A permission dynamic management method and device, an electronic device, and a medium

By configuring user and product information tables and combining them with permission query commands to obtain and visualize the target permission view, the complexity of permission management in enterprises is solved, and the accuracy and security of permission management are achieved.

CN119622780BActive Publication Date: 2025-11-11CHINA LIFE INSURANCE CO LTD SHANGHAI DATA CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411791694.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-11-11
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

As the number of enterprise users and information products grows, access control becomes complex and difficult to control accurately. Users have different permissions in different information products, requiring a reliable system to clarify the correspondence between user and product permissions.

Method used

Configure user permission information tables and product information tables, combine user identifiers, product identifiers and role information to determine target permission information under the product dimension, and obtain and visualize the target permission view through permission query commands to realize dynamic management of permissions and anomaly verification.

Benefits of technology

It improves the accuracy and real-time performance of access control, enabling timely identification and handling of access anomalies, achieving closed-loop access control, and ensuring the rationality and security of access allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622780B_ABST
    Figure CN119622780B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, electronic device, and medium for dynamic permission management. The method configures a user permission information table; configures a product information table; processes the user permission information table and the product information table, combining the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information for each user regarding the product at the product dimension; responds to a received permission query instruction, and obtains the target permission information matching the query conditions based on the query conditions in the permission query instruction; performs visualization processing on the target permission information matching the query conditions to generate a target permission view corresponding to the permission query instruction, and displays the target permission view; thereby improving the accuracy of permission management based on a "role-product-resource" corresponding permission management method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more specifically, to a method, apparatus, electronic device, and medium for dynamic permission management. Background Technology

[0002] With the continuous development of science and technology, all industries are gradually moving towards informatization, and the popularization of informatization has correspondingly led to the growth of information products. Enterprises possess a large number of information products, as well as a large number of users and resources. Different users have different job responsibilities and operational behaviors within these information products, requiring different types and levels of product permissions.

[0003] As the number of users and information products within an enterprise continues to grow, the difficulty of access control also increases. The same user may have different permissions across multiple different information products; the same product may grant different permissions to different users when it is made available to them; the relationship between users and information products is complex, diverse, and intertwined, requiring a reliable control system to clarify the correspondence between user and product permissions. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a method, apparatus, electronic device and medium for dynamic access control, which can improve the accuracy of access control.

[0005] This application provides a method for dynamic permission management, including the following steps:

[0006] Configure a user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information;

[0007] Configure a product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes user identifiers of at least one user;

[0008] Process the user permission information table and product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension;

[0009] Upon receiving a permission query instruction, the system retrieves the target permission information that matches the query conditions based on the query conditions in the permission query instruction.

[0010] The target permission information matching the query conditions is visualized to generate a target permission view corresponding to the permission query command, and the target permission view is displayed.

[0011] In some embodiments, the dynamic permission management method described above includes database permission information, host permission information, and firewall permission information.

[0012] Upon receiving a permission query instruction, the system retrieves target permission information matching the query conditions based on the query conditions in the instruction, including:

[0013] In response to a permission query instruction for permission information of a target type, the target permission information of the target type that matches the query conditions in the permission query instruction is obtained.

[0014] In some embodiments, the dynamic permission management method further includes:

[0015] Configure exception verification rules based on abnormal permission conditions; the abnormal permission conditions include: the user has permissions unrelated to the product, the user has permissions that do not match the role, and there are unassigned resources under the product;

[0016] Based on the anomaly verification rules, determine whether there is any anomaly information in the target permission information that conforms to the anomaly verification rules;

[0017] Based on the abnormal information, determine the permission status of the user permission information table;

[0018] When visualizing the target permission information that matches the query conditions, an exception identifier is generated for the exception information, and a target permission view corresponding to the permission query instruction is generated. The target permission view includes the exception identifier for the exception information.

[0019] In some embodiments, the dynamic permission management method further includes: generating a permission modification work order for abnormal information that conforms to the abnormality verification rules;

[0020] Based on the permission modification work order, modify the user permission information table and / or product information table.

[0021] In some embodiments, the dynamic permission management method, wherein configuring the user permission information table includes:

[0022] Obtain each type of permission information from the business system associated with each type of permission information;

[0023] Configure a user permission information table based on each type of permission information obtained.

