A permission retrieval and verification method and system based on relational database
By establishing a hierarchical link field permission tree in a relational database, the problems of slow permission retrieval and insufficient permission isolation in the existing technology are solved, fast permission positioning and accurate permission verification are achieved, and permission management in multiple business scenarios is supported.
Patent Information
- Application Number
- CN202211669530.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-12-23
AI Technical Summary
In the prior art, permission retrieval is realized through step-by-step query method, and people cannot be quickly located, and superiors cannot query the permissions of subordinates, and there is a lack of permission isolation mechanism.
Based on the relational database, a hierarchical link field permission tree is established, and the operator's organizational information is obtained for indexing and verification, its usage permissions are determined, and the permission tree is stored in the database to achieve rapid permission positioning and verification.
It realizes rapid query and data positioning within the scope of operator authority, ensures the accuracy of permission verification, and supports permission management in various business scenarios.
Smart Images

Figure CN116226292B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of tree-shaped permissions, and more particularly, to a permission retrieval and verification method and system based on a relational database. Background Art
[0002] In the era of rapid development of the Internet, informatization and globalization have become development trends. In companies, groups, or various large-scale public systems, there will be many different types of organizations or management authority trees. For example, large groups have various branches, branches have various cooperative companies, and even various departments, secondary departments and other organizational structures. Through system authority control, administrator users of parent companies or departments, if granted authority, can query all data within their authority scope, but must not query data outside of their authority scope. These things are generally implemented through organizational structures or departmental affiliations. The general system is implemented through step-by-step lazy loading, drilling down to query level by level, and realizing a layer-by-layer display of permissions. This business has great limitations. If you don't know the department you belong to, you can't quickly locate people.
[0003] In the existing technology, the first query is used to locate the results that meet the conditions, and then the second query is performed using the results. The above method is a currently commonly used step-by-step query method, which implements data retrieval through a program. At the same time, it does not enable the superior to query the subordinate, and does not implement permission isolation for subsets of different superiors. Summary of the Invention
[0004] To address the above issues, the present invention proposes a permission retrieval and verification method based on a relational database, comprising:
[0005] Obtaining architecture information of a target organization, setting hierarchical link fields for multiple organizations at different levels of the organization in a preset manner based on the architecture information, determining usage rights of the organization's public system corresponding to the hierarchical link fields, and establishing a permission tree with the hierarchical link fields for operators of the organization's public system based on the hierarchical link fields and the corresponding usage rights, and storing the permission tree and the architecture information in a relational database;
[0006] When an operator of an organization uses a corresponding service of the organization's public system, the organization information of the operator in the organization is obtained, the public field in the link field corresponding to the operator is determined based on the organization information, the public field is generally indexed in a relational database to determine the link field corresponding to the operator, and the link field corresponding to the operator is precisely indexed in the relational database to determine the operator's permission to use the organization's public system. If the permission to use matches the corresponding service, the operator is allowed to use the corresponding service of the organization's public system.
[0007] When the operator uses other operators' usage rights for the organization's public system, the link fields corresponding to the operator and the other operators are obtained at the same time, and the link fields corresponding to the operator and the other operators are verified. If the link field corresponding to the other operators contains the link field corresponding to the operator, the operator is allowed to use other operators' usage rights for the organization's public system.
[0008] Optionally, the lower the level of the organization, the longer the link field, and the link field of the lower-level organization completely includes the link field of the higher-level organization.
[0009] Optionally, the higher the level of the organization, the higher the authority of operators within the organization to use the organization's public system.
[0010] Optionally, the operator's permission to use the organization's public system is modified by modifying the link field of the organization to which the operator belongs.
[0011] In another aspect, the present invention further proposes a permission retrieval and verification system based on a relational database, comprising:
[0012] An information collection unit is configured to obtain the architecture information of a target organization, set hierarchical link fields for a plurality of organizations at different levels of the organization in a preset manner based on the architecture information, determine the use rights of the organization's public system corresponding to the hierarchical link fields, and establish a permission tree with the hierarchical link fields for operators of the organization's public system based on the hierarchical link fields and the corresponding use rights, and store the permission tree and the architecture information in a relational database;
[0013] An indexing unit is configured to obtain the organizational information of an operator in the organization when the operator uses a corresponding service of the organizational public system; determine the public field in the link field corresponding to the operator based on the organizational information; perform a common index on the public field in a relational database to determine the link field corresponding to the operator; perform a precise index on the link field corresponding to the operator in the relational database to determine the operator's permission to use the organizational public system; and if the permission matches the corresponding service, allow the operator to use the corresponding service of the organizational public system;
[0014] The verification unit is used to obtain the link fields corresponding to the operator and the other operators at the same time when the operator uses the usage rights of other operators to the public system of the organization, and to verify the link fields corresponding to the operator and the other operators. If the link fields corresponding to the other operators include the link fields corresponding to the operator, the operator is allowed to use the usage rights of other operators to the public system of the organization.
