A method and system for visualizing data authority management and control

By using a visual data access control method, administrators are provided with a visual interface to create roles and configure user permissions. This solves the problems of complexity in hierarchical access control and insufficient flexibility in role-based access control in existing technologies, and achieves fine-grained access control and improved data security.

CN117828635BActive Publication Date: 2025-11-28上海赛连信息科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311802965.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-25
Publication Date
2025-11-28
Estimated Expiration
2043-12-25

AI Technical Summary

Technical Problem

Existing hierarchical permission management structures are complex and cumbersome, difficult to deploy and maintain, and lack flexibility, making them unsuitable for complex business processes and multi-department collaborative work. Role-based permission management lacks fine-grained control, resulting in a poor user experience.

Method used

A visual data access control method is adopted, providing administrators with a visual access control interface. By creating roles, configuring user roles and data permissions, fine-grained access control can be achieved, reducing system complexity and improving management efficiency and flexibility.

Benefits of technology

It achieves fine-grained control based on centralized permission management, simplifies the configuration process, improves the efficiency and flexibility of permission management, and enhances data security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117828635B_ABST
    Figure CN117828635B_ABST
Patent Text Reader

Abstract

The application provides a visual data authority management method and system. The method comprises the following steps: providing a visual authority management interface for an administrator in a business system; the administrator logs in the business system; the administrator creates different roles in the visual authority management interface based on the business system; the administrator creates different users in the visual authority management interface based on the business system and configures different roles for each user; the administrator configures data authority for the different roles based on different data objects, wherein each data object comprises a plurality of data created or managed by different roles; a user logs in the business system; the user manages data objects according to the data authority configured by the administrator in the business system, wherein the user can only manage specific data filtered from the data objects based on the data authority. The visual data authority management method and system can realize that only authorized users can access sensitive data in enterprises and organizations, and is beneficial to protecting the security of data in enterprises and organizations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data access control technology, specifically to a visual data access control method and system. Background Technology

[0002] With the rapid development of information technology, data security and privacy protection have received increasing attention. For enterprises and organizations, on the one hand, the rapid development of informatization helps them better manage and utilize their resources, improve work efficiency, and enhance collaboration among members. On the other hand, excessive information sharing leads to the risk of data leakage, compromising the security of sensitive data and posing risks to business operations. Therefore, internal information security is crucial for enterprises and organizations, requiring them to effectively manage data within their business systems.

[0003] To address the data security issues faced by the aforementioned enterprises and organizations, existing technologies include two main solutions: hierarchical access control and role-based access control. Hierarchical access control is attribute-based, allowing users to access data based on their attributes or combinations of attributes. For example, only managers in a specific region might have access to sales data for that region, while managers in other regions might not. Role-based access control, on the other hand, is a common data access control solution. Users are assigned to different roles, and each role is granted corresponding data permissions. This ensures that users can only access data relevant to their role, and permissions can be allocated and managed as needed.

[0004] However, hierarchical permission management structures are more complex and cumbersome, making deployment and maintenance difficult. Furthermore, hierarchical permission management cannot flexibly handle situations involving complex business processes and collaboration among multiple departments. Role-based permission management, on the other hand, is typically role-based, and therefore may lack fine-grained control over individual users in certain situations. Sometimes, a user may require specific permissions related to their individual responsibilities or tasks, which may not be achievable through simple role assignment. In addition, existing hierarchical and role-based permission management technologies lack intuitive visual management interfaces, resulting in a poor user experience. Summary of the Invention

[0005] To maintain data security and meet users' personalized needs for data management permissions, this invention provides a visual data permission control method and system. Based on data permission management, it further refines the data control, which not only maintains data security but also more flexibly adapts to the personalized needs of enterprises and organizations.

[0006] In a first aspect, the present invention provides a visual data access control method, characterized in that the method includes:

[0007] Provide administrators with a visual permission management interface in the business system;

[0008] The administrator logs into the business system;

[0009] The administrator creates different roles based on the business system in the visual permission management interface;

[0010] The administrator creates different users and configures different roles for each user based on the business system in the visual permission management interface.

