Service configuration method, apparatus, device, storage medium, and program product
By setting multiple identity information for administrators and judging their permissions, the problem of administrators accessing service configurations without authorization is solved, thereby improving security and efficiency.
Patent Information
- Application Number
- CN202411374701.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2044-09-29
AI Technical Summary
In existing technologies, administrators can trigger other services that are not within their own needs when configuring services, leading to unauthorized access and reducing the security of service configuration.
By pre-setting multiple identity information for administrators and specifying the service identifiers required for different identity information, the system monitors the administrator's triggered operations, obtains their identity and regional information, determines whether they have access permissions from the permission configuration file, and only displays the configuration interface and obtains the configuration policy for configuration when it is determined that they have the permissions.
The security of service configuration has been improved, unauthorized access has been prevented, and the administrator's identity has been further verified through multiple authentication methods, thereby improving the security and efficiency of configuration.
Smart Images

Figure CN119356751B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a service configuration method, apparatus, device, storage medium, and program product. Background Technology
[0002] With the continuous development of the Internet and computer technology, the performance of application systems is also constantly improving. It is necessary to configure the services on the application system to ensure the normal operation of the application system.
[0003] Currently, service configuration typically involves pre-granting configuration permissions to each administrator. When an administrator needs to configure a service, they select and access any service provided by the application system to configure that service.
[0004] However, during this service configuration process, each administrator can trigger other services that are not within their own needs, leading to unauthorized access and reducing the security of the service configuration. Summary of the Invention
[0005] This application provides a service configuration method, apparatus, device, storage medium, and program product to solve the problem in the prior art where each administrator can trigger other services that are not within their own needs, resulting in unauthorized access and reduced security of service configuration.
[0006] Firstly, this application provides a service configuration method. The method is applied to a management node corresponding to an application system, which carries multiple services. When the management node determines that each service is triggered by an administrator, it executes the service configuration method. The method includes: responding to a trigger operation by a target administrator targeting a target service identifier, obtaining the target service identifier and the target identity information of the target administrator, and determining the target region information of the target administrator; the target administrator's account has passed preset authentication and successfully logged into the application system; the preset authentication is one or more of static authentication, dynamic authentication, and biometric authentication.
[0007] The permission configuration file is obtained from a preset database and loaded into the corresponding memory. The permission configuration file includes multiple identity information and a first permission scope corresponding to each identity information. The first permission scope includes at least one service identifier.
[0008] Based on the memory, the permission configuration file is used to determine whether the target service identifier is within the first permission scope corresponding to the target identity information;
[0009] If yes, a configuration interface corresponding to the target service is displayed, and a configuration policy input in the configuration interface is acquired according to the target region information, so that the target service is configured by using the configuration policy.
[0010] In a possible design, the permission configuration file further includes a plurality of region information and a second permission range corresponding to each region information, the second permission range including at least one data identifier; the acquiring, according to the target region information, of the configuration policy input in the configuration interface includes: monitoring, based on the configuration interface, an acquisition operation of the target administrator on a target data identifier, and determining, based on the memory, whether the target data identifier is located in the second permission range corresponding to the target region information in the permission configuration file; if yes, displaying target data, and acquiring a configuration policy input by the target administrator according to the target data.
[0011] In a possible design, the configuring, by using the configuration policy, of the target service includes: performing integrity verification on the configuration policy, and applying the configuration policy on the target service when the verification is passed.
[0012] In a possible design, the permission configuration file further includes a third permission range corresponding to each identity information, the third permission range including at least one menu identifier; the menu identifier indicates that there is at least one service identifier under the menu; before the acquiring, in response to a trigger operation of the target administrator on a target service identifier, of the target service identifier and target identity information of the target administrator, the method further includes: acquiring the target menu identifier and determining target identity information of the target administrator in response to a trigger operation of the target administrator on a target menu identifier; determining, based on the memory, whether the target menu identifier is located in the third permission range corresponding to the target identity information in the permission configuration file; if yes, displaying at least one service identifier under the target menu, and monitoring a trigger operation of the target administrator based on each service identifier.
[0013] In a possible design, after determining whether the target service identifier is located in the first permission range corresponding to the target identity information, or determining whether the target data identifier is located in the second permission range corresponding to the target region information, or determining whether the target menu identifier is located in the third permission range corresponding to the target identity information, the method further includes: if no, generating and displaying corresponding target prompt information.
[0014] In a possible design, the target identity information is one of the following identity information: a user administrator, an encryption administrator, an authentication administrator, and a terminal administrator.
[0015] In a second aspect, the application provides a service configuration apparatus, comprising: a processing module, configured to, in response to a trigger operation identified by a target administrator for a target service, acquire the target service and target identity information of the target administrator; the target administrator is an administrator who successfully logs in the application system after preset authentication; the preset authentication is one or more of static authentication, dynamic authentication and biometric authentication; acquire a permission configuration file from a preset database and load the permission configuration file into a corresponding memory; the permission configuration file comprises a plurality of identity information and a first permission range corresponding to each identity information, and the first permission range comprises at least one service identifier; determine whether the target service identifier is located in the first permission range corresponding to the target identity information in the permission configuration file based on the memory; if yes, display a configuration interface corresponding to the target service and acquire a configuration strategy input by the target administrator in the configuration interface;
[0016] a configuration module, configured to configure the target service by using the configuration strategy.
[0017] In a third aspect, an electronic device is provided, comprising: at least one processor and a memory; the memory stores computer-executed instructions; the at least one processor executes the computer-executed instructions stored in the memory, so that the at least one processor executes the service configuration method in the first aspect and various possible designs of the first aspect.
[0018] In a fourth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium stores computer-executed instructions; when a processor executes the computer-executed instructions, the service configuration method in the first aspect and various possible designs of the first aspect is implemented.
