a permission management method provided by an embodiment of the present application is shown in FIG. 6.
[0026] Figure 6 A schematic diagram of a control level provided by an embodiment of the present application is shown in FIG. 8.
[0027] Figure 7 A schematic diagram of a structure of a distributed system provided by an embodiment of the present application is shown in FIG. 9.
[0028] Figure 8 Another schematic diagram of a structure of a distributed system provided by an embodiment of the present application is shown in FIG. 10.
[0029] Figure 9 A schematic diagram of a structure between a first node and a sub-node provided by an embodiment of the present application is shown in FIG. 11.
[0030] Figure 10 Another flowchart of a permission management method provided by an embodiment of the present application is shown in FIG. 6.
[0031] Figure 11 A schematic diagram of a structure of a permission management device provided by an embodiment of the present application is shown in FIG. 13.
[0032] Figure 12 A block diagram of a structure of a server provided by an embodiment of the present application is shown in FIG. 14. DETAILED DESCRIPTION
[0033] Embodiments of the present application are described in detail below with reference to the accompanying drawings, in which the same or similar notations or elements represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are intended to explain the present application, and should not be understood as limiting the present application.
[0034] The permission management method, device, server, distributed system and storage medium of an embodiment of the present application are described below with reference to the accompanying drawings.
[0035] In the technical solutions of the present application, the acquisition, storage and application of data comply with relevant laws and regulations and do not violate public order and good customs.
[0036] Figure 1 A flowchart of a permission management method provided by an embodiment of the present application is shown in FIG. 6.
[0037] As Figure 1As shown, the method comprises the following steps:
[0038] In step 101, an authorization request is received, wherein the authorization request is used to request the right to access the information related to the target object to the first node.
[0039] In the embodiment of the application, a plurality of provinces in the country manage their own databases, the target object is a user to be obtained user information, and the target object will flow in different regions based on the needs of learning and work, so that the information related to the target object may be stored in the database of the place of residence or in the database of the place other than the place of residence. Therefore, the servers maintaining the databases of the provinces form a distributed system of data, that is, the distributed system includes a plurality of data servers of the provinces, each data server of the provinces is regarded as a first node in the distributed system, each first node maintains a database, and at least one first node is configured with a sub-node.
[0040] As an example, the database of Zhejiang Province in the distributed system runs on server B, the database of Jiangsu Province runs on server C, server B and server C each correspond to a first node M and a first node L in the distributed system, the first node M receives an authorization request sent by the first node L, the authorization request requests to access the related data of the target object X in the first node M, and then the first node M distributes the authorization request of the first node L to the sub-node of the first node M for authorization management, wherein the authorization request is used to request the right to access the information related to the target object X in the database maintained by the first node M to the first node L.
[0041] The information related to the target object, for example, vaccination information or mobile trajectory information, etc.
[0042] In step 102, the target position of the target object is queried in response to the authorization request.
[0043] In the embodiment of the application, the target position of the target object is queried in the case of obtaining the authorization request, the target position is the position determined by real-time positioning of the target object, that is, the position of the area where the target object is currently actually located, as an implementation manner, the target object can be positioned in real time based on the GPS signal to determine the target position of the target object.
[0044] In step 103, the authority of the first node is managed according to the positional relationship between the target position and the target area associated with the first node.
[0045] In the embodiments of the present application, the first node is associated with the target region if the first node maintains the related information of the target object in the target region. The permission management includes authorizing the first node to access the related information of the target object, not authorizing the first node to access the related information of the target object, and revoking the authorization of the first node, so as to realize dynamic authorization.
[0046] In an implementation manner of the embodiments of the present application, the permission of the first node is managed according to the position relationship between the target position where the target object is located and the target region associated with the first node. The first node can be authorized to access at least part of the related information of the target object in response to at least one set condition met by the target object and the target region associated with the first node. The set condition indicates the space-time relationship between the target object and the target region. Based on the space-time position relationship, dynamic authorization in cross-region access can be realized. In the permission management method of the embodiments of the present application, an authorization request is received. The authorization request is used to request to grant the first node the right to access the related information of the target object. In response to the authorization request, the target position where the target object is located is queried. The permission of the first node is managed according to the position relationship between the target position and the target region associated with the first node. The permission of the first node is managed based on the determination of the position relationship between the target object position and the target region associated with the first node, so as to realize dynamic authorization in cross-region access and improve the efficiency.
[0047] Based on the above embodiments, another permission management method is provided in the embodiments, which illustrates how to manage the permission when the target object and the target region associated with the first node meet a set condition. Figure 2 A flowchart of another permission management method provided in the embodiments of the present application is shown.
[0048] As shown in the method, the method can include the following steps: Figure 2
[0049] Step 201, an authorization request is received.