[0011] The administrator configures data permissions for different roles based on different data objects, where each data object includes multiple data items created or managed by multiple different roles;

[0012] The user logs into the business system;

[0013] The user manages data objects in the business system according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0014] Secondly, the present invention also provides a visual data access control system, characterized in that the system includes a visualization module, an administrator login module, a role creation module, a user creation module, an administrator configuration module, a user login module, and a user management module, wherein:

[0015] The visualization module is used to provide administrators with a visual permission management interface in the business system;

[0016] The administrator login module is used by the administrator to log in to the business system;

[0017] The "Create Roles" module allows administrators to create different roles based on the business system within the visual permission management interface.

[0018] The "Create User" module is used by the administrator to create different users and configure different roles for each user based on the business system in the visual permission management interface.

[0019] The administrator configuration module is used by the administrator to configure data permissions for different roles based on different data objects, wherein each data object includes multiple data items created or managed by multiple different roles;

[0020] The user login module is used for users to log in to the business system.

[0021] The user management module is used by the user in the business system to manage data objects according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0022] The advantages of the visual data permission control method and system provided by this invention are as follows: First, this invention is based on a centralized permission management system, mainly including a role configuration module and a data permission configuration module, which reduces system complexity and facilitates system deployment and maintenance; Second, administrators can perform fine-grained permission control for users with different roles according to actual needs, improving the efficiency and flexibility of permission management; Third, this invention provides a more intuitive administrator visual interface, allowing administrators to clearly view and manage data permissions, simplifying the configuration process. Attached Figure Description

[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a flowchart of a visual data access control method provided in an embodiment of the present invention;

[0025] Figure 2 This is a visual flowchart of the management interface provided in an embodiment of the present invention;

[0026] Figure 3 This is a flowchart of the administrator permission configuration process provided in an embodiment of the present invention;

[0027] Figure 4 This is a flowchart of the user management data object provided in an embodiment of the present invention;

[0028] Figure 5 This is a block diagram of a flexible and visual data access control system provided in an embodiment of the present invention;

[0029] Figures 6a-6c This is the graphical interface provided in the embodiments of the present invention. Detailed Implementation

[0030] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Invention Overview

[0032] As mentioned above, this invention provides a flexible and visualized data access control method and system. While improving data security in enterprises and organizations, it can also flexibly customize different management permissions for different users according to the needs of enterprises and organizations through fine-grained access control.

[0033] Exemplary methods

[0034] Figure 1 This is a flowchart of a visual data access control method provided by an embodiment of the present invention. This embodiment includes the following steps:

[0035] S101: Provide administrators with a visual permission management interface in the business system to facilitate the management and configuration of management permissions for different users.

[0036] like Figure 2 As shown, step S101 specifically involves:

[0037] S201: Add visualization components to the business system, that is, first select appropriate visualization tools according to the needs of the business system.

[0038] S202: Configure and save the layout of the visualization interface.

[0039] Specifically, after adding the visualization component, the layout of the visualization interface needs to be further configured according to the specific needs of the business system and the administrator, and then the layout configuration interface of the visualization interface should be saved.

[0040] S203: Provide a visual display of the administrator's management interface.

[0041] Specifically, after the visualization interface is configured, the data in the business system is bound to the visualization component to ensure that the data in the business system can be correctly displayed through the visualization component. Then, the visualization interface is displayed in the business system, providing convenience for administrators to manage user permissions. The administrator's visual permission management interface is as follows: Figures 6a-6c .

[0042] S102: The administrator logs into the business system by filling in the administrator account and password on the login interface of the business system.

[0043] S103: The administrator creates different roles on the visual permission management interface based on the business system.