[0019] In a fifth aspect, a computer program product is provided, comprising a computer program; when a processor executes the computer program, the service configuration method in the first aspect and various possible designs of the first aspect is implemented.
[0020] The service configuration method, device, equipment, storage medium and program product provided by the application are applied to a management node corresponding to an application system, the application system is loaded with multiple services, and the management node is used to execute the service configuration method when each service is triggered by an administrator. The method comprises the following steps: in response to a triggering operation of a target administrator for a target service identifier, obtaining the target service identifier and target identity information of the target administrator, and determining target regional information of the target administrator; an account of the target administrator passes a preset authentication and successfully logs in the application system; the preset authentication is one or more of static authentication, dynamic authentication and biometric authentication; a permission configuration file is obtained from a preset database, and the permission configuration file is loaded into a corresponding memory; the permission configuration file comprises multiple identity information and a first permission range corresponding to each identity information, and the first permission range comprises at least one service identifier; whether the target service identifier is located in the first permission range corresponding to the target identity information is judged in the permission configuration file based on the memory; if yes, a configuration interface corresponding to the target service is displayed, and a configuration strategy input by the configuration interface is obtained according to the target regional information, so that the target service is configured by using the configuration strategy. Since at least one service identifier allowed to be accessed corresponding to each identity information, i.e., the first permission range, is set in advance, and the permission configuration file is formed based on the setting result, when the account of the target administrator passes the preset authentication, i.e., one or more authentication methods of static authentication, dynamic authentication and biometric authentication, and successfully logs in the application system, the target service identifier and the target identity information of the target administrator can be obtained based on the triggering operation of the target administrator for the target service identifier, and the target regional information of the target administrator can be further determined. By obtaining the permission configuration file from the preset database and loading the permission configuration file into the corresponding memory, whether the target service identifier is located in the first permission range corresponding to the target identity information can be judged in the permission configuration file based on the memory, so that the configuration interface corresponding to the target service is displayed when it is determined that the target service identifier is located in the first permission range corresponding to the target identity information, and the configuration strategy input by the configuration interface is obtained according to the target regional information, so that the target service is configured by using the configuration strategy. Therefore, each administrator can only trigger a service within the demand of the administrator, access rights are avoided, and the security of service configuration is improved. In addition, multiple authentication methods are set to verify the identity of the administrator, further improving the security of service configuration. Further, the reading efficiency is improved based on the memory reading the configuration file, thereby improving the efficiency of service configuration. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0022] Figure 1 The application scenario of the service configuration method provided by the embodiment of the present application is shown in the figure;
[0023] Figure 2 The method flow of the service configuration method provided by the embodiment of the present application is shown in the figure Figure 1 ;
[0024] Figure 3 The method flow of the service configuration method provided by the embodiment of the present application is shown in the figure Figure 2 ;
[0025] Figure 4 The structure diagram of the service configuration device provided by the embodiment of the present application is shown in the figure;
[0026] Figure 5 The structure diagram of the electronic device provided by the embodiment of the present application is shown in the figure.
[0027] Through the above figures, the specific embodiments of the present application have been shown, and more detailed descriptions will be given hereinafter. These figures and textual descriptions are not intended to limit the scope of the concept of the present application by any means, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0028] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. Unless otherwise indicated, the same numbers on different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments are not meant to represent all implementations consistent with the present application. Rather, they are merely examples that can be implemented in conjunction with some aspects of the present application, as detailed in the appended claims.
[0029] It should be noted that in the technical solutions of the present application, the collection, storage, use, processing, transmission, provision and disclosure of information such as financial data or user data, etc. comply with relevant laws and regulations and do not violate public order and good customs. The user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal.
[0030] Terminology explanation:
[0031] Application system: a system that uses a computer to realize various services under certain conditions with the support of software or hardware, such as a Web (World Wide Web) application system, an APP (Application) application system, and the like.
[0032] Management node: a component responsible for managing and monitoring the running state of the entire application system.
[0033] Service: an independent unit responsible for completing specific business logic or technical tasks in an application system.
[0034] In the prior art, when configuring services in an application system, the permissions for configuring services are generally opened for each administrator in advance based on the difference between users and administrators. When each administrator has a demand for configuring services, the administrator clicks a button corresponding to the service to be configured in any service supported by the application system, thereby accessing the service and configuring it. However, in the process of service configuration, each administrator can trigger other services that are not within the demand of the administrator, resulting in unauthorized access and reducing the security of service configuration.
[0035] To prevent unauthorized access and improve the security of service configuration, the present application proposes the following technical concept: instead of opening permissions for configuring services for each administrator based on the difference between users and administrators, a plurality of administrator identities are pre-set, and at least one service identifier to be configured by each administrator identity is specified, so that each administrator only has the permission to access each service to be configured. When the application system determines that the account of a certain administrator has passed authentication and successfully logged in, the triggering operation of the administrator is monitored, so that when the administrator clicks a button corresponding to a service identifier, the service identifier and the identity of the administrator are obtained, and the area where the administrator is located is determined. Then, the pre-stored setting content is obtained, and it is judged whether the administrator has the permission to access the service corresponding to the service identifier based on the setting content, so that when it is determined that the administrator has the permission, the configuration interface of the service is provided to the administrator, and then the configuration strategy input by the administrator in the configuration interface based on the area where the administrator is located is obtained, and the service is configured by using the configuration strategy. Each administrator can only trigger services within the demand of the administrator, avoiding unauthorized access and improving the security of service configuration.
[0036] Figure 1 The application scenario of the service configuration method provided by the embodiment of the present application is shown in the following figure. Figure 1As shown, this application scenario includes: administrator terminal 1, management node 2, and preset database 3. Administrator terminal 1 is the user terminal where each administrator resides. Management node 2 is the node that manages various services within the application system, which hosts multiple services. Preset database 3 is a database that stores various configuration data, such as permission configuration files and user data. Management node 2 is communicatively connected to both administrator terminal 1 and preset database 3.
