Method, device, electronic device and readable storage medium for changing control of permissions

By granting and revoking change permissions within a specified time period, the problem of changing permissions in technology products has been solved, thus improving security.

CN119513855BActive Publication Date: 2025-11-11CHINA LIFE INSURANCE CO LTD SHANGHAI DATA CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411516281.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-29
Publication Date
2025-11-11
Estimated Expiration
2044-10-29

AI Technical Summary

Technical Problem

In existing technologies, the permission to modify technological products usually remains indefinitely, making it difficult to guarantee security.

Method used

By determining the access control information and role configuration information of the product to be changed, receiving change plan and operation time authorization information, granting change permissions to operators only within the specified time period, and revoking permissions at the end time or when the change result changes.

Benefits of technology

It enables precise control over changing operation permissions, thereby improving the security of technological products.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119513855B_ABST
    Figure CN119513855B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, electronic device, and readable storage medium for controlling change permissions. The method includes: determining the product to be changed; querying the permission control information and role configuration information of the product to be changed; receiving a change plan and operation time authorization information for the product to be changed input by an administrator; for each target operator, determining the target change start time and target change end time of the target operator from the operation time authorization information, determining the target role of the target operator from the role configuration information, and determining the target change operation permission of the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time. This method achieves precise control over change operation permissions, thereby improving the security of the product to be changed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and readable storage medium for controlling changes in permissions. Background Technology

[0002] For modern technology products, each product typically contains multiple services that run on servers. During the maintenance and operation of these products, when one or more of these services need to be changed, the staff responsible for the product must perform the necessary changes on the server.

[0003] Considering the security issues of technology products, currently only personnel with modification permissions can typically make changes to the business operations of a technology product on the server. However, in existing technologies, this modification permission usually remains indefinitely, meaning that the personnel can arbitrarily change the business operations of the technology product at any time, which can easily compromise the security of the technology product. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a method, device, electronic device and readable storage medium for controlling the change of permissions, so as to achieve precise control over the change of operation permissions and thereby improve the security of the product to be changed.

[0005] In a first aspect, embodiments of this application provide a method for controlling changes in permissions, including:

[0006] Identify the product to be changed, and based on the product to be changed, query the corresponding access control information and role configuration information; wherein, the access control information includes the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed;

[0007] The system receives change plans and operation time authorization information for the product to be changed from the management personnel; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators.

[0008] For each target operator, the target change start time and target change end time of the target operator are determined from the operation time authorization information, the target role of the target operator is determined from the role configuration information, and the target change operation permission of the target role is determined from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0009] In conjunction with the first aspect, this application provides a first possible implementation of the first aspect, wherein, after granting the target operator the target change operation permission, the method further includes:

[0010] If the current time exceeds the target change end time for the target operator, the target change operation permission granted to the target operator will be revoked.

[0011] In conjunction with the first aspect, this application provides a second possible implementation of the first aspect, wherein, after granting the target operator the target change operation permission, the method further includes:

[0012] When the target operator receives any of the following change results, the target change operation permission granted to the target operator is revoked; the change results include: change successful, change failed, change cancelled, and change time modified.

[0013] In conjunction with the second possible implementation of the first aspect, this application provides a third possible implementation of the first aspect, wherein the step of determining the product to be changed, and querying the access control information and role configuration information corresponding to the product to be changed, includes:

[0014] Create a change process instance; wherein, the process nodes contained in the change process instance are in the following order: start node, plan node, approval node, implementation node, verification node, and end node;

[0015] In the planning node, the product to be changed is determined from multiple products, and the permission control information and role configuration information corresponding to the product to be changed are queried based on the product to be changed.

[0016] The information received from the administrator regarding the change plan and operation time authorization for the product to be changed includes:

[0017] In the planning node, the change plan and operation time authorization information for the product to be changed are received by the administrator.