[0024] In some embodiments, the dynamic permission management method further includes: generating a permission management work order in response to a user's permission management operation;

[0025] In response to the permission management work order, update the user permission information table.

[0026] In some embodiments, the dynamic permission management method further includes: configuring a backup user permission information table and a backup product information table for the user permission information table and the product information table, respectively;

[0027] Configure a preset management timing strategy; the preset management timing strategy includes alternating first preset time periods and second preset time periods;

[0028] Permission management is performed based on the user permission information table and product information table during the first preset time period, and the backup user permission information table and backup product information table are synchronized.

[0029] During the second preset time period, permission management is performed based on the backup user permission information table and the backup product information table, and the user permission information table and the product information table are synchronized.

[0030] In some embodiments, a dynamic permission management device is also provided, the device comprising:

[0031] The first configuration module is used to configure the user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information.

[0032] The second configuration module is used to configure the product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes the user identifier of at least one user.

[0033] The processing module is used to process the user permission information table and the product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension.

[0034] The acquisition module is used to respond to a received permission query instruction and, based on the query conditions in the permission query instruction, acquire the target permission information that matches the query conditions;

[0035] The generation module is used to perform visualization processing on the target permission information that matches the query conditions, generate a target permission view corresponding to the permission query instruction, and display the target permission view.

[0036] In some embodiments, an electronic device is also provided, the electronic device including: a processor, a memory and a bus, the memory storing machine-readable instructions executable by the processor, the processor communicating with the memory via the bus when the electronic device is running, and the steps of the dynamic permission management method being executed by the processor when the machine-readable instructions are executed.

[0037] In some embodiments, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, performs the steps of the aforementioned dynamic permission management method.

[0038] This application provides a method, apparatus, electronic device, and medium for dynamic permission management. The method configures a user permission information table; the user permission information table includes a user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user role includes multiple types of permission information; configures a product information table; the product information table includes a product identifier, product type, product role personnel information, and different types of resource information; the product role personnel information includes at least one user's user identifier; processes the user permission information table and the product information table, combining the user identifier and product identifier in the user permission information table and the product identifier and product information table. Product role personnel information is used to determine the target permission information for each user under the product dimension; upon receiving a permission query instruction, the target permission information matching the query conditions is obtained based on the query conditions in the permission query instruction; the target permission information matching the query conditions is visualized to generate a target permission view corresponding to the permission query instruction, and the target permission view is displayed; thereby determining the permission measurement standard and allocating the permission scope according to different product roles, linking user permissions with products, and realizing a logical closed loop of permission control under the product containing role information and resource information, improving the accuracy of permission management based on the management method of "role-product-resource" corresponding to related permissions. Attached Figure Description

[0039] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 A flowchart of the dynamic permission management method described in an embodiment of this application is shown;

[0041] Figure 2 A schematic diagram of the structure of the permission dynamic management system described in an embodiment of this application is shown;

[0042] Figure 3 A flowchart of the dynamic permission management method described in an embodiment of this application is shown;

[0043] Figure 4 A flowchart of the method for automatically authorizing user permissions according to an embodiment of this application is shown;

[0044] Figure 5 A flowchart illustrating multi-table data synchronization in an embodiment of this application is shown;

[0045] Figure 6 A schematic diagram of the structure of the permission dynamic management device described in an embodiment of this application is shown;

[0046] Figure 7 A schematic diagram of the structure of the electronic device described in an embodiment of this application is shown. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0048] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0049] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0050] With the continuous development of science and technology, all industries are gradually moving towards informatization, and the popularization of informatization has correspondingly led to the growth of information products. Enterprises possess a large number of information products, as well as a large number of users and resources. Different users have different job responsibilities and operational behaviors within these information products, requiring different types and levels of product permissions.

[0051] As the number of users and information products within an enterprise continues to grow, the difficulty of access control also increases. The same user may have different permissions across multiple different information products; the same product may grant different permissions to different users when it is made available to them; the relationship between users and information products is complex, diverse, and intertwined, requiring a reliable control system to clarify the correspondence between user and product permissions.

