A method and system for managing rights of a PLM system
By adopting contextual background management in the PLM system, and combining factors such as user roles, projects, and organizations, user permissions can be precisely controlled, solving the problems of unauthorized behavior and the complexity of multi-system management in traditional PLM systems, and improving data security and availability.
Patent Information
- Application Number
- CN202411676859.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-11-22
AI Technical Summary
In traditional PLM systems, role-based access control methods cannot accurately constrain data permissions, leading to frequent unauthorized actions and serious data security and availability issues. In particular, role authorization management is complex and inconsistent in multi-system environments, causing system application disorder.
By adopting an environment context background management approach, and by establishing a security dimension matrix and user identity information, combined with factors such as user roles, projects, and organizations, we can precisely control users' access to and operation permissions for product data, replacing the traditional role management approach.
It enables precise access to and operation permission control of product data, improves data sharing and confidentiality, reduces unauthorized behavior, simplifies permission management across multiple systems, reduces license fees, and enhances system security and availability.
Smart Images

Figure CN119885149B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of project access control technology, specifically relating to an access control method and system for a PLM system. Background Technology
[0002] The data types and formats in a PLM (Product Lifecycle Management) system are diverse, as are the types of users who provide and use this data. The function of a product data system is to systematically manage the corresponding data usage permissions for various users, granting different access and operation permissions to each user so that all users can access and operate the data they need.
[0003] Traditional PLM systems typically use role-based access control to implement data access and operation permissions, such as... Figure 2 As PLM product data becomes increasingly specialized, with more and more professional components and a growing number of vehicle models, along with diverse partners and collaboration methods, project development deadlines are becoming increasingly stringent. Relying solely on roles to allocate access and operation permissions for product system data can lead to more unauthorized actions: content that shouldn't be seen is seen, objects that shouldn't be manipulated are manipulated, and it may be impossible to trace who performed the actions. This is a very serious problem for PLM systems, specifically manifested in the following ways:
[0004] (1) Product data security
[0005] Traditional product information systems' role-based access control methods can only control interface menus and button operations, failing to provide precise constraints on data permissions. For example, in our current system, a designer of a particular specialty can see objects belonging to all designers and can modify objects belonging to other designers; such as a chassis designer seeing and modifying chassis-related product data. Similarly, a designer for one project can modify product data for another project.
[0006] This problem is less noticeable when the product system has a small amount of data, but as the amount of data in the product system increases, data security issues, if not controlled, may lead to major technical or quality incidents.
[0007] (2) Product data security and availability
[0008] Traditional function menus and buttons require separate role and permission configurations for each component, leading to repetitive work and a high risk of errors. For example, in a company's product management system and product design system, user roles need to be managed separately.
[0009] Under normal circumstances, the users of two related systems may be different, but most of the product data is interconnected between the two systems. Product data information needs to be exchanged, and role authorization is carried out separately in the two systems. There are differences and consistency in the roles between the two systems. For example, the product management system has roles such as product designer, approver, queryer, and product data engineer, but the product design system only has roles such as designer, queryer, and DMU engineer. The inconsistency of roles between the systems can lead to a series of system application disorder problems due to the complexity of authorization management and the availability of product data. In severe cases, it can cause the system function to fail. Summary of the Invention
[0010] To address the issues of product data being accessed or even incorrectly modified by unauthorized personnel in the system, as well as the availability of product data across multiple systems and roles, this invention proposes a permission management method and system for a PLM system.
[0011] A method for access control in a PLM system, which achieves one of the objectives of this invention, includes:
[0012] User identity information in the PLM system is assigned based on user roles and the projects the user participates in; the identity information includes: user roles and the user's security dimensions;
[0013] Based on the user's identity information and the security dimension tags of each product data object, the PLM system determines the user's permissions for each product data object, and assigns the user access and / or operation permissions for each product data object according to the permissions.
[0014] The user's security dimension includes the projects the user is involved in and / or the organizations to which those projects are located;
[0015] The security dimension tags of the product data object include the project and / or the organization to which the project belongs.
[0016] Furthermore, methods for assigning user identity information in the PLM system include:
[0017] Establish a security dimension matrix for product data, where each piece of product data corresponds to a security dimension label consisting of the project and the organization to which the project belongs; the security dimension matrix is used to control user access permissions to the data.
[0018] User roles are added to the security dimension matrix to obtain the user's environmental context; the user roles are used to control the user's access permissions to data.