[0037] First, the target administrator clicks the button containing the target service identifier via administrator terminal 1. Management node 2 responds to this trigger operation by obtaining the target service identifier, the target administrator's target identity information, and determining the target administrator's target region information. Then, it retrieves a permission configuration file from the preset database 3, containing multiple identity information entries and their corresponding first permission scopes, and loads this configuration file into the corresponding memory. Based on the memory location and the permission configuration file, it determines whether the target service identifier is within the first permission scope corresponding to the target identity information. Further, if it is determined to be within the first permission scope, the configuration interface corresponding to the target service is displayed, and the configuration policy input on the configuration interface is obtained based on the target region information. This configuration policy is then used to configure the target service.
[0038] It is understood that the target administrator's account passed the preset authentication and successfully logged into the application system. This preset authentication can be one or more of static authentication, dynamic authentication, and biometric authentication. The first permission scope includes at least one service identifier.
[0039] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0040] Figure 2 Method flow of the service configuration method provided in the embodiments of this application Figure 1 .like Figure 2 As shown, the execution entity of this solution is a service configuration device, which is specifically located in an electronic device, such as a management node. This management node is the management node corresponding to the application system, which carries multiple services. When the management node determines that each service has been triggered by the administrator, it executes the method of this embodiment:
[0041] S201, in response to a trigger operation identified by a target administrator for a target service, obtaining target service identification and target identity information of the target administrator, and determining target regional information of the target administrator; the account of the target administrator passes a preset authentication and successfully logs in the application system; the preset authentication is one or more of static authentication, dynamic authentication, and biometric authentication.
[0042] The target administrator is any administrator allowed to configure the application system.
[0043] The target service identification is any identification representing the identity of the target service, such as the name, number, etc. of the target service. The embodiment does not limit the specific identification form. The target service is any service to be configured by the target administrator.
[0044] The target identity information is information representing the identity of the target administrator, which can be one of a user administrator, an encryption administrator, an authentication administrator, and a terminal administrator. The user administrator is an administrator who manages and maintains user accounts and their permissions in the application system. The encryption administrator is an administrator who implements, manages, and maintains encryption technology in the application system. The authentication administrator is an administrator who manages user identity authentication, permission authentication, and related authentication devices and processes in the application system. The terminal administrator is an administrator who manages and maintains the normal operation of the terminal corresponding to the application system.
[0045] Based on this, the target administrator enters the page of the application system through the administrator terminal, and inputs the account based on the page. Correspondingly, the management node obtains the account and verifies the account. Specifically, one or more of static authentication, dynamic authentication, and biometric authentication are sent to the administrator terminal, and the authentication result fed back by the administrator terminal is received. The authentication result is compared with the registration information corresponding to the target administrator. If they are consistent, it is determined that the account of the target administrator passes the authentication.
[0046] The static authentication is an authentication method indicating that the administrator authenticates the static password set during registration. The dynamic authentication is an authentication method indicating that the administrator authenticates the one-time password based on the administrator terminal address. The biometric authentication is an authentication method indicating that the administrator authenticates the biometric feature collected during registration, which can be a face, a fingerprint, etc.
[0047] The registration information is information related to the administrator pre-stored when the administrator registers the account based on the application system, which can be the static password set by the administrator, the administrator terminal address, the biometric feature of the administrator, etc.
[0048] It can be understood that when it is determined that the account of the target administrator is authenticated, the application system is automatically logged in based on the result of the authentication.
[0049] Further, the target administrator clicks the button where the target service identifier is located through the corresponding administrator terminal, and then the target service identifier and the target identity information of the target administrator are acquired in response to the triggering operation of the target administrator on the target service identifier, and the target regional information of the target administrator is determined.
[0050] The target regional information is information for representing the region where the target administrator is located. For example, if the target administrator is currently located in A city, the target regional information can be a field where the "A city" is located.
[0051] In the process of acquiring the target identity information of the target administrator, the account of all registered administrators can be acquired in advance, and the multiple identity information set by the administrators can be acquired. The accounts of the administrators are assigned corresponding identity information according to the functions of the administrators. Then, in the process of acquiring the target identity information of the target administrator, the account of the target administrator is acquired, and the identity information assigned to the account is determined as the target identity information of the target administrator.
[0052] In the process of determining the target regional information of the target administrator, the account of all registered administrators can be acquired in advance, and the regional information of the administrators can be marked according to the regions where the administrators are located. For example, the accounts of the administrators in A city are marked with a field where the "A city" is located. Then, in the process of determining the target regional information of the target administrator, the account of the target administrator is acquired, and the regional information marked for the account is determined as the target regional information of the target administrator.
[0053] It can be understood that the above examples are only examples and should not constitute any limitation on the present application.
[0054] S202, acquire a permission configuration file from a preset database, and load the permission configuration file into a corresponding memory; the permission configuration file includes multiple identity information and a first permission range corresponding to each identity information, and the first permission range includes at least one service identifier.
[0055] The permission configuration file is a file with configuration permissions that each administrator should have, which is written in advance by a person responsible for the application system, and can include multiple identity information and a first permission range corresponding to each identity information, and the first permission range includes at least one service identifier.
[0056] The first permission range is a service range that can be accessed by a certain identity information, and specifically includes at least one service identifier. The service identifier is an identifier corresponding to any service in the application system.
[0057] It can be understood that for each service in the application system, there may be some services that involve user accounts and their permissions when used, so for these services, a user administrator is needed to perform related user configuration. Similarly, there may be some services that involve encryption technology when used, so for these services, an encryption administrator is needed to perform related encryption configuration. Similarly, there may be some services that involve related authentication processes when used, so for these services, an authentication administrator is needed to perform related authentication configuration. Similarly, there may be some services that involve frequent interaction with terminals when used, so for these services, a terminal administrator is needed to perform related terminal configuration. Therefore, by constructing a mapping relationship between each identity information and the services required for the configuration of each identity information, the access permission of each administrator to the services can be indicated based on the identity information of each administrator.
