A data authority management method for a power station

By introducing a permission management system based on role-based permission control in power plants and combining it with a three-level permission mapping table of cache and database, the security and efficiency issues of data permission management in industrial and commercial power plants are solved, and efficient data resource access and security management are achieved.

CN119416234BActive Publication Date: 2025-10-03CUIJI TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411446540.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-16
Publication Date
2025-10-03
Estimated Expiration
2044-10-16

AI Technical Summary

Technical Problem

In industrial and commercial power plants, due to the need for equipment sharing and complex collaboration parties, traditional data permission management is difficult to ensure data security and efficiency.

Method used

Adopt a permission management system based on role permission control, combine cache and database, use three-level permission mapping table and authorization relationship table to optimize user permission query and authorization process.

Benefits of technology

It improves the security and query efficiency of data resources, saves storage space, is compatible with internal and external role authorization, simplifies the authorization chain, and reduces system complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119416234B_ABST
    Figure CN119416234B_ABST
Patent Text Reader

Abstract

The present invention provides a data rights management method for a power station, comprising: step 1, providing a rights management system; step 2, a user accessing a data resource of a power station; step 3, the rights management system querying whether the user has a record based on the cached three-level rights mapping table; if so, directly returning the data resource requested for access; if not, jumping to step 4; step 4, the rights management system querying whether the user has internal rights based on the database; if so, adding a record to the cached three-level rights mapping table; if not, jumping to step 5; step 5, the rights management system querying whether the user has external rights based on the database; if not, returning no access rights; if so, adding a record to the cached three-level rights mapping table. The present invention is compatible with internal and external role authorization relationships, saves storage space, and improves system efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of power stations, and in particular to the technical field of data permissions of power stations. Background Art

[0002] Traditional data rights management designs often use organizations (such as WeChat groups or companies in OA systems) as the unit of data rights. However, in IoT platforms, devices often require sharing (i.e., A purchases a device and needs to grant B some permissions to add, delete, modify, and query). This creates challenges for data rights management and security in commercial and industrial power plants due to their high costs, numerous collaborating parties, and complex membership.

[0003] In view of this, this application is filed. Summary of the Invention

[0004] The present invention provides a data authority management method for a power station, comprising the following steps:

[0005] Step 1: Provide a rights management system; the rights management system includes a cache and a database; the cache stores a three-level rights mapping table; the database includes a user table, a power station table, a role table, an organization table, a function rights table, a data access rights table, a power station organization table, a user-organization association table, an organization-role association table, a role-function rights table, a role-data access rights table, and an authorization relationship table; the three-level rights mapping table is a three-level mapping of user ID-rights string identifier-merchant and power station ID; the three-level rights mapping table is formed based on the database;

[0006] Step 2: The user accesses the data resources of a power station;

[0007] Step 3: The authority management system queries whether the user has a record based on the cached three-level authority mapping table. If yes, the data resource requested for access is directly returned; if not, the process jumps to step 4.

[0008] Step 4: The authority management system queries the database to determine whether the user has internal authority; if so, a record is added to the cached three-level authority mapping table; if not, the process jumps to step 4;

[0009] Step 5: The authority management system queries the database to see whether the user has external authority. If not, it returns no access authority; if so, it adds a record to the cached three-level authority mapping table;

[0010] The data permissions include internal permissions and external permissions;

[0011] The internal permissions include data access permissions and functional permissions;

[0012] The external permissions include data access permissions and function permissions.

[0013] Furthermore, in step 4, the authority management system queries the database based on whether the user has internal authority, including:

[0014] Step 4.1, the authority management system queries whether the user has created the power station, and if so, adds a record to the cached three-level authority mapping table;

[0015] Step 4.2: The authority management system queries the database to see whether the merchant to which the user belongs has created the power station. If so, the process jumps to step 4.3; if not, the process jumps to step 5.

[0016] Step 4.3: The authority management system further queries the user's role in the merchant based on the database, and whether the role has the data access rights and the functional rights. If so, a record is added to the cached three-level authority mapping table; if not, jump to step 5.

[0017] Furthermore, in step 5, the authority management system queries the database based on whether the user has external authority, including:

[0018] In step 5.1, the authority management system queries the database to determine whether the user is granted the data access authority and the functional authority of the power station. If so, a record is added to the cached three-level authority mapping table; if not, the process jumps to step 5.2.

[0019] In step 5.2, the rights management system queries the user's merchant and whether the merchant is granted the data access permission and the function permission based on the database. If so, jump to step 5.3; if not, return to no access permission;

[0020] In step 5.3, the authority management system further queries the user's role under the authorized merchant based on the database and whether the role has the data access permission and the functional permission. If so, a record is added to the cached three-level authority mapping table; if not, no access permission is returned.

