Permission data processing method and device for distributed database
By querying metadata tables in distributed databases, establishing intermediate tables, and performing multiple permission analysis processing, the problem of complex user rights in distributed databases is solved, and fine permission management and data processing support is realized.
Patent Information
- Application Number
- CN202510090986.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-13
AI Technical Summary
In financial business scenarios, distributed databases have many users and complex permissions, and it is difficult to sort out user permissions in a comprehensive and detailed manner, which affects data processing such as permission recovery, overprivileged detection and system migration.
By querying the metadata table of the target distributed database, the user's explicit permission data is obtained and the intermediate table is established; combining the inherited relationship data between users, preset permission analysis processing rules are used to perform multiple hierarchical permission analysis processing to determine the user's implicit permission data; finally, based on the explicit and implicit permission data, a detailed list of user permission relationships is established.
In the big data scenario, it realizes that users' relevant permissions to distributed databases are comprehensively and meticulously determined to avoid omissions, and supports subsequent data processing such as permission recovery, overprivileges detection and system migration.
Smart Images

Figure CN119989414A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of big data technology, and more particularly to a method and device for processing permission data of a distributed database. Background Art
[0002] In financial business scenarios, the data processing systems of trading institutions such as banks involve a large number of systems and complex data dependencies between systems, resulting in the corresponding distributed databases having characteristics such as a large number of users and complex authority relationships.
[0003] Based on existing methods, it is often difficult to comprehensively and meticulously sort out the user rights of each user on a distributed database, which in turn affects subsequent data processing such as permission recovery, unauthorized detection, and system migration.
[0004] To address the above problems, no effective solution has been proposed yet. Summary of the invention
[0005] This specification provides a method and device for processing permission data of a distributed database, which can be well adapted to big data scenarios with huge data volumes and complex relationships, and comprehensively and precisely determine the user's relevant user permissions on the target distributed database.
[0006] This specification provides a method for processing permission data in a distributed database, including:
[0007] Querying the metadata table of the target distributed database to obtain explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes permission data of the user on the data object of the target distributed database based on SQL explicit authorization;
[0008] According to the explicit permission data, a corresponding intermediate table is established; and inheritance relationship data between users is obtained;
[0009] According to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processing to determine the user's implicit permission data on the target distributed database based on inheritance implicit authorization; wherein the implicit permission data includes the user's permission data on the data object of the target distributed database based on inheritance implicit authorization;
[0010] According to the implicit permission data, implicit association information about the implicit permission data is determined; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method;
[0011] A user permission relationship detail table of a target distributed database is established based on explicit permission data, implicit permission data, and implicit association information.
[0012] In one embodiment, the data object includes at least one of the following: a schema, a table, a tablespace, a view;
[0013] Correspondingly, the user permission relationship details table includes at least one of the following: a user permission relationship details table regarding the model of the target distributed database, a user permission relationship details table regarding the table of the target distributed database, a user permission relationship details table regarding the table space of the target distributed database, and a user permission relationship details table regarding the view of the target distributed database.
[0014] In one embodiment, according to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processing, including:
[0015] According to the preset permission resolution processing rules, the current permission resolution processing is performed in the following manner:
[0016] Get the last updated intermediate table as the current intermediate table;
[0017] Based on the current intermediate table, a user node that does not currently have a parent node is determined as the current level node;
[0018] According to the user ID and inheritance relationship data corresponding to the node of the current level node, traverse the current intermediate table to determine the child nodes of the current level node;
[0019] According to the permission data of the current level node, the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes are determined;
[0020] According to the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes, the relevant data in the current intermediate table is updated; and the permission data of the current level node is removed from the current intermediate table to obtain the updated intermediate table of the current time.
[0021] In one embodiment, after obtaining the currently updated intermediate table, the method further includes:
[0022] Check whether there is a user node without a parent node in the intermediate table after the current update;
[0023] When it is determined that there is no user node without a parent node in the intermediate table after the current update, the multiple level-by-level authority resolution processes are terminated;
[0024] Obtain and determine the user's implicit permission data based on inherited implicit authorization on the target distributed database according to the permission data of each current user node.