[0018] In conjunction with the third possible implementation of the first aspect, this application provides a fourth possible implementation of the first aspect, wherein, for each target operator, determining the target change start time and target change end time of the target operator from the operation time authorization information, determining the target role of the target operator from the role configuration information, and determining the target change operation permission of the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time, includes:

[0019] In the approval node, the approval result for the change plan and the operation time authorization information input by the approver is received. When the approval result is approved, the change plan, the operation time authorization information, the access control information, and the role configuration information are sent to the access control system. This allows the access control system to determine the target change start time and target change end time for each target operator from the operation time authorization information, determine the target role for the target operator from the role configuration information, and determine the target change operation permission for the target role from the access control information. In this way, the target change operation permission is granted to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0020] In conjunction with the third possible implementation of the first aspect, this application provides a fifth possible implementation of the first aspect, wherein, when any of the following change results are received from the target operator, the target change operation permission granted to the target operator is revoked, including:

[0021] In the implementation node, the change result input by the target operator is received; when the received change result is a change failure, cancellation of change, or modification of change time, the change result is sent to the access control system so that the access control system revokes the target change operation permission granted to the target operator; when the received change result is a change success, the change result is sent to the verification node.

[0022] In the verification node, the verification result input by the verifier is received. When the verification result is successful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a first prompt message indicating successful change to the administrator's user terminal. When the verification result is unsuccessful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a second prompt message indicating unsuccessful change to the administrator's user terminal.

[0023] In conjunction with the fifth possible implementation of the first aspect, this application provides a sixth possible implementation of the first aspect, wherein the product to be changed includes multiple services. When the target operator's target change operation permission is to change the target service in the product to be changed, the verifier logs into the target service system running the target service to determine whether the target service has been successfully changed. When the target service is successfully changed, the verification result entered by the verifier is "verification passed"; when the target service change fails, the verification result entered by the verifier is "verification failed".

[0024] Secondly, embodiments of this application also provide a control device for changing permissions, including:

[0025] The determination module is used to determine the product to be changed, and to query the access control information and role configuration information corresponding to the product to be changed based on the product to be changed; wherein, the access control information includes the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed;

[0026] The receiving module is used to receive the change plan and operation time authorization information for the product to be changed input by the management personnel; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators;

[0027] The authorization module is used to determine the target change start time and target change end time of each target operator from the operation time authorization information, determine the target role of the target operator from the role configuration information, and determine the target change operation permission of the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0028] In conjunction with the second aspect, embodiments of this application provide a first possible implementation of the second aspect, wherein the apparatus further includes:

[0029] The first revocation module is used to revoke the target change operation permission granted to the target operator after the authorization module has granted the target operator the target change operation permission, if the current time exceeds the target change end time of the target operator.

[0030] In conjunction with the second aspect, this application provides a second possible implementation of the second aspect, wherein the apparatus further includes:

[0031] The second revocation module is used to revoke the target change operation permission granted to the target operator after the authorization module grants the target operator the target change operation permission, when it receives any of the following change results input by the target operator: change successful, change failed, change cancelled, and change time modified.

[0032] In conjunction with the second possible implementation of the second aspect, this application provides a third possible implementation of the second aspect, wherein the determining module, when used to determine the product to be changed and, based on the product to be changed, queries the permission control information and role configuration information corresponding to the product to be changed, is specifically used for:

[0033] Create a change process instance; wherein, the process nodes contained in the change process instance are in the following order: start node, plan node, approval node, implementation node, verification node, and end node;

[0034] In the planning node, the product to be changed is determined from multiple products, and the permission control information and role configuration information corresponding to the product to be changed are queried based on the product to be changed.

[0035] When receiving change plans and operation time authorization information for the product to be changed, input by the administrator, the receiving module is specifically used for:

[0036] In the planning node, the change plan and operation time authorization information for the product to be changed are received by the administrator.

