Data permission management method, device, computer equipment and storage medium

Through the unified management of data resource packages and adjustment of permission types, the problem of low efficiency in data permission management is solved, and efficient and unified adjustment of multiple data resource permission types is achieved.

CN116933291BActive Publication Date: 2025-09-19BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311029085.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-15
Publication Date
2025-09-19
Estimated Expiration
2043-08-15

AI Technical Summary

Technical Problem

The management and control of data permissions is inefficient, especially when data tables change and re-authorization is required, resulting in cumbersome and inefficient operations.

Method used

Through the unified management of data resource packages, the target data resource packages are used to uniformly adjust the permission types, including unified adjustment of permissions for resource types such as databases, data tables, data rows and data columns, to achieve one-time adjustment of permission types for multiple data resources.

Benefits of technology

The efficiency of data permission management and control has been improved. The permission type of multiple data resources can be adjusted through one adjustment, which simplifies the authorization process and improves operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116933291B_ABST
    Figure CN116933291B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the field of computer technology and discloses a method, apparatus, computer equipment and storage medium for managing and controlling data permissions. The method provided by the present disclosure includes obtaining a target data resource package and the current permission type of the authorized party corresponding to the target data resource package, wherein the target data resource package includes multiple data resources, and the resource type of the data resources includes at least one of a database, a data table, a data row and a data column; obtaining a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party, and the permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package, and the permission types include read-only and read-write; and sending a permission type adjustment message to the authorized party. By adjusting the permission type of the target data resource package, the permission types of multiple data resources can be uniformly adjusted, thereby improving the management and control efficiency of data permissions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computers, and in particular to methods, devices, computer equipment, and storage media for managing and controlling data permissions. Background Art

[0002] When data users develop application scenarios or perform data analysis, they need to involve a large amount of data. Accordingly, they need to grant permissions to a large number of data tables or all tables tagged with a certain business tag. This means that these tables need to be authorized to the corresponding data users every time authorization is performed. Alternatively, when the list of tables under a tag changes, the changed data tables need to be re-authorized, resulting in low efficiency in data permission management and control. Summary of the Invention

[0003] In view of this, the present disclosure provides a data permission management method, apparatus, computer device and storage medium to solve the problem of low efficiency in data permission management.

[0004] In a first aspect, the present disclosure provides a method for managing and controlling data permissions, the method comprising:

[0005] Acquire a target data resource package and a current permission type of an authorized party corresponding to the target data resource package, wherein the target data resource package includes a plurality of data resources, and the resource types of the data resources include at least one of a database, a data table, a data row, and a data column;

[0006] Obtaining a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party, wherein the permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package, wherein the permission types include read-only and read-write;

[0007] Sending a rights type adjustment message to the authorized party.

[0008] In a second aspect, the present disclosure provides a data permission management and control device, the device comprising:

[0009] a data resource package acquisition module, configured to acquire a target data resource package and a current permission type of a permission holder corresponding to the target data resource package, wherein the target data resource includes a plurality of data resources, and the resource type of the data resource includes at least one of a database, a data table, a data row, and a data column;

[0010] A permission type adjustment instruction acquisition module is used to obtain a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party. The permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package. The permission types include read-only and read-write.

[0011] The permission type adjustment message sending module is used to send a permission type adjustment message to the authorized party.

[0012] In a third aspect, the present disclosure provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the data permission management method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0013] In a fourth aspect, the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the data permission management method of the first aspect or any corresponding embodiment thereof.

[0014] The data permission management and control method provided by the embodiment of the present disclosure uniformly manages multiple data resources using a target data resource package, and achieves unified adjustment of the permission types of multiple data resources by adjusting the permission types of the target data resource package. That is, the permission types of multiple data resources can be adjusted through a single adjustment, thereby improving the management and control efficiency of data permissions. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0016] Figure 1 is a flowchart of a method for controlling data permissions according to an embodiment of the present disclosure;

[0017] Figure 2 is a flowchart of a method for determining a target data resource package according to an embodiment of the present disclosure;

[0018] Figure 3a-3c is a schematic diagram of creating a new target data resource package according to an embodiment of the present disclosure;

[0019] Figure 4 This is a flow chart of adjusting data resources in a method for managing and controlling data permissions according to an embodiment of the present disclosure;

[0020] Figure 5 is a schematic diagram of a resource package page according to an embodiment of the present disclosure;

[0021] Figure 6 is a schematic diagram of a resource details page of a target data resource package according to an embodiment of the present disclosure;

[0022] Figure 7 is a schematic diagram of processing a data resource package according to an embodiment of the present disclosure;

[0023] Figure 8 is a schematic diagram of permission application for a data resource package according to an embodiment of the present disclosure;

[0024] Figure 9 is a schematic diagram of authorization of a data resource package according to an embodiment of the present disclosure;

[0025] Figure 10 is a schematic diagram of reclaiming expired permissions of a data resource package according to an embodiment of the present disclosure;

[0026] Figure 11 is a structural block diagram of a data authority management and control device according to an embodiment of the present disclosure;

[0027] Figure 12 Schematic diagram of the hardware structure of the computer device according to the embodiment of the present disclosure. DETAILED DESCRIPTION

[0028] To make the purpose, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present disclosure.

[0029] In related technologies, analyzing data for a scenario typically involves multiple data tables, such as a table representing consumables, a table representing progress, a table representing workload, and so on. When managing permissions for these data tables, permissions must be managed separately for each table. Furthermore, if the content of a data table changes, each table must be reauthorized, resulting in low permission management efficiency.