[0025] In one embodiment, after establishing the user authority relationship detail table for the target distributed database, the method further includes:
[0026] Receiving a permission recovery request for a target user; wherein the permission recovery request carries at least a user identifier of the target user;
[0027] In response to the permission recovery request, query the user permission relationship table according to the user identifier of the target user to obtain the target permission data directly and indirectly related to the target user;
[0028] Based on the target permission data, build a user permission traceability chain diagram for the target user;
[0029] According to the user permission tracing chain diagram of the target user, relevant permission recovery operations are performed.
[0030] In one embodiment, after establishing the user authority relationship detail table for the target distributed database, the method further includes:
[0031] Receiving an unauthorized risk detection request for a target user group; wherein the unauthorized risk detection request carries at least a group identifier of the target user group;
[0032] In response to the unauthorized risk detection request, query the inheritance relationship data between users according to the group identifier of the target user group, and determine the user identifiers of multiple users belonging to the target user group;
[0033] According to the user IDs of multiple users, query the user authority relationship detail table to obtain the authority data of multiple users;
[0034] Based on the permission data of multiple users, a target knowledge graph about the permission relationship of the target user group is constructed;
[0035] Based on the target knowledge graph, detect whether the target user group has the risk of exceeding authority.
[0036] In one embodiment, after establishing the user authority relationship detail table for the target distributed database, the method further includes:
[0037] Receiving a system split request for a target distributed cluster of a target distributed database; wherein the target distributed cluster includes a plurality of physical subsystems;
[0038] In response to the system splitting request, obtaining data objects of the target distributed database and storage information of user data of each physical subsystem in the target distributed cluster;
[0039] According to the user authority relationship details table and the storage information, determine the data objects of the target distributed database and the system authority relationship table of the user data of each physical subsystem in the target distributed cluster;
[0040] Determine the dependency relationship between physical subsystems based on the system authority relationship table and user authority relationship detail table;
[0041] According to the dependency relationship between the physical subsystems, multiple physical subsystems in the target distributed cluster are divided into multiple system groups; wherein each system group includes multiple physical subsystems with direct or indirect dependency relationship, and there is no dependency relationship between different system groups.
[0042] In one embodiment, after dividing the multiple physical subsystems in the target distributed cluster into multiple system groups, the method further includes:
[0043] Receive and respond to a system migration instruction for a target distributed cluster, and perform matching migration operations on multiple system groups in the target distributed cluster.
[0044] This specification also provides a distributed database authority data processing device, including:
[0045] A query module, used to query the metadata table of the target distributed database, and obtain the explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes the permission data of the user on the data object of the target distributed database based on SQL explicit authorization;
[0046] The first processing module is used to establish a corresponding intermediate table according to the explicit permission data; and obtain inheritance relationship data between users;
[0047] The second processing module is used to perform multiple level-by-level permission parsing processes according to a preset permission parsing processing rule, jointly using the intermediate table and the inheritance relationship data between users, and determine the user's implicit permission data based on inheritance implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data on the data object of the target distributed database based on inheritance implicit authorization;
[0048] A determination module, used to determine implicit association information about the implicit authority data according to the implicit authority data; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method;
[0049] A module is established to establish a user authority relationship detail table about a target distributed database according to explicit authority data, implicit authority data, and implicit association information.
[0050] The present specification also provides a computer-readable storage medium on which computer instructions are stored. When the instructions are executed by a processor, the relevant steps of the method for processing permission data of the distributed database are implemented.
[0051] Based on the permission data processing method and device of the distributed database provided in this specification, the user's explicit permission data on the target distributed database can be obtained by querying the metadata table of the target distributed database, and the corresponding intermediate table can be established; at the same time, the inheritance relationship data between users can be obtained; then according to the preset permission parsing processing rules, the intermediate table and the inheritance relationship data between users are used in combination, and the implicit permission data based on inheritance implicit authorization of each user on the target distributed database is determined layer by layer by performing multiple layer-by-layer permission parsing processes; and the corresponding implicit association information is determined according to the implicit permission data; then according to the explicit permission data, the implicit permission data, and the implicit association information, a user permission relationship detailed table about the target distributed database is established. Thus, it can be better adapted to the big data scenario with huge data volume and complex permission relationship, and the relevant user permissions of each user on the target distributed database can be determined comprehensively and finely to avoid omissions. Then, based on the above-mentioned user permission relationship detailed table, the dependency relationship between the physical subsystems in the target distributed cluster of the target distributed database can be more accurately determined, and relevant data processing such as permission recovery, unauthorized detection, and system migration can be accurately realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. The drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0053] Figure 1 It is a flowchart of a method for processing authority data of a distributed database provided by an embodiment of this specification;
[0054] Figure 2 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0055] Figure 3It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0056] Figure 4 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0057] Figure 5 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0058] Figure 6 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0059] Figure 7 It is a schematic diagram of the structure of a server provided by an embodiment of this specification;
[0060] Figure 8 It is a schematic diagram of the structure of a permission data processing device of a distributed database provided by an embodiment of this specification;
[0061] Fig. 9 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0062] Fig.10 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0063] Fig.11 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example;
[0064] Fig.12 It is a schematic diagram of an embodiment of a method for processing authority data of a distributed database provided by an embodiment of this specification, in a scenario example. DETAILED DESCRIPTION
[0065] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.
