Role authorization method and device and authentication method and device
By defining the target role in the permission system and granting the target subject the role, the problem of cumbersome authorization operations in the existing technology is solved, automatic authorization and refined management are realized, and authorization efficiency and convenience of permission management are improved.
Patent Information
- Application Number
- CN202510362062.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-05-09
AI Technical Summary
When the existing permission system allocates business permissions, the administrator needs to grant each account one by one, which makes the authorization operation more troublesome.
By defining the target role and granting the target role to the target subject (such as account, organization, organization position, organization leader), it will have corresponding permissions and simplify authorization operations.
It realizes the authority to automatically have the corresponding target role when new members join the organization or hold an organization position, reduces the steps of additional applications and permission adjustments, and improves the efficiency of authorization and the convenience of authority management.
Smart Images

Figure CN119961896A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information technology and relates to a permission, and in particular to a role authorization method, device and authentication method, device. Background Art
[0002] With the deepening development of information systems, each field of society usually develops corresponding business information systems; for example, business information systems in the management field, business information systems in the audit field, etc. For any unit that uses a business information system, it is necessary to establish work accounts for each employee in the unit and allocate different business permissions according to the employee's job responsibilities.
[0003] The existing permission system for allocating business permissions provides authorization in the account dimension, usually by directly granting corresponding permissions to each account one by one through the administrator, which makes the authorization operation more troublesome. Summary of the invention
[0004] The purpose of this application is to provide a role authorization method, device and authentication method, device to solve the problems pointed out in the above background technology.
[0005] In a first aspect, the present application provides a role authorization method, which is applied to a permission system. The role authorization method includes: determining a target role that needs to be authorized; determining a target subject that needs to be authorized; receiving an authorization instruction to grant the target role to the target subject so that the target subject has the permission of the target role.
[0006] In this application, by defining a target role and granting the target role to a target subject, so that the target subject has the permissions of the target role, compared with the prior art of directly granting corresponding permissions to accounts one by one, the authorization operation becomes simple and quick.
[0007] In an implementation of the first aspect, the target subject includes at least any one of the following: an account, an organization; when the target subject is the organization, and after the target role is granted to the target subject, all members of the organization have the authority of the target role.
[0008] In this implementation, different target subjects are defined, that is, the target subject is not limited to an account, for example, it can also be an organization; specifically, by granting a target role to an organization, all members of the organization can have the authority of the target role. This method saves the trouble of authorizing roles to all members of the organization one by one, making role authorization simpler and also conducive to subsequent authority management.
[0009] In an implementation of the first aspect, when a member of the organization holds an organizational position and / or is the person in charge of the organization, if the target subject is the organizational position and after the target role is granted to the target subject, the member holding the organizational position has the authority of the target role; if the target subject is the person in charge of the organization and after the target role is granted to the target subject, the member holding the person in charge of the organization has the authority of the target role.
[0010] In this implementation, by defining the target subject as the organizational position / organization head, more refined role authorization management is achieved compared to when the target subject is the organization.
[0011] In an implementation of the first aspect, when the target subject is the organization position, determining the target subject that needs to be authorized includes: first determining the organization, and then determining the organization position; when the target subject is the organization head, determining the target subject that needs to be authorized includes: first determining the organization, and then determining the organization head.
[0012] In an implementation of the first aspect, before the step of receiving the authorization instruction, the role authorization method further includes: determining an authorization duration.
[0013] In this implementation, the authorization duration is set so that important permissions can be authorized for a short time.
[0014] In the second aspect, the present application provides a role authorization device, which is applied to a permission system, and the role authorization device includes: a first determination module, used to determine the target role that needs to be authorized; a second determination module, used to determine the target subject that needs to be authorized; a role authorization module, used to receive an authorization instruction to grant the target role to the target subject, so that the target subject has the permission of the target role.
[0015] In the third aspect, the present application provides an authentication method based on the above-mentioned role authorization method, which is applied to a permission system, and the authentication method includes: when the current user performs a target operation, querying all roles granted to the current user; determining whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles; when the judgment result is yes, the authentication passes, and the current user is allowed to perform the target operation; when the judgment result is no, the authentication fails, and the current user is prevented from performing the target operation.
[0016] In the present application, when there is a current user performing a target operation, the target operation is authenticated to determine whether the target operation is within the role authority of the current user to ensure the executability of the operation.