[0030] Based on this, the embodiment of the present disclosure provides a method for managing and controlling data permissions, which uniformly manages and controls the permissions of data resources through a data resource package. Among them, the resource types of data resources include but are not limited to databases, data tables, data rows or data columns, and the specific types are set according to actual needs. For example, for multiple data tables in the same scenario, or data tables with the same permission requirements in different scenarios, a data resource package can be used to uniformly manage permissions. Of course, as mentioned above, the resource types included in the data resource package can be multiple, and are not limited to the same resource type.

[0031] For example, data resource package A includes data resources 1 to 4. The data type of data resource 1 is database, the data types of data resources 2 to 3 are data tables, and the data type of data resource 4 is data row.

[0032] Data resource package B includes data resources 1 to 3, and the data types of data resources 1 to 3 are all data tables;

[0033] Data resource package C includes data resources 1 to 5. The data types of data resources 1 to 4 are databases, and the data type of data resource 5 is data row.

[0034] It should be noted that the above resource types of data resources in the data resource package are merely examples and do not limit the protection scope of the present disclosure. They are set according to actual needs.

[0035] Data resources from different data sources can be added to a data resource package. Data sources include but are not limited to LAS, ByteHouseCE, HIVE, ClickHouse, and Doris. There can be multiple data resources, and multiple data resources come from at least one data source. As mentioned above, the resource type of a data resource can be data row or data column. That is, the resource granularity of the data resources added to the data resource package is refined to the row and column level.

[0036] A data resource package is related to the data resources it contains. If all the data resources in a data resource package are deleted, the data resource package will also be automatically deleted. In other words, a data resource package can change as the data resources it contains change.

[0037] According to an embodiment of the present disclosure, an embodiment of a method for managing and controlling data permissions is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0038] In this embodiment, a data permission management method is provided, which can be used for computer devices, such as computers and mobile terminals, where mobile devices include but are not limited to mobile phones and tablet computers. Figure 1 is a flow chart of a method for controlling data permissions according to an embodiment of the present disclosure, such as Figure 1 As shown, the process includes the following steps:

[0039] Step S101: Acquire a target data resource package and the current permission type of the authorized party corresponding to the target data resource package.

[0040] The target data resource package includes a plurality of data resources, and the resource types of the data resources include at least one of a database, a data table, a data row, and a data column.

[0041] The target data resource package is an established data resource package, which includes multiple data resources. For the resource types of the multiple data resources, please refer to the above description and will not be repeated here.

[0042] The target data resource package can be selected by the user from multiple data resource packages through interaction, can be obtained by searching for the data resource package by its name, or can be obtained through interaction with a third-party device. For example, the relevant information of each data resource package is stored in the cloud, and the client obtains the target data resource package from the cloud through communication with the cloud. Of course, the method of obtaining the target data resource package is not limited to the above, and can also be obtained by other methods, which are not limited to this.

[0043] The authorized party corresponding to the target data resource package is the object that has access rights to the target data resource package. The access rights can be read-only, read-write, etc. For the target data resource package, objects with the same access rights are in the same user group. The authorized party corresponding to the target data resource package can be determined through authorization when the target data resource package is created, or it can be determined through corresponding permission application, etc. When maintaining the authorized party, a data table can be used to describe the authorized party corresponding to each target data resource package. Of course, it can also be expressed in the form of a user group.

[0044] For example, for data resource package A, the authorized parties are a1-a4; for data resource package B, the authorized parties are a1, b1-b5. That is, the same object can have permissions for multiple data resource packages, and the same data resource package can correspond to multiple authorized parties. There is no limit on the number of authorized parties corresponding to each data resource package. In some cases, an upper limit can be set for the number of authorized parties. If the current number of authorized parties is determined and the corresponding upper limit is reached, a prompt message will be issued.

[0045] The current permission type of the authorized party can be read-only, read-write, etc., depending on the permission type setting of the target data resource package. As mentioned above, the target data resource package includes multiple data resources. If the current permission type of the authorized party is read-only, the authorized party has read-only permission for multiple data resources in the target data resource; if the current permission type of the authorized party is read-write, the authorized party has read and write permission for multiple data resources in the target data resource.

[0046] Step S102: obtaining a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party.

[0047] The permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package, and the permission types include read-only and read-write.

[0048] The user adjusts the permission type of the target data resource package by interacting with the page. Accordingly, the permission adjustment instruction for the target data resource package is obtained. After obtaining the permission adjustment instruction, the permission type is adjusted to the corresponding target permission type. For example, after interacting with the page, the user changes the permission type of the target data resource package from read-only to read-write. Correspondingly, the current permission type of the authorized party is changed from read-only to the target permission type of read-write.

[0049] For example, if the target data resource package includes three data resources, and the current permission type of the authorized party is read-only, after receiving the permission type adjustment instruction and determining that the target permission type is read-write, the authorized party will adjust the permission type of all three data resources to read-write. In other words, by modifying the target data resource package once, the permission type of all data resources in the target data resource package can be uniformly adjusted.

[0050] Step S103: Send a permission type adjustment message to the authorized party.

[0051] After the permission type is adjusted, the corresponding authorized party needs to be informed, and a permission type adjustment message is sent to the authorized party. For example, the adjustment message includes a title and a body. The title is "Permission type adjustment of data resource package A", and the body is "Permission type of data resource package A is adjusted from read-only to read-write."

[0052] Of course, the above is only a representation of the permission type adjustment message, but it does not limit the protection scope of the present disclosure and is specifically set according to actual needs.