[0050] The authorization request is used to request to grant the first node the right to access the related information of the target object.
[0051] The authorization request also carries the institutional identity information of the first node.
[0052] Step 202, in response to the authorization request, the target position where the target object is located is queried.
[0053] The explanations in the foregoing embodiments are also applicable to the present embodiment, and the principles are the same, which will not be described here.
[0054] At step 203, at least part of the related information allowed to be accessed is determined according to the institution identity information carried in the authorization request.
[0055] In the embodiments of the present application, in order to improve the security of the target object information and avoid information leakage, the related information that can be accessed is different for different institution identity information corresponding to the first node, and different institution identity information has corresponding accessible related information. For example, if the institution identity information indicates that the institution is a public security department, the public security department can access the target object's identity card number, accommodation information, movement trajectory and medical information, etc. If the institution identity information indicates that the institution is a human resources department, the human resources department can access the target object's employment information, school, etc., but cannot access the accommodation information, movement trajectory and medical information, etc.
[0056] At step 204, in response to the target object and the target area associated with the first node satisfying at least one set condition, the first node is authorized to access at least part of the related information of the target object.
[0057] The set condition includes a first condition, and the first condition is that the target position of the target object is in the target area associated with the first node.
[0058] In the embodiments of the present application, the target position of the target object is compared with the target area associated with the first node, and in response to the target position of the target object being in the target area associated with the first node, it is considered that the target position of the target object meets the authorization condition, that is, the first node is authorized to access at least part of the related information of the target object.
[0059] As an example, the target object is user 1, user 1 has lived in province A, province A has user 1's vaccination information, user 1 returns to the place of residence, i.e. province B, and applies for vaccination in the epidemic prevention department of province B, and the epidemic prevention department of province B needs to call user 1's vaccination record from province A for reference, then the first node corresponding to province A will receive the authorization request of the first node corresponding to province B for the vaccination data, and then the first node corresponding to province A queries the target position of user 1 according to the authorization request, and determines that the target position of user 1 is in province B, then it is considered that the application of the epidemic prevention department of province B to call user 1's vaccination data is reasonable, which does not belong to the random call of the third party and is not easy to cause the leakage of user 1's vaccination data, therefore, the authorization request of the first node corresponding to province B can be authorized, that is, the first node is authorized to access the related information of user 1's vaccination, which avoids the leakage of information, realizes the rapid authorization when accessing across regions based on the position, and improves the accuracy of authorization.
[0060] It should be noted that in one scenario, the target object resides in a provincial boundary area, and there is a situation of frequently going back and forth between two provinces. In order to improve the accuracy of the determination, therefore, when determining whether the target object is in the target area, as one implementation, a set distance between the target object and the boundary of the target area can be set. If the distance between the target object and the boundary of the target area is less than the set distance, it is determined that the target object is in the target area. As an example, the set distance is 500 meters. User A resides in the boundary area of M province and N province. When the first node associated with M province requests to access the relevant information of user A in N province, if the distance between user A and the boundary line of the target area associated with the first node, i.e., M province, is less than 500 meters, it is considered that user A does not move across the province, and it is determined that user A is in M province, thereby improving the accuracy of the determination.
[0061] As another implementation, when the target object is in the boundary enclosed range, it is determined that the target object is in the target area. For example, user A is in M province, and user A is in the boundary enclosed range.
[0062] In the permission management method of the embodiments of the present application, when processing the first node's application to access the relevant information of the target object, when the target object is in the target area associated with the first node, the first node is authorized to access at least part of the relevant information of the target object, thereby realizing fast authorization when performing cross-area access based on location, and improving the accuracy of the authorization.
[0063] Based on the above embodiment, another permission management method is provided, which explains how to perform permission management when the target area associated with the target object and the first node meets multiple set conditions. Figure 3 The flowchart of another permission management method provided by the embodiments of the present application is shown.
[0064] As shown in Figure 3 The method can include the following steps:
[0065] Step 301, receiving an authorization request, wherein the authorization request is used to request to grant the first node the right to access the relevant information of the target object.
[0066] Step 302, in response to the authorization request, querying the target position of the target object.
[0067] The explanation and description in the foregoing embodiments are also applicable to this embodiment, and the principles are the same, which will not be repeated here.
[0068] Step 303, in response to the target area associated with the target object and the first node meeting at least one set condition, the first node is authorized to access at least part of the relevant information of the target object.
[0069] In the embodiments of the present application, the set conditions include a first condition and a second condition.
[0070] The first condition is that the target position of the target object is in the target area associated with the first node.
[0071] The second condition includes at least one of the following conditions:
[0072] In the set historical period, the target object is in the target area for a time period reaching a first set time period; or the target object moves to the target position along a set route.