[0044] Specifically, the roles in the business system are set by the administrator according to the needs of the specific business. The administrator first needs to select the "Create Role" button to enter the interface for creating a specific role in the business system. Then, the administrator needs to add relevant information about the role, including role name, role description, and creation time.

[0045] S104: The administrator creates different users on the visual permission management interface based on the business system and configures different roles for each user.

[0046] The data object refers to a structured data unit in the business system used to store and manage data related to a specific business entity. Examples include various data tables, each containing multiple fields and multiple rows of specific data. (See also...) Figure 6a The leftmost column lists the table names, including: customer_info (customer information table), distributor_sign_apply_one (first-tier distributor contract and change table), etc. Users create specific data within a data object. Multiple different users can create different specific data within the same data table. The user's role for that specific data is that of a creator. For example, if user A creates records 1-4 in the customer information table, and user B creates records 5-20, then user A is the creator of records 1-4, and user B is the creator of records 5-20. This creator role is automatically assigned based on the user's data creation behavior, not configured by the administrator. The administrator role refers to the user associated with specific data within the data object. Administrator roles include at least one or more of the following: Key Account Manager, Sales Manager, General Agent Salesperson, City Agent Salesperson, and Second-Tier Distributor Salesperson.

[0047] Specifically, users in the business system are added by the administrator according to the specific business needs of the business system. The administrator first needs to select the "Create User" button to enter the interface for creating a specific user in the business system. Then, the administrator needs to add the user's relevant information, including the user account, username, password, and role. The role refers to the specific position the user holds in the enterprise or organization, including roles such as key account manager, sales manager, and general agent manager.

[0048] S105: The administrator configures data permissions for the different roles based on different data objects.

[0049] The data permissions mentioned above refer to the administrator configuring different data management scopes for different roles based on different data objects.

[0050] like Figure 3As shown, step S105 specifically involves:

[0051] S301: The administrator configures different roles for different data objects.

[0052] Specifically, administrators need to configure different roles for different data objects to manage the specific data of the data objects according to the needs of specific business operations.

[0053] For example, in the customer table, it is necessary to assign creators and managers to manage their specific data, while in the contract table, it is only necessary to assign managers to manage their specific data.

[0054] S302: The administrator configures different data permissions for different roles so that different users can manage the data objects within different scopes.

[0055] The administrator configures different ranges of permissions for different users to query, modify, and delete data in the data objects for different data objects. The different ranges include the user, the user's department, the user's department and its subordinate departments, and all users.

[0056] Specifically, after configuring data management roles for data objects, administrators also need to restrict the scope of data management for different roles based on the actual situation. This is to prevent excessive data sharing within the business system and the leakage of sensitive data. Although both the creator and the administrator may have the authority to manage the specific data of the same data object, their scope of data management may differ. In addition, the scope of management for the same data object may also differ for administrators at different levels.

[0057] For example, regarding the customer table, both the creator and the administrator can manage its specific data, but their management permissions are different. For the creator, the creator has the permission to query, modify, and delete the specific data in the customer table they created. For the administrator, the administrator can configure all administrators to only have the permission to query the data related to their own department and its subordinate departments.

[0058] For example, regarding the customer table, different levels of managers may have different permissions for data management. Key account managers have the permission to query, modify, and delete all data in the customer table; sales managers, general sales agents, and city sales agents have the permission to query data in the customer table that is related to their own department and its subordinate departments; while secondary distributors only have the permission to query data in the customer table that is related to themselves.

[0059] S106: The user logs into the business system by filling in their personal account and password on the login interface of the business system.

[0060] S107: The user manages data objects in the business system according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0061] like Figure 4 As shown, step S107 specifically includes:

[0062] S401: The business system queries the data permissions configured by the user for different data objects.

[0063] Specifically, after a user logs into the business system, the system queries the user's data permissions in different data objects based on the user's ID, name, and role.