[0053] The data permission management and control method provided in this embodiment uniformly manages multiple data resources using a target data resource package, and achieves unified adjustment of the permission types of multiple data resources by adjusting the permission types of the target data resource package. That is, the permission types of multiple data resources can be adjusted through a single adjustment, thereby improving the efficiency of data permission management and control.

[0054] This embodiment provides a method for determining a target data resource package within a data permissions management method. This method can be used on computing devices such as computers and mobile terminals, including but not limited to mobile phones and tablets. Data permissions are managed based on data resource packages, requiring the creation of new data resource packages. Figure 2 is a flow chart of a method for determining a target data resource package according to an embodiment of the present disclosure. Figure 2 As shown, the process includes the following steps:

[0055] Step S201: obtaining a new instruction for a data resource package to display a new page for creating a data resource package.

[0056] The creation of new data resource packages and subsequent configuration of these packages are implemented through interactions, such as page interactions. Specifically, when a new data resource package is needed, a corresponding page is displayed, which contains a new data resource package control. The user interacts with the control to generate a new creation instruction, which in turn receives the new creation instruction for the data resource package. In response to this creation instruction, the new data resource package page is displayed.

[0057] Of course, the method for generating the new instruction is not limited to the above-mentioned method of interacting with the new control, and can also be implemented in other ways, which are not limited here.

[0058] The new page is used to guide users in creating a new data resource package and setting information such as the permission type for the data resource package. The creation of a new data resource package can be completed on the same page, or different steps can be completed on different pages. For example, if the creation of a new data resource package requires four steps, then these four steps can be displayed on the same page. Due to the size of the display screen, it may not be possible to display all of them on one page. The corresponding content can be displayed by dragging the slider; or, these four steps can be displayed on four pages respectively, with each page corresponding to one step.

[0059] Step S202 : obtaining a setting instruction for basic information and resource information of the data resource package in the newly created page, so as to obtain the basic information of the data resource package and a plurality of data resources.

[0060] The basic information includes the data source, database, and name corresponding to the resource data package, and the resource information includes the resource type and data resource of the data resource.

[0061] The data sources included in the basic information of a data resource package can be displayed in a list or selection control to facilitate user selection. A data resource package can include at least one data source, including but not limited to LAS, ByteHouseCE, HIVE, CliceHouse, and Doris. Databases are associated with data sources. For example, after selecting the data source LAS, the corresponding optional databases are displayed in the database.

[0062] The resource package name is set according to actual needs and may include letters, numbers, special characters, etc. In some optional implementations, the length of the resource package name has a corresponding length threshold, so the resource package name needs to be set within the length threshold.

[0063] Resource types include but are not limited to databases, data tables, data rows, and data columns. Data resources correspond to resource types. For example, if Database 1 is selected in the resource type, the data resources are the data resources in Database 1.

[0064] For example, Figure 3a The page shows the settings for basic information and resource information in the Create New Page. This page includes two sections: Basic Information and Add Resource. By interacting with the corresponding controls in the Basic Information section, basic information settings instructions are generated. In response to these settings instructions, the basic information of the data resource package is obtained. Similarly, by interacting with the corresponding controls in the Add Resource section, resource information settings instructions are generated. In response to these settings instructions, multiple data resources in the data resource package are obtained.

[0065] exist Figure 3a The figure shows the four steps involved in creating a new data resource package: basic information, permission settings, approval flow, and automatic approval. On each page, by interacting with the corresponding controls, corresponding setting instructions are generated, and responding to these setting instructions will obtain the corresponding setting results.

[0066] Step S203: Obtain the permission setting instruction for the data resource package to obtain permission information of the data resource package.

[0067] After completing the basic information and resource information settings, you can switch to the next page to set permissions by interacting with the Next control on the new page. Permission settings are used to determine the permission information of the data resource package, including but not limited to permission type and confidentiality level.

[0068] Permission types include but are not limited to read-only and read-write. The confidentiality level can be expressed as low, medium, or high, or as L0 to LN. The value of N is set according to actual needs. When defining the confidentiality level, the larger N is, the higher the corresponding confidentiality level.

[0069] In some optional implementations, the above step S203 includes:

[0070] Step a1: displaying the permission setting page, which includes setting controls for permission holders and confidentiality levels.

[0071] Step a2: Obtain the highest confidentiality level of all data resources in the data resource package.

[0072] Step a3, obtain the first setting instruction of the setting control corresponding to the authority person and the second setting instruction of the setting control corresponding to the confidentiality level to obtain the authority person and confidentiality level of the data resource package. The confidentiality level of the data resource package is not lower than the highest confidentiality level.

[0073] The permissions settings page is used to set permissions for a data resource package. It includes controls for permissions holders and confidentiality levels. The permissions holder is used to manage permissions for the data resource package. The confidentiality level of a data resource package is related to the confidentiality levels of the multiple data resources included in the package. That is, the confidentiality level of a data resource package must be no lower than the highest confidentiality level of the multiple data resources. Therefore, before setting the confidentiality level of a data resource package, it is necessary to obtain the confidentiality levels of the multiple data resources included in the package and select the highest confidentiality level. If the confidentiality levels are L0 to L4, with L4 being the highest configurable level, and the highest confidentiality level of multiple data resources is L2, then when setting the confidentiality level of the data resource package, the corresponding confidentiality levels L0 to L1 are unselectable in the corresponding confidentiality level settings. For example, L0 to L1 can be grayed out, leaving only L2 to L4 available. Alternatively, L0 to L4 are displayed normally, and if the user interactively selects L1, a pop-up window prompts the user that the currently set confidentiality level must be no lower than L2. Alternatively, other forms of representation are used, and no limitation is imposed on the specific representation form. It is only necessary to ensure that the confidentiality level of the set data resource package is not lower than the highest confidentiality level of the multiple data resources.