[0017] In an implementation of the third aspect, the querying of all roles granted to the current user includes: querying the first role of the current user authorized to the account; querying the second role of the current user authorized to the organization; querying the third role of the organizational position authorized to the current user; querying the fourth role of the organization's head authorized to the current user; the all roles include: the first role, the second role, the third role and the fourth role.
[0018] In an implementation of the third aspect, the querying of the second role of the organization authorized by the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the role of the current user authorized to the organization and the parent organization; the second role includes: the role of the current user authorized to the organization and the parent organization; and / or the querying of the third role of the organizational position authorized by the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the role of the organizational position authorized by the current user within the organization and the parent organization of the organization; the third role includes: the role of the organizational position authorized by the current user within the organization and the parent organization of the organization.
[0019] In a fourth aspect, the present application provides an authentication device based on the above-mentioned role authorization method, which is applied to a permission system, and the authentication device includes: a query module, which is used to query all roles granted to the current user when the current user performs a target operation; a judgment module, which is used to judge whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles; an authentication module, which is used to authenticate when the judgment result is yes and allow the current user to perform the target operation; when the judgment result is no, the authentication fails and prevents the current user from performing the target operation.
[0020] As described above, the role authorization method, device and authentication method and device described in this application have the following beneficial effects:
[0021] (1) Compared with the prior art, the present application targets organizations and organizational positions, and through pre-setting corresponding target roles, can achieve that when a new member joins the organization or takes up a position in the organization, the new member automatically has the target role corresponding to the organization or the position in the organization, without the need for the new member to apply for an additional role, and can have the authority of the target role, so as to quickly enter the working status; at the same time, when the new member makes changes within the organization, there is no need to make additional authority adjustments.
[0022] (2) This application is targeted at the head of the organization. By pre-setting the corresponding target role, when the organization subsequently changes the head of the organization, the new head of the organization automatically has the permissions of the target role without having to apply for permissions, and the administrator does not need to actively revoke the permissions of the old head of the organization.
[0023] (3) This application can implement role authorization for a single account, so as to enable refined management of important permissions.
[0024] (4) This application implements structured management by authorizing roles for accounts, organizations, organizational positions, and organizational leaders. By structuring the authorization information, the authorization steps are greatly simplified to facilitate permission management. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 Shown is a flowchart of the role authorization method described in an embodiment of the present application.
[0026] Figure 2 Shown is a schematic diagram of the structure of the role authorization device described in an embodiment of the present application.
[0027] Figure 3 Shown is a flow chart of the authentication method described in an embodiment of the present application.
[0028] Figure 4 Shown is a schematic diagram of the structure of the authentication device described in an embodiment of the present application. DETAILED DESCRIPTION
[0029] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.
[0030] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed at will, and the component layout may also be more complicated.
[0031] See also Figures 1 to 4. The following embodiments of the present application provide a role authorization method, device and authentication method, device. Compared with the prior art, the present application is aimed at organizations and organizational positions. Through the corresponding pre-set target roles, when a new member joins the organization or takes up a position in the organization, the new member automatically has the target role corresponding to the organization or the organizational position, and the new member does not need to apply for an additional role to have the authority of the target role, so as to quickly enter the working state; at the same time, when the new member changes within the organization, there is no need to make additional authority adjustments; the present application is aimed at the head of the organization. Through the corresponding pre-set target roles, when the organization replaces the head of the organization, the new head of the organization automatically has the authority of the target role without applying for authority, and the administrator does not need to actively recover the authority of the old head of the organization; the present application can realize role authorization for a single account, so as to carry out refined management of important permissions; the present application realizes structured management by performing role authorization on accounts, organizations, organizational positions and heads of organizations, and by structuring the authorization information, the authorization steps are greatly simplified to facilitate authority management.
[0032] The explanations of the professional terms appearing in this application are as follows:
[0033] (1) Account: Users use their accounts to access and operate the system.
[0034] (2) Organization: A group of users who collaborate with each other to achieve certain goals. Within a company, it can be divided into administrative organizations managed by personnel and virtual organizations created for permission management. An organization can have members, sub-organizations, and organization leaders. Members are represented as accounts in the permission system.
[0035] Examples:
[0036] The "Sales Department" is an administrative organization managed by personnel management, and new salespeople will be hired into the Sales Department.
[0037] "xx Project Group" is a virtual organization created to achieve the same goal and facilitate similar authority management.
[0038] (3) Position: refers to the specific duties and powers held by a user in an organization.