[0015] Optionally, the lower the level of the organization, the longer the link field, and the link field of the lower-level organization completely includes the link field of the higher-level organization.
[0016] Optionally, the higher the level of the organization, the higher the authority of operators within the organization to use the organization's public system.
[0017] Optionally, the operator's permission to use the organization's public system is modified by modifying the link field of the organization to which the operator belongs.
[0018] In yet another aspect, the present invention further provides a computing device comprising: one or more processors;
[0019] a processor for executing one or more programs;
[0020] When the one or more programs are executed by the one or more processors, the above-described method is implemented.
[0021] In another aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed, the method described above is implemented.
[0022] Compared with the prior art, the present invention has the following beneficial effects:
[0023] The present invention provides a method for retrieving and verifying permissions based on a relational database, comprising: obtaining the architectural information of a target organization, setting hierarchical link fields for a plurality of organizations of different levels of the organization in a preset manner based on the architectural information, and determining the use permissions of the organizational public system corresponding to the hierarchical link fields, and establishing a permission tree with hierarchical link fields for operators of the organizational public system according to the hierarchical link fields and the corresponding use permissions, and being able to store the permission tree and the architectural information in a relational database; when an organizational operator uses a corresponding service of the organizational public system, obtaining the organizational information of the operator in the organization, determining the public fields in the link fields corresponding to the operator according to the organizational information, and verifying the use permissions of the public fields in the relevant A general index is performed in the relational database to determine the link field corresponding to the operator, and a precise index is performed in the relational database for the link field corresponding to the operator to determine the operator's permission to use the public system of the organization. If the permission matches the corresponding service, the operator is allowed to use the corresponding service of the public system of the organization. When the operator uses the permission of other operators to use the public system of the organization, the link field corresponding to the operator and the other operators is obtained at the same time, and the link field corresponding to the operator and the other operators is verified. If the link field corresponding to the other operator contains the link field corresponding to the operator, the operator is allowed to use the permission of other operators to use the public system of the organization. The present invention can quickly locate the authority of the operator, which is convenient for authority management of the operators of the public system of the organization. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 This is a flow chart of a permission retrieval and verification method based on a relational database of the present invention;
[0025] Figure 2 A schematic diagram of link fields of multiple organizations at different levels of an organization in accordance with an embodiment of a method for authority retrieval and verification based on a relational database of the present invention;
[0026] Figure 3 This is a structural diagram of a permission retrieval and verification system based on a relational database of the present invention. DETAILED DESCRIPTION
[0027] Exemplary embodiments of the present invention will now be described with reference to the accompanying drawings. However, the present invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to provide a thorough and complete disclosure of the present invention and to fully convey the scope of the present invention to those skilled in the art. The terminology used in the exemplary embodiments shown in the accompanying drawings is not intended to limit the present invention. In the accompanying drawings, identical elements are denoted by the same reference numerals.
[0028] Unless otherwise specified, the terms used herein (including technical terms) have the meanings commonly understood by those skilled in the art. In addition, it is understood that terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0029] Example 1:
[0030] The present invention proposes a permission retrieval and verification method based on a relational database, such as Figure 1 Shown, including:
[0031] Step 1: Obtaining the architecture information of the target organization, setting hierarchical link fields for multiple organizations at different levels of the organization in a preset manner based on the architecture information, and determining the use rights of the organization's public system corresponding to the hierarchical link fields. Based on the hierarchical link fields and the corresponding use rights, establishing a permission tree with the hierarchical link fields for operators of the organization's public system, and storing the permission tree and the architecture information in a relational database;
[0032] Step 2: When an operator of an organization uses a corresponding service of the organization's public system, the organization information of the operator in the organization is obtained, and the public field in the link field corresponding to the operator is determined based on the organization information. The public field is generally indexed in a relational database to determine the link field corresponding to the operator. The link field corresponding to the operator is precisely indexed in the relational database to determine the operator's permission to use the organization's public system. If the permission matches the corresponding service, the operator is allowed to use the corresponding service of the organization's public system.
[0033] Step 3. When the operator uses the usage rights of other operators for the public system of the organization, the link fields corresponding to the operator and the other operators are obtained at the same time, and the link fields corresponding to the operator and the other operators are verified. If the link field corresponding to the other operators contains the link field corresponding to the operator, the operator is allowed to use the usage rights of other operators for the public system of the organization.