[0074] For example, Figure 3bThe permission setting page is shown, including the person in charge of the permission, confidentiality level, permission ownership, and renewal configuration. Among them, permission ownership is used to indicate the owner of the permission of the data resource package, for example, the inherited superior, etc. If the superior's permission type is read-only, the permission type of the data resource package is also read-only. If you choose to customize, you can customize the permission type of the data resource package here. When authorizing the authorized party, the validity period of the authorization will be given. If you still want to have the corresponding permission after the validity period, the corresponding Figure 3b The renewal configuration in the config determines whether the data resource package is allowed to be renewed. If renewal is allowed, the data resource package can be renewed after the expiration date. If renewal is not allowed, the data resource package cannot be renewed after the expiration date.

[0075] When setting the permission information of the target data resource, the confidentiality level of the data resource package is set based on the highest confidentiality level of all data resources in the data resource package, thereby improving the security of the data resources in the target data resource package.

[0076] Step S204: Acquire the approval setting instruction for the data resource package to obtain the approval flow of the data resource package.

[0077] After creating a new data resource package, permissions can be granted to the package owner through either active authorization or a permission application. The permission application process involves approval. Therefore, during the creation of a new data resource package, an approval flow must be configured to ensure a standardized approval process.

[0078] When setting up approval for a data resource package, determine the approval flow of the data resource package by interacting with the corresponding controls on the approval flow setting page.

[0079] In some optional implementations, step S204 includes:

[0080] Step b1: Display the approval flow setting page, which includes setting controls for approvers corresponding to each approval level.

[0081] Step b2: obtaining a setting instruction for the setting control of the approval personnel to obtain the approval process of the data resource package.

[0082] Step b3: displaying an automatic approval page, which is used to display target approval levels that can be automatically approved in the approval hierarchy.

[0083] Step b4: Obtain the setting instruction for the target approval level to obtain the approval flow of the data resource package.

[0084] The Approval Flow Settings page includes various approval levels. The default approval flow is four levels, but you can also add or delete approval levels based on the four levels. For example, deleting an approval level will result in a three-level approval, while adding an approval level will result in a five-level approval.

[0085] Each approval level has a corresponding approver setting control to set the approvers for that approval level. Specifically, the user interacts with the approver setting control corresponding to the approval level to generate a corresponding setting instruction. In response to the setting instruction, the approver corresponding to the approval level is obtained.

[0086] For example, Figure 3c The approval flow setting page is shown, which displays three approval levels, and each approval level has a corresponding approver setting control. Figure 3c The approver setting control is presented in the form of a drop-down list. Of course, it is not limited to this representation form, and other methods can also be used, such as search, etc. The specific representation form is set according to actual needs and is not limited here.

[0087] Figure 3c The figure also shows the add / delete control for the approval level. By interacting with the add / delete control, the approval level of the data resource package can be adjusted. After the approval level and its corresponding approver are set, the next step is to set up automatic approval.

[0088] Automatic approval is used to automatically approve applications submitted by approvers at a certain level. The automatic approval page displays the target approval levels within the approval hierarchy that can automatically approve applications. The target approval level displayed on the automatic approval page can be adjusted. If the automatic approval levels are Approval Levels 2 and 3, the interactive settings for the automatic approval levels will ultimately determine Approval Level 2 as the automatic approval level.

[0089] After setting up the approval process and automatic approval described above, the approval process for a data resource package is established. Data resource package information is maintained using a settings table. Each record in the settings table corresponds to a data resource package, and the recorded information includes the package's basic information, permission settings, approval process, and automatic approval information. The multiple data resources included in a data resource package are represented using a mapping table.

[0090] When setting up the approval process, an automatic approval setting is introduced, which enables automatic approval at the corresponding approval level, thereby improving approval efficiency.

[0091] Step S205 : determining the target data resource package based on the basic information, resource information, authority information, and approval flow of the data resource package.

[0092] After completing the four steps above, the target data resource package is obtained. That is, the target data resource package includes basic information, resource information, permission information, and approval flow.

[0093] The data permission management method provided in this embodiment determines the target data resource package. When creating the target data resource package, its basic information, included resource information, initially set permission information and approval flow are defined, thereby achieving the integrity of the relevant information of the newly created target data resource package.

[0094] In some optional implementations, after the target data resource package is set, a list page of created data resource packages may be displayed, showing partial information of each created data resource package, such as name, permission type, confidentiality level, etc.

[0095] This embodiment provides a method for adjusting data resources within a data permissions management method, which can be used on computing devices such as computers and mobile terminals, where mobile devices include but are not limited to mobile phones and tablet computers. For a target data resource package, the multiple data resources included therein can be adjusted based on demand, for example, to add data resources or delete existing data resources. Figure 4 is a flow chart of a method for adjusting data resources according to an embodiment of the present disclosure. Figure 4 As shown, the process includes the following steps:

[0096] Step S401: obtaining an adjustment instruction for a plurality of data resources included in a target data resource package to determine the data resources included in the adjusted target resource data package.

[0097] For the multiple data resources included in the target data resource package, the user interactively adjusts the multiple data resources, generates adjustment instructions for the multiple data resources, and responds to the adjustment instructions to determine the data resources included in the adjusted target data resource package. For example, if the target data resource package originally contains four data resource packages, after interactive adjustment, the adjusted target data resource package will include six data resources.

[0098] In some optional implementations, the step S401 of obtaining adjustment instructions for the plurality of data resources included in the target data resource package includes:

[0099] Step c1: displaying a resource package page, which includes an entry of a created data resource package, and the entry of the created data resource package includes a resource detail control.