[0064] For example, user A's ID is 123456, user name is Zhang San, and user role is sales manager. In the customer table, Zhang San has the permission to query data related to his department and its subordinate departments; in the contract table, Zhang San has the permission to query, modify, and delete data related to his department and its subordinate departments.

[0065] Suppose user b has ID 454325, name Li Si, and role is Sales Manager, but belongs to a different department than Zhang San. In the customer table, Li Si also has permission to query data related to his department and its subordinate departments. However, because Li Si and Zhang San belong to different departments, the specific data they can manage is also different. This specific data is filtered based on the department field, using Zhang San's and Li Si's department names respectively. Therefore, even if users have the same role and permission configuration, the specific data they can manage, filtered from the data object according to their permission configuration, will differ due to differences in other user attributes. This allows for more granular permission management. Besides... Figure 6c In addition to the attribute options such as "Myself, My Department, My Department and Below, All", other optional attribute options (such as specific department names, customer's location, etc.) can be added in the permission configuration. In this way, when managing specific data, the specific data that the user role can manage will be automatically filtered according to the configured attribute options.

[0066] S402: Based on the query results, enter the list of data objects managed by the user. That is, the user's interface can only display a list of specific data of the data objects that the user has permission to manage.

[0067] S403: In the list of data objects, the user manages the specific data according to the data permissions configured by the administrator.

[0068] Specifically, when a user is the creator of specific data within a data object, the user manages the specific data according to the data permissions configured by the administrator for the creator of the data object; when a user is the manager of specific data within a data object, the user manages the specific data according to the data permissions configured by the administrator for the manager of the data object.

[0069] For example, Zhang San's user role in the company is a sales manager. In the customer table, the creator's data permissions allow them to query, modify, and delete the specific data in the customer table they created. The sales manager's data permissions allow Zhang San to query data in the customer table related to their department and its subordinate departments. When Zhang San enters a piece of data into the customer table, Zhang San is the creator of that data and therefore has the permissions to query, modify, and delete it. However, because Zhang San's role in the company is sales manager, they only have the permission to query other data in the customer table related to their department and its subordinate departments, excluding data they created themselves.

[0070] Exemplary System

[0071] Accordingly, embodiments of the present invention also provide a flexible and visual data access control system. Figure 5 This is a block diagram of a flexible and visual data access control system provided in an embodiment of the present invention, such as... Figure 3 As shown, the system 500 provided in this embodiment includes:

[0072] A visual data access control system, characterized in that the system includes a visualization module 501, an administrator login module 502, a role creation module 503, a user creation module 504, an administrator configuration module 505, a user login module 506, and a user management module 507, wherein:

[0073] Visualization module 501 is used to provide administrators with a visual permission management interface in the business system;

[0074] Administrator login module 502 is used for the administrator to log in to the business system;

[0075] Module 503: Create new roles. The user, the administrator, creates different roles based on the business system in the visual permission management interface.

[0076] The new user module 504 is used by the administrator to create different users and configure different roles for each user based on the business system in the visual permission management interface.

[0077] The administrator configuration module 505 is used by the administrator to configure data permissions for different roles based on different data objects, wherein each data object includes multiple data items created or managed by multiple different roles;

[0078] User login module 506 is used for users to log in to the business system;

[0079] User management module 507 is used by the user in the business system to manage data objects according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0080] The visualization 501 module includes:

[0081] Add module 508 to add visualization components to the business system;

[0082] The layout configuration module 509 is used to configure and save the layout of the visual interface;

[0083] The visualization module 510 is used to visualize the administrator's management interface.

[0084] The newly created character 503 module includes:

[0085] The "Select New Role" module 511 is used by the administrator to select options for creating a new role.

[0086] The Add Role Information module 512 is used by the administrator to add relevant information about roles, including role name, role description information, and the role's position in the enterprise.

[0087] The newly created user module 504 includes:

[0088] Select the new user module 513, which is used by the administrator to select the option to create a new user;

[0089] The user information module 514 is used by the administrator to add relevant information about users, including user account, username, password and role information.