[0058] Based on this, the person in charge of the application system pre-acquires a plurality of identity information set, and specifies at least one service allowed to access for each identity information, and then constructs a mapping relationship between each identity information and the at least one service identifier specified for it based on the specification result, to obtain the first permission range corresponding to each identity information.
[0059] Exemplarily, if the identity information is an encryption administrator, at least one service involving encryption technology can be specified for the identity information, and a mapping relationship between the identity information and the services involving encryption technology is constructed based on the specification result, to obtain the first permission range corresponding to the identity information.
[0060] Then in this embodiment, after obtaining the target service identifier and the target identity information of the target administrator, in order to further determine whether the target administrator has the permission to access the target service, the permission configuration file is acquired based on the communication connection with the preset database, and the permission configuration file is loaded into the corresponding memory.
[0061] It can be understood that the preset database is a database set based on an independent server, and the memory is a memory device set in the management node, therefore, by first acquiring the permission configuration file from the preset database and then loading the permission configuration file into the memory, the permission configuration file can be read based on the memory subsequently, improving the reading efficiency, and further improving the efficiency of service configuration.
[0062] S203, judging whether the target service identifier is located in the first permission range corresponding to the target identity information in the permission configuration file based on the memory.
[0063] In this embodiment, after obtaining the target service identifier, the target identity information of the target administrator and the permission configuration file, the field where the target service identifier is located is read, and based on the permission configuration file in the memory, the first permission range corresponding to the target identity information is determined and read, so as to judge whether the field where the target service identifier is located is in the first permission range corresponding to the target identity information based on the read result.
[0064] S204, if yes, the configuration interface corresponding to the target service is displayed, and the configuration policy input by the configuration interface is obtained according to the target region information, so as to configure the target service by using the configuration policy.
[0065] The configuration interface is an operation interface for configuring the service.
[0066] The configuration policy is a policy formed by data required by the configuration service.
[0067] In this embodiment, based on the judgment of whether the target service identifier is located in the first permission range corresponding to the target identity information, if yes, it indicates that the target administrator has the permission to access the target service corresponding to the target service identifier, the configuration interface corresponding to the target service is obtained, and the configuration interface is displayed on the administrator terminal.
[0068] Therefore, the target administrator inputs the configuration content required by the configuration interface into the corresponding configuration content according to the corresponding target region information to obtain the corresponding configuration data, forms the configuration policy, and triggers the confirmation operation. Correspondingly, the configuration policy input by the target administrator in the configuration interface is obtained based on the confirmation operation, and the target service is configured by using the configuration policy.
[0069] The service configuration method provided in the embodiment sets at least one allowed access service identifier, i.e., a corresponding first permission range, for each identity information in advance, forms a permission configuration file based on the setting result, and when the account of the target administrator successfully logs in the application system through preset authentication, i.e., one or more of static authentication, dynamic authentication, and biometric authentication, and the target service identifier and the target identity information of the target administrator can be obtained based on the triggering operation of the target administrator to the target service identifier, and the target regional information of the target administrator can be further determined. The permission configuration file is obtained from the preset database and loaded into the corresponding memory, and it is determined in the memory whether the target service identifier is located in the first permission range corresponding to the target identity information in the permission configuration file, so that the configuration interface corresponding to the target service is displayed when it is determined that the target service identifier is located in the first permission range corresponding to the target identity information, and the configuration strategy input by the configuration interface is obtained according to the target regional information, so that the target service is configured by using the configuration strategy. The administrator can only trigger the service within the demand of the administrator, the access of the administrator is avoided, the security of the service configuration is improved, and the identity of the administrator is verified by using multiple authentication methods, so that the security of the service configuration is further improved. Further, the reading efficiency is improved based on the memory reading the configuration file, so that the efficiency of the service configuration is improved.
[0070] As an optional embodiment, the content included in the permission configuration file is further refined based on the above-mentioned embodiments, and the configuration strategy input by the configuration interface according to the target regional information is further refined. In this embodiment, the permission configuration file further includes a plurality of regional information and a second permission range corresponding to each regional information, and the second permission range includes at least one data identifier. When the configuration strategy input by the configuration interface according to the target regional information is obtained, the following steps are included:
[0071] Step a1: Based on the configuration interface, the obtaining operation of the target administrator to the target data identifier is monitored, and it is determined in the memory whether the target data identifier is located in the second permission range corresponding to the target regional information in the permission configuration file.
[0072] In this embodiment, the permission configuration file further includes a plurality of regional information and a second permission range corresponding to each regional information, and the second permission range includes at least one data identifier.
[0073] The regional information is information representing the region of the administrator.
[0074] The second permission range is a data range that can be accessed by each regional information, and specifically includes at least one data identifier. The data identifier is an identifier of data required when the service is configured.
[0075] It can be understood that the regions where the administrators are located can be different, so for administrators in different regions, they can only use the data of the corresponding region to configure services when configuring services.
[0076] Based on this, the application system responsible person can pre-acquire the set multiple regional information, and specify at least one data allowed to be accessed for each regional information, and then based on the specification result, a mapping relationship is constructed between each regional information and the at least one data identifier specified therefor, to obtain the second authority scope corresponding to each regional information.
[0077] Exemplarily, if there is an administrator located in B city, the corresponding regional information is the field where B city is located, and the second authority scope corresponding to the regional information is the data related to B city, such as the user data of B city.
[0078] Then in this embodiment, the target data identifier is the identifier corresponding to the data required by the target administrator to configure the target service. When the configuration strategy input by the configuration interface according to the target regional information is acquired, the operation of the target administrator to the configuration interface is monitored in real time, and when it is determined that the target administrator performs the acquisition operation to the target data identifier, the field where the target data identifier is located is read, and based on the authority configuration file in the memory, the second authority scope corresponding to the target regional information is read, and it is judged whether the field where the target data identifier is located is located in the above-mentioned second authority scope.