[0100] Step c2: obtaining a selection instruction of a resource details control in the target data resource package entry to display a resource details page of the target data resource package.

[0101] Step c3: obtaining adjustment instructions for the multiple data resources included in the target data resource package in the resource details page.

[0102] The Resource Packages page displays existing data resource packages, which are presented in a list format. Each entry on the Resource Packages page contains information about an existing data resource package, including a resource detail control. Resource detail controls can be displayed as hyperlinks, buttons, or other similar forms, with no specific restrictions.

[0103] The resource package page displays existing data resource packages, of which there may be multiple. To adjust the data resources in a specific existing data resource package, you must first select the data resource package. For ease of description, the existing data resource package to be adjusted is referred to as the target data resource package below, i.e., the newly created data resource package described above.

[0104] It should be noted that the target data resource package can be selected by selecting the target data resource package or by selecting the resource details control in the entry of the target data resource package. That is, selecting the resource details control in a certain entry is considered to be the selection of the data resource package corresponding to the resource details control.

[0105] For example, Figure 5 The resource package page is shown, which displays four data resource packages named A to D. If you select the resource details control corresponding to data resource package A, you will enter the Figure 6 The resource details page shown in the figure shows the included data resources. The data resources included in the data resource package A can be adjusted by adding resource controls or deleting controls to generate adjustment instructions for multiple data resources included in the data resource package A.

[0106] In some optional implementations, the resource details page also includes an editing control, and the information of the data resource package can be edited by interacting with the editing control. That is, for an already created data resource package, its related information can be adjusted again.

[0107] Adjustments to multiple data resources within the target data resource package are determined through interaction with the resource details control in the established data resource package entry on the resource package page. Through interaction with the resource details control, the resource details page of the target data resource package, i.e., the list of data resources, can be displayed, thereby enabling intuitive adjustments to the data resources.

[0108] In some optional implementations, the created data resource package entry also includes an authorization details control, and the above-mentioned data permission management method further includes:

[0109] Step d1: obtaining a selection instruction for an authorization details control in a target data resource package entry to display an authorization details page of the target data resource package.

[0110] Step d2: Obtain the audit tag of each authorized party in the authorization details page to determine the target authorized party corresponding to the target data resource package.

[0111] Each data resource package entry on the resource details page also includes an authorization details control. Through interaction with the authorization details control, an authorization details instruction is generated, and the authorization details page of the target data resource package is displayed in response to the authorization details instruction. The authorization details page is used to display the authorized party of the target data resource package, for example, the name of the acquirer, the reason for authorization, and so on. The user audits the authorized party by viewing the information of the authorized party displayed on the page and sets an audit label. The audit label is used to indicate whether the authorized party should have the authority to the target data resource package. If the audit label indicates that the authorized party should not have the authority to the target data resource package, it is necessary to contact the authorized party's authority to the target data resource package, thereby updating the authorized party of the target data resource package and determining the target authorized party.

[0112] The created data resource package entry also includes an authorization details control. By interacting with the authorization details control, the authorization details page is displayed. The authorization details page displays all authorized parties of the target data resource package. By obtaining the audit tags of each authorized party, invalid authorized parties are identified, and permissions are reclaimed to ensure the security of data resources in the target data resource package.

[0113] Step S402: Acquire all authorized parties of the target data resource package.

[0114] All authorized parties of the target data resource package can be maintained in the form of a data table or other methods. In the data table, the authorized parties corresponding to each data resource package are recorded, and the target data resource package can be queried by its name or identifier to obtain all authorized parties.

[0115] Step S403: Send a resource adjustment message of the target data resource package to all authorized parties.

[0116] Since the data resources in the target data resource package are adjusted in the above step S401, in order to facilitate the authorized parties to timely understand the data resources in the target data resource package, a resource adjustment message of the target data resource package needs to be sent to all authorized parties.

[0117] In some optional implementations, the resource adjustment message includes a title and a body, where the title is used to indicate the type of resource adjustment, and the body is used to indicate the impact of the resource adjustment on the authorized party, where the types of resource adjustment include adding new data resources and deleting data resources.

[0118] For example, if a new data resource is added, the resource adjustment message will have the title: Resources in the resource package have been adjusted, and the body text: The resource package ***New data resource*** for which you have permission has been added, with read-only permission. You have been granted the corresponding permission.

[0119] If you delete data resources, the title of the resource adjustment message is: Resources in the resource package are adjusted, and the body of the message is: The resource package you have permission to ***Delete resources***, read-only permission, has been revoked for you.

[0120] The resource adjustment message includes a title and a body. The title is used to indicate the focus of the adjustment, and the body is used to represent the specific content, so that the authorized party can intuitively understand the impact of the adjustment of the target data resource package on itself.

[0121] The method for adjusting data resources in the data permission management method provided in this embodiment, for multiple data resources in the target data resource package, when they are adjusted according to needs, the adjustment status is sent to all acquirers of the target data resource package, so that the authorized parties can understand the data resources in the target data resource package in a timely manner.

[0122] In some optional implementations, the above-mentioned data permission management method further includes:

[0123] Step e1: Display the permission application page.

[0124] Step e2: obtaining setting instructions for the data resource package to be authorized, the target authorized party, and the authorization reason in the permission application page to determine the permission application request.

[0125] Step e3: Send the permission application request, and approve the permission application request based on the approval flow of the data resource package to be authorized to obtain an approval result.