[0021] Furthermore, the authorization relationship table records the original authorizer and the final authorizer, and does not record the intermediate authorizer.

[0022] Furthermore, the role table includes an external role table and an internal role table.

[0023] Furthermore, the function permission table includes an external function permission table and an internal function permission table.

[0024] Furthermore, the data access permission table includes an external data access permission table and an internal data access permission table.

[0025] Furthermore, the role and function permission table includes an external role and external function permission table, and an internal role and internal function permission table.

[0026] Furthermore, the role and data access permission table includes an external role and external data function permission table, and an internal role and internal data access permission table.

[0027] Compared with the prior art, the present invention has the following beneficial effects:

[0028] (1) The present invention is based on RBAC (role-based authority control), which unbinds authority from login behavior and effectively improves the security of data resources.

[0029] (2) The present invention realizes fast query of user permissions through the three-level permission mapping table in the cache.

[0030] (3) The present invention designs the authorization relationship table based on the agent concept, that is, only the original authorizer and the final authorized party are recorded, while the intermediate agency process is ignored, which greatly reduces the problem of the authorization chain being too long and effectively saves storage space.

[0031] (4) The present invention is compatible with internal and external role authorization relationships, saving storage space and improving system efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0033] Figure 1 Schematic diagram of the process of the rights management system of this embodiment. DETAILED DESCRIPTION

[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0035] The rights management method of this embodiment is established on the basis of a management system, which includes a cache and a database. In the database, a user table, a power plant table, a role table, an organization table, a function permission table, a data access permission table, a power plant organization table, a user-organization association table, an organization-role association table, a role-function permission table, a role-data access permission table, and an authorization relationship table are established based on the principle of RBAC (role-based access control).

[0036] The cache includes a three-level permission mapping table; the three-level permission mapping table is a three-level mapping of user ID-permission string identifier-merchant and power station ID; the three-level permission mapping table is established based on various tables in the database.

[0037] Based on the above management system, the data authority management method of this embodiment is:

[0038] Figure 1 FIG. 1 shows a flow chart of the rights management system of this embodiment. Figure 1 As shown, the data rights management method implemented in this embodiment includes the following steps:

[0039] Step 1: Provide a rights management system; the rights management system includes a cache and a database; the cache stores a three-level rights mapping table; the database includes a user table, a power station table, a role table, an organization table, a function rights table, a data access rights table, a power station organization table, a user-organization association table, an organization-role association table, a role-function rights table, a role-data access rights table, and an authorization relationship table; the three-level rights mapping table is a three-level mapping of user ID-rights string identifier-merchant and power station ID; the three-level rights mapping table is formed based on the database;

[0040] Step 2: The user accesses the data resources of a power station;

[0041] Step 3: The authority management system queries whether the user has a record based on the cached three-level authority mapping table. If yes, the data resource requested for access is directly returned; if not, the process jumps to step 4.

[0042] Step 4: The authority management system queries the database to determine whether the user has internal authority; if so, a record is added to the cached three-level authority mapping table; if not, the process jumps to step 4;

[0043] Step 5: The authority management system queries the database to see whether the user has external authority. If not, it returns no access authority; if so, it adds a record to the cached three-level authority mapping table;

[0044] The data permissions include internal permissions and external permissions;

[0045] The internal permissions include data access permissions and functional permissions;

[0046] The external permissions include data access permissions and function permissions.

[0047] Optionally, in step 4, the rights management system queries the database based on whether the user has internal rights, including:

[0048] Step 4.1, the authority management system queries whether the user has created the power station, and if so, adds a record to the cached three-level authority mapping table;

[0049] Step 4.2: The authority management system queries the database to see whether the merchant to which the user belongs has created the power station. If so, the process jumps to step 4.3; if not, the process jumps to step 5.

[0050] Step 4.3: The authority management system further queries the user's role in the merchant based on the database, and whether the role has the data access rights and the functional rights. If so, a record is added to the cached three-level authority mapping table; if not, jump to step 5.

[0051] Optionally, in step 5, the rights management system queries the database based on whether the user has external rights, including:

[0052] In step 5.1, the authority management system queries the database to determine whether the user is granted the data access authority and the functional authority of the power station. If so, a record is added to the cached three-level authority mapping table; if not, the process jumps to step 5.2.

[0053] In step 5.2, the rights management system queries the user's merchant and whether the merchant is granted the data access permission and the function permission based on the database. If so, jump to step 5.3; if not, return to no access permission;

[0054] In step 5.3, the authority management system further queries the user's role under the authorized merchant based on the database and whether the role has the data access permission and the functional permission. If so, a record is added to the cached three-level authority mapping table; if not, no access permission is returned.