[0079] Step a2: if yes, the target data is displayed, and the configuration strategy input by the target administrator according to the target data is acquired.
[0080] Among them, the target data is the data required by the target administrator to configure the target service.
[0081] In this embodiment, based on the judgment of whether the target data identifier is located in the second authority scope corresponding to the target regional information, if yes, based on the communication connection with the preset database, the target data corresponding to the target data identifier is acquired, and the target data is displayed on the administrator terminal.
[0082] Alternatively, based on the communication connection with the preset database, the target data can be loaded into the corresponding memory first, and then the target data is acquired based on the memory, so as to display the target data on the administrator terminal.
[0083] Based on this, the target administrator inputs the required configuration data in the configuration interface according to the provided target data, to form the configuration strategy for the target service, so as to acquire the configuration strategy input by the target administrator according to the target data.
[0084] The service configuration method provided in the embodiment sets at least one allowed data identifier corresponding to each regional information in the permission configuration file in advance, that is, a corresponding second permission range, so that by monitoring the acquisition operation of the target administrator located in the target regional information on the target data identifier in the configuration interface, it can be determined in the permission configuration file based on the memory whether the target data identifier is located in the second permission range corresponding to the target regional information, so that the target data is displayed when it is determined to be located, and thus the configuration strategy input by the target administrator according to the target data is obtained. The administrators in different regions can only obtain the related data of their corresponding regions, avoiding data overreach, and further improving the security of the configuration service.
[0085] As an optional embodiment, the embodiment in the Figure 2 Based on the corresponding embodiment, the configuration strategy is further refined for configuring the target service, and the embodiment specifically includes the following steps when the configuration strategy is used to configure the target service:
[0086] The integrity of the configuration strategy is verified, and the configuration strategy is applied to the target service when the verification is passed.
[0087] The integrity verification is a process to ensure that the configuration strategy is not damaged or lost.
[0088] In the embodiment, after obtaining the configuration strategy, the integrity of the configuration strategy is verified, specifically, the fields where the configuration strategy is located are identified, and when all the fields are successfully identified, it is determined that the verification is passed. According to the policy content reflected by the configuration strategy, the configuration of the target service is adjusted, including but not limited to modifying the corresponding configuration file, adjusting the system parameter, etc., so as to apply the configuration strategy to the target service.
[0089] The service configuration method provided in the embodiment avoids the failure of the configuration service caused by the damage or loss of the configuration strategy by verifying the integrity of the configuration strategy and applying the configuration strategy to the target service when the verification is passed, thereby improving the success rate of the configuration service.
[0090] As an optional embodiment, the embodiment in the Figure 2 Based on the corresponding embodiment, the content included in the permission configuration file is further refined, and in the embodiment, the permission configuration file further includes a third permission range corresponding to each identity information. The third permission range includes at least one menu identifier, and the menu identifier indicates that there is at least one service identifier under the menu. Before responding to the trigger operation of the target administrator on the target service identifier, the target service identifier and the target identity information of the target administrator are further included in the following steps:
[0091] Step b1: in response to a trigger operation of the target administrator for the target menu identifier, obtaining the target menu identifier and determining the target identity information of the target administrator.
[0092] In this embodiment, the permission configuration file further includes a third permission range corresponding to each identity information, the third permission range including at least one menu identifier, and the menu indicated by the menu identifier having at least one service identifier. The third permission range is a menu range that can be accessed by a certain identity information, and specifically includes at least one menu identifier. The menu identifier is an identifier corresponding to any menu in the application system.
[0093] It can be understood that for multiple services in the application system, they can also be distributed under different menus according to certain rules for ease of management. For example, if at least one service needs to be authenticated when used by a user, the at least one service can be deployed in the same menu.
[0094] In this embodiment, the person in charge of the application system can pre-obtain multiple identity information set, and specify at least one menu that each identity information is allowed to access, and then based on the specification result, a mapping relationship is established between each identity information and the at least one menu identifier specified therefor, to obtain the third permission range corresponding to each identity information.
[0095] Based on this, before obtaining the target service identifier and the target identity information of the target administrator in response to the trigger operation of the target administrator for the target service identifier, the trigger operation of the target administrator for the target menu identifier is monitored first, and when the trigger is determined, the target menu identifier is obtained, and the target identity information of the target administrator is determined. The specific determination method is similar to the determination method mentioned when obtaining the target identity information of the target administrator in S201, which will not be repeated here.
[0096] Step b2: determining whether the target menu identifier is located in the third permission range corresponding to the target identity information based on the permission configuration file in the memory.
[0097] Specifically, after obtaining the target menu identifier and determining the target identity information of the target administrator, the field where the target menu identifier is located is read, and based on the permission configuration file in the memory, the third permission range corresponding to the target identity information is determined and read, so as to determine whether the field where the target menu identifier is located is located in the third permission range corresponding to the target identity information based on the read result.
[0098] Step b3: if yes, displaying at least one service identifier under the target menu, and monitoring the trigger operation of the target administrator based on each service identifier.
[0099] In this embodiment, based on judging whether the target menu identifier is located in the third permission range corresponding to the target identity information, if yes, it indicates that the target administrator has the permission to access the target menu indicated by the target menu identifier. It can be understood that when the target administrator has the permission to access the target menu, it is further needed to determine whether the target administrator has the permission to access at least one service under the target menu.
[0100] Based on this, the at least one service identifier under the target menu is displayed on the administrator terminal, and the triggering operation of the target administrator on each service identifier through the administrator terminal is monitored, and then the subsequent service configuration method is executed, and the specific execution process is similar to S201-S204, which will not be described here.
