Project file access method and electronic equipment
By verifying and configuring access permissions, ensuring that only authorized access objects can access the target project files, solving the problems of external file transfer security and permission verification complexity, and improving the security and efficiency of project file access.
Patent Information
- Application Number
- CN202411834774.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-13
AI Technical Summary
The prior art requires external tools when loading external files, resulting in lack of security in the transmission process of external files, and the process of permission verification of external files is complicated and inefficient.
Provide a project file access method, by verifying the first access permission of the access object and configuring the second access permission, ensuring that only the authorized access object can access the target project file, and perform fine-grained permission control based on the permission information.
It effectively avoids the risk of leakage of target project files, improves the security and stability of accessing target project files, and simplifies file access operations and improves efficiency.
Smart Images

Figure CN119939647A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a project file access method and electronic device. Background Art
[0002] In practical applications, project file access is an indispensable part of engineering applications. In related technologies, file access mainly relies on reading engineering project files stored in local directories. However, this method requires the use of external tools when loading external files, resulting in a lack of security during the transmission of external files. At the same time, the process of verifying the permissions of external files also makes file access operations complicated and cumbersome, resulting in low file access efficiency. Summary of the invention
[0003] The following is a summary of the subject matter of the detailed description of the present disclosure. This summary is not intended to limit the scope of the claims.
[0004] The disclosed embodiment provides a project file access method, which effectively avoids the risk of leakage of the target project file, thereby improving the security and stability of accessing the target project file.
[0005] In one aspect, an embodiment of the present disclosure provides a project file access method, comprising:
[0006] In response to a request to access a target project file, verify a first access right of an access object, wherein an access request operation of the access object is executed in a target application;
[0007] Sending the target project file to the target application based on the verification result of the first access right;
[0008] configuring a second access permission for the access object, obtaining permission information corresponding to the second access permission, and sending the permission information to the target application, so that the target application sends a request for allowing access to the target project file according to the permission information;
[0009] In response to the request for allowing access to the target project file, an access service to the target project file within the scope of the permission information is provided to the access object.
[0010] On the other hand, an embodiment of the present disclosure further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned project file access method when executing the computer program.
[0011] The disclosed embodiments include at least the following beneficial effects: responding to a request to access a target project file, verifying a first access right of an access object to ensure that the access object has the right to access the target project file, sending the target project file to a target application based on the verification result of the first access right, configuring a second access right for the access object, obtaining permission information corresponding to the second access right, sending the permission information to the target application so that the target application sends a request for permission to access the target project file according to the permission information, performing fine-grained permission control on the target project file based on the second access right to ensure that the target project file can only be accessed by authorized access objects, responding to a request for permission to access the target project file, providing the access object with access services to the target project file within the scope of the permission information, effectively avoiding the risk of leakage of the target project file, and thus improving the security and stability of access to the target project file.
[0012] Other features and advantages of the present disclosure will be set forth in the following description, and in part will be apparent from the description, or may be learned by practicing the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The accompanying drawings are used to provide further understanding of the technical solution of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the technical solution of the present disclosure and do not constitute a limitation on the technical solution of the present disclosure.
[0014] Figure 1 A schematic diagram of an optional implementation environment provided for an embodiment of the present disclosure;
[0015] Figure 2 An optional flowchart of a project file access method provided in an embodiment of the present disclosure;
[0016] Figure 3 An optional schematic diagram of authorizing entity permissions for access roles provided in an embodiment of the present disclosure;
[0017] Figure 4 An optional schematic diagram of authorizing entity rights for accessing an object provided in an embodiment of the present disclosure;
[0018] Figure 5 An optional schematic diagram of a second access permission configuration provided in an embodiment of the present application;
[0019] Figure 6 Another optional schematic diagram of the second access permission configuration provided by the embodiment of the present disclosure;
[0020] Figure 7 An optional overall process for accessing project files provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical solution and advantages of the present disclosure more clear, the present disclosure is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present disclosure and are not used to limit the present disclosure.
[0022] It should be noted that in various specific embodiments of the present disclosure, when it comes to the need to perform relevant processing based on data related to the characteristics of the target object such as the target object attribute information or attribute information set, the permission or consent of the target object will be obtained first, and the collection, use and processing of these data will comply with relevant laws, regulations and standards. Among them, the target object can be a user. In addition, when the embodiment of the present disclosure needs to obtain the attribute information of the target object, the separate permission or separate consent of the target object will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the separate permission or separate consent of the target object, the necessary target object-related data used to enable the normal operation of the embodiment of the present disclosure will be obtained.
[0023] In the embodiments of the present disclosure, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0024] To facilitate understanding of the technical solution provided by the embodiments of the present disclosure, some key terms used in the embodiments of the present disclosure are explained here:
[0025] Transmission protocol: refers to the rules that must be followed in data transmission to ensure the reliability and integrity of data during transmission. Through the transmission protocol, data can be transmitted stably and efficiently, thereby realizing information sharing. Commonly used transmission protocols include HTTP protocol, TCP protocol, FTP protocol, etc.
[0026] Key: A specific value or string used to encrypt and decrypt data, usually randomly generated to ensure its security and unpredictability. During the encryption process, the key is combined with the encryption algorithm to convert plaintext data into ciphertext data; during the decryption process, the key is used to restore the ciphertext data to plaintext data.