[0090] The data object is a structured data unit used in the business system to store and manage data related to a specific business entity; the different roles include creators and managers; if a user creates specific data for a data object, then the user's role for that specific data is creator; the manager is a user associated with the specific data in the data object, and the manager includes at least one or more of the following: key account manager, sales manager, general agent sales, city agent sales, and secondary distributor sales; the data permissions are configured by the administrator for different data objects and different roles, specifying different data management scopes.

[0091] The administrator configuration module 505 includes:

[0092] The role configuration module 515 is used by the administrator to configure different roles for different data objects.

[0093] The data permission configuration module 516 is used by the administrator to configure different data permissions for different roles, so that different users can manage the data objects within different scopes.

[0094] The configuration data permission module 516 includes:

[0095] This is used by the administrator to configure different ranges of permissions for different users to query, modify, and delete data in the data objects for different data objects, wherein the different ranges include the user, the department, the department and its subordinate departments, and all sub-modules.

[0096] The user management module 507 includes:

[0097] The query module 517 is used by the business system to query the data permissions configured by the user for different data objects;

[0098] Enter list module 518, which is used to access the list of user-managed data objects based on the query results;

[0099] The specific data management module 519 is used to allow users to manage specific data in the data object list according to the data permissions configured by the administrator.

[0100] The specific data management module 519 includes:

[0101] The creator management module 520 is used to manage the specific data according to the data permissions configured by the administrator for the creator of the data object when the user is the creator of the specific data in the data object.

[0102] The administrator management module 521 is used to manage the specific data according to the data permissions configured by the administrator for the data object when the user is the manager of the specific data in the data object.

[0103] It should be noted that although the operations of the visual data access control method of the present invention are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0104] Furthermore, although several devices, units, or modules of a flexible and visual data access control system have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.

[0105] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0106] According to the above disclosure of the present invention, the present invention provides:

[0107] 1. A method for visual data access control, characterized in that the method includes:

[0108] Provide administrators with a visual permission management interface in the business system;

[0109] The administrator logs into the business system;

[0110] The administrator creates different roles based on the business system in the visual permission management interface;

[0111] The administrator creates different users and configures different roles for each user based on the business system in the visual permission management interface.

[0112] The administrator configures data permissions for different roles based on different data objects, where each data object includes multiple data items created or managed by multiple different roles;

[0113] The user logs into the business system;

[0114] The user manages data objects in the business system according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0115] 2. The visual data access control method described in item 1 above is characterized in that the step of providing a visual access control interface for administrators in the business system specifically includes:

[0116] Add visualization components to the business system;

[0117] Configure and save the layout of the visualization interface;

[0118] The administrator's management interface is presented visually.

[0119] 3. The visual data access control method described in item 1 above is characterized in that the step of the administrator creating different roles based on the business system in the visual access control interface specifically includes:

[0120] The administrator selects the option to create a new role;

[0121] The administrator adds relevant information about the role, including the role name, role description, and creation time.

[0122] 4. The visual data access control method described in item 3 above is characterized in that the step of the administrator creating different users and configuring different roles for each user based on the business system in the visual access control interface specifically includes:

[0123] The administrator selects the option to create a new user;

[0124] The administrator adds relevant user information, including user account, username, password, and role information.

[0125] 5. The visual data access control method described in item 1 above is characterized in that the data object is a structured data unit in the business system used for storing and managing specific business entities.

[0126] 6. The visual data access control method described in item 1 above, wherein the different roles include creators and administrators;

[0127] Wherein the specific data of the data object created by the user, the user's role with respect to the specific data is that of the creator;

[0128] Managers are users associated with specific data in the data object, and managers include at least one or more of the following: key account manager, sales manager, general agent sales, city agent sales, and secondary distributor sales.

[0129] 7. The visual data permission control method according to item 1 or item 6 above is characterized in that the data permission is configured by the administrator for different roles for different data objects.