[0126] If a user wishes to obtain permission for a data resource package, they must apply for permission. Accordingly, a permission application page is displayed. This page includes controls corresponding to the data resource package to be authorized, the authorized party, and the reason for authorization. Interaction with these controls generates corresponding setup instructions. In response to the setup instructions, the user's input of the data resource package to be authorized, the target authorized party, and the reason for authorization is obtained to generate a permission application request.

[0127] The permission request is sent to the first-level approver of the data resource package to be authorized. This approval process is followed by approval of the permission request, resulting in an approval result. The approval result indicates that the target authorized party has permission to the data resource package, or that the target authorized party is denied permission to the data resource package.

[0128] For the data resource packages to be authorized, a permission application is initiated on the permission application page, and then it is approved through the approval flow of the data resource packages to be authorized to obtain the approval result. By defining the approval flow of each data resource package, timely processing of permission applications is facilitated.

[0129] In some optional implementations, the approval process of the permission application request based on the approval flow of the data resource package to be authorized in step e3 to obtain an approval result includes:

[0130] Step e31: Check whether there is an unprocessed permission request that is the same as the permission request.

[0131] In step e32, if there is no permission application request that is the same as the permission application request and has not been processed, the permission application request is approved based on the approval flow of the data resource package to be authorized to obtain an approval result.

[0132] When processing a permission application request, first check whether there is a permission application request that is the same as the permission application request and has not been processed. If so, ignore the permission application request; if not, approve the permission application request based on the approval flow of the data resource package to be authorized to obtain the approval result.

[0133] Before processing a permission application request, first determine whether there are identical permission application requests that have not been processed to avoid duplicate processing of permission applications.

[0134] In some optional implementations, the above-mentioned data permission management method further includes:

[0135] Step f1: Check whether the permissions of each authorized party of the target data resource package have expired.

[0136] Step f2: If there is an authorized party whose authority has expired, the authority of the authorized party whose authority has expired to the target data resource package is revoked.

[0137] Each authorized party in the target data resource package has a corresponding validity period. The expiration of each authorized party's permissions can be checked regularly. If any party's permissions have expired, their permissions to the target data resource package are revoked. Timely recovery of expired permissions ensures the security of the data resources in the target data resource package.

[0138] Of course, the detection of whether the authority of the authorized party has expired can be timed, or triggered according to needs, etc., and there is no limitation on the specific timing of the detection.

[0139] As a specific application example of the present disclosure, Figure 7 A schematic diagram illustrates the processing of data resource packages. Data resource package processing methods include creating new data resource packages, modifying data resource packages, and deleting data resource packages. Creating a new data resource package includes basic information, permission information, and the approval process. This information is stored in a settings package, and the data resources associated with the data resource package are stored in a mapping table. To facilitate viewing historical information about the data resource package, the new information about the data resource package is also stored in a history table. Modifying a data resource package involves modifying the permission type and adding or deleting data resources. After modifying the permission type, an adjustment message is sent to the corresponding authorized party. Adding or deleting data resources adjusts both the data resource corresponding to the data resource package and the authorized party's permissions to the changed data resource. Deleting a data resource revokes the permissions granted to the authorized party for that data resource. Adding a new data resource grants the authorized party permissions to that data resource. Deleting a data resource revoks permissions from all authorized parties for the data resource package, and the data resource package is marked as deleted in the history table.

[0140] As a specific application example of the present disclosure, Figure 8 The process of permission application is shown. On the permission application page, select the data resource package for which permission needs to be applied, and generate a work order corresponding to the permission application request. First, verify the in-transit work orders to determine whether there are identical and unprocessed work orders. If so, the work order submission is not allowed. If not, perform the existing permission verification, that is, determine whether the requester already has the permission for the data resource package. If so, the work order submission is not allowed. If not, the work order is submitted. An approval flow is generated based on the permission settings, and the work order is approved. If the approval is passed, the authorized party will be added to the user group corresponding to the data resource package and recorded in the authorization log. If the approval is not passed, the work order ends and is not authorized.

[0141] As a specific application example of the present disclosure, Figure 9 The process of active authorization is shown. The authorized party of the data resource package is selected and added to the user group associated with the data resource package. The authorization log is recorded and the authorization records are stored in a new table according to the authorized resource package.

[0142] As a specific application example of the present disclosure, Figure 10The following figure shows the detection process for expired permissions. A scheduled task triggers a permissions check, obtains and traverses the expired permission records of the data resource package, removes the authorized party of the expired permission from the user group, deletes the authorization record of the data resource package, and records the expired permission in the historical permissions.

[0143] As a specific application embodiment of the embodiment of the present disclosure, the current user can view all data resource packages for which he has obtained permissions. For example, all data resource packages with permissions are displayed on the My Permissions page. These data resource packages are presented in a list format, and partial information of the data resource packages is displayed. If you want to view the detailed information of the data resource package, a viewing instruction is generated through interaction with the data resource package. In response to the viewing instruction, the detailed information of the data resource package is displayed in the form of a drawer at a preset position on the My Permissions page. The preset position can be the side position of the My Permissions page, etc., and is set according to actual needs.

[0144] In this embodiment, a data permission management and control device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation methods, and will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0145] This embodiment provides a data authority management and control device, such as Figure 11 As shown, including:

[0146] The data resource package acquisition module 1101 is used to acquire the target data resource package and the current permission type of the authorized party corresponding to the target data resource package. The target data resource includes multiple data resources, and the resource type of the data resource includes at least one of a database, a data table, a data row, and a data column.

[0147] The permission type adjustment instruction acquisition module 1102 is used to obtain the permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party. The permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package. The permission types include read-only and read-write.