[0027] In practical applications, project file access is an indispensable part of engineering applications. At present, file access mainly relies on existing structural analysis software, which reads engineering project files stored in local directories. When loading files from external sources, other network transmission tools or mobile media are usually relied on for file transmission. At the same time, the loaded external files are verified for permissions to ensure the credibility of the external files. However, this method of loading external files with the help of external tools may face security risks such as data leakage and data tampering, and the transmission path is not completely controllable, resulting in a lack of security for external files during transmission. On the other hand, although the permission verification of external files can increase the security of project files, it also makes file access operations complicated and cumbersome, and there is a problem of low file access efficiency.
[0028] Based on this, the embodiments of the present disclosure provide a project file access method, which effectively avoids the risk of leakage of the target project file, thereby improving the security and stability of accessing the project file.
[0029] Reference Figure 1 , Figure 1 A schematic diagram of an optional implementation environment provided for an embodiment of the present disclosure, the implementation environment includes a terminal 101 and a server 102. Specifically, the terminal 101 sends a request to the server 102 for accessing a target project file, and the server 102 responds to the request to access the target project file, verifies the first access permission of the access object, and sends the target project file to the terminal 101 based on the verification result of the first access permission. In the server 102, a second access permission is configured for the access object, permission information corresponding to the second access permission is obtained, and the permission information is sent to the terminal 101, so that the terminal 101 sends a request to the server 102 for allowing access to the target project file according to the permission information. The server 102 responds to the request to allow access to the target project file, and provides the access object with access services to the target project file within the scope of the permission information, so that the target project file is displayed in the terminal 101.
[0030] Reference Figure 2 , Figure 2 An optional flow chart of a project file access method provided in an embodiment of the present disclosure may specifically include but not be limited to the following steps S201 to S204:
[0031] Step S201: responding to a request to access a target project file, verifying a first access right of the access object.
[0032] Specifically, the target project file is a project file that the access object needs to access. The target project file can be a project file in a project, or all project files in a project (i.e., a complete project); the first access permission is used to indicate the access object's access permission to the target project file, and the access permission includes the permission to obtain the target project file. The first access permission of the access object is sent to the database, and the first access permission of the access object is verified in the database. By verifying the first access permission of the access object, it is ensured that the access object has the permission to access the target project file, which helps to improve the security of the target project file. It should be noted that when verifying the first access permission of the access object, it can be verified in the database of the server or in an independent database, and this application does not make specific limitations.
[0033] In response to the request to access the target project file, before verifying the first access right of the access object, the access object can select the project file to be uploaded through the target application. After the access object selects the project file, the project file is uploaded to the server, and the uploaded project file is saved in the designated directory of the server. The designated directory of the server can be a designated directory in the database of the server, or a designated directory in the file storage service provided by the server, or a designated directory in other services of the server, which is not specifically limited in this application. In order to ensure the security of the project files stored in the server, security policies can be configured in the server, for example, configuring inbound and outbound rules, restricting open ports, setting application interface whitelists, and regularly backing up stored project files. By uploading all project files to the server, it can ensure that all project files are centrally stored and managed. On this basis, configuring security policies in the server can reduce the risk of project file loss or damage, facilitate the backup and recovery of project files, and effectively improve the security of project file storage.
[0034] In order to further enhance the security of data storage and data transmission, specifically, when the access object uploads the project file to the server through the target application, the server can be set to only accept connection requests from a specific network address, which can be an intranet network address. This ensures that the project file can only be uploaded to the server by logging into the target application in the intranet environment, thereby effectively avoiding potential security risks from the external network.
[0035] Step S202: Sending a target project file to a target application based on the verification result of the first access authority.
[0036] The target application is an application that the access object logs in to through a login account. In the target application, it is possible to upload project files, request access to project files, perform permission operations on project files, and the like.
[0037] Specifically, according to the above step S201, when the verification result of the first access right is that the access object has the access right to access the target project file, the target project file is extracted from the database, and the target project file is sent to the server for storage, and then the server sends the target project file to the target application. When the verification result of the first access right is that the access object does not have the access right to access the target project file, the target project file is not sent to the access object.
[0038] Step S203: configuring a second access right for the access object, obtaining permission information corresponding to the second access right, and sending the permission information to the target application, so that the target application sends a request for allowing access to the target project file according to the permission information.
[0039] Among them, the second access right is used to indicate the access object's operation rights on the target project file, and its permission information includes the permission operation type. The second access right includes system access rights to the entire target project, and its permission operation types include viewing, editing, deleting, etc. It also includes entity data access rights to specific project files, project charts and other entity data in the target project, and its permission operation types include display, details, addition, editing, deletion, authorization, document viewing, document creation, document modification, full control, etc.
[0040] In a possible implementation, in the process of configuring a second access right for an access object, obtaining permission information corresponding to the second access right, and sending the permission information to a target application so that the target application sends a request for access to a target project file according to the permission information, it can be specifically configured with a corresponding target access role for the access object, recording the role configuration operation, determining the second access right of the access object according to the configured target access role, obtaining permission information corresponding to the second access right, and sending the permission information to the target application. The target access role is a role with permission configured for the access object, the role configuration operation is recorded in a permission configuration log, and the permission configuration log is used to record information related to the permission configuration.