[0073] As the first implementation, in response to the target object and the target area associated with the first node satisfying the first condition and at least one second condition, the first node is authorized to access all related information of the target object.
[0074] In one scenario, in response to the target object and the target area associated with the first node satisfying the first condition, and the time period of the target object being in the target area reaching the first set time period in the set historical period, the first node is authorized to access all related information of the target object.
[0075] As an example, the first set time period is 12 hours, the target area associated with the first node is X province, the target object A arrives in X province and stays in X province, and the staying time period is counted from the arrival in X province, and the staying time period has reached 13 hours, so the first node is authorized to access all related information of the target object A, that is, the maximum permission can be authorized in the case of meeting the requirements of time and space.
[0076] In another scenario, in response to the target object and the target area associated with the first node satisfying the first condition, and the target object moving to the target position along a set route, the first node is authorized to access all related information of the target object.
[0077] In the embodiments of the present application, in some special scenarios, such as expressway, high-speed rail, airplane and other rapid long-distance transportation scenarios, taking the expressway scenario as an example, the long-distance bus driver can cross multiple provinces in the first set time period during the transportation process due to the fast driving speed, and finally gets off the expressway, so the expressway toll station needs to obtain the related driving information of the long-distance bus driver. In this scenario, the long-distance bus driver is the target object, and the electronic device corresponding to the expressway toll station is the first node. In this scenario, the first node requests to access the related driving information of the long-distance bus driver, and does not need to wait for the first set time period to authorize, that is, in the case that the long-distance bus driver moves along the specified route, the target object (such as the long-distance bus driver) is regarded as a moving point, and the national expressway information is set as a line. When deviating from the specified route, that is, getting off the expressway toll station, authorization is performed, that is, the first node is authorized to access all related information of the target object.
[0078] As the second implementation, in response to the target object and the target area associated with the first node satisfying the first condition and not satisfying any second condition, the first node is authorized to access the partial relevant information of the target object.
[0079] In the embodiments of the present application, in order to improve the accuracy of authorization, when it is determined that the target object and the target area associated with the first node satisfy the first condition and do not satisfy any second condition, the first node is authorized to access the partial relevant information of the target object, that is, in the case that it is determined that the target object is in the target area associated with the first node, but does not satisfy the time condition or does not satisfy the condition of moving along the set route to the target position, the partial authorization is started, that is, the first node is authorized to access the partial relevant information of the target object, wherein the determination of the partial relevant information can be determined according to the access mechanism corresponding to the first node requesting access.
[0080] As an example, the mechanism corresponding to the first node requesting to access user data is an airline, and the associated target area is C province. When the target object B takes a high-speed long-distance transportation tool such as a high-speed train or an airplane, it will pass through C province at a high speed, that is, the target position of the target object B will be in C province for a short time, but the time of staying in C province is short and does not satisfy the first set time length, so the first node is authorized to access the partial relevant information of the target object, for example, the age, gender, marital status and flight data of the target object B.
[0081] Step 304, in response to the target object leaving the target area associated with the first node for more than a second set time length, the authorization to the first node is revoked.
[0082] In the embodiments, in order to facilitate the distinction, the preset time length is referred to as a first set time length and a second set time length, wherein the second set time length and the first set time length can be the same or different. The second set time length is a preset time length, for example, 12 hours, or 24 hours, etc.
[0083] In the embodiments, after it is determined that the target object is in the target area associated with the first node, if the target object leaves the target area associated with the first node for more than a second set time length, it is considered that the target object is no longer in the target area. If the first node is continuously authorized to access the relevant information of the target object, there is a risk of information leakage. Therefore, the authorization of the first node needs to be improved to improve the security of user information and increase the reliability of dynamic authorization.
[0084] It should be noted that if the target object leaves the target area associated with the first node, but the time does not exceed the second set time length, it may be a short leave of the target object, and the authorization to the first node is maintained to avoid repeated application.
[0085] Step 305, in response to the target object and the target region associated with the first node do not satisfy any one of the set conditions, the first node is denied access to the relevant information of the target object.
[0086] In the embodiment of the present application, if the target object and the target region associated with the first node do not satisfy the first condition and do not satisfy any one of the second conditions, that is, do not meet the requirements of the spatial position and do not meet the requirements of the time, the first node is denied access to the relevant information of the target object, so as to improve the security of the relevant information of the target object and avoid the leakage of the target object information.
[0087] In order to further clearly illustrate the management of the access permission of the first node in the embodiment of the present application, in combination with Figure 4 , the access permission of the first node is described. Figure 4 A schematic diagram of the permission management provided by the embodiment of the present application is shown in Figure 4 , the access permission of the first node includes partial authorization, full authorization and no authorization, wherein the partial authorization means that the first node is authorized to access part of the relevant information of the target object; the full authorization means that the first node is authorized to access all of the relevant information of the target object; and the no authorization means that the first node is denied access to the relevant information of the target object.