[0066] It should be noted that the user-related information and data involved in the embodiments of this specification are all information and data authorized by the user or fully authorized by relevant parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users or relevant parties to choose to authorize or refuse.
[0067] It should also be noted that in the embodiments of this specification, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or will necessarily use the solution.
[0068] See also Figure 1 As shown, the embodiment of this specification provides a method for processing permission data of a distributed database, wherein the method is specifically applied to the server side. When implemented specifically, the method may include the following contents:
[0069] S101: querying a metadata table of a target distributed database to obtain explicit permission data of a user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes permission data of a user on a data object of the target distributed database based on SQL explicit authorization;
[0070] S102: Establishing a corresponding intermediate table according to the explicit authority data; and obtaining inheritance relationship data between users;
[0071] S103: According to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processing to determine the user's implicit permission data based on inheritance implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data based on inheritance implicit authorization on the data object of the target distributed database
[0072] S104: Determine implicit association information about the implicit permission data according to the implicit permission data; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method;
[0073] S105: Establish a user authority relationship detail table for the target distributed database according to the explicit authority data, the implicit authority data, and the implicit association information.
[0074] The target distributed database can be understood as a business database based on a distributed database structure for storing and processing massive transaction business data on the trading platform. The transaction business data can include one or more of the following: order data, transfer data, payment data, etc.
[0075] The above-mentioned distributed database may specifically refer to connecting multiple physically dispersed data storage nodes using a high-speed network to form a logically unified database to support larger storage capacity and higher concurrent access volume.
[0076] The metadata may specifically refer to data information about the organization of data in the target distributed database, data domains and relationships thereof. In short, it may be understood as data about the data in the target distributed database.
[0077] The above metadata table can be specifically understood as a special system table based on the target distributed database for storing and managing relevant metadata. By querying the above metadata table, detailed information of the target distributed database can be obtained, such as the structure information, index information, permission information, etc. of the distributed database, to help operation and maintenance personnel operate and maintain the database.
[0078] Furthermore, the system specifically used to store and manage metadata in the target distributed database may be a target distributed cluster (or metadata cluster). The target distributed cluster may include multiple physical subsystems.
[0079] The physical subsystem may specifically be a combination of hardware (eg, database, network device, memory, etc.) used to complete one or more specific functional modules in the target distributed cluster and codes, software, etc. deployed thereon.
[0080] Specifically, the above explicit permission data can be understood as the permission data for the data objects in the target distributed database obtained by the user through SQL explicit authorization. The above SQL (Structured Query Language) specifically refers to a database query and programming language used to access data and query, update and manage relational database systems. Usually, explicit permission data related to the user can be recorded in the metadata table. For example, the user actively applies to the system, and the system specifically authorizes the user's permission data based on the corresponding instructions.
[0081] The above implicit permission data can be specifically understood as the permission data for data objects in the target distributed database that the user indirectly obtains from other users or user groups through implicit authorization based on the inheritance relationship of other users or user groups. Usually, the above implicit permission data is not recorded in the metadata table. For example, when a user joins a business department (a user group), he automatically inherits the permission data that belongs to the business department and can be enjoyed by members of the business department.