[0041] Specifically, the administrator configures the second access right for the access object. The administrator logs in to the target application through the administrator account. The administrator mainly configures and modifies the access role and the permission. The administrator configures the corresponding target access role for the access object according to the actual work content and actual job position of the access object, associates the target access role with the login account of the access object, records the role configuration operation of configuring the target access role for the access object in the permission configuration log, and uses the permission corresponding to the target access role as the second access right. Then, the role name of the target access role is sent to the server, and the server searches according to the role name to obtain the permission information corresponding to the target access role, that is, the permission information corresponding to the second access right, and sends the permission information of the second access right to the target application. When the target application allows the access object to access the target project file, a request to allow access to the target project file is sent to the server; when the target application does not allow the access object to access the target project file, the access is prohibited on the browsing page of the target application to notify the access object. Since an access role corresponds to at least one type of permission operation, by configuring the access role for the access object, the permission configuration process can be simplified, and the efficiency of permission allocation can be effectively improved.
[0042] Before configuring the second access right for the access object, the administrator can preset the access role and the operation right corresponding to the access role according to the specific content of the target project file and the work scope of the actual job position of the access object. The preset access role can correspond to the actual job position. For example, for an engineering project, the actual job positions include project manager, production manager, quality engineer, measurement engineer, etc., and the corresponding preset access roles can be project manager, production manager, quality engineer, measurement engineer, etc. The second access right preset for the project manager role can be delete, edit, view, the second access right preset for the production manager role can be edit, view, and the second access right preset for the quality engineer role and the measurement engineer role can be view. The method of setting the access object based on the work content and work scope enables the setting of the access role to be dynamically adjusted according to the actual project needs, promotes information sharing and collaboration between access objects, effectively improves the flexibility of permission management, and reduces the maintenance cost of permission management. At the same time, each access role corresponds to different permissions, which helps to reduce the operation conflicts between access objects and further promotes team collaboration and communication.
[0043] Furthermore, when the second access right is entity data access right, before configuring entity data access right for the access role, the access role needs to be authorized. Only when the access role is authorized to have entity data access right can the entity data access right be configured for the access role. Specifically, the administrator can authorize the entity data access right for the access role on the first permission management page, wherein the first permission management page can be the permission management page of the target application or the permission management page of the server database. Figure 3 , Figure 3 An optional schematic diagram of authorizing entity permissions for access roles provided in an embodiment of the present disclosure, Figure 3 All access roles set in the project platform item of the project platform in the first management page are displayed. The displayed information includes the role ID of the access role, the role name, the data level configured for the access role, and the creation time of the access role. The access roles include administrator role, project manager role, production manager role, surveying engineer role, quality engineer role, test engineer role, project leader, etc. When the role authorization selection control 301 is checked, the access role is authorized to have entity data access rights. If the role authorization selection control 301 corresponding to the project manager column is checked, the project manager role is authorized to have entity data access rights. Specific entity data access rights can be configured for the project manager role later.
[0044] In addition, when configuring the second access permission for the access object, the administrator can authorize the entity data access permission for the access object on the second permission management page, wherein the second permission management page can be the permission management page of the target application or the permission management page of the server database, refer to Figure 4 , Figure 4 An optional schematic diagram of authorizing entity rights for accessing an object provided in an embodiment of the present disclosure, Figure 4 All access objects in the project platform item of the second permission management page are displayed, and the displayed information includes user account, access object name, contact information, and email address. When it is necessary to temporarily authorize entity permissions for a certain access object, entity permissions can be authorized for the access object in the second permission management page. When the object authorization selection control 401 is checked, the access object is authorized to have entity data access permissions. If the object authorization selection control 401 corresponding to the access object A column is checked, the access object A is authorized to have entity data access permissions.
[0045] It should also be noted that an access role permission mapping table can be configured in the server, and the corresponding relationship between the role name and the permission information is stored in the access role permission mapping table. The server searches for the permission information corresponding to the role name in the access role permission mapping table according to the role name. In addition, the corresponding relationship between the role identifier of the access role and the permission information can also be stored in the access role permission mapping table. In the above process of obtaining permission information, the server can also search in the access role permission mapping table according to the role identifier to obtain the permission information corresponding to the target access object.
[0046] In a possible implementation, the permission configuration log also records the access object behavior pattern and the access object organizational structure. In the process of configuring the corresponding target access role for the access object, the access object behavior pattern and the access object organizational structure in the permission configuration log can be analyzed, a new access role can be recommended based on the analysis results, and the corresponding target access role can be configured for the access object based on the new access role. Among them, the access object behavior pattern is used to describe the operation and rules of the access object when accessing the target project file, for example, the frequency and content of the access object when accessing the target project file, and the access object organizational structure is used to describe the management structure of the actual job positions among all access objects accessing the target project file, for example, the project manager manages the production manager, the production manager manages the measurement engineer, etc.; the method for analyzing the access object behavior pattern and the access object organizational structure can be statistical analysis or cluster analysis, which is not specifically limited in this application; the new access role is an access role that has not been created in history.