[0130] 8. The visual data permission control method described in item 7 above is characterized in that the step of the administrator configuring data permissions for different roles based on different data objects, wherein each data object includes multiple data items created or managed by multiple different roles, specifically includes:

[0131] The administrator configures different roles for different data objects;

[0132] The administrator configures different data permissions for different roles, so that different users can manage the data objects within different scopes.

[0133] 9. The visual data access control method described in item 8 above, characterized in that the step of configuring different data permissions for different roles by the administrator so that different users can manage the data objects within different scopes specifically includes:

[0134] The administrator configures different ranges of permissions for different users to query, modify, and delete data in the data objects for different data objects, wherein the different ranges include the user, the user's department, the user's department and its subordinate departments, and all users.

[0135] 10. The visual data access control method according to any one of items 1-9 above, characterized in that the user manages specific data objects in the business system according to the data permissions configured by the administrator, wherein the step of the user only being able to manage specific data filtered from the data objects based on data permissions specifically includes:

[0136] The business system queries the data permissions configured by the user for different data objects;

[0137] Access the user management data object list based on the query results;

[0138] In the list of data objects, users manage the specific data according to the data permissions configured by the administrator.

[0139] 11. The visual data permission control method according to item 10 above, characterized in that the step of the user managing the specific data according to the data permissions configured by the administrator in the data object list specifically includes:

[0140] When a user is the creator of specific data within a data object, the user manages the specific data according to the data permissions configured by the administrator for the creator of the data object.

[0141] When a user is the manager of specific data within a data object, the user manages the specific data according to the data permissions configured by the administrator for the data object.

[0142] 12. A visual data access control system, characterized in that the system comprises a visualization module, an administrator login module, a role creation module, a user creation module, an administrator configuration module, a user login module, and a user management module, wherein:

[0143] The visualization module is used to provide administrators with a visual permission management interface in the business system;

[0144] The administrator login module is used by the administrator to log in to the business system;

[0145] The "Create Roles" module allows administrators to create different roles based on the business system within the visual permission management interface.

[0146] The "Create User" module is used by the administrator to create different users and configure different roles for each user based on the business system in the visual permission management interface.

[0147] The administrator configuration module is used by the administrator to configure data permissions for different roles based on different data objects, wherein each data object includes multiple data items created or managed by multiple different roles;

[0148] The user login module is used for users to log in to the business system.

[0149] The user management module is used by the user in the business system to manage data objects according to the data permissions configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permissions.

[0150] 13. The visual data access control system according to item 12 above, characterized in that the visualization module includes:

[0151] Add a module to add visual components to the business system;

[0152] The layout configuration module is used to configure and save the layout of the visual interface;

[0153] The visualization module is used to visually display the administrator's management interface.

[0154] 14. The visual data access control system according to item 12 above, characterized in that the new role module includes:

[0155] The "Create New Role" module provides an option for administrators to select new roles.

[0156] The Add Role Information module is used by the administrator to add relevant information about roles, including role name, role description, and creation time.

[0157] 15. The visual data access control system according to item 14 above, characterized in that the new user module includes:

[0158] The "Select New User" module is used by the administrator to select options for creating a new user.

[0159] The Add User Information module is used by the administrator to add relevant information about users, including user account, username, password, and role information.

[0160] 16. The visual data access control system according to item 12 above, wherein the data object is a structured data unit in the business system used for storing and managing specific business entities.

[0161] 17. The visual data access control system according to item 12 above, wherein the different roles include creators and administrators;

[0162] Wherein the specific data of the data object created by the user, the user's role with respect to the specific data is that of the creator;

[0163] Managers are users associated with specific data in the data object, and managers include at least one or more of the following: key account manager, sales manager, general agent sales, city agent sales, and secondary distributor sales.

[0164] 18. The visual data access control system according to item 12 or 17 above is characterized in that the data access is configured by the administrator for different data objects and different roles, with different data management scopes.