[0082] The above-mentioned query of the metadata table of the target distributed database to obtain the user's explicit permission data based on SQL explicit authorization on the target distributed database may include the following contents during specific implementation: querying the metadata table to determine the metadata sub-table related to the user's permission; determining the field characteristics of the user identifier; searching the metadata sub-table according to the field characteristics of the user identifier to find the table character string that complies with the relevant protocol rules; according to the relevant protocol rules, by parsing the above-mentioned table character string, determining the SQL-based authorization instruction, as well as the authorization instruction-associated authorizer identifier (for example, the authorizer's user identifier or user group identifier), the authorizedee identifier (for example, the authorizedee's user identifier or user group identifier), the authorization content and other relevant permission information; and then obtaining the full amount of explicit permission data based on the above-mentioned permission information.
[0083] Specifically, for example, in an mpp (Massively Parallel Processing) database (a distributed database), the metadata table will record the permissions granted by the grant command (an explicit permission based on SQL explicit authorization). Accordingly, you can retrieve the display permission data in the relevant metadata table and obtain it according to the corresponding grant command.
[0084] The above-mentioned acquisition of inheritance relationship data between users, when specifically implemented, may include: querying a metadata table to determine a metadata subtable related to user relationships; then acquiring and searching the metadata subtable based on field features of user identifiers to determine user relationship data; wherein user relationships include: relationships between users, relationships between users and user groups, and relationships between user groups and user groups; then, based on the user relationship data, determining other users and / or other user groups that have relationships with each user, and then determining inheritance relationship data between users; wherein the above-mentioned inheritance relationship data may include relationship data of users inheriting partial permissions or all permissions of other users with whom they have relationships, and / or relationship data of users inheriting partial permissions or all permissions of other user groups with whom they have relationships.
[0085] In specific implementation, according to the preset permission resolution processing rules, multiple level-by-level permission resolution processing can be performed by jointly using the intermediate table and the inheritance relationship data between users, and the implicit permission data of each user based on the inherited implicit authorization on the target distributed database and the implicit association information about the implicit permission data can be sorted out and determined level by level.
[0086] Among them, the above-mentioned implicit association information may specifically include: implicit authorizer identification (for example, user identification or user group identification of implicit authorizer, etc.), implicit authorization type (for example, full authority authorization, partial authority authorization, etc.), implicit authorization method (for example, persistent authorization, temporary authorization, etc.), etc.
[0087] In specific implementation, implicit association information about inherited implicit permission data may be determined based on inheritance relationship data between users and agreed rules of other users or other user groups inherited by the user.
[0088] In specific implementation, explicit permission data, implicit permission data, and implicit association information can be used together to establish a user permission relationship detail table for the target distributed database. The user permission relationship detail table can include all the permission data of all users for different data objects in the target distributed database.
[0089] Accordingly, the user authority relationship details table can be used to efficiently and accurately query and obtain the full amount of user authority data of a certain user on the target distributed database.
[0090] The permission data processing method of the above-mentioned distributed database can be specifically applied to the server side. Among them, the above-mentioned server may include a background server that is applied to the transaction data processing system side of the transaction institution and can realize functions such as data transmission and data processing. Specifically, the server can be, for example, an electronic device with data calculation, storage and network interaction functions. Alternatively, the server can also be a software program running in the electronic device to provide support for data processing, storage and network interaction. In this embodiment, the number of the servers is not specifically limited. The server can be specifically one server, or several servers, or a server cluster formed by several servers.
[0091] Based on the above embodiments, it can be better adapted to big data scenarios with huge data volumes and complex relationships, especially transaction data processing scenarios based on big data, and can comprehensively and precisely determine the user's relevant user rights on the target distributed database to avoid omissions.
[0092] In some embodiments, the data object may specifically include at least one of the following: a schema, a table, a table space, a view, etc.
[0093] The table can be understood as a data table in a distributed database for storing and managing specific data. The mode can be understood as an operation processing rule for the table. The table space can be understood as a storage area for the table. The view can be understood as a processing result obtained after performing corresponding operation processing on the table.
[0094] Of course, it should be noted that the data objects listed above are only schematic illustrations. In specific implementation, according to specific circumstances and processing requirements, the data objects may also include other data related to the target distributed database. This specification does not limit this.
[0095] Correspondingly, the user permission relationship details table may include at least one of the following: a user permission relationship details table regarding the model of the target distributed database, a user permission relationship details table regarding the table of the target distributed database, a user permission relationship details table regarding the table space of the target distributed database, a user permission relationship details table regarding the view of the target distributed database, etc.