[0037] In conjunction with the third possible implementation of the second aspect, this application provides a fourth possible implementation of the second aspect, wherein the authorization module, when determining the target change start time and target change end time of each target operator from the operation time authorization information, determining the target role of the target operator from the role configuration information, and determining the target change operation permission of the target role from the permission control information, and granting the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time, is specifically used for:

[0038] In the approval node, the approval result for the change plan and the operation time authorization information input by the approver is received. When the approval result is approved, the change plan, the operation time authorization information, the access control information, and the role configuration information are sent to the access control system. This allows the access control system to determine the target change start time and target change end time for each target operator from the operation time authorization information, determine the target role for the target operator from the role configuration information, and determine the target change operation permission for the target role from the access control information. In this way, the target change operation permission is granted to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0039] In conjunction with the fourth possible implementation of the second aspect, this application provides a fifth possible implementation of the second aspect, wherein the second revocation module, when used to revoke the target change operation permission granted to the target operator upon receiving any of the following change results input by the target operator, is specifically used for:

[0040] In the implementation node, the change result input by the target operator is received; when the received change result is a change failure, cancellation of change, or modification of change time, the change result is sent to the access control system so that the access control system revokes the target change operation permission granted to the target operator; when the received change result is a change success, the change result is sent to the verification node.

[0041] In the verification node, the verification result input by the verifier is received. When the verification result is successful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a first prompt message indicating successful change to the administrator's user terminal. When the verification result is unsuccessful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a second prompt message indicating unsuccessful change to the administrator's user terminal.

[0042] In conjunction with the fifth possible implementation of the second aspect, this application provides a sixth possible implementation of the second aspect, wherein the product to be changed includes multiple services. When the target operator's target change operation permission is to change the target service in the product to be changed, the verifier logs into the target service system running the target service to determine whether the target service has been successfully changed. When the target service is successfully changed, the verification result entered by the verifier is "verification passed"; when the target service change fails, the verification result entered by the verifier is "verification failed".

[0043] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the memory via the bus, and when the machine-readable instructions are executed by the processor, the steps in any of the possible implementations of the first aspect described above are performed.

[0044] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps in any of the possible implementations of the first aspect described above.

[0045] This application provides a method, apparatus, electronic device, and readable storage medium for controlling change permissions. In this method, after identifying the product to be changed, the method directly queries the permission control information and role configuration information corresponding to the product, and receives the change plan and operation time authorization information for the product from the administrator. The permission control information includes the change operation permissions of each role under the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed; and the operation time authorization information includes the change start time and change end time configured for each target operator. When granting change operation permissions to each target operator, specifically for each target operator, the target change start time and target change end time are determined from the operation time authorization information, the target role is determined from the role configuration information, and the target change operation permissions for the target role are determined from the permission control information. The target change operation permissions are then granted to the target operator within the target time period corresponding to the target change start time to the target change end time. In this way, each target operator can only have target change operation permissions within the target time period specified for them. That is, the target operator is only allowed to make changes to the product to be changed within their corresponding target time period, thereby achieving precise control over change operation permissions and improving the security of the product to be changed.

[0046] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0047] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 A flowchart of a method for controlling changes in permissions provided in an embodiment of this application is shown;

[0049] Figure 2 This illustration shows a schematic diagram of an access control information provided in an embodiment of this application;

[0050] Figure 3 This illustration shows a schematic diagram of role configuration information provided in an embodiment of this application;

[0051] Figure 4A schematic diagram illustrating an example of a change process provided in an embodiment of this application is shown;

[0052] Figure 5 This illustration shows a schematic diagram of an operation time authorization information provided in an embodiment of this application;

[0053] Figure 6 This illustration shows a schematic diagram of a control device for changing permissions provided in an embodiment of this application;

[0054] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0056] Considering the security issues of technology products, currently, only personnel with modification permissions can typically make changes to the business operations of a technology product on a server. However, in existing technologies, this modification permission usually remains indefinitely, meaning that the personnel can arbitrarily modify the business operations of the technology product at any time, which can easily compromise the security of the technology product. Based on this, embodiments of this application provide a method, apparatus, electronic device, and readable storage medium for controlling modification permissions, to achieve precise control over modification operation permissions, thereby improving the security of the product to be modified. The following is a description through embodiments.

[0057] To facilitate understanding of this embodiment, a method for controlling permission changes disclosed in this application will first be described in detail. This method is applied to a process engine system, such as... Figure 1 As shown, the method includes the following steps S101-S103:

[0058] S101: Determine the product to be changed, and query the corresponding access control information and role configuration information based on the product to be changed; wherein, the access control information contains the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information contains the operators configured for each role under the product to be changed.