[0148] The permission type adjustment message sending module 1103 is used to send a permission type adjustment message to the authorized party.

[0149] In some optional implementations, the target data resource package determination module includes:

[0150] The new creation instruction acquisition unit is used to acquire the new creation instruction of the data resource package to display the new creation page of the data resource package.

[0151] The setting instruction acquisition unit is used to obtain the setting instructions for the basic information and resource information of the data resource package in the newly created page to obtain the basic information of the data resource package and multiple data resources. The basic information includes the data source, database and name corresponding to the resource data package, and the resource information includes the resource type and data resource of the data resource.

[0152] The permission setting instruction acquisition unit is used to acquire the permission setting instruction for the data resource package to obtain the permission information of the data resource package.

[0153] The approval setting instruction acquisition unit is used to acquire the approval setting instruction for the data resource package to obtain the approval flow of the data resource package.

[0154] The resource package determining unit is configured to determine a target data resource package based on the basic information, resource information, authority information, and approval flow of the data resource package.

[0155] In some optional implementations, the permission setting instruction acquisition unit includes:

[0156] The permission setting page display sub-unit is used to display the permission setting page, which includes setting controls for permission holders and confidentiality levels.

[0157] The confidentiality level acquisition subunit is used to obtain the highest confidentiality level of all data resources in the data resource package.

[0158] The first setting instruction acquisition sub-unit is used to obtain the first setting instruction of the setting control corresponding to the authority person and the second setting instruction of the setting control corresponding to the confidentiality level, so as to obtain the authority person and the confidentiality level of the data resource package. The confidentiality level of the data resource package is not lower than the highest confidentiality level.

[0159] In some optional implementations, the approval setting instruction acquisition unit includes:

[0160] The approval flow setting page display sub-unit is used to display the approval flow setting page. The approval flow setting page includes setting controls for approvers corresponding to each approval level.

[0161] The second setting instruction acquisition subunit is used to acquire the setting instruction of the setting control of the approval personnel to obtain the approval process of the data resource package.

[0162] The automatic approval page display subunit is used to display the automatic approval page. The automatic approval page is used to display the target approval level in the approval hierarchy that can be automatically approved.

[0163] The third setting instruction acquisition subunit is used to acquire setting instructions for the target approval level to obtain the approval flow of the data resource package.

[0164] In some optional embodiments, the device further comprises:

[0165] The adjustment instruction acquisition module is used to acquire adjustment instructions for multiple data resources included in the target data resource package to determine the data resources included in the adjusted target resource data package.

[0166] The authorized party acquisition module is used to obtain all authorized parties of the target data resource package.

[0167] The adjustment message sending module is used to send resource adjustment messages of the target data resource package to all authorized parties.

[0168] In some optional implementations, the resource adjustment message includes a title and a body, where the title is used to indicate the type of resource adjustment, and the body is used to indicate the impact of the resource adjustment on the authorized party, where the types of resource adjustment include adding new data resources and deleting data resources.

[0169] In some optional implementations, the adjustment instruction acquisition module includes:

[0170] The resource package page display unit is used to display the resource package page. The resource package page includes an established data resource package entry, and the established data resource package entry includes a resource detail control.

[0171] The selection instruction acquisition unit is used to acquire the selection instruction of the resource detail control in the target data resource package entry to display the resource detail page of the target data resource package.

[0172] The adjustment instruction acquisition unit is used to acquire adjustment instructions for multiple data resources included in the target data resource package in the resource details page.

[0173] In some optional implementations, the created data resource package entry further includes an authorization details control, and the apparatus further includes:

[0174] The selection instruction acquisition module is used to obtain the selection instruction of the authorization details control in the target data resource package entry to display the authorization details page of the target data resource package.

[0175] The audit tag acquisition module is used to obtain the audit tags of each authorized party in the authorization details page to determine the target authorized party corresponding to the target data resource package.

[0176] In some optional embodiments, the device further comprises:

[0177] The permission application page display module is used to display the permission application page.

[0178] The setting instruction acquisition module is used to obtain the setting instructions for the data resource package to be authorized, the target authorized party and the reason for authorization in the permission application page to determine the permission application request.

[0179] The permission application request sending module is used to send the permission application request, so as to approve the permission application request based on the approval flow of the data resource package to be authorized and obtain an approval result.

[0180] In some optional implementations, the permission application request sending module includes:

[0181] The query unit is used to query whether there is an unprocessed permission application request that is the same as the permission application request.

[0182] The approval unit is used to approve the permission application request based on the approval flow of the data resource package to be authorized to obtain an approval result if there is no permission application request that is the same as the permission application request and has not been processed.

[0183] In some optional embodiments, the device further comprises:

[0184] The query module is used to query whether the permissions of each authorized party of the target data resource package have expired.

[0185] The permission revocation module is used to revoke the permission of the authorized party with expired permission to the target data resource package if there is one.

[0186] The data permission management and control device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0187] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0188] The present disclosure also provides a computer device having the above Figure 11 The data permission management device shown.

[0189] See also Figure 12 , Figure 12 is a structural diagram of a computer device provided by an optional embodiment of the present disclosure, such as Figure 12As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 12 A processor 10 is taken as an example.

[0190] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0191] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0192] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0193] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0194] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 can be connected via a bus or other means. Figure 12 The bus connection is taken as an example.

[0195] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), and a tactile feedback device (e.g., a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0196] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0197] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0198] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the operation requested will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operations of the disclosed technical solution based on the prompt message.