[0039] (4) Permission: Permission refers to a user's access to or permission to operate specific resources and functions in the system.
[0040] (5) Role: A role is a collection of permissions, which means that a role has permission to access multiple functional points.
[0041] Examples:
[0042] The "Account Administrator" role has permission to access the "Create Account", "Modify Account", "Query Account", and "Delete Account" functions.
[0043] (6) Authorization: When an administrator grants a role to a subject (account / organization / organization position / organization leader), the subject will then have the permissions corresponding to the role.
[0044] Case 1: The administrator grants the "Inventory Administrator" role to the "Zhang San" account, so Zhang San can query inventory information.
[0045] Case 2: The administrator grants the "Inventory Administrator" role to the "Logistics Support" department. Li Si is an employee of the Logistics Support Department, so Li Si can query inventory information. Wang Wu, as a new employee joining the Logistics Support Department, automatically has the permission to query inventory information without the administrator's additional operation.
[0046] The technical solutions in the embodiments of the present application will be described in detail below in conjunction with the drawings in the embodiments of the present application.
[0047] like Figure 1 As shown, in one embodiment, the present application provides a role authorization method, which is applied to a permission system, and the role authorization method includes:
[0048] Step S11: Determine the target role that needs to be authorized.
[0049] It should be noted that the role (ie, target role) in the permission system is a collection of permissions; specifically, multiple specific system permissions are packaged to form a logical unit to simplify the management and allocation of permissions.
[0050] In this embodiment, the target role is pre-set so that the corresponding target role can be directly granted to the target subject later, so that the target subject directly possesses a series of permissions of the target role.
[0051] Step S12: Determine the target entity to be authorized.
[0052] It should be noted that by defining the target subject and then granting the target role to the target subject, the target subject can directly possess the permissions of the target role; the target subject is not limited to an account, as described below, it can also be an organization, an organizational position or an organization leader. Compared with the prior art, which can only authorize accounts, the versatility of permission management is improved, and at the same time, it can simplify the authorization steps and facilitate subsequent permission management.
[0053] Step S13: receiving an authorization instruction to grant the target role to the target subject so that the target subject has the authority of the target role.
[0054] In one embodiment, the target subject includes at least but is not limited to any one of the following: an account, an organization.
[0055] Specifically, when the target subject is the organization, and after the target role is granted to the target subject, all members of the organization have the authority of the target role.
[0056] It should be noted that for companies of a slightly larger scale, due to the large number of employees, it is obviously difficult for the administrator to authorize each account, and it is also not conducive to the subsequent permission management. In this embodiment, by authorizing the organization to a role, all members of the organization can have the permissions of the target role, thereby eliminating the trouble of authorizing roles to all members of the organization one by one, thereby improving the authorization efficiency. Moreover, if a new member joins the organization, he or she can also automatically obtain the permissions of the corresponding target role without having to apply for additional permissions. Similarly, if a member leaves the organization, the member automatically no longer has the permissions of the corresponding target role.
[0057] In one embodiment, after the target role is granted to the target subject, the role authorization method further includes: recording the corresponding relationship between the target subject and the target role.
[0058] Specifically, the correspondence between the target subject and the target role is recorded in the permission system.
[0059] For example, if the target subject is an account, the correspondence between the account and the corresponding target role will be recorded; if the target subject is an organization, similarly, the correspondence between the organization and the corresponding target role will be recorded; when the target subject is an organizational position or an organizational person in charge, the working principle is the same, so it will not be described in detail later.
[0060] Specifically, after the target role is granted to an organization, the correspondence between the organization and the corresponding target role will be recorded in the permission system. Correspondingly, all members of the organization will have the permissions of the target role, but the correspondence between all members of the organization and the target role will not be recorded in the permission system.
[0061] For example, in one embodiment, an organization is a "Technology Center", and there is a member named "Zhang San" in the "Technology Center" (in addition to "Zhang San", there are other members); specifically, after the "Development" role is granted to the "Technology Center", all members in the "Technology Center" have the authority corresponding to the target role of "Development", but only the corresponding relationship between "Technology Center" and "Development" will be recorded in the permission system.
[0062] In one embodiment, when the target subject is an organization and a new member joins the organization, the target role granted to the organization is queried, and the new member has the authority of the target role granted to the organization.
[0063] Specifically, when a new member joins an organization that is granted a corresponding target role, since the corresponding relationship between the organization and the target role is recorded in the permission system, it can be determined through query that the new member will automatically have the permissions of the target role.