[0019] The environmental context is distributed to each user according to business needs, serving as the user's identity information in the PLM system.
[0020] Furthermore, the methods for determining the user's access permissions for each product data object include:
[0021] Users log in to the PLM system with their environmental context;
[0022] If the security dimension label of a product data object matches the environmental context carried by the user, then the user can access the product data.
[0023] The methods for determining consistency include:
[0024] The level of the organization and / or project in the user's environmental context is greater than or equal to the level of the organization and / or project to which the product data object to be accessed belongs.
[0025] Furthermore, the methods for determining the user's operational permissions for each product data object include:
[0026] Users log in to the PLM system with their environmental context;
[0027] When the security dimension label of a product data object matches the environmental context carried by the user, and the user role matches the product data object, then the user can operate the product data object.
[0028] Furthermore, the matching determination methods include:
[0029] When a user's role in the context of their environment matches the development progress of a product data object, that user can perform operations on the product data object.
[0030] Furthermore, if the user's role in the context is the first role, and the development progress of the product data object includes: during work or release, then the user is considered to match the product data object.
[0031] If a user's role in the context is the first role and the development progress of the product data object includes "frozen" or "pending approval," then the user is considered to be mismatched with the product data object.
[0032] When the development progress of a product data object is in the "working" state, it means that the product data object is being actively developed, modified, or tested. During this stage, the development team or relevant users can create, edit, update, test, or perform other related work on the product data object. The product data object may contain incomplete or unverified information and may change frequently.
[0033] The product data object's development progress is in the "Release" state, meaning that the product data object has completed all necessary development, testing, and verification work and has been officially released or delivered to end users or customers. At this stage, the product data object is generally considered stable and complete, and no further large-scale modifications are expected.
[0034] The development progress of the product data object is in a "frozen" state, which means that the product data object has been locked for some reason (such as an upcoming new version release, maintenance, etc.) and no further modifications or updates are allowed. At this stage, the product data object is protected to prevent accidental or unauthorized changes.
[0035] The product data object's development progress is in the "pending approval" state, indicating that the product data object has completed development or modifications, but has not yet undergone the necessary approval process, and therefore has not been officially released or delivered for use. At this stage, the product data object may still need to undergo internal review, compliance checks, or other approval steps.
[0036] When a user's role in the context is the first role, the user can perform a first operation on a product data object whose development progress is "working"; the first operation includes modification, version upgrade, or deletion; the user can perform a second operation on a product data object whose development progress is "released"; the second operation includes cloning and version upgrade.
[0037] When a user's role in the context is primary, that user cannot perform any operations on product data objects whose maturity level is frozen or pending approval.
[0038] The first role includes roles involved in the project design, development, acceptance, and release processes; such as the role of a designer.
[0039] The access control system of the PLM system that achieves the second objective of this invention includes:
[0040] The allocation module is used to allocate user identity information in the PLM system based on user roles and the projects the user participates in; the identity information includes: user roles and the user's security dimensions;
[0041] The permission determination module is used to determine the user's permissions for each product data object based on the user's identity information and the security dimension tags of each product data object. The PLM system then assigns access and / or operation permissions for each product data object to the user based on these permissions.
[0042] The user's security dimension includes the projects the user is involved in and / or the organizations to which those projects are located;
[0043] The security dimension tags of the product data object include the project and / or the organization to which the project belongs.
[0044] This invention achieves precise control of data permissions by replacing role-based management with an environment context management approach, resulting in the following beneficial effects:
[0045] 1. Sharing and confidentiality: By managing access permissions through Context, each user can more precisely control what product data they should see in the relevant product information system and not see what data they should not see, thus ensuring the sharing and confidentiality of product data.
[0046] 2. Precise Operation Permissions: Context-based management ensures that each user's system operation permissions are controlled within their designated business scope, guaranteeing product data security.
[0047] 3. Accurately estimate the number of system licenses needed: By uniformly managing Context permissions and tracking the actual usage of Contexts, combined with the number of future running projects and the number of participants in the projects, it is easy to calculate the number of system licenses needed in the next few years, saving on license costs. Attached Figure Description
[0048] Figure 1 This is a flowchart illustrating the method described in this invention;
[0049] Figure 2 This is a schematic diagram of a traditional PLM system;
[0050] Figure 3 This is a diagram of a matrix organizational structure;
[0051] Figure 4 This is a diagram illustrating how to determine a user's product data access permissions;
[0052] Figure 5 This is a diagram illustrating how to determine a user's product data access permissions;
[0053] Figure 6 This is a diagram illustrating how user access permissions for parts are determined based on user context.