[0165] 19. The visual data access control system according to item 18 above, characterized in that the administrator configuration module includes:

[0166] The role configuration module is used by the administrator to configure different roles for different data objects.

[0167] The data permission configuration module is used by the administrator to configure different data permissions for different roles, so that different users can manage the data objects within different scopes.

[0168] 20. The visual data access control system according to item 19 above, characterized in that the data access configuration module includes:

[0169] This is used by the administrator to configure different ranges of permissions for different users to query, modify, and delete data in the data objects for different data objects, wherein the different ranges include the user, the department, the department and its subordinate departments, and all sub-modules.

[0170] 21. The visual data access control system according to any one of items 12-20 above, characterized in that the user management module includes:

[0171] The query module is used by the business system to query the data permissions configured by the user for different data objects;

[0172] Enter the list module to access the list of user-managed data objects based on the query results;

[0173] The specific data management module is used to allow users to manage specific data in the data object list according to the data permissions configured by the administrator.

[0174] 22. The visual data access control system according to item 21 above, characterized in that the specific data management module includes:

[0175] The creator management module is used to manage the specific data in a data object according to the data permissions configured by the administrator for the creator when the user is the creator of the specific data in the data object.

[0176] The administrator management module is used so that when a user is the administrator of specific data in a data object, the user manages the specific data according to the data permissions configured by the administrator for the data object.

Claims

1. A method for visualizing data authority management, characterized in that, The method comprises: providing an administrator with a visual permission management interface in a business system; the administrator logs in the business system; the administrator creates different roles in the visual permission management interface based on the business system; the administrator creates different users in the visual permission management interface based on the business system and configures different roles for each user; the administrator configures data permissions for the different roles based on different data objects, wherein each data object includes multiple pieces of data created or managed by multiple different roles; the step of the administrator configuring data permissions for the different roles based on different data objects specifically comprises: the administrator configuring different ranges of permissions for the different users to query, modify and delete data in the data objects for the different data objects in the visual permission management interface, wherein the different ranges include self, department, department and subordinate departments, and all; a user logs in the business system; the user manages data objects according to the data permission configured by the administrator in the business system, wherein the user can only manage specific data filtered from the data objects based on data permissions.

2. The method of claim 1, wherein, The step of providing an administrator with a visual permission management interface in a business system specifically comprises: adding a visual component in the business system; configuring and saving the layout of the visual interface; visualizing the administrator management interface.

3. The method of claim 1, wherein, The step of the administrator creating different roles in the visual permission management interface based on the business system specifically comprises: the administrator selects the option of creating a role; the administrator adds related information of the role, including role name, role description information and creation time.

4. The method of claim 3, wherein, The step of the administrator creating different users in the visual permission management interface based on the business system and configuring different roles for each user specifically comprises: the administrator selects the option of creating a user; the administrator adds related information of the user, including user account, user name, password and role information.

5. The method of claim 1, wherein, The data object is a structured data unit in the business system for storing and managing data related to a specific business entity.

6. The method of claim 1, wherein, The different roles include creators and managers; wherein the user creates specific data of a data object, and the role of the user for the specific data is creator; the manager is a user associated with the specific data in the data object, wherein the manager includes one or more of a major customer manager, a sales manager, a general sales agent, a city sales agent, and a secondary distributor sales.

7. The method of claim 1, wherein, The data permission is a data management range configured by the administrator for the different roles for different data objects.

8. The method of claim 7, wherein, The step of the administrator configuring data permissions for the different roles based on different data objects, wherein each data object includes multiple pieces of data created or managed by multiple different roles, specifically comprises: the administrator configures different roles for different data objects; the administrator configures different data permissions for different roles so that the different users can manage the data objects in different ranges.

9. The visualized data rights governance method of any of claims 1-8, wherein, The user manages specific data objects in the business system according to the data permission configured by the administrator, wherein the step of managing the specific data by the user according to the data permission configured by the administrator specifically comprises: The business system queries the data permission configured by the administrator for different data objects; According to the query result, enter the data object list managed by the user; In the data object list, the user manages the specific data according to the data permission configured by the administrator.