[0034] The lower the level of the organization, the longer the link field is, and the link field of the low-level organization completely includes the link field of the high-level organization.
[0035] The higher the level of the organization, the higher the authority of the operators within the organization to use the public system of the organization.
[0036] The operator's permission to use the public system of an organization is modified by modifying the link field of the organization to which the operator belongs.
[0037] The effects that the present invention can achieve are as follows:
[0038] Public system operators can quickly query data within their authority: By obtaining the operator's authority (such as a company's human resources department), they can quickly define the query scope within the entire company or group. Within the authority scope, they can combine other query conditions to quickly query the data they need to display.
[0039] Permission verification of the operated data: When operating data through the front-end page or other business channels, the permission field of the person being operated is obtained, and the permission field of the operator is also obtained. If the permission field of the person being operated includes the permission field of the operator, it can be ensured that the person has the operation permission. If it does not include it, it can be determined that the person does not have the permission to operate the data.
[0040] Universal Business Functionality: The permission tree can be integrated with various business scenarios. For example, an organization's permission tree can be used to link individuals, positions, and workflows within the organization, enabling data permissions verification. Alternatively, a tax agency tree can be used to link tax officials across provinces, or even the entire country, allowing individual tax agency administrators to add, delete, modify, and query the information of individuals within their authority.
[0041] The following is an example of a company's organizational structure:
[0042] Set the link field for the organizational structure of the above company, such as Figure 2 As shown, Figure 2A / B / C are link fields. The link field of the head office is set to A. The multiple branches under the head office are set to A, B, A, C, A, D, etc. The branches are further divided into multiple departments, such as E1 (A, B, B1, E1), a secondary department under B1, and branch B (A, B). The deeper the level, the longer the permission field and the lower the level. When the lower permission field completely contains the higher permission field, it means that the lower one must be controlled at a certain level. (A, B, B1, E1) completely contains (A, B), so branch B can control E1. There is no need to know how many levels there are in between. As long as it is completely contained, the permission is allowed.
[0043] The organizations under branch company B are (A,B,B1), (A,B,B2), (A,B,B1,E1), and (A,B,B1,E2). The common point of these permission fields is that they start with A and B, so we can identify the permission fields. All those starting with (A,B) are subordinate organizations of company B and below. As long as a normal index is set for this field, right fuzzy query can be used on MySQL, which can use the index of the relational database to quickly query some information related to the permission tree in combination with other query conditions.
[0044] The present invention can facilitate operators to quickly locate authority ownership. As long as they know the authority field of the current operator and the authority field of the operated data, they can make a simple inclusion judgment to determine the ownership relationship without the need for intermediate recursive judgment.
[0045] The present invention can directly query all data within the scope of authority based on the database index, which is convenient for screening or displaying query results in combination with other conditions.
[0046] The present invention records the upper and lower level relationships of the entire link by adding a new field in the relational database table, thereby realizing the verification of the authority of the superior and subordinate institutions. At the same time, based on this field, the full-link tracking from the top level of the authority tree to the current node can be known. At the same time, by reasonably using this value, the database index conditions can be used at the database level to quickly query all subordinate institutions within the authority range.
[0047] Example 2:
[0048] The present invention also proposes a permission retrieval and verification system 200 based on a relational database, such as Figure 3 Shown, including:
[0049] The information collection unit 201 is configured to obtain the architecture information of the target organization, set hierarchical link fields for multiple organizations at different levels of the organization in a preset manner based on the architecture information, determine the use rights of the organization's public system corresponding to the hierarchical link fields, and establish a permission tree with the hierarchical link fields for operators of the organization's public system based on the hierarchical link fields and the corresponding use rights, and store the permission tree and the architecture information in a relational database;
[0050] Indexing unit 202 is used to obtain the organization information of the operator in the organization when the operator uses the corresponding service of the organization's public system, determine the public field in the link field corresponding to the operator based on the organization information, perform a common index on the public field in the relational database to determine the link field corresponding to the operator, perform a precise index on the link field corresponding to the operator in the relational database, determine the operator's permission to use the organization's public system, and if the permission matches the corresponding service, allow the operator to use the corresponding service of the organization's public system;
[0051] The verification unit 203 is used to obtain the link fields corresponding to the operator and the other operators at the same time when the operator uses the usage rights of other operators to the public system of the organization, and to verify the link fields corresponding to the operator and the other operators. If the link fields corresponding to the other operators include the link fields corresponding to the operator, the operator is allowed to use the usage rights of other operators to the public system of the organization.