[0088] First, the change of the first node between the no authorization state and the full authorization state is described.
[0089] In one scenario, the permission of the first node is no authorization, and if it is re-determined that the target object and the target region associated with the first node satisfy the first condition and satisfy any one of the second conditions, that is, meet the requirements of the spatial position and meet the requirements of the time, the permission of the first node is changed from no authorization to full authorization, that is, the first node is authorized to access all of the relevant information of the target object.
[0090] In another scenario, the permission of the first node is full authorization, and if it is re-determined that the target object and the target region associated with the first node do not satisfy the first condition and do not satisfy any one of the second conditions, that is, do not meet the requirements of the spatial position and do not meet the requirements of the time, the permission of the first node is changed from full authorization to no authorization, that is, the first node is denied access to the relevant information of the target object.
[0091] Second, the change of the first node between the partial authorization state and the full authorization state is described.
[0092] In one scenario, the permission of the first node is full authorization, and if it is re-determined that the target object and the target region associated with the first node do not satisfy any one of the second conditions, the permission of the first node is changed from full authorization to partial authorization, that is, the first node is authorized to access part of the relevant information of the target object.
[0093] In another scenario, the first node has a partial authorization, and if the re-determined target object and the target area associated with the first node meet any one of the second conditions, the authorization of the first node changes from the partial authorization to the full authorization, i.e., the first node is authorized to access all related information of the target object.
[0094] Thirdly, the change of the first node between the partial authorization and the no authorization is explained.
[0095] In one scenario, the first node has no authorization, and if the re-determined target object and the target area associated with the first node meet the first condition and do not meet any one of the second conditions, the authorization of the first node changes from the no authorization to the partial authorization, i.e., the first node is authorized to access part of the related information of the target object.
[0096] In another scenario, the first node has a partial authorization, and if the re-determined target object and the target area associated with the first node do not meet the first condition, the authorization of the first node changes from the partial authorization to the no authorization, i.e., the first node is denied to access the related information of the target object.
[0097] The specific method of managing the authorization of the first node can refer to the above-mentioned explanations, and the principle is the same, which will not be repeated here.
[0098] In the authorization management method of the embodiments of the present application, when the data volume is large and cannot be uniformly built into a database and needs to be accessed across domains, a database can be built in each region, and the databases of each region are maintained through the corresponding first nodes of each region, avoiding the problem of slow query performance when the data volume of a single database is large. At the same time, the data access authorization of the requesting first node is dynamically authorized through the space-time position information, realizing data cross-domain sharing and intercommunication, improving the database access performance, avoiding manual operation and management of multiple user configurations and multiple authorization problems, and improving the efficiency. At the same time, combined with the actual scene, the space-time position relationship is used for rapid authorization, and when the high-speed transportation meets the space condition but not the time condition, real-time rapid authorization is realized, improving the reliability of the authorization.
[0099] Based on the above embodiments, Figure 5 Another flowchart of an authorization management method provided by the embodiments of the present application is shown.
[0100] As Figure 5 shown, the method can include the following steps:
[0101] Step 501, receiving an authorization request, wherein the authorization request is used to request to grant the first node the right to access the related information of the target object.
[0102] Step 502, in response to the authorization request, querying a target position where the target object is located.
[0103] Wherein, the step 501 and step 502 can refer to the explanation in the foregoing embodiments, the same principle, this place will not be repeated.
[0104] Step 503, according to the access permission configured by the control area, determining at least part of the relevant information allowed to be authorized to access.
[0105] Wherein, the control area, that is, the area under blockade control, that is, the personnel access is controlled. For example, after the popular event occurs, the area temporarily blocked for safety, such as school or hospital, can be used as a point, the traffic road can be used as a line, and the control can be controlled by the vector position relationship, and the control area can be drawn. It should be understood that the control area is different, the control level is different, and the access permission configured is different, which realizes the permission setting based on the control level, improves the accuracy and diversity of the permission management.
[0106] In an implementation manner of the embodiment of the application, according to the field allowed to access in the access permission configured by the control area, the relevant information matched with the field is taken as at least part of the relevant information allowed to be authorized to access.
[0107] Further, in the embodiment of the application, the control area is drawn according to the actual scene, and the target area and the control area are compared. If the target area is a blocked control area, the target object can be reminded when the target object enters the control area. If the target object enters the control area, the first node needs to access the relevant information of the target object, and then needs to access the relevant information matched with the field allowed in the access permission configured by the control area, as at least part of the relevant information allowed to be authorized to access.