[0101] The service configuration method provided in this embodiment, since the corresponding at least one allowed access menu identifier, i.e., the corresponding third permission range, is set for each identity information in advance, the target menu identifier can be obtained based on the triggering operation of the target administrator on the target menu identifier, and the target identity information of the target administrator can be further determined. And by judging whether the target menu identifier is located in the third permission range corresponding to the target identity information based on the permission configuration file in the internal memory, when it is determined that it is located, the at least one service identifier under the target menu is displayed, so as to monitor the triggering operation of the target administrator based on each service identifier, so that the menu permission of the administrator is verified before the administrator triggers a certain service identifier, and the security of the service configuration is further improved.
[0102] As an optional embodiment, based on any of the above embodiments, after judging whether the target service identifier is located in the first permission range corresponding to the target identity information, or after judging whether the target data identifier is located in the second permission range corresponding to the target regional information, or after judging whether the target menu identifier is located in the third permission range corresponding to the target identity information, the following steps are further included:
[0103] If no, the corresponding target prompt information is generated and displayed.
[0104] The target prompt information is information prompting the target administrator that he does not have a certain permission.
[0105] In the embodiment, after determining whether the target menu identifier is located in the third permission range corresponding to the target identity information, if not, it indicates that the target administrator does not have the permission to access the target menu, and the corresponding target prompt information is generated based on the result, for example, the field where "no permission to access the target menu" is located. Similarly, after determining whether the target service identifier is located in the first permission range corresponding to the target identity information, if not, it indicates that the target administrator does not have the permission to access the target service, and the corresponding target prompt information is generated based on the result, for example, the field where "no permission to access the target service" is located. Similarly, after determining whether the target data identifier is located in the second permission range corresponding to the target region information, if not, it indicates that the target administrator does not have the permission to access the target data, and the corresponding target prompt information is generated based on the result, for example, the field where "no permission to access the target data" is located.
[0106] It can be understood that the above examples are only examples and should not constitute any limitation on the present application.
[0107] The service configuration method provided in the embodiment can make the target administrator know the result that he or she does not have the permission, improve user experience, because the target administrator can not have a certain permission, and the corresponding target prompt information is generated and displayed when it is determined that the target administrator does not have the certain permission.
[0108] As an optional embodiment, the target identity information is one of the following identity information: user administrator, encryption administrator, authentication administrator, and terminal administrator, based on any of the above embodiments. Thus, the identities of the administrators are divided, and the success rate of subsequent service configuration is improved.
[0109] It should be noted that there can be multiple administrators for a certain identity information, that is, there are multiple administrators with the same identity information, and when the first permission range corresponding to each identity information is configured in the permission configuration file, different administrators under the same identity information can be further considered, and different services are allocated to different administrators under the same identity information, so that the work efficiency of service configuration can be improved. For example, if the C administrator and the D administrator are both encryption administrators, and the first permission range corresponding to the encryption administrator in the permission configuration file includes a service identifier, a service identifier, a service identifier, and a service identifier, a mapping relationship can be further established between the account of the C administrator and the a service identifier and the b service identifier, and a mapping relationship can be further established between the account of the D administrator and the c service identifier and the d service identifier, so as to allocate different services to the C administrator and the D administrator.
[0110] It can be understood that the above examples are only examples and should not constitute any limitation on the present application.
[0111] Figure 3 Method flow of the service configuration method provided for the embodiments of the present application Figure 2 As shown in Figure 3 , a complete flowchart of the service configuration method is given.
[0112] S301, in response to a login operation of a target administrator to an application system, an account of the target administrator is obtained.
[0113] S302, the account is subjected to preset authentication, and the application system is logged in when the account passes the preset authentication; the preset authentication is one or more of static authentication, dynamic authentication and biometric authentication.
[0114] S303, in response to a trigger operation of the target administrator to a target menu identifier, the target menu identifier is obtained, and target identity information of the target administrator is determined.
[0115] S304, a permission configuration file is obtained from a preset database, and the permission configuration file is loaded into a corresponding memory; the permission configuration file includes: a plurality of identity information and first permission ranges and third permission ranges corresponding to each identity information, and a plurality of regional information and second permission ranges corresponding to each regional information; the first permission range includes at least one service identifier, the second permission range includes at least one data identifier, and the third permission range includes at least one menu identifier; the menu identifier indicates that there is at least one service identifier under the menu.
[0116] S305, it is judged in the permission configuration file based on the memory whether the target menu identifier is located in the third permission range corresponding to the target identity information, if yes, S306 is continued to be executed, and if not, S313 is executed.
[0117] S306, at least one service identifier under the target menu is displayed, and a trigger operation of the target administrator based on each service identifier is monitored.
[0118] S307, in response to a trigger operation of the target administrator to a target service identifier, the target service identifier and target identity information of the target administrator are obtained, and target regional information of the target administrator is determined.
[0119] Among them, the target identity information is one of the following identity information: user administrator, encryption administrator, authentication administrator, terminal administrator.
[0120] S308, it is judged in the permission configuration file based on the memory whether the target service identifier is located in the first permission range corresponding to the target identity information, if yes, S309 is continued to be executed, and if not, S313 is executed.
[0121] S309, display the configuration interface corresponding to the target service, and monitor the target administrator's obtaining operation on the target data identifier based on the configuration interface.
[0122] S310, determine whether the target data identifier is located in the second permission range corresponding to the target region information in the permission configuration file based on the internal memory, if yes, continue to perform S311, if not, perform S313.
[0123] S311, display the target data, and obtain the configuration policy input by the target administrator according to the target data.
[0124] S312, integrity verification is performed on the configuration policy, and the configuration policy is applied to the target service when the verification is passed.
[0125] S313, generate and display the corresponding target prompt information.
[0126] Figure 4 The structure schematic diagram of the service configuration device provided by the embodiment of the application is shown in the figure. Figure 4 As shown in the figure, the service configuration device 40 includes a processing module 41 and a configuration module 42.