[0096] In some embodiments, the above-mentioned authorization parsing processing is performed multiple times level by level according to the preset authorization parsing processing rules, in combination with the intermediate table and the inheritance relationship data between users. For specific implementation, refer to Figure 2 As shown, according to the preset permission resolution processing rules, the current permission resolution processing can be performed in the following manner:
[0097] S1: Get the last updated intermediate table as the current intermediate table;
[0098] S2: Based on the current intermediate table, determine the user node that currently has no parent node as the current level node;
[0099] S3: According to the user identifier and inheritance relationship data corresponding to the node of the current level node, traverse the current intermediate table to determine the child nodes of the current level node;
[0100] S4: According to the permission data of the current level node, determining the permission data of the child node of the current level node and the permission inheritance information between the current level node and the child node;
[0101] S5: Update the relevant data in the current intermediate table according to the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes; and remove the permission data of the current level node from the current intermediate table to obtain the updated intermediate table of the current time.
[0102] The last updated intermediate table may be specifically understood as an intermediate table that is finally updated based on the last intermediate table after the last permission resolution process.
[0103] In specific implementation, according to the preset permission parsing and processing rules and combined with the inheritance relationship data between users, each user node in the current intermediate table can be traversed to find out the user who does not exist in the previous level, or the user node of the previous level user (i.e., the parent node) to which it belongs, as the current level node. Further, according to the user identifier (or user group identifier) corresponding to the current level node, combined with the inheritance relationship data, each user node in the current intermediate table can be traversed to find the user who has a relationship with the current level node as a child node; then according to the permission data of the current level node and the inheritance relationship data, the permission data that can be transferred to the child node based on the current level node is determined, and combined with the existing permission data that can be directly determined by the child node based on the current intermediate table, the current complete permission data of the child node can be determined; at the same time, the permission inheritance information between the current level node and the child node can be determined in combination with the inheritance relationship data (for example, including: the inherited permission content, the mapping relationship between the upper node and the lower node of the inherited permission, etc.); further, according to the permission data of the current level node and the permission inheritance information between the current level node and the child node, the relevant data in the current intermediate table can be updated; at the same time, the permission data of the current level node is removed from the current intermediate table, and the permission data of the above-mentioned current level node is stored in the cache, so that the updated intermediate table of the current time can be obtained.
[0104] Among them, the permission data of the current level node stored in the cache can specifically be the full permission data (including explicit permission data and implicit permission data) of the user (or user group) corresponding to the current level node determined based on the previous permission resolution processing.
[0105] Based on the above embodiment, the full amount of permission data of nodes at each level can be carefully and comprehensively sorted out and determined by performing multiple level-by-level permission analysis processes according to preset permission analysis and processing rules.
[0106] In some embodiments, after obtaining the updated intermediate table for the current time, refer to Figure 3 As shown, when the method is implemented specifically, it may also include the following contents:
[0107] S1: Check whether there is a user node without a parent node in the intermediate table after the current update;
[0108] S2: when it is determined that there is no user node without a parent node in the intermediate table after the current update, the multiple level-by-level authority resolution processes are terminated;
[0109] S3: Obtain and determine the user's implicit permission data based on inherited implicit authorization on the target distributed database according to the permission data of each current user node.
[0110] In specific implementation, when it is detected that there are still user nodes without parent nodes in the currently updated intermediate table, the above method can be repeated to continue the next permission resolution process using the currently updated intermediate table.
[0111] When it is detected that there is no user node without a parent node in the intermediate table after the current update, the multiple level-by-level permission resolution processes are terminated; then the permission data of each current user node is obtained by querying the cache and the intermediate table after the current update; then, according to the initial intermediate table determined initially, the implicit permission data of the user based on inherited implicit authorization on the target distributed database is screened and determined from the permission data of each current user node.
[0112] Based on the above embodiments, the implicit permission data of each user with respect to the target distributed data can be accurately determined according to the preset permission parsing process.
[0113] In some embodiments, after establishing a user authority relationship table for a target distributed database, refer to Figure 4 As shown, when the method is implemented specifically, it may also include the following contents:
[0114] S1: receiving a permission recovery request for a target user; wherein the permission recovery request carries at least a user identifier of the target user;
[0115] S2: responding to the permission recovery request, querying the user permission relationship table according to the user ID of the target user, and obtaining the target permission data directly and indirectly related to the target user;
[0116] S3: Based on the target permission data, a user permission traceability chain diagram for the target user is constructed;
[0117] S4: Perform relevant permission recovery operations according to the user permission traceability chain diagram of the target user.