[0047] Specifically, the access object behavior pattern of each access object and the access object organizational structure corresponding to each project are extracted from the permission configuration log, and the access object behavior pattern and the access object organizational structure are analyzed, for example, the access frequency of the access object, the type of access content, and the number of permission operations are analyzed. A new access role is generated based on the analysis results, and the new access role is recommended to the administrator. When the administrator adopts the new access role, the new access role can be configured to the corresponding access object during the next role configuration. Alternatively, optimization suggestions for existing access roles can also be proposed based on the analysis results, for example, adding or deleting the operation permissions of the access role, changing the name of the access role, merging or deleting the access role, etc. By analyzing the access object behavior pattern and the access object organizational structure, a recommended new access role can be obtained, or optimization suggestions for existing access roles can be obtained, which simplifies the role management process, ensures the consistency and rationality of the role configuration, and effectively improves the efficiency of permission configuration.
[0048] In a possible implementation, after configuring the corresponding target access role for the access object and recording the role configuration operation, the second access right configured for the access object may be modified, the permission change operation may be recorded, all permission change operations in the permission configuration log may be analyzed, the configuration of the second access right of the access object may be evaluated according to the analysis result, an evaluation result may be obtained, and the configuration of the second access right of the access object may be adjusted according to the evaluation result. The permission change operation may be recorded in the permission configuration log; the evaluation result may be used to indicate that the configuration of the second access right of the access object is reasonable, or may be used to indicate that the configuration of the second access right of the access object is unreasonable.
[0049] Specifically, the permission information of the second access right configured for the access object is obtained, and the permission information of the second access right of the access object is modified, for example, the permission operation type is added or deleted, and the permission change operation is recorded in the permission configuration log. All permission change operations are extracted from the permission configuration log, and all permission change operations are sorted and analyzed, which can be analyzed from the change time, or from the change frequency, etc. The configuration of the second access right of the access object is evaluated according to the analysis result to obtain an evaluation result. When the evaluation result indicates that the configuration of the second access right of the access object is reasonable, the configuration of the second access right of the access object remains unchanged. When the evaluation result indicates that the configuration of the second access right of the access object is unreasonable, the second access right of the access object is adjusted, for example, the permission operation type of the second access right is modified, or the target access role of the access object is modified (the second access right is indirectly modified by modifying the target access role). By analyzing and evaluating permission change operations, potential security vulnerabilities, inefficient access, or permission allocations that do not comply with access processes can be identified. Based on this, permission configuration policies can be adjusted based on the evaluation results, which helps to create and optimize more reasonable access roles that better meet access requirements, ensure that permission configuration policies match access requirements, and thus improve the security and accuracy of access to target project files.
[0050] Further, when the evaluation results show that the second access rights of the access object frequently have other rights beyond the second access rights, for example, the second access rights of the current access object A are display and editing, and when the access role of the access object A is often temporarily granted the rights of deletion and management, it is necessary to re-evaluate the access role of the access object A, change the access role of the access object A, or create a new access role suitable for the access object A. Alternatively, when the evaluation results show that the second access rights of the access object are frequently changed in a short period of time, or are changed during abnormal time periods (such as non-working hours, etc.), it is possible to refuse to continue to change the second access rights of the access object, or interrupt the association between the login account of the access object and the corresponding target access role, and not allow the access object to continue to access the target project file. In addition, for sensitive data in the target project file, it is necessary to strictly control the access to these sensitive data, record all access operations to sensitive data, conduct regular audits on the records, check whether there are abnormal access behaviors or potential security risks based on the audit results, and evaluate the effectiveness of the current permission configuration strategy. Alternatively, all historical operation records in the permission configuration log may be evaluated and audited, and the effectiveness of various permission configuration strategies may be summarized based on the evaluation results and the audit results. Effective permission configuration strategies may be retained (for example, when the permission configuration strategy is used, the target project file is not subject to malicious access, or the response speed of access to the target project file is fast, etc.), and redundant permission configuration strategies may be removed (for example, when the permission configuration strategy is used, the target project file is subject to malicious access frequently, or the response speed of access to the target project file is slow, etc.).
[0051] In a possible implementation, different access roles correspond to different role permission levels, and the second access rights corresponding to access roles of different role permission levels can be merged or inherited. In the process of modifying the second access rights configured for the access object, it can be specifically to obtain the second access rights corresponding to the target access role of the first access object, and obtain the second access rights corresponding to the target access role of the second access object. When the permission selection of the first access object is through, the second access rights of the first access object are the permission set of the second access rights of the first access object and the second access rights of the second access object. Among them, the role permission level of the target access role of the first access object is higher than the target access role of the second access object. The role permission level is used to describe the management hierarchy relationship between access roles. For example, the project manager role manages the test engineer role, so the role permission level of the project manager role is higher than that of the test engineer role.
[0052] Specifically, the second access right corresponding to the target access role of the first access object is obtained, and the second access right corresponding to the target access role of the second access object is obtained. The second access right of the first access object and the second access right of the second access object both contain permission information. When the permission selection of the first access object is through, the second access right of the first access object is the permission set of the second access right of the first access object and the second access right of the second access object. For example, the permission of the first access object is management and display, and the permission of the second access object is editing and display. When the permission selection of the first access object is through, the permission of the first access object is management, editing, and display.
[0053] When the permission of the first access object is not selected to be through, the second access permission of the first access object and the second access permission of the second access object do not change. Specifically, the second access permission of the first access object and the second access permission of the second access object both contain permission information. When the permission of the first access object is not selected to be through, the second access permission of the first access object and the second access permission of the second access object do not change. For example, the permission of the first access object is management and display, and the permission of the second access object is editing and display. When the permission of the first access object is not selected to be through, at this time, the permission of the first access object is management and display, and the permission of the second access object is editing and display. Alternatively, when the permission of the second access object is selected to be through, and the permission of the first access object is not selected to be through, since the role permission level of the target access role of the first access object is higher than the target access role of the second access object, at this time, the second access permission of the second access object and the second access permission of the first access object do not change.