[0059] In this embodiment, each technology product typically contains multiple services, and the product to be changed refers to a technology product for which at least one service needs to be modified. Each technology product (or each product to be changed) corresponds to its own access control information and role configuration information.

[0060] For example, such as Figure 2 The example shown illustrates the access control information for a product to be changed. In this example, different roles under the product to be changed have different permissions for changing operations.

[0061] like Figure 3 The image shows an example of role configuration information for a product to be changed. In this example, each role under the product to be changed corresponds to its respective operator.

[0062] In one possible implementation, when performing step S101, the following steps S1011-S1012 can be specifically performed:

[0063] S1011: Create a change process instance; wherein, the process nodes contained in the change process instance are in the following order: start node, plan node, approval node, implementation node, verification node and end node.

[0064] In this embodiment, the process engine system responds to the administrator's operation of creating a change process instance for the product to be changed, and creates a change process instance, such as... Figure 4 As shown, the process nodes in the change process example are arranged in the following order: start node, planning node, approval node, implementation node, verification node, and end node.

[0065] S1012: In the planning node, identify the product to be changed from multiple products, and query the corresponding access control information and role configuration information for the product to be changed.

[0066] In this embodiment, at the planning node, the process engine system responds to the manager's selection operation for the product to be changed from multiple products to determine the product to be changed from multiple products.

[0067] S102: Receive the change plan and operation time authorization information for the product to be changed from the management personnel; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators.

[0068] In this embodiment, the change plan includes information such as the details of the changes to the product to be changed and the timing of the changes. For example... Figure 5 As shown, an example of operation time authorization information is presented. The target operator is the operator needed when making changes to the product to be changed.

[0069] In one possible implementation, when performing step S102, the following steps may be performed: In the planning node, receive the change plan and operation time authorization information for the product to be changed input by the administrator.

[0070] S103: For each target operator, determine the target change start time and target change end time from the operation time authorization information, determine the target role of the target operator from the role configuration information, and determine the target change operation permission of the target role from the access control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0071] In this embodiment, at the approval node, the approval result for the change plan and operation time authorization information input by the approver is received. When the approval result is approved, the change plan, operation time authorization information, access control information, and role configuration information are sent to the access control system. This allows the access control system to determine the target change start time and target change end time for each target operator from the operation time authorization information, determine the target role for the target operator from the role configuration information, and determine the target change operation permission for the target role from the access control information. In this way, the target change operation permission is granted to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0072] In one possible implementation, after granting the target operator the target change operation permission, the following steps may also be performed:

[0073] If the current time exceeds the target change end time for the target operator, the target change operation permission granted to the target operator will be revoked.

[0074] When the target operator receives any of the following change results, the target change operation permission granted to the target operator will be revoked; the change results include: change successful, change failed, change cancelled, and change time modified.

[0075] In one possible implementation, such as Figure 4 As shown, when the execution step receives any of the following change results input by the target operator, the target change operation permission granted to the target operator is revoked. Specifically, the following steps can be followed:

[0076] In the implementation node, the change result input by the target operator is received; when the received change result is that the change failed, the change was canceled, or the change time was modified, the change result is sent to the access control system so that the access control system can revoke the target change operation permission granted to the target operator; when the received change result is that the change was successful, the change result is sent to the verification node.

[0077] In the verification node, the verification result input by the verifier is received. When the verification result is successful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a first prompt message to the administrator's user terminal to indicate that the change was successful. When the verification result is unsuccessful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a second prompt message to the administrator's user terminal to indicate that the change failed.

[0078] The product to be changed contains multiple services. When the target operator's target change operation permission is to change the target service in the product to be changed, the verifier logs into the target service system running the target service to determine whether the target service has been changed successfully. When the target service is changed successfully, the verification result entered by the verifier is "verification passed". When the target service is changed unsuccessfully, the verification result entered by the verifier is "verification failed".

[0079] Based on the same technical concept, embodiments of this application also provide a control device for changing permissions, such as... Figure 6 As shown, the device includes:

[0080] The determination module 601 is used to determine the product to be changed, and to query the permission control information and role configuration information corresponding to the product to be changed based on the product to be changed; wherein, the permission control information includes the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed.