[0108] Wherein, the access permission configured by the control area can be adjusted according to the specific situation of the control, for example, the control level, such as Figure 6 As shown, if the control level is reduced, the access permission configured by the control area is also reduced, that is, the field allowed in the access permission is reduced; if the control level is increased, the access permission configured by the control area is also increased, that is, the field allowed in the access permission is increased, to obtain more relevant information. For the control area, the access permission is allowed to be flexibly configured, so as to open different degrees of access permission according to the control demand, and realize the investigation of the personnel entering the control area.
[0109] As an example, in a control area with a popular event, the number of infected people in area A is larger, and the control level is higher. The configured access permission allows access to the fields including the source place, residence place, daily activity track of the target object, and the data related to the epidemic detection of the target object. Area B has personnel in close contact with the infected people, and the control level is low. The configured access permission allows access to the fields including the source place, residence place of the target object, and the data related to the epidemic detection of the target object. Since the personnel in close contact have been controlled, the daily activity track of the target object can not be monitored, thereby achieving different control levels according to the emergency or danger level of the situation in the control area, and improving the pertinence and flexibility.
[0110] In step 504, in response to the control area associated with the target object and the first node satisfying at least one set condition, the first node is authorized to access at least part of the related information of the target object.
[0111] The control area is a scenario of the target area, and the specific implementation manner can refer to the foregoing explanation and description of the target area in the foregoing embodiments, and the principle is the same, which will not be described here again.
[0112] In the permission management method of the embodiments of the present application, different data permissions are given to different areas by drawing a spatial control area, thereby realizing dynamic control of the area and diversity of the permission. In addition, the access permission is flexibly configured for the control area, so as to open different degrees of access permission according to the control requirement, realize reasonable investigation of the personnel entering the control area, and improve the control effect.
[0113] Based on the foregoing embodiments, the embodiments of the present application provide a distributed system, Figure 7 A structure diagram of a distributed system provided by the embodiments of the present application is shown in FIG. 7, which includes: Figure 7
[0114] A plurality of first nodes 71, each of which maintains a database; wherein at least one of the first nodes is configured with a sub-node 710, and the sub-node 710 is used to execute the method described in the foregoing method embodiments.
[0115] The foregoing related explanation and description in the method embodiments are also applicable to the present embodiment, and the principle is the same, which will not be described here again.
[0116] In one implementation manner of the embodiments of the present application, as shown in FIG. 7, the distributed system includes: Figure 8 As shown, the distributed system may also include a master node 72, which manages each first node and coordinates the databases maintained by each first node. Specifically, for each first node's access request, the access request is sent to the corresponding first node. The requested first node stores the relevant information of the target object. The requested first node forwards the authorization request to the corresponding child node. The corresponding child node is used to schedule the access request, manage the access permissions of the requesting first node, and obtain the relevant information of the requested target object to feed back to the requesting first node.
[0117] As an example, let's take vaccine data as an example, such as Figure 8 As shown, each province's vaccine management department maintains a database of vaccine data. Each province's database is maintained by a corresponding server, and these servers form a distributed system. The server maintaining each province's vaccine database can be considered a first node in this distributed system. The vaccine data for target object A is stored in vaccine management department 1 of province L1. Target object A is currently in province L2. For ease of explanation, the first node 71 corresponding to vaccine management department 1 of province L1 is referred to as first node 1, and the first node 71 corresponding to vaccine management department 2 of province L2 is referred to as first node 2. When vaccine management department 2 of province L2 wants to access the vaccine data of target object A, it determines through the main node 72 that the vaccine data for target object A is stored in vaccine management department 1 of province L1. Then, second node 2 sends an authorization request to first node 1 to request access to the relevant vaccine data of target object A in first node 1. The process of authorization management handled by the child nodes corresponding to first node 1 can be referred to the explanation in the previous embodiment; the principle is the same and will not be repeated here.
[0118] It is important to understand that for each first node, its corresponding child nodes are easy to deploy and can be dynamically expanded. Thus, each first node can deploy management child nodes to be responsible for requesting space services, scheduling request tasks to obtain request results, avoiding management pressure on the database maintained by the first node. At the same time, when it is necessary to open permissions or expand applications, only the expansion management child nodes need to be deployed, which improves flexibility.
[0119] In real-world scenarios, setting different accounts with different permissions for different regions can create pressure in access control. Therefore, in this embodiment, multiple child nodes can be set for each first node to handle different levels of authorization requests, thereby determining the appropriate access permissions and distributing the processing load across individual child nodes to improve efficiency. For example, ... Figure 9As shown, for the same level of authorization request, the provincial authorization request can be allocated to the sub-node 1 for processing; the municipal and county level authorization request and the township level authorization request can be allocated to the sub-node 2 for processing; the third party institution authorization request can be allocated to the sub-node 3 for processing. Taking the sub-node 1 as an example, when processing the authorization request of each first node corresponding to the same level of each province, it is mapped to the same account, and then the spatial position comparison service set in the first node is called to manage the permissions of each first node requesting authorization, that is, to determine the permissions of each first node requesting authorization, which is called access permission 1. Thus, by setting multiple sub-nodes to process authorization requests of different levels, distributed processing is achieved, the processing pressure is shared, and the processing efficiency is improved.