[0199] As an optional but non-limiting implementation, in response to receiving a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0200] It is understandable that the above notification and user authorization process are merely illustrative and do not limit the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0201] Although the embodiments of the present disclosure have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A data authority management and control method, characterized in that: The method comprises: Acquire a target data resource package and a current permission type of an authorized party corresponding to the target data resource package, wherein the target data resource package includes a plurality of data resources, and the resource types of the data resources include at least one of a database, a data table, a data row, and a data column; Obtaining a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party, wherein the permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package, wherein the permission types include read-only and read-write; Sending a permission type adjustment message to the authorized party; Acquire an adjustment instruction for a plurality of data resources included in the target data resource package to determine the data resources included in the adjusted target resource data package; Obtain all authorized parties of the target data resource package; Sending a resource adjustment message of the target data resource package to all authorized parties; The resource adjustment message includes a title and a body, wherein the title is used to indicate the type of the resource adjustment, and the body is used to indicate the impact of the resource adjustment on the authorized party, and the types of resource adjustment include adding new data resources and deleting data resources.

2. The method according to claim 1, characterized in that Methods for determining the target data resource package include: Get the new instruction of the data resource package to display the new page of the data resource package; Obtaining instructions for setting basic information and resource information of the data resource package in the new page to obtain basic information of the data resource package and the multiple data resources, wherein the basic information includes a data source, a database, and a name corresponding to the resource data package, and the resource information includes a resource type of the data resource and the data resource; Obtaining a permission setting instruction for the data resource package to obtain permission information of the data resource package; Acquire an approval setting instruction for the data resource package to obtain an approval flow for the data resource package; The target data resource package is determined based on the basic information, the resource information, the authority information, and the approval flow of the data resource package.

3. The method according to claim 2, characterized in that The step of obtaining the permission setting instruction for the data resource package to obtain permission information of the data resource package includes: Displaying the permission setting page, which includes setting controls for permission holders and confidentiality levels; Obtaining the highest confidentiality level of all data resources in the data resource package; Obtain a first setting instruction for the setting control corresponding to the authority holder and a second setting instruction for the setting control corresponding to the confidentiality level to obtain the authority holder and the confidentiality level of the data resource package, wherein the confidentiality level of the data resource package is not lower than the highest confidentiality level.

4. The method according to claim 2, characterized in that The step of obtaining the approval setting instruction for the data resource package to obtain the approval flow of the data resource package includes: Display the approval flow setting page, which includes setting controls for approvers corresponding to each approval level; Obtaining a setting instruction for the setting control of the approver to obtain the approval process of the data resource package; Displaying an automatic approval page, wherein the automatic approval page is used to display the target approval levels that can be automatically approved in the approval levels; Acquire a setting instruction for the target approval level to obtain an approval flow for the data resource package.

5. The method according to claim 1, wherein The obtaining of adjustment instructions for the plurality of data resources included in the target data resource package includes: Displaying a resource package page, wherein the resource package page includes an entry for a created data resource package, and the entry for the created data resource package includes a resource details control; Obtaining a selection instruction for the resource details control in the target data resource package entry to display a resource details page for the target data resource package; Acquire adjustment instructions for a plurality of data resources included in the target data resource package on the resource details page.

6. The method according to claim 5, characterized in that The created data resource package entry also includes an authorization details control, and the method further includes: Obtaining a selection instruction for the authorization details control in the target data resource package entry to display an authorization details page for the target data resource package; The audit tag of each authorized party in the authorization details page is obtained to determine the target authorized party corresponding to the target data resource package.

7. The method according to claim 1, characterized in that The method further comprises: Display the permission application page; Obtaining setting instructions for the data resource package to be authorized, the target authorized party, and the reason for authorization on the permission application page to determine the permission application request; The permission application request is sent, and the permission application request is approved based on the approval flow of the data resource package to be authorized to obtain an approval result.

8. The method according to claim 7, characterized in that The step of approving the permission application request based on the approval flow of the data resource package to be authorized to obtain an approval result includes: Check whether there is an unprocessed permission request that is the same as the permission request; If there is no permission application request that is the same as the permission application request and has not been processed, the permission application request is approved based on the approval flow of the data resource package to be authorized to obtain an approval result.

9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: Check whether the permissions of each authorized party of the target data resource package have expired; If there is an authorized party whose authority has expired, the authority of the authorized party whose authority has expired to the target data resource package is revoked.

10. A data authority management and control device, characterized in that: The device comprises: a data resource package acquisition module, configured to acquire a target data resource package and a current permission type of a permission holder corresponding to the target data resource package, wherein the target data resource includes a plurality of data resources, and the resource type of the data resource includes at least one of a database, a data table, a data row, and a data column; A permission type adjustment instruction acquisition module is used to obtain a permission type adjustment instruction for the target data resource package to determine the target permission type of the authorized party. The permission type adjustment instruction is used to uniformly adjust the permission types of multiple data resources in the target data resource package. The permission types include read-only and read-write. A permission type adjustment message sending module, configured to send a permission type adjustment message to the authorized party; An adjustment instruction acquisition module, configured to acquire adjustment instructions for a plurality of data resources included in the target data resource package, so as to determine the data resources included in the adjusted target resource data package; An authorized party acquisition module, used to acquire all authorized parties of the target data resource package; An adjustment message sending module, configured to send a resource adjustment message of the target data resource package to all authorized parties; The resource adjustment message includes a title and a body, wherein the title is used to indicate the type of the resource adjustment, and the body is used to indicate the impact of the resource adjustment on the authorized party, and the types of resource adjustment include adding new data resources and deleting data resources.

11. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the data permission management method according to any one of claims 1 to 9 by executing the computer instructions.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the data authority management method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Authority management method and device, equipment and storage medium

    CN115618325A