[0052] Based on this, embodiments of this application provide a method, device, electronic device, and medium for dynamic permission management. The method configures a user permission information table; the user permission information table includes a user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user role includes multiple types of permission information; configures a product information table; the product information table includes a product identifier, product type, product role personnel information, and different types of resource information; the product role personnel information includes at least one user identifier; processes the user permission information table and the product information table, combining the user identifier, product identifier, and product identifier from the user permission information table and the product identifier from the product information table. The system identifies and assigns target permissions to each user for the product based on their product role and user information. Upon receiving a permission query command, it retrieves the target permission information matching the query conditions. The system then visualizes the target permission information matching the query conditions, generating and displaying a target permission view corresponding to the query command. This allows the system to determine permission standards and allocate permission ranges based on different product roles, linking user permissions to products. Since products contain role information and resource information, this creates a logical closed loop for permission control. Based on a "role-product-resource" approach to corresponding permissions, the system improves the accuracy of permission management.

[0053] Please refer to Figure 1 , Figure 1 A flowchart of the dynamic permission management method described in an embodiment of this application is shown; as follows: Figure 1As shown, the dynamic permission management method includes the following steps S101-S105:

[0054] S101. Configure the user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information.

[0055] S102. Configure the product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes the user identifier of at least one user.

[0056] S103. Process the user permission information table and the product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension.

[0057] S104. Upon receiving a permission query instruction, obtain the target permission information that matches the query conditions based on the query conditions in the permission query instruction;

[0058] S105. Visualize the target permission information that matches the query conditions, generate a target permission view corresponding to the permission query instruction, and display the target permission view.

[0059] Please refer to Figure 2 The dynamic permission management method is applied to the dynamic permission management system 200, which includes a database permission management module 201, a production host permission management module 202, and a firewall permission management module 203, for managing and displaying different types of permission information.

[0060] In step S101, a user permission information table is configured; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information.

[0061] Here, the various types of permission information include database permission information, host permission information, and firewall permission information.

[0062] The database permission information, host permission information, and firewall permission information correspond to the dynamic management system, which includes a database permission management module, a production host permission management module, and a firewall permission management module. Based on the database permission management module, the production host permission management module, and the firewall permission management module, the corresponding types of permission information can be added, deleted, modified, and queried.

[0063] In other words, in response to the permission query instruction received in S104, and based on the query conditions in the permission query instruction, the target permission information matching the query conditions is obtained, including: in response to the permission query instruction for permission information of a target type, based on the query conditions for permission information of a target type in the permission query instruction, the target permission information of the target type matching the query conditions is obtained.

[0064] The user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information.

[0065] The user identifier includes user name, employee number, ID, etc.; the user identifier is an identifier used to uniquely identify each user in the system.

[0066] The user roles define a user's identity and responsibilities in the system. Different roles have different permission levels and permission grades. The user roles include individuals, responsible persons, product managers, etc.

[0067] The permission information refers to the permission scope corresponding to the user role.

[0068] In some embodiments, the permission information includes: database permissions: permissions to access, modify, and delete data in the database; production host permissions: permissions to perform specific operations on the production host (such as starting or stopping services, accessing specific files, etc.); firewall permissions: permissions to configure firewall rules, view firewall logs, etc.

[0069] The permission status indicates the current status of the user's permissions, such as whether they are enabled, expired, or suspended.

[0070] The product identifier is associated with user permissions and a specific product. This is because the same user may have different roles and permission information in different products. Therefore, user permissions are associated with a specific product based on the product identifier.

[0071] In some embodiments, the permission status includes normal and abnormal, indicating whether the user has permissions unrelated to the product or permissions that do not match the role. When a user has permissions unrelated to the product or permissions that do not match the role, the permission status is abnormal.

[0072] In step S102, a product information table is configured; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information of the product role includes the user identifier of at least one user.

[0073] The products mentioned are information products, such as email systems, business systems, and apps.

[0074] The product identifier is used to uniquely identify each information product and can be a product ID, product name, etc.

[0075] The product roles include product testers, requirements administrators, deployment and operations personnel, and development testers.

[0076] The personnel information corresponding to the product role includes the user identifier of at least one user. For example, product testing includes user 001, user 002, etc., thereby establishing the permission relationship between role-product-user.

[0077] After configuring the user permission information table and product information table, store the user permission information table and product information table in the permission management database.

[0078] In step S103, the user permission information table and the product information table are processed. By combining the user identifier and product identifier in the user permission information table and the product identifier and product role personnel information in the product information table, the target permission information for each user for the product under the product dimension is determined.