[0081] The receiving module 602 is used to receive the change plan and operation time authorization information for the product to be changed input by the manager; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators;

[0082] The authorization module 603 is used to determine, for each target operator, the target change start time and target change end time of the target operator from the operation time authorization information, the target role of the target operator from the role configuration information, and the target change operation permission of the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0083] Optionally, the device further includes:

[0084] The first revocation module is used to revoke the target change operation permission granted to the target operator after the authorization module 603 has granted the target operator the target change operation permission, if the current time exceeds the target change end time of the target operator.

[0085] Optionally, the device further includes:

[0086] The second revocation module is used to revoke the target change operation permission granted to the target operator after the authorization module 603 grants the target operator the target change operation permission, when it receives any of the following change results input by the target operator: change successful, change failed, change cancelled, and change time modified.

[0087] Optionally, when the determining module 601 is used to determine the product to be changed, and to query the access control information and role configuration information corresponding to the product to be changed, it is specifically used for:

[0088] Create a change process instance; wherein, the process nodes contained in the change process instance are in the following order: start node, plan node, approval node, implementation node, verification node, and end node;

[0089] In the planning node, the product to be changed is determined from multiple products, and the permission control information and role configuration information corresponding to the product to be changed are queried based on the product to be changed.

[0090] When receiving the change plan and operation time authorization information for the product to be changed, input by the administrator, the receiving module 602 is specifically used for:

[0091] In the planning node, the change plan and operation time authorization information for the product to be changed are received by the administrator.

[0092] Optionally, when the authorization module 603 determines the target change start time and target change end time for each target operator from the operation time authorization information, determines the target role for the target operator from the role configuration information, and determines the target change operation permission for the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time, it is specifically used for:

[0093] In the approval node, the approval result for the change plan and the operation time authorization information input by the approver is received. When the approval result is approved, the change plan, the operation time authorization information, the access control information, and the role configuration information are sent to the access control system. This allows the access control system to determine the target change start time and target change end time for each target operator from the operation time authorization information, determine the target role for the target operator from the role configuration information, and determine the target change operation permission for the target role from the access control information. In this way, the target change operation permission is granted to the target operator within the target time period corresponding to the target change start time to the target change end time.

[0094] Optionally, when the second revocation module revokes the target change operation permission granted to the target operator upon receiving any of the following change results input by the target operator, it is specifically used for:

[0095] In the implementation node, the change result input by the target operator is received; when the received change result is a change failure, cancellation of change, or modification of change time, the change result is sent to the access control system so that the access control system revokes the target change operation permission granted to the target operator; when the received change result is a change success, the change result is sent to the verification node.

[0096] In the verification node, the verification result input by the verifier is received. When the verification result is successful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a first prompt message indicating successful change to the administrator's user terminal. When the verification result is unsuccessful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a second prompt message indicating unsuccessful change to the administrator's user terminal.

[0097] Optionally, the product to be changed includes multiple services. When the target operator's target change operation permission is to change the target service in the product to be changed, the verifier logs into the target service system running the target service to determine whether the target service has been changed successfully. When the target service is changed successfully, the verification result entered by the verifier is "verification passed". When the target service is changed unsuccessfully, the verification result entered by the verifier is "verification failed".

[0098] Figure 7 A schematic diagram of an electronic device provided in this application embodiment includes: a processor 701, a memory 702, and a bus 703. The memory 702 stores machine-readable instructions executable by the processor 701. When the electronic device runs the above-described information processing method, the processor 701 and the memory 702 communicate through the bus 703. The processor 701 executes the machine-readable instructions to perform the steps of the method described in Embodiment 1.

[0099] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps described in Embodiment 1.

[0100] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, electronic devices, and computer-readable storage media described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0101] In the several embodiments provided in this application, it should be understood that the disclosed methods, apparatuses, electronic devices, and computer-readable storage media can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or modules may be electrical, mechanical, or other forms.

[0102] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0103] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0104] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0105] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of protection of the claims.