[0064] In one embodiment, a tissue includes at least one sub-tissue.
[0065] Specifically, the organization is the parent organization of the sub-organization.
[0066] Similarly, a sub-organization can also include at least one subordinate organization (the parent organization of the subordinate organization is the sub-organization)...
[0067] For example, in one embodiment, an organization is a "Technology Center", and the "Technology Center" has a sub-organization "Development Group 1", and "Development Group 1" has a member named "Zhang San"; specifically, after the "Development" role is granted to the "Technology Center", only the corresponding relationship between "Technology Center" and "Development" will be recorded in the permission system, that is, there is no corresponding relationship between "Development Group 1" and "Development", and "Zhang San" and "Development".
[0068] In one embodiment, when the target subject is an organization and a new member joins the organization, the target role granted to the organization (i.e., the organization to which the new member belongs) and the parent organization of the organization are queried, and the new member has the permissions of the target role granted to the organization and the parent organization of the organization.
[0069] It should be noted that when a new member enters "Development Group 1", first, it is determined that the new member belongs to "Development Group 1", and then the parent organization "Technology Center" of "Development Group 1" is queried; finally, by querying the corresponding relationship between "Technology Center" and "Development", it is determined that the new member has the authority corresponding to the "Development" role (the same working principle as querying the second role authorized by the current user to the organization during the authentication operation performed on the current user through the authentication method described below).
[0070] In one embodiment, the above-mentioned “parent organization of an organization” includes at least the first-level parent organization of the organization.
[0071] In one embodiment, the parent organization of the organization includes not only the first-level parent organization of the organization, but also the second-level parent organization (i.e., the parent organization of the first-level parent organization), the third-level parent organization (i.e., the parent organization of the second-level parent organization), and so on until the top-level organization.
[0072] For example, in one embodiment, a first-level organization is a "sales center department", and the "sales center department" has a second-level child organization "East China Sales Group", and the "East China Sales Group" has a third-level subordinate organization "Shanghai Sales Group". When a new member joins the "Shanghai Sales Group", the target role granted to the "Shanghai Sales Group", the first-level parent organization "East China Sales Group" of the "Shanghai Sales Group", and the second-level parent organization of the "Shanghai Sales Group" - the parent organization "Sales Center Department" of the "East China Sales Group" are queried, thereby determining the permissions of the target role possessed by the new member (the same working principle as querying the second role of the organization authorized by the current user during the authentication operation performed on the current user through the authentication method described below).
[0073] It should be noted that the following working principle when the target subject is an organizational position and a new member joins and takes up the position in the organization is the same as the above-mentioned working principle when a new member joins the organization (that is, the corresponding target subject is the organization), so it will not be repeated in detail later.
[0074] In one embodiment, when a member of the organization holds an organizational position and / or is the person in charge of the organization, if the target subject is the organizational position and the target role is granted to the target subject, the member holding the organizational position has the authority of the target role; if the target subject is the person in charge of the organization and the target role is granted to the target subject, the member holding the person in charge of the organization has the authority of the target role.
[0075] It should be noted that in this embodiment, when a member holding an organizational position is granted a corresponding target role, once the member holding the organizational position leaves the organization, he or she will no longer have the authority of the corresponding target role; similarly, if the member holding the organizational position no longer holds the organizational position, he or she will no longer have the authority of the corresponding target role.
[0076] In one embodiment, under the same organization, there may be different organizational positions, and for different organizational positions, the corresponding target roles granted may be the same or different.
[0077] In one embodiment, the same organizational position may exist in different organizations. By granting the corresponding target role to the organizational position, the same organizational position in different organizations can have the authority of the corresponding target role at the same time.
[0078] Similarly, in this embodiment, when a member who serves as the head of an organization is granted the corresponding target role, once the member no longer serves as the head of the organization, he or she will no longer have the authority of the corresponding target role; and when a new member serves as the head of the organization, he or she will automatically have the authority of the target role without the need for additional application.
[0079] In one embodiment, under the same organization, there may be different organization heads, and for different organization heads, the corresponding target roles granted may be the same or different.
[0080] In one embodiment, the same organization head may exist in different organizations. By granting the corresponding target role to the organization head, the same organization head in different organizations can have the authority of the corresponding target role at the same time.
[0081] In one embodiment, when the target subject is the organizational position, determining the target subject to be authorized includes: first determining the organization, and then determining the organizational position.