[0079] The same user has different permissions in multiple different information products; the same product will also grant different permissions to different users when it is opened to different users. Based on the user permission information table and product information table, the relationship between users and information products can be processed quickly.

[0080] In step S104, in response to receiving a permission query instruction, target permission information matching the query conditions is obtained based on the query conditions in the permission query instruction.

[0081] The permission dynamic management system receives and parses permission query instructions from users or applications. The permission query instructions include query conditions, which define the permission information to be obtained.

[0082] Users determine the permission query results corresponding to permission keywords (product name, role name, resource information, etc.) based on the permission information stored in the permission management database.

[0083] In step S105, the target permission information matching the query conditions is visualized to generate a target permission view corresponding to the permission query instruction, and the target permission view is displayed.

[0084] After filtering out the target permission information that matches the query conditions from the database query results, the results are further visualized to ensure that the information returned to the user is both accurate and easy to understand, clearly displaying the user's permissions, abnormal permission status, and abnormal information, thus facilitating permission management.

[0085] Please refer to Figure 3 , Figure 3 A flowchart of the dynamic permission management method described in an embodiment of this application is shown; as follows: Figure 3 As shown, the method further includes the following steps S301-S304:

[0086] S301. Configure exception verification rules based on permission exception situations; the permission exception situations include: the user has permissions unrelated to the product, the user has permissions that do not match the role, and there are unassigned resources under the product;

[0087] S302. Based on the anomaly verification rules, determine whether there is any anomaly information in the target permission information that conforms to the anomaly verification rules;

[0088] S303. Based on the abnormal information, determine the permission status of the user permission information table;

[0089] S304. When performing visualization processing on the target permission information that matches the query conditions, an exception identifier for the exception information is generated, and a target permission view corresponding to the permission query instruction is generated, wherein the target permission view includes the exception identifier for the exception information.

[0090] In other words, the view identifies abnormal permissions in the following ways: personnel have permissions unrelated to the product, personnel have permissions that do not match their roles, and there are unassigned resources under the product. Users need to periodically take management actions such as adjusting personnel roles, adjusting resource ownership, and deleting permissions based on permission information, permission status, and abnormal indicators in the target permission view.

[0091] In other words, the dynamic permission management method described in this application classifies permissions and can dynamically judge the current permission information for different management strategies, and reflect it in the system permission view.

[0092] Taking the production host permission management module as an example, firstly, different roles within the product have different permissions. For instance, privileged accounts on the host can only be held by the system administrator. If a user with another role holds such a permission, it will be marked as an abnormal permission, prompting the user and relevant personnel to remove it. Secondly, when different production management strategies exist, the permission anomaly can be dynamically assessed by raising the strategy level, achieving precise control, real-time feedback, and timely removal of abnormal permissions. Finally, the dynamic permission management method described in this application will periodically backtrack abnormal permissions, automatically generate reports on abnormal permissions, and notify relevant personnel, thus achieving closed-loop permission management.

[0093] Specifically, in some embodiments, the dynamic permission management method further includes:

[0094] For abnormal information that conforms to the aforementioned abnormality verification rules, generate an access control modification work order;

[0095] Based on the permission modification work order, modify the user permission information table and / or product information table.

[0096] In other words, by modifying work orders based on permissions, automatic reports can be generated for abnormal permissions, and relevant personnel can be notified, thus achieving closed-loop management of permissions.

[0097] In some embodiments, the configuration user permission information table includes:

[0098] Obtain each type of permission information from the business system associated with each type of permission information;

[0099] Configure a user permission information table based on each type of permission information obtained.

[0100] Please refer to Figure 2 , Figure 2 The dynamic permission management system 200 shown is divided into three parts: a database permission management module 201, a production host permission management module 202, and a firewall permission management module 203, mainly displaying different types of permission information. The data in the database permission management module 201 comes from three different business systems, while the data in the firewall permission management module 202 and the production host permission management module 203 both come from two different business systems. Information is obtained from the business systems to configure the user permission information table, facilitating improved real-time performance and accuracy of data synchronization.

[0101] Taking the database permission management module as an example, the data sources of this module are divided into data usage permission operation platform permission data, direct database (single instance) permission data, and cloud database permission data. The data from these three modules together constitute the data of the database permission module.