[0054] Figure 7 It is a conceptual diagram of a multi-product system. Detailed Implementation
[0055] The following detailed embodiments are provided to explain the technical solutions of the claims of this invention, so that those skilled in the art can understand the claims. The scope of protection of this invention is not limited to the following specific embodiments. Any modifications made by those skilled in the art that incorporate the technical solutions of the claims but differ from the following detailed embodiments are also within the scope of protection of this invention.
[0056] Example 1
[0057] A method for access control in a PLM system, such as Figure 1 Shown, including:
[0058] S1. Assign user identity information in the PLM system based on user role and the projects the user participates in; the identity information includes: user role and user security dimension;
[0059] User roles can be divided into different roles such as system administrator, project manager, designer, engineer, quality personnel, and procurement personnel, and detailed responsibilities and permissions can be set for each role;
[0060] Depending on business needs, user roles can be further subdivided, such as senior designers and junior engineers, to more precisely control permissions. In addition to internal organizations (such as R&D, production, and sales departments), external organizations such as partner organizations, outsourced organizations, and supplier organizations are also included. A unique organization ID is assigned to each organization, and its data access scope and permission level within the PLM system are clearly defined.
[0061] At the same time, a project ID is assigned to each project and associated with a specific organization.
[0062] Project permissions are further subdivided based on project phase (such as conceptual design, detailed design, production preparation, production implementation, etc.) and project type (such as new product development, improvement project, etc.).
[0063] Each user is assigned a unique identity based on their role, organization, and project, including a user ID, role identifier, organization ID, and project ID. This identity information should be updated regularly to ensure consistency with the user's actual responsibilities and permissions. Specifically:
[0064] In some embodiments, the method for assigning user identity information in the PLM system includes:
[0065] Establish a security dimension matrix for product data, where each piece of product data corresponds to a security dimension label consisting of the project and the organization to which the project belongs; the security dimension matrix is used to control user access permissions to the data.
[0066] User roles are added to the security dimension matrix to obtain the user's environmental context; the user roles are used to control the user's access permissions to data.
[0067] The environmental context is distributed to each user according to business needs, serving as the user's identity information in the PLM system.
[0068] In some embodiments, the method for assigning user identity information in the PLM system includes:
[0069] Establish a two-dimensional security matrix for product data: organization + project, forming the core elements of data access control, such as... Figure 3 As shown, a role dimension is added to this two-dimensional security matrix to form a complete environment context background for the login product system. In this embodiment, the environment context background is: Context = Role + Organization + Project. The organization dimension and project dimension are used for data permission control, and the role dimension is used for operation permission control. The three are combined to form the environment context background of the login product system. It is independently encapsulated and distributed to different account users according to business needs.
[0070] S2. Determine the user's permissions for each product data object based on the user's identity information and the security dimension tags of each product data object. The PLM system then assigns access and / or operation permissions for each product data object to the user based on the permissions.
[0071] The user's security dimension includes the projects the user is involved in and / or the organizations to which those projects are located;
[0072] The security dimension tags of the product data object include the project and / or the organization to which the project belongs.
[0073] In some embodiments, the method for determining the user's access permissions for each product data object includes:
[0074] Users log in to the PLM system with their environmental context;
[0075] If the security dimension label of a product data object matches the environmental context carried by the user, then the user can access the product data.
[0076] The methods for determining consistency include:
[0077] The level of the organization and / or project in the user's environmental context is greater than or equal to the level of the organization and / or project to which the product data object to be accessed belongs; the level is defined according to the actual project, for example, the following four organizational levels are set in the following order: horizontal > electrical > chassis > power; this invention does not limit this, and the level is set according to the actual situation of the project.