10. The method of claim 8, wherein, In the data object list, the user manages the specific data according to the data permission configured by the administrator. When the user is the creator of the specific data in the data object, the user manages the specific data according to the data permission of the creator configured by the administrator for the data object; When the user is the manager of the specific data in the data object, the user manages the specific data according to the data permission of the manager configured by the administrator for the data object.

11. A visualized data authority management system, characterized in that, The system comprises a visualization module, an administrator login module, a new role module, a new user module, an administrator configuration module, a user login module and a user management module, wherein: The visualization module is used to provide a visual permission management interface for the administrator in the business system; The administrator login module is used for the administrator to log in to the business system; The new role module is used for the administrator to create different roles in the visual permission management interface based on the business system; The new user module is used for the administrator to create different users and configure different roles for each user in the visual permission management interface based on the business system; The administrator configuration module is used for the administrator to configure data permissions for different roles based on different data objects, wherein each data object includes a plurality of data created or managed by a plurality of different roles, and the administrator configuration module further comprises a configuration data permission module, which is used for the administrator to configure different ranges of query, modification and deletion of data in the data object for different users in the visual permission management interface for different data objects, wherein the different ranges include self, department, department and subordinate department, and all submodules; The user login module is used for the user to log in to the business system; The user management module is used for the user to manage data objects in the business system according to the data permission configured by the administrator, wherein the user can only manage specific data filtered from the data objects based on the data permission.

12. The visual data rights governance system of claim 11, wherein, The visualization module comprises: An adding module for adding visual components in the business system; A layout configuration module for configuring and saving the layout of the visual interface; A visual display module for visualizing the administrator management interface.

13. The visual data rights governance system of claim 11, wherein, The new role module comprises: A selection new role module for the administrator to select the option of creating a new role; An adding role information module for the administrator to add related information of the role, including role name, role description information and creation time.

14. The visual data rights governance system of claim 13, wherein, The new user module comprises: The new user module is selected for the administrator to select the option of creating a new user; The user information adding module is used for the administrator to add relevant information of the user, including user account, user name, password and role information.

15. The visual data rights governance system of claim 11, wherein, The data object is a structured data unit in the business system for storing and managing specific business entities.

16. The visual data rights governance system of claim 11, wherein, The different roles include creators and managers; The specific data of the user creating the data object is the creator of the specific data; The manager is a user associated with the specific data in the data object, and the manager at least includes one or more of the following: a major customer manager, a sales manager, a general sales agent, a city sales agent and a secondary distributor.

17. The visual data rights governance system of claim 11, wherein, The data permission is a different data management range configured by the administrator for different roles for different data objects.

18. The visual data rights governance system of claim 17, wherein, The administrator configuration module comprises: The role configuration module is used for the administrator to configure different roles for different data objects; The data permission configuration module is used for the administrator to configure different data permissions for different roles, so that the different users manage the data objects in different ranges.

19. The visualized data rights governance system of any of claims 11-18, wherein, The user management module comprises: The query module is used for the business system to query the data permissions configured by the user for different data objects; The list entering module is used for entering the data object list of the user management according to the query result; The specific data management module is used for the user to manage the specific data according to the data permission configured by the administrator in the data object list.

20. The visual data rights governance system of claim 19, wherein, The specific data management module comprises: The creator management module is used for the user to manage the specific data according to the data permission of the creator configured by the administrator for the data object when the user is the creator of the specific data in the data object; The manager management module is used for the user to manage the specific data according to the data permission of the manager configured by the administrator for the data object when the user is the manager of the specific data in the data object.

Citation Information

Patent Citations

  • Data permission control system and method for equipment management business

    CN107844708A

  • Data visualization system and data authority management method thereof

    CN111428212A