[0127] The processing module 41 is configured to obtain the target service identifier and the target identity information of the target administrator in response to the triggering operation of the target administrator on the target service identifier; the target administrator is an administrator who successfully logs in the application system through preset authentication; the preset authentication is one or more of static authentication, dynamic authentication and biometric authentication; the permission configuration file is obtained from the preset database and loaded into the corresponding internal memory; the permission configuration file includes a plurality of identity information and a first permission range corresponding to each identity information, and the first permission range includes at least one service identifier; it is determined whether the target service identifier is located in the first permission range corresponding to the target identity information in the permission configuration file based on the internal memory; if yes, the configuration interface corresponding to the target service is displayed, and the configuration policy input by the target administrator on the configuration interface is obtained; the configuration module 42 is configured to configure the target service by using the configuration policy.
[0128] Optionally, the permission configuration file further includes a plurality of region information and a second permission range corresponding to each region information, and the second permission range includes at least one data identifier.
[0129] Correspondingly, the processing module 41, when obtaining the configuration policy input on the configuration interface according to the target region information, is specifically configured to:
[0130] Based on the configuration interface, the monitoring target administrator acquires the operation of the target data identifier, and judges whether the target data identifier is located in the second permission range corresponding to the target region information in the permission configuration file based on the internal storage; if yes, the target data is displayed, and the configuration strategy input by the target administrator according to the target data is acquired.
[0131] Optionally, the configuration module 42, when configuring the target service by using the configuration strategy, is specifically configured to:
[0132] verify the integrity of the configuration strategy, and apply the configuration strategy on the target service when the verification is passed.
[0133] Optionally, the permission configuration file further includes a third permission range corresponding to each identity information, and the third permission range includes at least one menu identifier; the menu identifier indicates that there is at least one service identifier under the menu;
[0134] Correspondingly, the processing module 41 is further configured to, in response to the trigger operation of the target administrator on the target menu identifier, acquire the target menu identifier and the target identity information of the target administrator before acquiring the target service identifier and the target identity information of the target administrator, judge whether the target menu identifier is located in the third permission range corresponding to the target identity information in the permission configuration file based on the internal storage; if yes, display at least one service identifier under the target menu, and monitor the trigger operation of the target administrator based on each service identifier.
[0135] Optionally, the processing module 41 is further configured to, after judging whether the target service identifier is located in the first permission range corresponding to the target identity information, or after judging whether the target data identifier is located in the second permission range corresponding to the target region information, or after judging whether the target menu identifier is located in the third permission range corresponding to the target identity information, if no, generate and display the corresponding target prompt information.
[0136] Optionally, the target identity information is one of the following identity information: a user administrator, an encryption administrator, an authentication administrator, and a terminal administrator.
[0137] It should be noted that the division of each module of the above apparatus is only a logical function division, and all or part of the modules can be integrated into a physical entity or physically separated when actually implemented. The modules can all be implemented in the form of software invoked by a processing element, all in the form of hardware, or part of the modules are implemented in the form of software invoked by a processing element and part of the modules are implemented in the form of hardware. Each module can be a separately established processing element, or can be integrated in a chip of the above apparatus, in addition, the functions of each module can also be stored in the form of program code in the memory of the above apparatus, and called and executed by a processing element of the above apparatus. In addition, all or part of the modules can be integrated together or independently implemented. The processing element herein can be an integrated circuit with signal processing capability. In the implementation process, each step of the above method or each module can be completed by integrated logic circuits of hardware in the processing element or instructions in the form of software.
[0138] Figure 5 The structure schematic diagram of an electronic device provided by the embodiment of the present application is shown in FIG. 1. As shown in the figure, the electronic device 50 can include a processor 51 and a memory 52. Figure 5
[0139] The processor 51 executes the computer execution instructions stored in the memory, so that the processor 51 executes the scheme in the above embodiment. The processor 51 can be a general-purpose processor, including a central processing unit CPU, a network processor NP, etc.; and can also be a digital signal processor DSP, an application-specific integrated circuit ASIC, a field programmable gate array FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0140] The memory 52 is connected with the processor 51 through a system bus and completes mutual communication, and the memory 52 is used for storing computer program instructions.
[0141] The system bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, or the like. The system bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in the figure, but it does not mean that there is only one bus or only one type of bus. The transceiver is used to realize the communication between the database access device and other computers (such as clients, read-write libraries and read-only libraries). The memory can include random access memory (RAM) and can also include non-volatile memory.
[0142] The electronic device provided by the embodiment of the present application can further include a transceiver for transceiving data.
[0143] The electronic device provided by the embodiment of the present application can be a management node of the above-mentioned embodiment.
[0144] The embodiment of the present application further provides a chip for running instructions, which is used to execute the technical solutions of the service configuration method in the above-mentioned embodiments.
[0145] The embodiment of the present application further provides a computer readable storage medium, which stores computer instructions, and when the computer instructions are run on a computer, the computer executes the technical solutions of the service configuration method in the above-mentioned embodiments.
[0146] The embodiment of the present application further provides a computer program product, which includes a computer program stored in a computer readable storage medium, at least one processor can read the computer program from the computer readable storage medium, and when the at least one processor executes the computer program, the technical solutions of the service configuration method in the above-mentioned embodiments can be realized.
[0147] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interfaces, devices or modules, and can be electrical, mechanical or other forms.
[0148] The modules illustrated as separate components may or may not be physically separate, and the components illustrated as modules may or may not be physical units, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the modules can be selected to implement the embodiments according to actual needs.
[0149] In addition, the functional modules in each embodiment of the present application can be integrated in one processing unit, or each module can be physically present alone, or two or more modules can be integrated in one unit. The units of the above modules can be realized in the form of hardware or in the form of hardware plus software functional units.
[0150] The integrated modules realized in the form of software functional modules can be stored in a computer readable storage medium. The software functional modules stored in a storage medium include a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute part of the steps of the method of each embodiment of the present application.