[0054] When the second access right of the second access object does not exist, the second access right of the first access object is used as the second access right of the second access object. Specifically, the second access right of the first access object includes permission information, and the second access right of the second access object does not include permission information, that is, the second access right is not configured for the second access object. At this time, regardless of whether the permission of the second access object is selected to be through, the second access right of the first access object is used as the second access right of the second access object.
[0055] By setting the penetration function for the access objects that have been configured with access roles, the current permission information can be quickly changed according to the role permission level. It can also effectively avoid the situation where a certain access object is not configured with the second access permission, thereby improving the efficiency of permission configuration.
[0056] In a possible implementation, the target project file is a plurality of project files, and the second access right also includes a file data level. In the process of determining the second access right of the access object, the file data level can be configured for the target project file, the permission information configured for the access object is obtained, the permission operation type is assigned to the file data level based on the permission information, and the second access right of the access object is determined according to the file data level and the permission operation type. The file data level is used to divide the data level of the target project file, which can be divided based on the content type of the project file or the importance of the project file.
[0057] Specifically, the file data level is configured for each target project file, the permission information configured for the target access role of the access object is obtained, and the permission information configured for the target access role of the access object is the permission operation type. Based on the permission information, a corresponding permission operation type is assigned to each file data level, and one of the permission operation types included in the permission information is selected and configured to the file data level, and the second access right of the access object is determined according to the file data level and the permission operation type. For example, referring to Figure 5 , Figure 5 An optional schematic diagram of a second access permission configuration provided in an embodiment of the present application, Figure 5 What is shown is the third permission management page for configuring the second access right of the access object configured with the authorized access role. The third permission management page displays the access role identification, access role name and access object, whether it is permeable, the corresponding permission of the access object, the permission of data level 1, the permission of data level 2 and the permission of data level 3. The administrator can edit the entity permission of the access object and the permission type corresponding to each data level on the third permission management page. For the access object A whose access role is represented as 0001, its target access role is project manager, and the permission of access object A is display, add, edit and delete. The edit permission is configured for data level 1, the display permission is configured for data level 2, and the display permission is configured for data level 3. Assuming that file A is configured with data level 1, file B is configured with data level 2, file C is configured with data level 3, and file D is configured with data level 1, then the access object A can edit files A and D, and can display files B and C. By configuring the file data level for the target project file, the permission isolation can be performed on the data, and the flexible configuration of the access right of the target project file is realized, which further ensures the security of access to the target project file.
[0058] Reference Figure 6 , Figure 6 Another optional schematic diagram of the second access permission configuration provided by the embodiment of the present disclosure, Figure 6What is displayed is the fourth permission management page for configuring the second access permission for all access objects. The fourth permission management page displays authorized objects and all objects. The authorized objects include access objects with configured target access roles, and all objects include access objects with configured target access roles and access objects without configured target access roles. Access objects without configured target access roles can directly configure permissions on the fourth permission management page.
[0059] By configuring the file data level for the project file, fine-grained permission control can be performed on each project or project file to ensure that each access object can only access project files within the scope of their respective permission information, avoiding data damage that may be caused by multiple accesses. At the same time, it protects sensitive information from being accessed at will, further improving the security and stability of access to the target project file.
[0060] Step S204: In response to the request for permission to access the target project file, the target project file access service within the scope of the permission information is provided to the access object.
[0061] According to the above steps S201 to S203, the server responds to the request to access the target project file, verifies the first access right of the access object, and sends the target project file to the target application when the verification result of the first access right indicates that the access object is an authorized access object. Then, multiple access roles are pre-set in the server, and the second access right is configured for the access object according to the configured access role, and the permission information corresponding to the second access right is obtained, and the permission information is sent to the target application. The target application sends a request to the server to allow access to the target project file according to the permission information, and the server responds to the request and provides the access object with access services for the target project file within the scope of the permission information. Among them, the access service within the scope of the permission information includes the access service scope determined according to the file data level and the permission operation type. For example, file A is configured with data level 1, file B is configured with data level 2, and file C is configured with data level 1. The second access right of the access object is to edit files at data level 1, then the access service within the scope of the permission information corresponding to the access object is that files A and B can be accessed, but file C cannot be accessed.
[0062] In a possible implementation, when providing the access object with the access service of the target project file within the scope of the permission information, specifically, in response to the request for allowing access to the target project file, providing the access object with the access service of the target project file within the scope of the permission information, and transmitting the accessed target project file according to the first transmission protocol, so that the target project file is displayed in the browsing page of the target application. The first transmission protocol is used to transmit the target project file between the target application and the server, and may be a hypertext transfer protocol.
[0063] Specifically, the server responds to a request allowing access to the target project file, and the request allowing access to the target project file carries the second access permission of the access object. The file storage service of the server provides the access object with access services to the target project file within the scope of the permission information corresponding to the second access permission based on the second access permission of the access object, for example, an access port for accessing the target project file is opened to the access object, so that the target application can connect to the access port provided by the server. Next, the target project file is loaded from the security directory of the file storage service of the server, and the target project file is transmitted from the server to the target application through the network according to the first transmission protocol, and the target project file is displayed in the browsing page of the target application. Since the first transmission protocol allows the transmission of multiple types of data and can reduce network delay and bandwidth occupancy, the transmission of the target project file through the first transmission protocol can improve the response speed of the server and help improve the transmission efficiency of the target project file.