[0102] Permissions in information products are determined by users' job responsibilities. However, in enterprises with a large user base, organizational structure changes and business adjustments are more frequent. How to quickly and accurately handle the changing permissions when changes and adjustments occur is a thorny issue. Negligence by permission administrators, insufficient system automation, or non-standard processes can easily lead to security vulnerabilities and risks. In this embodiment, the permission information comes from the business system. When a permission addition or deletion request is received from the business system, the permission information contained in the request is retrieved, facilitating dynamic data updates and improving the real-time performance and accuracy of data synchronization.

[0103] In some embodiments, the dynamic permission management method further includes:

[0104] In response to user permission management operations, generate permission management work orders;

[0105] In response to the permission management work order, update the user permission information table.

[0106] The user's permission management operations include adding permissions, deleting permissions, and modifying permissions.

[0107] Based on the aforementioned permission management work order, automatic authorization of user permissions is realized. Users can manage their own permissions and add or delete permissions by submitting corresponding permission work orders in the system, thus achieving self-checking, self-inspection, and self-cancellation of permission control.

[0108] Please refer to Figure 4 , Figure 4 A flowchart of the method for automatically authorizing user permissions according to an embodiment of this application is shown; as follows: Figure 4 As shown, when granting a user authorization, the user, host, and account must be entered; the permission dynamic management system ( Figure 4 The process is referred to as 4a) to check if the user has already been created. If "the user has already been created in 4a", the process continues to the step of querying host information. If the user does not exist, the "create 4a user" operation is performed, i.e., a new account is created. After confirming that the user has been created, the system checks if the host already exists. If "the host has already been created in 4a", the process continues to the step of querying account information. If the host does not exist, the "4a create host" operation is performed. After confirming that "the host has already been created in 4a", the system checks if the account already exists. If it does not exist, the system queries the host information and creates the account. If it exists, the system adds authorization and ends the process.

[0109] Once the process is complete, the dynamic permission management system will send a message to the user indicating that automatic authorization has been completed.

[0110] In this embodiment, the user permission information table and the product information table are stored in the database. However, because different business systems have different database types, and due to security and management requirements, the database log files (such as MySQL's binlog) cannot be opened, some older database tables do not have timestamp fields, which makes it difficult to synchronize data in real time. Based on this, the present invention uses a multi-table approach to synchronize all data in the entire table, so that the user is unaware of the synchronization time even when it is long.

[0111] In some embodiments, the dynamic permission management method further includes:

[0112] Configure backup user permission information tables and backup product information tables for the aforementioned user permission information tables and product information tables, respectively;

[0113] Configure a preset management timing strategy; the preset management timing strategy includes alternating first preset time periods and second preset time periods;

[0114] Permission management is performed based on the user permission information table and product information table during the first preset time period, and the backup user permission information table and backup product information table are synchronized.

[0115] During the second preset time period, permission management is performed based on the backup user permission information table and the backup product information table, and the user permission information table and the product information table are synchronized.

[0116] The first preset time period and the second preset time period have the same duration.

[0117] Please refer to Figure 5 , Figure 5 The flowchart illustrating multi-table data synchronization in an embodiment of this application is shown. Taking a first preset time period and a second preset time period of 30 minutes (meaning synchronization occurs every 30 minutes) as an example, the original table and the backup table are labeled as table A and table B, respectively. The directed query pointer is labeled as "current," which directs the query to the database table to be queried. Initially, the directed query pointer points to table A. The 30-minute synchronization timer updates table B. After synchronization is complete, the "current" pointer points to table B. In the next synchronization, table A is updated, and after the update, the "current" pointer points to table A again, and this process repeats. The advantage of this method is that, while ensuring real-time synchronization within 30 minutes, there is no need to worry about the synchronization process affecting the data displayed by the system. This is because the "current" pointer is only modified after successful synchronization. Furthermore, due to the full table update mechanism, deletion and addition permissions are reflected in the system's display interface in real time, achieving real-time, seamless, and accurate data synchronization.

[0118] Based on the same inventive concept, this application also provides a permission dynamic management device corresponding to the permission dynamic management method. Since the principle of the device in this application is similar to the permission dynamic management method described above in this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0119] Please refer to Figure 6 , Figure 6 A schematic diagram of the structure of the permission dynamic management device according to an embodiment of this application is shown; the permission dynamic management device includes:

[0120] The first configuration module 601 is used to configure a user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information.