[0052] The lower the level of the organization, the longer the link field is, and the link field of the low-level organization completely includes the link field of the high-level organization.
[0053] The higher the level of the organization, the higher the authority of the operators within the organization to use the public system of the organization.
[0054] The operator's permission to use the public system of an organization is modified by modifying the link field of the organization to which the operator belongs.
[0055] The present invention can quickly locate the authority ownership of operators, and facilitates authority management of operators of public systems of organizations.
[0056] Example 3:
[0057] Based on the same inventive concept, the present invention also provides a computer device, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of the method in the above embodiment.
[0058] Example 4:
[0059] Based on the same inventive concept, the present invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It can be understood that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space that stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the steps of the method in the above embodiment.
[0060] It will be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented in various computer languages, for example, the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0061] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0062] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0064] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0065] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A permission retrieval and verification method based on a relational database, characterized in that: The method comprises: Obtaining architecture information of a target organization, setting hierarchical link fields for multiple organizations at different levels of the organization in a preset manner based on the architecture information, determining usage permissions of the organization's public system corresponding to the hierarchical link fields, and establishing a permission tree with the hierarchical link fields for operators of the organization's public system based on the hierarchical link fields and the corresponding usage permissions, and storing the permission tree and the architecture information in a relational database; When an operator of an organization uses a corresponding service of the organization's public system, the organization information of the operator in the organization is obtained, the public field in the link field corresponding to the operator is determined based on the organization information, the public field is generally indexed in a relational database to determine the link field corresponding to the operator, and the link field corresponding to the operator is precisely indexed in the relational database to determine the operator's permission to use the organization's public system. If the permission to use matches the corresponding service, the operator is allowed to use the corresponding service of the organization's public system. When the operator uses other operators' usage rights for the organization's public system, the link fields corresponding to the operator and the other operators are obtained at the same time, and the link fields corresponding to the operator and the other operators are verified. If the link field corresponding to the other operators contains the link field corresponding to the operator, the operator is allowed to use other operators' usage rights for the organization's public system.
2. The method according to claim 1, characterized in that The lower the level of the organization, the longer the link field is, and the link field of the lower-level organization completely includes the link field of the higher-level organization.
3. The method according to claim 1, characterized in that The higher the level of the organization, the higher the authority of the operators within the organization to use the public system of the organization.
4. The method according to claim 1, wherein The operator's permission to use the public system of an organization is modified by modifying the link field of the organization to which the operator belongs.
5. A permission retrieval and verification system based on a relational database, characterized in that: The system comprises: An information collection unit is configured to obtain architecture information of a target organization, set hierarchical link fields for a plurality of different levels of organizations of the organization in a preset manner based on the architecture information, determine usage rights of a public system of the organization corresponding to the hierarchical link fields, establish a permission tree with the hierarchical link fields for operators of the public system of the organization based on the hierarchical link fields and the corresponding usage rights, and store the permission tree and the architecture information in a relational database; An indexing unit is configured to obtain the organizational information of an operator in the organization when the operator uses a corresponding service of the organizational public system; determine the public field in the link field corresponding to the operator based on the organizational information; perform a common index on the public field in a relational database to determine the link field corresponding to the operator; perform a precise index on the link field corresponding to the operator in the relational database to determine the operator's permission to use the organizational public system; and if the permission matches the corresponding service, allow the operator to use the corresponding service of the organizational public system; The verification unit is used to obtain the link fields corresponding to the operator and the other operators at the same time when the operator uses the usage rights of other operators to the public system of the organization, and to verify the link fields corresponding to the operator and the other operators. If the link fields corresponding to the other operators include the link fields corresponding to the operator, the operator is allowed to use the usage rights of other operators to the public system of the organization.
6. The system according to claim 5, characterized in that The lower the level of the organization, the longer the link field is, and the link field of the lower-level organization completely includes the link field of the higher-level organization.
7. The system according to claim 5, characterized in that The higher the level of the organization, the higher the authority of the operators within the organization to use the public system of the organization.
8. The system according to claim 5, wherein: The operator's permission to use the public system of an organization is modified by modifying the link field of the organization to which the operator belongs.
9. A computer device, characterized in that: include: one or more processors; a processor for executing one or more programs; When the one or more programs are executed by the one or more processors, the method according to any one of claims 1 to 4 is implemented.
10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed, the method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Organization application permission management method and service system based on tree-shaped organization model
CN108322432A
Resource operation authority control method and device and electronic equipment
CN111259429A