[0064] Furthermore, the server may also adopt a caching mechanism to cache project files in the memory area of the server. When the target project file that the access object needs to access is cached in the memory area, the target project file can be loaded directly from the memory area, thereby reducing the operation of repeatedly loading the target project file from the server's security directory and reducing the number of network requests, thereby effectively improving the response speed of the server and thereby improving the efficiency of accessing the target project file.
[0065] In a possible implementation, the first transmission protocol is combined with the second transmission protocol to encrypt and transmit the target project file. The second transmission protocol generates a first key during the transmission process. When the accessed target project file is transmitted according to the first transmission protocol, the first key may be obtained, the target project file is encrypted based on the first key, and the first encrypted data is obtained. The first encrypted data is transmitted to the target application, so that the target application decrypts the first encrypted data based on the first key to obtain the restored target project file. The first key is used to encrypt and transmit the target project file during the file transmission process, including a public key and a private key; the second transmission protocol is used to encrypt the transmitted target project file, which may be a secure socket layer protocol or a transport layer security protocol.
[0066] Specifically, the first key generated by the second transmission protocol during the transmission process is obtained, the target project file is encrypted based on the public key of the first key to obtain the first encrypted data, the first encrypted data is transmitted to the target application through the first transmission protocol, the target application decrypts the first encrypted data based on the private key of the first key to obtain the restored target project file, and the restored target project file is displayed in the browsing page of the target application. By using the second transmission protocol to encrypt the target project file, the transmission security of the target project file can be guaranteed. Even if the target project file is intercepted, information cannot be easily obtained from it, which effectively avoids the risk of leakage of the target project file.
[0067] In a possible implementation, in the process of obtaining the first key, it can be specifically responding to an access request sent by a target application, sending verification information to the target application for verification by the target application, the target application verifies the authentication certificate, and when the verification passes, randomly generates a third key, encrypts the third key according to the second key, obtains the second encrypted data, receives the second encrypted data sent by the target application, decrypts the second encrypted data, and obtains the restored third key. Among them, the access request carries a first random string, the first random string is randomly generated by the target application, and is used to generate the first key; the verification information carries information to be authenticated and a second random string, the information to be authenticated is information provided by the server for verifying the credibility of the server, including the second key and the authentication certificate, the second key is a public key provided by the server, and is used to encrypt the key generated by the target application, the authentication certificate is used to verify the identity of the server, and the second random string is randomly generated by the server and is used to generate the first key.
[0068] Specifically, the server responds to the access request sent by the target application, connects the target application to the server, and then sends the information to be authenticated and the second random string to the target application. The target application verifies the authentication certificate in the information to be authenticated, and when the verification passes, randomly generates a third key, encrypts the third key with the second key, obtains the second encrypted data, and sends the second encrypted data to the server. After receiving the second encrypted data, the server decrypts the second encrypted data with the private key corresponding to the second key to obtain the restored third key.
[0069] Next, a first key is generated based on the first random string, the second random string and the third key. Specifically, through the above steps, the target application and the server both hold the first random string, the second random string and the third key. The first key is generated in the target application and the server through a key generation function based on the first random string, the second random string and the third key, and the target project file is encrypted and transmitted based on the first key. Since the first random string, the second random string and the third key are all randomly generated by the target application or the server, the first key generated by the first random string, the second random string and the third key has high security and confidentiality, which effectively improves the security of the target project file during transmission.
[0070] It should also be noted that each time the target application establishes a connection with the connection server, a new first key will be regenerated according to the above steps. Even if the first key used in a certain transmission process is leaked, the encrypted data transmitted in other transmission processes will not be threatened, effectively avoiding the risk of large-scale interception or tampering of the transmitted data, and further improving the security of the target project files during transmission.
[0071] In addition, during the encrypted transmission of the target project file, the second transmission protocol can not only encrypt the target project file, but also provide a data protection mechanism, which can ensure that the target project file is not tampered with during the transmission process to protect the integrity of the transmitted data. If the target project file is modified during the transmission process, the target application or server as the recipient can compare the received target project file with the check value generated during the transmission process. When the comparison result shows that the check value is inconsistent with the received target project file, the target project file can be refused to be received, thereby preventing the recipient from abnormal attacks implanted in the middle.
[0072] It should also be noted that the operations of uploading the project file to the server and sending the target project file between the target application and the server mentioned in steps S201 to S203 are all encrypted transmission of the project file through the first transmission protocol and the second transmission protocol. The uploading process refers to the transmission process in step S204 and will not be repeated here.
[0073] In a possible implementation, when the application scenario of the embodiment of the present application is to access engineering project files, refer to Figure 7 , Figure 7 An optional overall process of the project file access method provided in the embodiment of the present disclosure.