[0078] In some embodiments, the method for determining the user's access permissions for each product data object includes:
[0079] In some embodiments, after a user logs into the product system with their environment context, the created product data is automatically tagged with the security dimension label from that user's context, i.e., organization + project. All product data in the system carries the user account and security dimension attributes. When other users log into the system with their respective contexts, the system automatically calculates their product data access permissions, using an algorithm as follows: Figure 4 As shown in the diagram, the product data access function f(x, y) is determined based on the company's business needs. It determines whether the security dimension label of the product data object matches the environmental context of the login system account. If so, the account can access the data; otherwise, it cannot. For example, setting organizational permission rules: Horizontal > Appliances > Chassis > Power. If the level of "Organization" in the security dimension label of the login account is greater than or equal to a certain product data organization, then the account can access that product data. Therefore, if the "Organization" in the security dimension label of the logged-in account is a chassis organization, then the account can access product data with organizations of "Chassis" and "Power," but cannot access product data with organizations of "Horizontal" and "Appliances." Similarly, rules can be defined for projects, or they can be defined using the relationship between organization and project. In short, the specific definition requirements are ultimately determined based on the company's own business needs.
[0080] At the same time, "organization" can also be extended to the company's partner organization, outsourced organization, supplier organization, etc. By formulating the organization's data access strategy, the scope of data access by each external company can be precisely controlled.
[0081] S3. Determine the operation permission control mode for product data objects.
[0082] Based on the strategy and state patterns in the methodology "Design Patterns: Elements of Reusable Object-Oriented Software", the state pattern allows an object to change its behavior when its internal state changes; it defines a family of algorithms, encapsulates them one by one, and makes them interchangeable, so that the algorithm can vary independently of the clients that use it.
[0083] In some embodiments, the method for determining the user's operational permissions for each product data object includes:
[0084] Users log in to the PLM system with their environmental context;
[0085] When the security dimension label of a product data object matches the user's environmental context, and the user role matches the product data object, then the user can interact with the product data object. The matching methods include:
[0086] When a user's role in the context of their environment matches the development progress of a product data object, that user can perform operations on the product data object.
[0087] When a user's role in the context is the first role, and the development progress of the product data object includes: during work or release, then the user is considered to match the product data object.
[0088] If a user's role in the context is the first role and the development progress of the product data object includes "frozen" or "pending approval," then the user is considered to be mismatched with the product data object.
[0089] When a user's role in the context is the first role, the user can perform a first operation on a product data object whose development progress is "working"; the first operation includes modification, version upgrade, or deletion; the user can perform a second operation on a product data object whose development progress is "released"; the second operation includes cloning and version upgrade.
[0090] When a user's role in the context is primary, that user cannot perform any operations on product data objects whose maturity level is frozen or pending approval.
[0091] The first role refers to the role involved in the project design, project development, project acceptance, and project release process.
[0092] In some embodiments, such as Figure 5 As shown. The product data manipulation function g(x, y) receives the security dimension label of the product data object and the environment context information of the logged-in user, and then calculates the operation permissions of the product data object for that logged-in user. For example... Figure 6 As shown. From Figure 6 As can be seen, under the constraints of the part maturity strategy, through simple calculation, user 0011 has obtained the operation permissions of modifying, upgrading and deleting part 1, the operation permissions of cloning and upgrading part 2, and no operation permissions for part 3.
[0093] Of course, the product data manipulation function g(x, y) can be tailored to the company’s actual business needs, taking into account the security dimension attributes of other contexts (other roles, other organizations, and other projects) of the login product system and the target product data, and establish a more detailed control algorithm to ensure that any user has the corresponding correct operation permissions for all data in the system.
[0094] At the same time, the organization can also be extended to the company's partner organizations, outsourced organizations, supplier organizations, etc. By formulating the organization's data access strategy, the scope of data operation by each external company can be precisely controlled.
[0095] Traditional product information systems typically consist of two basic systems: PDM and CAD, with relatively simple access control. However, future collaborative work will require the addition of multiple systems such as CAE and CAPP. As the same data flows across these systems, access control needs to consider a simpler and more convenient way to centrally manage various user groups, as shown in the attached document. Figure 7 As shown: Each user has different responsibilities in each system, so they always have their own Context. Because the Context is independently encapsulated and always associated with the account, and because the Context is adapted to each PLM system, the same account has the same Context when logging into each PLM system. Users only need to select the appropriate PLM system's Context to log in, eliminating the need to develop different Contexts for each PLM system separately, making it very convenient for users. PLM system Contexts are created and canceled centrally by the administrator. Based on business needs, the administrator assigns these Contexts to different user accounts. Since Contexts are associated with licenses, the required number of system licenses can be estimated by counting the number of Contexts of each type. Furthermore, the actual number of Contexts used can be used to calculate the actual number of licenses used, allowing for more accurate procurement of the appropriate number of licenses.