[0121] The second configuration module 602 is used to configure the product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes the user identifier of at least one user.

[0122] Processing module 603 is used to process the user permission information table and the product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension;

[0123] The acquisition module 604 is used to respond to a received permission query instruction and, based on the query conditions in the permission query instruction, acquire target permission information that matches the query conditions;

[0124] The generation module 605 is used to perform visualization processing on the target permission information that matches the query conditions, generate a target permission view corresponding to the permission query instruction, and display the target permission view.

[0125] In some embodiments, the multiple types of permission information in the permission dynamic management device include database permission information, host permission information, and firewall permission information;

[0126] The acquisition module, upon receiving a permission query instruction and acquiring target permission information matching the query conditions based on the query conditions in the permission query instruction, is specifically used for:

[0127] In response to a permission query instruction for permission information of a target type, the target permission information of the target type that matches the query conditions in the permission query instruction is obtained.

[0128] In some embodiments, the dynamic permission management device further includes:

[0129] The judgment module is used to configure anomaly verification rules based on abnormal permission conditions; the abnormal permission conditions include: the user has permissions unrelated to the product, the user has permissions that do not match the role, and there are unassigned resources under the product;

[0130] Based on the anomaly verification rules, determine whether there is any anomaly information in the target permission information that conforms to the anomaly verification rules;

[0131] Based on the abnormal information, determine the permission status of the user permission information table;

[0132] When visualizing the target permission information that matches the query conditions, an exception identifier is generated for the exception information, and a target permission view corresponding to the permission query instruction is generated. The target permission view includes the exception identifier for the exception information.

[0133] In some embodiments, the dynamic permission management device further includes:

[0134] The modification module is used to generate permission modification work orders for abnormal information that conforms to the aforementioned abnormality verification rules.

[0135] Based on the permission modification work order, modify the user permission information table and / or product information table.

[0136] In some embodiments, the first configuration module in the permission dynamic management device is specifically used for configuring the user permission information table as follows:

[0137] Obtain each type of permission information from the business system associated with each type of permission information;

[0138] Configure a user permission information table based on each type of permission information obtained.

[0139] In some embodiments, the dynamic permission management device further includes:

[0140] The update module is used to respond to user permission management operations and generate permission management work orders;

[0141] In response to the permission management work order, update the user permission information table.

[0142] In some embodiments, the dynamic permission management device further includes:

[0143] The synchronization module is used to configure backup user permission information tables and backup product information tables for the user permission information table and the product information table, respectively.

[0144] Configure a preset management timing strategy; the preset management timing strategy includes alternating first preset time periods and second preset time periods;

[0145] Permission management is performed based on the user permission information table and product information table during the first preset time period, and the backup user permission information table and backup product information table are synchronized.

[0146] During the second preset time period, permission management is performed based on the backup user permission information table and the backup product information table, and the user permission information table and the product information table are synchronized.

[0147] Based on the same inventive concept, this application also provides an electronic device corresponding to the dynamic permission management method. Since the principle of solving the problem by the electronic device in this application is similar to the dynamic permission management method described above in this application, the implementation of the electronic device can refer to the implementation of the method, and the repeated parts will not be described again.

[0148] Please refer to Figure 7 , Figure 7 A schematic diagram of the structure of the electronic device according to an embodiment of this application is shown; the electronic device 700 includes: a processor 702, a memory 701 and a bus. The memory 701 stores machine-readable instructions that can be executed by the processor 702. When the electronic device 700 is running, the processor 702 communicates with the memory 701 through the bus. When the machine-readable instructions are executed by the processor 702, the steps of the dynamic permission management method are performed.

[0149] Based on the same inventive concept, this application also provides a computer-readable storage medium corresponding to the dynamic permission management method. Since the principle of the computer-readable storage medium in this application is similar to the dynamic permission management method described above in this application, the implementation of the computer-readable storage medium can refer to the implementation of the method, and the repeated parts will not be described again.

[0150] A computer-readable storage medium storing a computer program that, when executed by a processor, performs the steps of the aforementioned dynamic permission management method.

[0151] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some communication interfaces; the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.