[0055] Optionally, the authorization relationship table records the original authorizer and the final authorizer, and does not record the intermediate authorizer.

[0056] Optionally, the role table includes an external role table and an internal role table.

[0057] Optionally, the function permission table includes an external function permission table and an internal function permission table

[0058] Optionally, the data access permission table includes an external data access permission table and an internal data access permission table.

[0059] Optionally, the role and function permission table includes an external role and external function permission table, and an internal role and internal function permission table.

[0060] Optionally, the role and data access permission table includes an external role and external data function permission table, and an internal role and internal data access permission table.

[0061] The terms "equal," "same," or "equal" disclosed in the present invention must take into account the distribution of engineering parameters, with an error distribution within ±30%; the definition of "parallel" between two line segments or two straight lines is that the angle between the two line segments or two straight lines is less than or equal to 45 degrees; the definition of "perpendicular" between two line segments or two straight lines is that the angle between the two line segments or two straight lines is within the range of [60, 120] degrees; the definition of "phase mismatch" also needs to take into account the distribution of engineering parameters, with an error distribution of the degree of mismatch within ±30%. In addition, in this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article, or apparatus. Without more constraints, an element defined by the phrase "comprises a..." does not exclude the existence of additional identical elements in the process, method, article or apparatus that comprises the element.

[0062] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0063] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data authority management method for a power station, characterized in that: The following steps are involved: Step 1: Provide a rights management system; the rights management system includes a cache and a database; the cache stores a three-level rights mapping table; the database includes a user table, a power station table, a role table, an organization table, a function rights table, a data access rights table, a power station organization table, a user-organization association table, an organization-role association table, a role-function rights table, a role-data access rights table, and an authorization relationship table; the three-level rights mapping table is a three-level mapping of user ID-rights string identifier-merchant and power station ID; the three-level rights mapping table is formed based on the database; Step 2: The user accesses the data resources of a power station; Step 3: The authority management system queries whether the user has a record based on the cached three-level authority mapping table. If yes, the data resource requested for access is directly returned; if not, the process jumps to step 4. Step 4: The authority management system queries the database to see if the user has internal authority; if so, a record is added to the cached three-level authority mapping table; if not, the process jumps to step 5; Step 5: The authority management system queries the database to see whether the user has external authority. If not, it returns "no access authority"; If so, adding a record to the cached three-level permission mapping table; Data permissions include internal permissions and external permissions; The internal permissions include data access permissions and functional permissions; The external permissions include data access permissions and function permissions.

2. The data rights management method according to claim 1, wherein: In step 4, the authority management system queries the database based on whether the user has internal authority, including: Step 4.1, the authority management system queries whether the user has created the power station, and if so, adds a record to the cached three-level authority mapping table; Step 4.2: The authority management system queries the database to see whether the merchant to which the user belongs has created the power station. If so, the process jumps to step 4.3; if not, the process jumps to step 5. Step 4.3: The authority management system further queries the user's role in the merchant based on the database, and whether the role has the data access rights and the functional rights. If so, a record is added to the cached three-level authority mapping table; if not, jump to step 5.

3. The data rights management method according to claim 1, wherein: In step 5, the authority management system queries the database based on whether the user has external authority, including: Step 5.1: The authority management system queries the database to determine whether the user is granted the data access authority and the functional authority of the power station. If so, a record is added to the cached three-level authority mapping table; if not, the process proceeds to step 5.

2. In step 5.2, the rights management system queries the user's merchant and whether the merchant is granted the data access permission and the function permission based on the database. If so, jump to step 5.3; if not, return to no access permission; In step 5.3, the authority management system further queries the user's role under the authorized merchant based on the database and whether the role has the data access permission and the functional permission. If so, a record is added to the cached three-level authority mapping table; if not, no access permission is returned.

4. The data rights management method according to claim 1, wherein: The authorization relationship table records the original authorizer and the final authorizer, and does not record the intermediate authorizer.

5. The data rights management method according to claim 1, wherein: The role table includes an external role table and an internal role table.

6. The data rights management method according to claim 1, wherein: The function permission table includes an external function permission table and an internal function permission table.

7. The data rights management method according to claim 1, wherein: The data access permission table includes an external data access permission table and an internal data access permission table.

8. The data rights management method according to claim 1, wherein: The role and function permission table includes an external role and external function permission table, and an internal role and internal function permission table.

9. The data rights management method according to claim 1, wherein: The role and data access permission table includes an external role and external data access permission table, and an internal role and internal data access permission table.

Citation Information

Patent Citations

  • User authority management method and device based on cache

    CN106776706A

  • User authorization management system and method

    CN107506658A