[0096] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0097] Example 2
[0098] A permission management system for a PLM system includes:
[0099] The allocation module is used to allocate user identity information in the PLM system based on user roles and the projects the user participates in; the identity information includes: user roles and the user's security dimensions;
[0100] The permission determination module is used to determine the user's permissions for each product data object based on the user's identity information and the security dimension tags of each product data object. The PLM system then assigns access and / or operation permissions for each product data object to the user based on these permissions.
[0101] The user's security dimension includes the projects the user is involved in and / or the organizations to which those projects are located;
[0102] The security dimension tags of the product data object include the project and / or the organization to which the project belongs.
[0103] Example 3
[0104] A non-transitory computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a processor, implement the various steps of the method described in this invention, which will not be elaborated further here.
[0105] The computer-readable storage medium can be the data transmission apparatus or the internal storage unit of a computer device provided in any of the foregoing embodiments, such as the hard disk or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device.
[0106] Furthermore, the computer-readable storage medium may include both internal storage units and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that is to be output or has already been output.
[0107] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0108] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0109] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0111] The contents not described in detail in this specification are existing technologies known to those skilled in the art.
[0112] Example 4
[0113] A computer program product includes a computer program / instructions that, when executed by a processor, implement any step of the access control method of the PLM system.
Claims
1. A method for access control in a PLM system, characterized in that, include: User identity information in the PLM system is assigned based on user roles and the projects the user participates in; Based on the user's identity information and the security dimension tags of each product data object, the PLM system determines the user's permissions for each product data object, and assigns the user access and / or operation permissions for each product data object according to the permissions. The identity information includes the projects the user is involved in and / or the organizations to which the projects the user is involved in belong; The security dimension tags of the product data object include the project and / or the organization to which the project belongs; Methods for assigning user identity information in a PLM system include: Establish a security dimension matrix for product data, which is used to control user access permissions to the data; User roles are added to the security dimension matrix to obtain the user's environmental context; the user roles are used to control the user's access permissions to data. The environmental context is distributed to each user as their identity information in the PLM system. Methods for determining a user's access permissions for each product data object include: The user logs into the PLM system with the aforementioned environmental context background; If the security dimension label of a product data object matches the environmental context carried by the user, then the user can access the product data. The methods for determining consistency include: The level of the organization and / or project in the user's environmental context is greater than or equal to the level of the organization and / or project to which the product data object to be accessed belongs.
2. The access control method for a PLM system as described in claim 1, characterized in that, The methods for determining a user's operation permissions for each product data object include: Users log in to the PLM system with their environmental context; When the security dimension label of a product data object matches the environmental context carried by the user, and the user role matches the product data object, then the user can operate the product data object.
3. The access control method for a PLM system as described in claim 2, characterized in that, The methods for determining the match between user roles and product data objects include: When a user's role in the context of their environment matches the development progress of a product data object, that user can perform operations on the product data object.
4. The access control method for a PLM system as described in claim 3, characterized in that, When a user's role in the context is the first role, and the development progress of the product data object includes: during work or release, then the user is considered to match the product data object. If a user's role in the context is the first role and the development progress of the product data object includes "frozen" or "pending approval," then the user is considered to be mismatched with the product data object.
5. The access control method for a PLM system as described in claim 4, characterized in that, When a user's role in the context is the first role, the user can perform a first operation on a product data object whose development progress is "working"; the first operation includes modification, version upgrade, or deletion; the user can perform a second operation on a product data object whose development progress is "released", the second operation includes cloning and version upgrade.
6. A permission management system for implementing the PLM system as described in claim 1, characterized in that, include: The allocation module is used to allocate user identity information in the PLM system based on user roles and the projects the user participates in. The identity information includes: user role and user security dimensions; The permission determination module is used to determine the user's permissions for each product data object based on the user's identity information and the security dimension tags of each product data object. The PLM system then assigns access and / or operation permissions for each product data object to the user based on these permissions. The user's security dimension includes the projects the user is involved in and / or the organizations to which those projects are located; The security dimension tags of the product data object include the project and / or the organization to which the project belongs.
7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the access control method of the PLM system as described in any one of claims 1 to 5.
8. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements any step of the permission management method of the PLM system described in claims 1 to 5.
Citation Information
Patent Citations
Role engineering scoping and management
CN103890773A
Full-life-cycle digital mainline service system for complex products
CN111126961A