[0074] First, the access object selects the project files to be uploaded through the target application, uploads the project files to the server through the first transmission protocol and the second transmission protocol, and saves the uploaded project files in the designated security directory of the server to ensure that all project files can be centrally stored and managed. In order to ensure the security of the project files stored in the server, security policies such as inbound and outbound rules, restricted open ports, and regular backup of stored project files are configured in the server. In addition, in order to further enhance the security of data storage and data transmission, the access object is only allowed to access the server through the intranet network address, and the external access is restricted by deploying the intranet environment to enhance the security of project files.
[0075] Next, the access object sends a request to access the target project file through the target application. The request carries the first access permission of the access object. After the server responds to the request, it verifies the first access permission in the database. When the verification result of the first access permission indicates that the access object can access the target project file, the target project file is extracted from the database, sent to the server for storage, and then the server sends the target project file to the target application.
[0076] Next, the administrator can preset the access role according to the specific content of the target project file and the work scope of the actual job position of the access object. For example, in an engineering project, the access role can be a project manager role, a production manager role, a surveying engineer role, a quality engineer role, a test engineer role, etc. In the fifth permission management page, a corresponding series of operation permissions are configured for the access role. The operation permission can be a system operation permission for the overall target project, such as viewing, editing, and deleting. Then, in the first permission management page, the access role is authorized to have entity data access permissions. When the access role is authorized to have entity data access permissions, the entity data access permissions corresponding to the access role can be configured on the third permission management page, specifically, the operation permissions for specific files, charts, and other entity data in the target project, such as display, details, addition, editing, deletion, authorization, document viewing, document creation, document modification, full control, etc.
[0077] When the access object is not currently configured with an access role, the administrator configures the corresponding access role for the access object and associates the login account of the access object with the configured access role. When the access role corresponding to the access object needs to be modified later, the access role associated with the login account of the access object can be flexibly adjusted according to the project requirements. It should also be noted that in the permission management page, in addition to configuring permissions for access roles, permissions can also be configured for other access objects that do not have access roles configured.
[0078] In addition, system operation permissions for the overall target project can be configured for the access object in the first permission management page, entity data access permissions can be authorized for the access object in the second permission management page, and entity data access permissions corresponding to the access object can be configured in the third permission management page.
[0079] In addition to configuring permissions for access roles and access objects, you can also configure and manage permissions for a project or project file, and configure specific access roles or specific access objects that can access a project or project file. Specifically, grant detailed permissions to a project or project file. For example, you can configure file data levels for entity data such as project files, tables, and example diagrams. By configuring different permissions for file data levels, and then configuring file data levels to different access roles and access objects, when the file data level configured by the access role or access object does not match the file data level of the project file, the project file cannot be operated on. Further permission isolation is performed on the data to achieve a highly flexible effect in the permission configuration of the project.
[0080] Next, the access role configured for the access object is sent to the server. Based on the access role, the server obtains the permission information corresponding to the access role from the database and sends the permission information to the target application. The target application verifies whether the access object is the corresponding access role or has the corresponding operation permission based on the permission information. When the access object is an access role that meets the conditions and has the corresponding operation permission, the access object is allowed to access the target project file. At this time, a request for access to the target project file is sent to the file storage service of the server. The file storage service responds to the request and provides the access object with access service to the target project file; when the access object is an access role that does not meet the conditions and does not have the corresponding operation permission, the access object is denied access to the target project file.
[0081] When the access object is an eligible access role and has the corresponding operation authority, the target project file is loaded from the secure directory of the server's file storage service, the target project file is encrypted based on the first key generated by the second transmission protocol, the target project file is transmitted over the network based on the first transmission protocol, the target project file is transmitted from the server to the target application, and the target project file is displayed in the Web page of the target application. In addition, the server can also use a cache mechanism to cache the project file to the server's memory area, so that the server can directly load the target project file from the memory area to reduce the server's repeated operations of reading the target project file from the secure directory, thereby speeding up the response speed of accessing the target project file.
[0082] In addition, administrators can dynamically modify the access roles and permissions of access objects in the permission management page, and record all permission change operations. The records are used for post-review and troubleshooting, and can also be used to improve permission configuration strategies. After the transmission is completed, the permission change records can be analyzed to help identify potential security vulnerabilities, inefficient operations, or permission allocations that do not comply with business processes. Historical permission configuration operations can also be analyzed to identify effective permission combinations and redundant permission combinations. The user behavior of access objects and the organization of access objects in the permission configuration log can also be statistically analyzed to recommend appropriate new access roles to administrators or make optimization suggestions for existing roles. In addition, a graphical interface can be developed based on the connection between access objects and permissions, so that non-technical personnel can also intuitively view and manage permission configurations.
[0083] The project file access method provided by the embodiment of the present disclosure uploads the project files to the server for centralized management, deploys an intranet to restrict external access, provides fine-grained permission control for the project files based on role configuration and file data level configuration, and adopts a combination of the first transmission protocol and the second transmission protocol to transmit the project files, so as to realize shared access to the target project files by each access object, effectively avoid the risk of leakage of the target project files, and thus improve the security and stability of access to the project files.
[0084] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate to describe the embodiments of the present disclosure, such as being able to be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0085] It should be understood that in the present disclosure, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0086] It should be understood that in the description of the embodiments of the present disclosure, the meaning of multiple (or multiple items) is more than two, greater than, less than, exceed, etc. are understood to not include the number, and above, below, within, etc. are understood to include the number.
[0087] In the several embodiments provided in the present disclosure, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0088] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0089] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0090] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the various embodiments of the present disclosure. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store program codes.