[0082] In one embodiment, when the target subject is the person in charge of the organization, determining the target subject to be authorized includes: first determining the organization, and then determining the person in charge of the organization.
[0083] In one embodiment, before the step of receiving the authorization instruction, the role authorization method further includes: determining the authorization duration.
[0084] It should be noted that by setting the authorization duration, important permissions can be authorized for a short period of time.
[0085] The role authorization method of the present application is further explained below through specific embodiments.
[0086] Embodiment 1:
[0087] All employees under certain organizations within a company have similar job responsibilities, and their accounts usually need to have similar permissions.
[0088] For example, all employees in the sales department need to have common sales-related permissions. Employees in both sales group 1 and sales group 2 need permissions to query inventory, create sales orders, and perform other operations. Specifically, the sales department (corresponding organization) is taken as the target subject, and the role corresponding to permissions for operations such as querying inventory and creating sales orders is taken as the target role. By granting the target role to the target subject, all employees in the sales department can have permissions for operations such as querying inventory and creating sales orders.
[0089] Embodiment 2:
[0090] There are employees with the same position in multiple organizations within a company, and the accounts of these employees usually need to have similar permissions.
[0091] For example, the sales department, technology department, and product department all have employees holding HRBP positions, and all HRBPs require some personnel-related operational permissions. Specifically, the HRBP position (corresponding to the organizational position) is taken as the target subject, and the role corresponding to the personnel-related operational permissions is taken as the target role. By granting the target role to the target subject, all employees holding HRBP positions in the sales department, technology department, and product department can have personnel-related operational permissions.
[0092] Embodiment 3:
[0093] Usually, the organizational responsibilities within a company are relatively fixed, so the required authority is also relatively fixed, but the person in charge of the organization will change frequently.
[0094] For example, the permissions possessed by the head of the sales department will not change as the head changes; specifically, the head of the sales department (corresponding to the head of the organization) is taken as the target subject, and the role corresponding to the permissions possessed by the head is taken as the target role. By granting the target role to the target subject, the head of the sales department can have the corresponding permissions. When the head of the sales department changes, the changed head will automatically have the corresponding permissions, and the changed head does not need to apply for additional permissions.
[0095] The protection scope of the role authorization method described in the embodiment of the present application is not limited to the execution order of the steps listed in this embodiment. All solutions implemented by adding, reducing or replacing steps in the prior art based on the principles of the present application are included in the protection scope of the present application.
[0096] An embodiment of the present application also provides a role authorization device, which can implement the role authorization method described in the present application. However, the implementation device of the role authorization method described in the present application includes but is not limited to the structure of the role authorization device listed in this embodiment. All structural deformations and replacements of the prior art made according to the principles of the present application are included in the protection scope of the present application.
[0097] like Figure 2 As shown, in one embodiment, the present application provides a role authorization device, which is applied to a permission system, and the role authorization device includes:
[0098] The first determining module 21 is used to determine the target role that needs to be authorized.
[0099] The second determining module 22 is used to determine the target subject to be authorized.
[0100] The role authorization module 23 is used to receive an authorization instruction to grant the target role to the target subject so that the target subject has the authority of the target role.
[0101] It should be noted that the structures and principles of the first determination module 21, the second determination module 22 and the role authorization module 23 correspond one-to-one to the steps (steps S11 to S13) in the above-mentioned role authorization method, and their specific working principles can also be referred to the introduction to the role authorization method in the above-mentioned embodiment, so they will not be repeated here.
[0102] like Figure 3 As shown, in one embodiment, the present application also provides an authentication method based on the above-mentioned role authorization method, which is applied to a permission system, and the authentication method includes:
[0103] Step S31: When the current user performs a target operation, query all roles granted to the current user.
[0104] In one embodiment, querying all roles granted to the current user includes:
[0105] Step S311: Query the first role authorized by the current user to the account.
[0106] Step S312: Query the second role that the current user is authorized to the organization.
[0107] In one embodiment, querying the second role of the organization authorized by the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the roles authorized by the current user to the organization and the parent organization; the second role includes: the roles authorized by the current user to the organization and the parent organization.
[0108] In one embodiment, the parent organization of the organization to which the owner belongs includes at least a first-level parent organization of the organization to which the owner belongs.
[0109] In one embodiment, the parent organization of the organization includes not only the first-level parent organization of the organization, but also the second-level parent organization (i.e., the parent organization of the first-level parent organization), the third-level parent organization (i.e., the parent organization of the second-level parent organization), and so on until the top-level organization.