[0151] It should be understood that the above processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.
[0152] The memory can include a high-speed RAM memory, and can also include a non-volatile storage NVM, for example at least one disk memory, and can also be a U disk, a mobile hard disk, a read-only memory, a magnetic disk or an optical disk, etc.
[0153] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0154] The storage medium described above can be realized by any type of volatile or nonvolatile storage devices or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic storage, a flash memory, a magnetic disk or an optical disk. The storage medium can be any available medium that can be accessed by a general or special purpose computer.
[0155] An exemplary storage medium is coupled to the processor so that the processor can read information from, and write information to, the storage medium. Of course, the storage medium can be part of the processor. The processor and the storage medium can be located in an application specific integrated circuits (ASIC). Of course, the processor and the storage medium can exist as discrete components in an electronic control unit or a host device.
[0156] Those of ordinary skill in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by relevant hardware instructed by programs. The foregoing programs can be stored in a computer readable storage medium. When the programs are executed, the steps of the above-mentioned method embodiments are executed; and the foregoing storage medium includes various storage media that can store program codes, such as ROM, RAM, magnetic disks or optical disks.
[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A service configuration method, characterized by, The method is applied to a management node corresponding to an application system, the application system is loaded with a plurality of services, and the management node is configured to execute the service configuration method when each service is triggered by an administrator. The method comprises the following steps: In response to a triggering operation of a target administrator on a target service identifier, the target service identifier and target identity information of the target administrator are obtained, and target regional information of the target administrator is determined; an account of the target administrator has passed a preset authentication and successfully logged in the application system; the preset authentication is one or more of a static authentication, a dynamic authentication, and a biometric authentication; A permission configuration file is obtained from a preset database and loaded into a corresponding memory; the permission configuration file comprises a plurality of identity information and a first permission range corresponding to each identity information, and the first permission range comprises at least one service identifier; A field in which the target service identifier is located is read, and it is determined whether the field in which the target service identifier is located is located in the first permission range corresponding to the target identity information based on the permission configuration file in the memory; If yes, a configuration interface corresponding to the target service is displayed, and a configuration strategy input by the configuration interface is obtained according to the target regional information, and the target service is configured by using the configuration strategy; The permission configuration file further comprises a plurality of regional information and a second permission range corresponding to each regional information, and the second permission range comprises at least one data identifier; The configuration strategy input by the configuration interface according to the target regional information comprises the following steps: Based on the configuration interface, the acquisition operation of the target administrator on a target data identifier is monitored, a field in which the target data identifier is located is read, and it is determined whether the field in which the target data identifier is located is located in the second permission range corresponding to the target regional information based on the permission configuration file in the memory; If yes, target data is displayed, and a configuration strategy input by the target administrator according to the target data is obtained.
2. The method of claim 1, wherein, The configuration of the target service by using the configuration strategy comprises the following steps: The configuration strategy is subjected to integrity verification, and the configuration strategy is applied to the target service when the verification is passed.
3. The method of claim 1, wherein, The permission configuration file further comprises a third permission range corresponding to each identity information, and the third permission range comprises at least one menu identifier; the menu identifier indicates that there is at least one service identifier under a menu; Before the target service identifier and the target identity information of the target administrator are obtained in response to the triggering operation of the target administrator on the target service identifier, the following steps are further included: In response to a triggering operation of a target administrator on a target menu identifier, the target menu identifier is obtained, and target identity information of the target administrator is determined; It is determined whether the target menu identifier is located in the third permission range corresponding to the target identity information based on the permission configuration file in the memory; If yes, at least one service identifier under a target menu is displayed, and triggering operations of the target administrator based on each service identifier are monitored.
4. The method of claim 3, wherein, The method further comprises: If not, corresponding target prompt information is generated and displayed.
5. The method according to any one of claims 1 to 3, characterized in that, The target identity information is one of the following identity information: A user administrator, an encryption administrator, an authentication administrator, and a terminal administrator.
6. A service configuration apparatus characterized by comprising: The device comprises: A processing module configured to, in response to a triggering operation of a target administrator on a target service identifier, acquire the target service identifier and target identity information of the target administrator, and determine target region information of the target administrator; the target administrator is an administrator who successfully logs in an application system after a preset authentication; the preset authentication is one or more of a static authentication, a dynamic authentication, and a biometric authentication; acquire a permission configuration file from a preset database, and load the permission configuration file into a corresponding memory; the permission configuration file comprises a plurality of identity information and a first permission range corresponding to each identity information, and the first permission range comprises at least one service identifier; read a field in which the target service identifier is located, and determine whether the field in which the target service identifier is located is located in the first permission range corresponding to the target identity information based on the permission configuration file in the memory; if yes, display a configuration interface corresponding to the target service, and acquire a configuration strategy input by the configuration interface according to the target region information; A configuration module configured to configure the target service by using the configuration strategy. The permission configuration file further comprises a plurality of region information and a second permission range corresponding to each region information, and the second permission range comprises at least one data identifier; and the processing module, when acquiring the configuration strategy input by the configuration interface according to the target region information, is specifically configured to monitor an acquisition operation of the target administrator on a target data identifier based on the configuration interface, read a field in which the target data identifier is located, and determine whether the field in which the target data identifier is located is located in the second permission range corresponding to the target region information based on the permission configuration file in the memory; if yes, display target data, and acquire a configuration strategy input by the target administrator according to the target data.
7. An electronic device, comprising: Comprise: A processor and a memory connected with the processor in communication; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method in any one of claims 1-5.
9. A computer program product, characterised in that, A computer program is executed by the processor to implement the method in any one of claims 1-5.
Citation Information
Patent Citations
Permission control method and device, computer equipment and storage medium
CN111259412A
Access permission configuration method and device, equipment, storage medium and product
CN118211248A