[0152] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0153] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0154] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a platform server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0155] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for dynamic permission management, characterized in that, Includes the following steps: Configure a user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information; Configure a product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes user identifiers of at least one user; Process the user permission information table and product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension; Upon receiving a permission query instruction, the system retrieves the target permission information that matches the query conditions based on the query conditions in the permission query instruction. The target permission information matching the query conditions is visualized to generate a target permission view corresponding to the permission query instruction, and the target permission view is displayed. The method further includes: Configure backup user permission information tables and backup product information tables for the aforementioned user permission information tables and product information tables, respectively; Configure a preset management timing strategy; the preset management timing strategy includes alternating first preset time periods and second preset time periods; Permission management is performed based on the user permission information table and product information table during the first preset time period, and the backup user permission information table and backup product information table are synchronized. During the second preset time period, permission management is performed based on the backup user permission information table and the backup product information table, and the user permission information table and the product information table are synchronized.

2. The dynamic permission management method according to claim 1, characterized in that, The various types of permission information include database permission information, host permission information, and firewall permission information; Upon receiving a permission query instruction, the system retrieves target permission information matching the query conditions based on the query conditions in the instruction, including: In response to a permission query instruction for permission information of a target type, the target permission information of the target type that matches the query conditions in the permission query instruction is obtained.

3. The dynamic permission management method according to claim 1, characterized in that, The method further includes: Configure exception verification rules based on abnormal permission conditions; the abnormal permission conditions include: the user has permissions unrelated to the product, the user has permissions that do not match the role, and there are unassigned resources under the product; Based on the anomaly verification rules, determine whether there is any anomaly information in the target permission information that conforms to the anomaly verification rules; Based on the abnormal information, determine the permission status of the user permission information table; When visualizing the target permission information that matches the query conditions, an exception identifier is generated for the exception information, and a target permission view corresponding to the permission query instruction is generated. The target permission view includes the exception identifier for the exception information.

4. The dynamic permission management method according to claim 3, characterized in that, The method further includes: For abnormal information that conforms to the aforementioned abnormality verification rules, generate an access control modification work order; Based on the permission modification work order, modify the user permission information table and / or product information table.

5. The dynamic permission management method according to claim 1, characterized in that, The configured user permission information table includes: Obtain each type of permission information from the business system associated with each type of permission information; Configure a user permission information table based on each type of permission information obtained.

6. The dynamic permission management method according to claim 1, characterized in that, The method further includes: In response to user permission management operations, generate permission management work orders; In response to the permission management work order, update the user permission information table.

7. A dynamic access control device, characterized in that, The device includes: The first configuration module is used to configure the user permission information table; the user permission information table includes the user's user identifier, user role, permission information corresponding to the user role, permission status, and product identifier; the permission information corresponding to the user's user role includes multiple types of permission information. The second configuration module is used to configure the product information table; the product information table includes product identifier, product type, product role, personnel information corresponding to the product role, and different types of resource information; the personnel information corresponding to the product role includes the user identifier of at least one user. The processing module is used to process the user permission information table and the product information table, and combine the user identifier and product identifier in the user permission information table with the product identifier and product role personnel information in the product information table to determine the target permission information of each user for the product under the product dimension. The acquisition module is used to respond to a received permission query instruction and, based on the query conditions in the permission query instruction, acquire the target permission information that matches the query conditions; The generation module is used to perform visualization processing on the target permission information that matches the query conditions, generate a target permission view corresponding to the permission query instruction, and display the target permission view; The device further includes: The synchronization module is used to configure backup user permission information tables and backup product information tables for the user permission information table and the product information table, respectively. Configure a preset management timing strategy; the preset management timing strategy includes alternating first preset time periods and second preset time periods; Permission management is performed based on the user permission information table and product information table during the first preset time period, and the backup user permission information table and backup product information table are synchronized. During the second preset time period, permission management is performed based on the backup user permission information table and the backup product information table, and the user permission information table and the product information table are synchronized.

8. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. When the machine-readable instructions are executed by the processor, the steps of the dynamic permission management method as described in any one of claims 1 to 6 are performed.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the dynamic permission management method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • User permission data management apparatus and method, and computer readable storage medium

    CN108388604A

  • Standalone tool for certificate management

    US20200382324A1