[0110] It should be noted that the query of the roles authorized by the current user to the organization and the parent organization in step S312 is the same as the working principle when a new member joins the organization, so it will not be repeated here.
[0111] It should be noted that the working principle of the following step S313 is the same as that of step S312, so it will not be described in detail later.
[0112] Step S313: query the third role of the organization position authorized by the current user.
[0113] In one embodiment, the querying of the third role of the organizational position authorized to the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the role of the organizational position authorized to the current user within the organization to which the current user belongs and the parent organization of the organization; the third role includes: the role of the organizational position authorized to the current user within the organization to which the current user belongs and the parent organization of the organization.
[0114] Step S314: query whether the current user is authorized to be the fourth role of the organization leader.
[0115] In this embodiment, all the roles include: the first role, the second role, the third role, and the fourth role.
[0116] It should be noted that the execution order of the above-mentioned steps S311 to S314 is not a condition to limit the present application. In actual applications, they can be executed in sequence or simultaneously. When executed in sequence, which step is executed first and which step is executed later is also not a condition to limit the present application.
[0117] The working principle of step S31 is further explained below through a specific embodiment.
[0118] In one embodiment, an organization is a "Technology Center", and the "Technology Center" has a sub-organization "Development Group 1", and "Development Group 1" has a member named "Zhang San"; through the above-mentioned role authorization method, the "Technology Center" is granted the target role of "Development".
[0119] Specifically, when "Zhang San" performs the target operation as the current user, all roles granted to "Zhang San" are queried; as mentioned above, in the permission system, only the corresponding relationship such as "Technical Center" - "Development" is recorded, so, after querying through steps S311 to S314, only the role authorized by "Zhang San" to the parent organization "Technical Center" can be queried in step S312, that is, the "Development" role, so, in the end, all roles granted to "Zhang San" are "Development" roles.
[0120] It should be noted that, in this embodiment, the organization to which "Zhang San" belongs is "Development Group 1", and the parent organization of "Development Group 1" is "Technology Center"; in actual applications, the "parent organization of the organization to which he belongs" is not limited to only one level. For example, in the above embodiment, when "Li Si", a member of the "Shanghai Sales Group", performs the corresponding target operation as the current user, in step S312, it will be queried whether the organization "Shanghai Sales Group" to which "Li Si" belongs, the first-level parent organization "East China Sales Group" of the organization "Shanghai Sales Group", and the second-level parent organization of the organization "Shanghai Sales Group" - the parent organization "Sales Center Department" of the "East China Sales Group" have the target permissions corresponding to the target operation.
[0121] Step S32: Determine whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles.
[0122] Step S33: When the judgment result is yes, the authentication is passed, and the current user is allowed to perform the target operation; when the judgment result is no, the authentication is not passed, and the current user is prevented from performing the target operation.
[0123] It should be noted that, in this embodiment, when the current user performs a target operation, the target operation is authenticated to determine whether the target operation is within the role authority of the current user to ensure the executability of the operation.
[0124] The protection scope of the authentication method described in the embodiment of the present application is not limited to the execution order of the steps listed in the present embodiment. All solutions implemented by adding, reducing or replacing steps in the prior art based on the principles of the present application are included in the protection scope of the present application.
[0125] The embodiment of the present application also provides an authentication device, which can implement the authentication method described in the present application. However, the implementation device of the authentication method described in the present application includes but is not limited to the structure of the authentication device listed in the present embodiment. All structural deformations and replacements of the prior art made according to the principles of the present application are included in the protection scope of the present application.
[0126] like Figure 4 As shown, in one embodiment, the present application also provides an authentication device based on the above-mentioned role authorization method, which is applied to a permission system, and the authentication device includes:
[0127] The query module 41 is used to query all roles granted to the current user when the current user performs a target operation.
[0128] The judgment module 42 is used to judge whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles.
[0129] The authentication module 43 is used to, when the judgment result is yes, pass the authentication and allow the current user to perform the target operation; when the judgment result is no, fail the authentication and prevent the current user from performing the target operation.
[0130] It should be noted that the structures and principles of the query module 41, the judgment module 42 and the authentication module 43 correspond one-to-one to the steps in the above-mentioned authentication method (steps S31 to S33), and their specific working principles can also be referred to the introduction of the authentication method in the above-mentioned embodiment, so they will not be repeated here.