Claims

1. A method for controlling changes in permissions, characterized in that, include: Identify the product to be changed, and based on the product to be changed, query the corresponding access control information and role configuration information; wherein, the access control information includes the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed; The system receives change plans and operation time authorization information for the product to be changed from the management personnel; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators. For each target operator, the target change start time and target change end time of the target operator are determined from the operation time authorization information, the target role of the target operator is determined from the role configuration information, and the target change operation permission of the target role is determined from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

2. The method according to claim 1, characterized in that, After granting the target operator the target change operation permission, the method further includes: If the current time exceeds the target change end time for the target operator, the target change operation permission granted to the target operator will be revoked.

3. The method according to claim 1, characterized in that, After granting the target operator the target change operation permission, the method further includes: When the target operator receives any of the following change results, the target change operation permission granted to the target operator is revoked; the change results include: change successful, change failed, change cancelled, and change time modified.

4. The method according to claim 3, characterized in that, The process of determining the product to be changed, and querying the corresponding access control information and role configuration information based on the product to be changed, includes: Create a change process instance; wherein, the process nodes contained in the change process instance are in the following order: start node, plan node, approval node, implementation node, verification node, and end node; In the planning node, the product to be changed is determined from multiple products, and the permission control information and role configuration information corresponding to the product to be changed are queried based on the product to be changed. The information received from the administrator regarding the change plan and operation time authorization for the product to be changed includes: In the planning node, the change plan and operation time authorization information for the product to be changed are received by the administrator.

5. The method according to claim 4, characterized in that, For each target operator, the following steps are taken: determining the target change start time and target change end time from the operation time authorization information; determining the target role from the role configuration information; and determining the target change operation permission for the target role from the permission control information. This is to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time, including: In the approval node, the approval result for the change plan and the operation time authorization information input by the approver is received. When the approval result is approved, the change plan, the operation time authorization information, the access control information, and the role configuration information are sent to the access control system. This allows the access control system to determine the target change start time and target change end time for each target operator from the operation time authorization information, determine the target role for the target operator from the role configuration information, and determine the target change operation permission for the target role from the access control information. In this way, the target change operation permission is granted to the target operator within the target time period corresponding to the target change start time to the target change end time.

6. The method according to claim 4, characterized in that, When the target operator receives any of the following change results, the target change operation permission granted to the target operator is revoked, including: In the implementation node, the change result input by the target operator is received; when the received change result is a change failure, cancellation of change, or modification of change time, the change result is sent to the access control system so that the access control system revokes the target change operation permission granted to the target operator; when the received change result is a change success, the change result is sent to the verification node. In the verification node, the verification result input by the verifier is received. When the verification result is successful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a first prompt message indicating successful change to the administrator's user terminal. When the verification result is unsuccessful, the verification result is sent to the access control system, so that the access control system revokes the target change operation permission granted to the target operator and sends a second prompt message indicating unsuccessful change to the administrator's user terminal.

7. The method according to claim 6, characterized in that, The product to be changed contains multiple services. When the target operator's target change operation permission is to change the target service in the product to be changed, the verifier logs into the target service system running the target service to determine whether the target service has been changed successfully. When the target service is changed successfully, the verification result entered by the verifier is "verification passed". When the target service is changed unsuccessfully, the verification result entered by the verifier is "verification failed".

8. A control device for changing permissions, characterized in that, include: The determination module is used to determine the product to be changed, and to query the access control information and role configuration information corresponding to the product to be changed based on the product to be changed; wherein, the access control information includes the change operation permissions of each role under the product to be changed for the product to be changed; the role configuration information includes the operators configured for each role under the product to be changed; The receiving module is used to receive the change plan and operation time authorization information for the product to be changed input by the management personnel; the operation time authorization information includes the change start time and change end time configured for each target operator among the operators; The authorization module is used to determine the target change start time and target change end time of each target operator from the operation time authorization information, determine the target role of the target operator from the role configuration information, and determine the target change operation permission of the target role from the permission control information, so as to grant the target change operation permission to the target operator within the target time period corresponding to the target change start time to the target change end time.

9. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is in operation, the processor communicates with the memory via the bus, and the machine-readable instructions, when executed by the processor, perform the steps of the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Authority management method and device, electronic equipment and readable storage medium

    CN115189932A

  • Full-process permission operation and maintenance management and control method, equipment and medium

    CN116644477A