[0120] To illustrate the above embodiment, as an example, based on Figure 10 The flowchart shown is used for illustration.
[0121] After receiving the authorization request, the type of the first node's institution identity information and the target object's related information carried in the authorization request is obtained. According to the type of the first node's institution identity information and the target object's related information, it can be determined whether the institution has the permission to access the target object's related information. If it is determined that the institution does not have the permission to access the target object's related information, it is returned that the requesting institution does not have the permission to access the target object's related information. If it is determined that the institution has the permission to access the target object's related information, then according to the type of the target object's related information to be accessed, the province and department to which the target object's related information belongs are determined, so as to determine whether the target object's related information is stored in the target object's household registration place.
[0122] If the target object's related information is stored in the household registration place, the permission management method in the above embodiment is used to manage the permissions of the first node, that is, to determine whether the target object and the target area associated with the first node satisfy at least one set condition. If at least one set condition is satisfied, the access permission is opened to enable the first node to access the target database storing the target object's related information to obtain the target object's related information. If none of the set conditions is satisfied, it is considered that the first node does not have the permission to access the target object's related information, and the data access is prohibited, that is, there is no permission to access the target database.
[0123] If the target object's related information is not stored in the household registration place, the routing account table in the database maintained in the total node is needed to determine the target database storing the target object's related information according to the correspondence between the object's related information stored in the routing account table and the stored database, for example, referring to Figure 8If the vaccination information of the target object Y is stored in multiple provinces such as L1 province, L2 province or L3 province, the authorization request is sent to the node corresponding to the target database, and the first node requesting authorization is managed in terms of authority based on the authority management method in the above embodiment.
[0124] It should be noted that the above-mentioned embodiments are applicable to the present embodiment, and the principles are the same, which will not be repeated here.
[0125] In order to realize the above-mentioned embodiments, the application further provides a permission management device.
[0126] Figure 11 A structural schematic diagram of a permission management device provided by the embodiments of the application.
[0127] As shown in the figure, the device comprises: Figure 11
[0128] The receiving module 1101 is configured to receive an authorization request, wherein the authorization request is used to request to grant the first node the right to access the information related to the target object.
[0129] The query module 1102 is configured to query the target position of the target object in response to the authorization request.
[0130] The processing module 1103 is configured to manage the authority of the first node according to the positional relationship between the target position and the target area associated with the first node.
[0131] Further, in a possible implementation manner of the embodiments of the application, the processing module 1103 comprises:
[0132] The authorization unit is configured to authorize the first node to access at least part of the information related to the target object in response to the target object and the target area associated with the first node satisfying at least one set condition.
[0133] The set condition comprises a first condition, and the first condition is that the target position of the target object is in the target area associated with the first node.
[0134] In a possible implementation manner of the embodiments of the application, the set condition further comprises at least one of the following second conditions: the target object is in the target area for a first set time length within a set historical time period; or the target object moves to the target position along a set route.
[0135] The authorization unit is specifically configured to:
[0136] in response to the target object and the target area associated with the first node satisfying the first condition and at least one of the second conditions, the first node is authorized to access all related information of the target object;
[0137] in response to the target object and the target area associated with the first node satisfying the first condition and not satisfying any of the second conditions, the first node is authorized to access part of the related information of the target object.
[0138] In a possible implementation of the embodiment of the present application, the processing module 1103 further includes:
[0139] The rejection unit is configured to, in response to the target object and the target area associated with the first node not satisfying any of the set conditions, reject the authorization of the first node to access the related information of the target object.
[0140] In a possible implementation of the embodiment of the present application, the processing module 1103 further includes:
[0141] The revocation unit is configured to, in response to the target object leaving the target area associated with the first node for more than a second set time length, revoke the authorization of the first node.
[0142] In a possible implementation of the embodiment of the present application, the device further includes:
[0143] The first determination module is configured to determine that the target object is in the target area when the distance between the target object and the boundary of the target area is less than a set distance or the target object is in the range enclosed by the boundary.
[0144] In a possible implementation of the embodiment of the present application, the target area is a control area.
[0145] The device further includes:
[0146] The second determination module is configured to determine the at least part of the related information that is allowed to be authorized to access according to the access permission configured by the control area.
[0147] In a possible implementation of the embodiment of the present application, the second determination module is specifically configured to: according to the field allowed to be accessed in the access permission configured by the control area, match the related information of the field as the at least part of the related information allowed to be authorized to access.