[0131] In the several embodiments provided in the present application, it should be understood that the disclosed system, device or method can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules / units is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules or units, which can be electrical, mechanical or other forms.
[0132] The modules / units described as separate components may or may not be physically separated, and the components displayed as modules / units may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules / units may be selected according to actual needs to achieve the purpose of the embodiments of the present application. For example, the functional modules / units in the various embodiments of the present application may be integrated into one processing module, or each module / unit may exist physically separately, or two or more modules / units may be integrated into one module / unit.
[0133] Those of ordinary skill in the art should further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0134] The descriptions of the processes or structures corresponding to the above-mentioned figures have different emphases. For parts that are not described in detail in a certain process or structure, please refer to the relevant descriptions of other processes or structures.
[0135] The above embodiments are merely illustrative of the principles and effects of the present application and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.
Claims
1. A role authorization method, applied to a permission system, characterized in that: The role authorization method includes: Identify the target roles that need to be authorized; Determine the target entity that needs to be authorized; An authorization instruction is received to grant the target role to the target subject so that the target subject has the authority of the target role.
2. The role authorization method according to claim 1, characterized in that: The target subject includes at least any one of the following: an account, an organization; When the target subject is the organization and the target role is granted to the target subject, all members of the organization have the authority of the target role.
3. The role authorization method according to claim 2, characterized in that: When a member of the said organization holds an organizational position and / or is the head of the organization, If the target subject is the organizational position, and after the target role is granted to the target subject, the member holding the organizational position has the authority of the target role; If the target subject is the person in charge of the organization, and after the target role is granted to the target subject, the member who serves as the person in charge of the organization has the authority of the target role.
4. The role authorization method according to claim 3 is characterized in that: When the target subject is the organizational position, determining the target subject to be authorized includes: first determining the organization, and then determining the organizational position; When the target subject is the person in charge of the organization, determining the target subject to be authorized includes: first determining the organization, and then determining the person in charge of the organization.
5. The role authorization method according to any one of claims 1 to 4, characterized in that: Before the step of receiving the authorization instruction, the role authorization method further includes: determining the authorization duration.
6. A role authorization device, applied to a permission system, characterized in that: The role authorization device comprises: The first determination module is used to determine the target role that needs to be authorized; The second determination module is used to determine the target subject to be authorized; The role authorization module is used to receive an authorization instruction to grant the target role to the target subject so that the target subject has the authority of the target role.
7. An authentication method based on the role authorization method according to any one of claims 1 to 5, applied to a permission system, characterized in that: The authentication method comprises: When the current user performs the target operation, query all roles granted to the current user; Determine whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles; When the judgment result is yes, the authentication is passed, and the current user is allowed to perform the target operation; when the judgment result is no, the authentication is not passed, and the current user is prevented from performing the target operation.
8. The authentication method according to claim 7, characterized in that: The query of all roles granted to the current user includes: Query the first role authorized by the current user to the account; Query the second role that the current user is authorized to the organization; Query the third role that the current user is authorized to the organizational position; The fourth role of the organization leader authorized by the current user is queried; the all roles include: the first role, the second role, the third role and the fourth role.
9. The authentication method according to claim 8, characterized in that: The querying the second role of the organization authorized by the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the roles of the organization to which the current user belongs and the parent organization; the second role includes: the roles of the organization to which the current user belongs and the parent organization; and / or The querying of the third role of the organizational position authorized to the current user includes: querying the organization to which the current user belongs and the parent organization of the organization; obtaining the role of the organizational position authorized to the current user within the organization to which the current user belongs and the parent organization of the organization; the third role includes: the role of the organizational position authorized to the current user within the organization to which the current user belongs and the parent organization of the organization.
10. An authentication device based on the role authorization method according to any one of claims 1 to 5, applied to a permission system, characterized in that: The authentication device comprises: A query module, used to query all roles granted to the current user when the current user performs a target operation; A judgment module, used to judge whether the target permission corresponding to the target operation is within the permission range corresponding to all the roles; An authentication module, used for, when the judgment result is yes, authentication is passed and the current user is allowed to perform the target operation; When the judgment result is no, the authentication fails, and the current user is prevented from performing the target operation.
Citation Information
Patent Citations
Method for managing user purview and judging user operation validity
CN101232694A
Authority management method and device
CN111475784A
User authority setting system, setting method and recording medium thereof
CN1558354A