[0091] It should also be understood that the various implementations provided in the embodiments of the present disclosure can be combined arbitrarily to achieve different technical effects.
[0092] The above is a specific description of the preferred implementation of the present disclosure, but the present disclosure is not limited to the above-mentioned implementation mode. Technical personnel familiar with the field can also make various equivalent deformations or substitutions under the shared conditions without violating the spirit of the present disclosure. These equivalent deformations or substitutions are all included in the scope defined by the claims of the present disclosure.
Claims
1. A project file access method, characterized in that: include: In response to a request to access a target project file, verify a first access right of an access object, wherein an access request operation of the access object is executed in a target application; Sending the target project file to the target application based on the verification result of the first access right; configuring a second access permission for the access object, obtaining permission information corresponding to the second access permission, and sending the permission information to the target application, so that the target application sends a request for allowing access to the target project file according to the permission information; In response to the request for allowing access to the target project file, an access service to the target project file within the scope of the permission information is provided to the access object.
2. The project file access method according to claim 1, characterized in that: The configuring a second access right for the access object, obtaining permission information corresponding to the second access right, and sending the permission information to the target application so that the target application sends a request for allowing access to the target project file according to the permission information, includes: Configure a corresponding target access role for the access object, and record the role configuration operation, wherein the permission configuration operation is recorded in a permission configuration log; Determining the second access permission of the access object according to the configured target access role; The permission information corresponding to the second access permission is obtained, and the permission information is sent to the target application.
3. The project file access method according to claim 2, characterized in that: The permission configuration log also records the access object behavior pattern and the access object organizational structure. The configuration of the corresponding target access role for the access object includes: Analyze the access object behavior pattern and the access object organizational structure in the permission configuration log, and recommend new access roles based on the analysis results; The corresponding target access role is configured for the access object based on the new access role.
4. The project file access method according to claim 2, characterized in that: After configuring a corresponding target access role for the access object and recording the role configuration operation, the project file access method further includes: Modify the second access permission configured for the access object, and record the permission change operation, wherein the permission change operation is recorded in the permission configuration log; Analyze all the permission change operations in the permission configuration log, and evaluate the configuration of the second access permission of the access object according to the analysis result to obtain an evaluation result, wherein the evaluation result is used to indicate that the configuration of the second access permission of the access object is reasonable, or is used to indicate that the configuration of the second access permission of the access object is unreasonable; The configuration of the second access permission of the access object is adjusted according to the evaluation result.
5. The project file access method according to claim 4, characterized in that: Different access roles correspond to different role authority levels, and the modifying of the second access authority configured for the access object includes: Acquire the second access right corresponding to the target access role of the first access object, and acquire the second access right corresponding to the target access role of the second access object, wherein the role authority level of the target access role of the first access object is higher than that of the target access role of the second access object; When the permission selection of the first access object is through, the second access permission of the first access object is a permission set of the second access permission of the first access object and the second access permission of the second access object; When the permission of the first access object is not selected to be through, the second access permission of the first access object and the second access permission of the second access object are not changed; When the second access permission of the second access object does not exist, the second access permission of the first access object is used as the second access permission of the second access object.
6. The project file access method according to claim 2, characterized in that: The target project file is a plurality of project files, the second access permission further includes a file data level, and the determining the second access permission of the access object includes: Acquire the permission information configured for the access object, wherein the permission information includes a permission operation type; The file data level is configured for the target project file, the permission operation type is assigned to the file data level based on the permission information, and the second access permission of the access object is determined according to the file data level and the permission operation type.
7. The project file access method according to claim 1, characterized in that: The providing the access object with the access service of the target project file within the scope of the permission information includes: In response to a request for allowing access to the target project file, providing the access object with an access service to the target project file within the scope of the permission information; The accessed target project file is transmitted according to a first transmission protocol, so that the target project file is displayed on a browsing page of the target application.
8. The project file access method according to claim 7, characterized in that: The first transmission protocol is combined with the second transmission protocol to encrypt and transmit the target project file, the second transmission protocol generates a first key during the transmission process, and the accessed target project file is transmitted according to the first transmission protocol, including: Obtaining the first key; The target project file is encrypted based on the first key to obtain first encrypted data, and the first encrypted data is transmitted to the target application so that the target application decrypts the first encrypted data based on the first key to obtain the restored target project file.
9. The project file access method according to claim 8, characterized in that: The obtaining of the first key comprises: In response to an access request sent by the target application, verification information is sent to the target application for verification by the target application, wherein the access request carries a first random string, the verification information carries information to be authenticated and a second random string, and the information to be authenticated includes a second key and an authentication certificate; The target application verifies the authentication certificate, and when the verification passes, randomly generates a third key, and encrypts the third key according to the second key to obtain second encrypted data; receiving the second encrypted data sent by the target application, decrypting the second encrypted data, and obtaining the restored third key; The first key is generated based on the first random string, the second random string, and the third key.
10. An electronic device, characterized in that: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the project file access method according to any one of claims 1 to 9 when executing the computer program.
Citation Information
Patent Citations
Project design process management system
CN101556663A
Permission configuration method, permission configuration system and computer readable storage medium
CN111859442A
Project file management method and device, electronic equipment and storage medium
CN113343302A
Engineering information management system and method
CN116664065A
Data encryption system and method
US9800410B1