[0148] In a possible implementation of the embodiment of the present application, the authorization request further carries the institutional identity information of the first node.
[0149] The device further includes:
[0150] The third determining module is configured to determine the at least part of the related information allowed to be accessed according to the institution identity information.
[0151] It should be noted that the foregoing description of the method embodiments is also applicable to the device embodiments, and thus will not be repeated here.
[0152] The authorization request is used to request to grant the first node the right to access the related information of the target object. In response to the authorization request, the target position where the target object is located is queried. The right of the first node is managed according to the position relationship between the target position and a target area associated with the first node. Through the determination of the position relationship, dynamic authorization of cross-area access is realized, and the efficiency is improved.
[0153] To achieve the above-mentioned embodiments, the present application further provides a server, comprising at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to implement the method as described in the foregoing method embodiments.
[0154] To achieve the above-mentioned embodiments, the present application further provides a non-transitory computer readable storage medium storing computer instructions, and the computer program is stored thereon. When the computer program is executed by a processor, the method as described in the foregoing method embodiments is implemented.
[0155] To achieve the above-mentioned embodiments, the present application further provides a computer program product, and the computer program is stored thereon. When the computer program is executed by a processor, the method as described in the foregoing method embodiments is implemented.
[0156] Figure 12 A structural block diagram of a server provided by the embodiments of the present disclosure is provided. Figure 12 The server shown is merely an example, and should not limit the functions and use range of the embodiments of the present disclosure.
[0157] As Figure 12As shown, the server 10 includes a processor 11 which can perform various appropriate actions and processes in accordance with a program stored in a read only memory (ROM) 12 or a program loaded from a storage 16 into a random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the server 10 are also stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0158] Connected to the I / O interface 15 are: the storage 16 including a hard disk or the like; and a communication section 17 including a network interface card such as a LAN (Local Area Network) card, a modem, or the like, which performs communication processing via a network such as the Internet; and a drive 18 is also connected to the I / O interface 15 as necessary.
[0159] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program carrying on a computer readable medium, which contains program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by the communication section 17. When the computer program is executed by the processor 11, the above-described functions defined in the methods of the present disclosure are performed.
[0160] In an exemplary embodiment, a storage medium including instructions, such as the storage 16 including instructions, is also provided, which can be executed by the processor 11 of the server 10 to complete the above-described methods. Optionally, the storage medium can be a non-transitory computer readable storage medium, such as a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0161] In the description of the application, reference to "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" means that a particular feature, structure, material, or characteristic being described is included in at least one embodiment or example of the application. The appearances of the phrase in various places in the specification are not necessarily all referring to the same embodiment or example. Furthermore, the described specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples. Moreover, the usage of the terms "first", "second" or "third" does not limit the quantity or order of the specific features, structures, materials or characteristics, but rather the term "first", "second" or "third" can be used to distinguish different features, structures, materials or characteristics, which can be combined in any suitable manner. Furthermore, the singular forms "a", "an" and "the" include plural references unless the context clearly dictates otherwise.
[0162] Furthermore, the terms "first", "second", or the like, merely denote different instances of a similar feature, structure, material or characteristic, without necessarily implying any relative importance or any particular order. Thus, a feature defined with "first" or "second" can implicitly or explicitly include at least one of the features. The meaning of "a", "an" and "the" includes plural references unless the context clearly dictates otherwise.
[0163] Any process or method descriptions or blocks in flow charts or otherwise described herein represent embodiments which can be managed as one or more modules, segments, or portions of code which include one or more steps for implementing specific logic functions or steps, and the terms in the description are used for causing or carrying out or upgrading of an action between other hardware under their control. The description of processes and methods of operations should be considered as merely illustrative of the principles of the application.
[0164] The logic and / or steps represented in the flowcharts and / or described herein, for example, can be considered as a sequence of executable instructions stored in a computer readable medium, which can be executed by an instruction execution system, apparatus or device, such as a computer-based system, a processor-based system, or other system that can fetch the instructions from the instruction execution system, apparatus or device and execute the instructions, or a combination thereof. For the purposes of this specification, a "computer readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus or device. The computer readable medium can specifically be, but is not limited to, the following: an electronic connection (electronic apparatus) having one or more wires, a portable computer diskette (magnetic apparatus), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disk read-only memory (CDROM). In addition, the computer readable medium can even be paper or other suitable medium upon which the program can be printed, because the program can be electronically obtained, for example, by optically scanning the paper or other medium, then
[0165] It should be understood that portions of the application can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. As such, if implemented in hardware, and in another embodiment, any of the following technologies, known in the art, or a combination thereof, can be used: discrete logic circuitry having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and the like.
[0166] Those of ordinary skill in the art can understand that all or part of the steps carried out by the above-mentioned embodiment methods can be completed by programs instructing relevant hardware, and the programs can be stored in a computer readable storage medium. When the programs are executed, they include one of the steps of the method embodiments or a combination thereof.
[0167] In addition, each of the functional units in the various embodiments of the present application can be integrated in one processing module, or each of the units can be physically present separately, or two or more units can be integrated in one module. The integrated module can be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
[0168] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.
Claims
1. A rights management method, characterized by, The method comprises: receiving an authorization request, wherein the authorization request is used to request to grant the first node, which is a data server of each province, the right to access the information related to the target object; determining the target location where the target object is located according to real-time positioning information in response to the authorization request; dynamically managing the permission of the first node according to the positional relationship between the target location and the target area associated with the first node, specifically including: in response to the target object and the target area associated with the first node satisfying at least one set condition, authorizing the first node to access at least part of the information related to the target object; dynamically authorizing cross-regional access based on the set condition; wherein the set condition includes a first condition, the first condition is that the target location of the target object is within the target area associated with the first node, and the target area is the administrative region of each province; the set condition also includes at least one of the following second conditions: the target object is in the target area for a first set time length within a set historical period; or the target object moves to the target location along a set route; the response to the target object and the target area associated with the first node satisfying at least one set condition, authorizing the first node to access at least part of the information related to the target object, includes: in response to the target object and the target area associated with the first node satisfying the first condition and at least one of the second conditions, authorizing the first node to access all the information related to the target object; in response to the target object and the target area associated with the first node satisfying the first condition and not satisfying any of the second conditions, authorizing the first node to access part of the information related to the target object.
2. The method of claim 1, wherein, The method further comprises: in response to the target object and the target area associated with the first node not satisfying any of the set conditions, refusing to authorize the first node to access the information related to the target object.
3. The method of claim 1, wherein, The method further comprises: in response to the target object leaving the target area associated with the first node for more than a second set time length, revoking the authorization of the first node.
4. The method of claim 1, wherein, The method further comprises: determining that the target object is in the target area when the distance between the target object and the boundary of the target area is less than a set distance, or the target object is in the enclosed range of the boundary.
5. The method according to any of claims 1-2, characterized by, The target area is a control area; The method further comprises: determining the at least part of the information related to the target object that is allowed to be authorized to access according to the access permission configured by the control area.
6. The method of claim 5, wherein, The determination of the at least part of the information related to the target object that is allowed to be authorized to access according to the access permission configured by the control area includes: matching the information related to the field allowed to be accessed in the access permission configured by the control area as the at least part of the information related to the target object that is allowed to be authorized to access.
7. The method according to any one of claims 1-2, characterized in that, The authorization request also carries the institutional identity information of the first node; The method further comprises: According to the mechanism identity information, it is determined that the at least partial relevant information is allowed to be authorized to access.
8. A rights management apparatus characterized by comprising: Comprise: The receiving module is used for receiving an authorization request, wherein the authorization request is used for requesting to grant a first node a right to access relevant information of a target object, and the first node is a data server of each province; The query module is used for determining a target position where the target object is located according to real-time positioning information in response to the authorization request; The processing module is used for dynamically managing a right of the first node according to a position relationship between the target position and a target area associated with the first node, wherein the target area is an administrative area of each province; The processing module comprises: The authorization unit is used for authorizing the first node to access at least partial relevant information of the target object in response to the target area associated with the target object and the first node satisfying at least one set condition; and the dynamic authorization is realized based on the set condition when cross-area access is performed; wherein the set condition comprises a first condition, and the first condition is that the target position of the target object is located in the target area associated with the first node; and the set condition further comprises at least one of the following second conditions: a time length of the target object being located in the target area reaches a first set time length within a set historical period; or the target object moves to the target position along a set route; The authorization unit is specifically used for authorizing the first node to access all relevant information of the target object in response to the target area associated with the target object and the first node satisfying the first condition and at least one of the second conditions; and authorizing the first node to access partial relevant information of the target object in response to the target area associated with the target object and the first node satisfying the first condition and not satisfying any one of the second conditions.
9. A server, characterized by Comprise: At least one processor; And The memory is connected with the at least one processor in communication; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method in any one of claims 1-7.
10. A distributed system, characterized by Comprise: A plurality of first nodes, and each first node maintains a database; At least one of the first nodes is configured with a sub-node; The sub-node is used for executing the method in any one of claims 1-7.
11. A non-transitory computer-readable storage medium having stored thereon computer instructions, wherein, The computer instructions are used for enabling the computer to execute the method in any one of claims 1-7.
12. A computer program product, characterised in that, The computer program is used for enabling the processor to execute the method in any one of claims 1-7.
Citation Information
Patent Citations
Device access method and device and electronic device
CN106534102A