[0118] The target user may be, for example, a user who is about to leave a certain trading organization.
[0119] For the above-mentioned target users, it is necessary to revoke the relevant permissions of the target users, and at the same time, it is also necessary to revoke the relevant permissions directly or indirectly obtained by other users based on the target users to ensure the internal permissions security of the trading organization.
[0120] In specific implementation, the explicit permission data and implicit permission data of the target user, as well as the explicit permission data and implicit permission data obtained by other sub-users who have a relationship with the target user based on the target user, can be determined based on the user permission traceability chain diagram; further, detect whether the source of the permission of other sub-users based on the explicit permission data obtained by the target user is the explicit permission data or implicit permission data of the target user; and according to the source of permission, the permission data of other sub-users based on the explicit permission data obtained by the target user, whose source is implicit permission data and whose implicit authorization method is persistent authorization, is used as reserved permission data; and then the explicit permission data and implicit permission data of the target user, as well as other permission data other than the reserved permission data in the explicit permission data and implicit permission data obtained by other sub-users who have a relationship with the target user based on the target user, are determined as permission data to be recovered. Then, the above permission data to be recovered can be set to be invalid to implement the relevant permission recovery operation.
[0121] During specific implementation, when determining the retained permission data, other implicit associated information such as implicit authorization type (full permission authorization or partial permission authorization) can also be combined to more accurately determine the retained permission data.
[0122] Based on the above embodiment, a permission recovery request for a target user can be responded to, and the full amount of permission data to be recovered related to the target user can be comprehensively and precisely determined, thereby accurately implementing the relevant permission recovery operation.
[0123] In some embodiments, after establishing a user authority relationship table for a target distributed database, refer to Figure 5 As shown, when the method is implemented specifically, it may also include the following contents:
[0124] S1: receiving an unauthorized risk detection request for a target user group; wherein the unauthorized risk detection request carries at least a group identifier of the target user group;
[0125] S2: responding to the unauthorized risk detection request, querying the inheritance relationship data between users according to the group identifier of the target user group, and determining the user identifiers of multiple users belonging to the target user group;
[0126] S3: According to the user IDs of multiple users, query the user authority relationship detail table to obtain the authority data of multiple users;
[0127] S4: Based on the permission data of multiple users, a target knowledge graph about the permission relationship of the target user group is constructed;
[0128] S5: Based on the target knowledge graph, detect whether the target user group has the risk of unauthorized access.
[0129] The target user group may be an organization or a business department in an organization. Each target user group may also include multiple business groups.
[0130] In specific implementation, multiple nodes can be constructed based on the permission data of multiple users of the target user group using the user IDs; then the node of the authorizer is connected to the node of the authorized person using directed line segments; at the same time, based on the permission type (explicit permission data or implicit permission data), authorization method, authorization type and other information of the permission data, the corresponding attribute information is marked on the edge connecting the two nodes to obtain the target knowledge graph about the permission relationship of the target user group.
[0131] During specific implementation, the target knowledge graph can be used, and the idea of image processing can be adopted to efficiently sort out the complex permission relationships within the target user group and accurately detect the risk of unauthorized access.
[0132] In specific implementation, the target knowledge graph can be processed by using the preset risk detection model obtained by pre-training to obtain the corresponding target detection result; based on the target detection result, it is determined whether the target user group has the risk of unauthorized access. Furthermore, in the case of determining that the target user group has the risk of unauthorized access, the target knowledge graph can be combed according to the target detection result to determine the risk user in the target user group who has the risk of unauthorized access; and risk warning information about the risk user is generated, and the risk warning information is sent to the operation and maintenance terminal, so that the operation and maintenance personnel can eliminate the risk of unauthorized access in the target user group in a timely manner based on the above risk warning information displayed by the operation and maintenance terminal.
[0133] The operation and maintenance terminal may specifically include a front end applied to the operation and maintenance personnel and capable of realizing functions such as data collection and data transmission. Specifically, the operation and maintenance terminal may be, for example, an electronic device such as a desktop computer, a tablet computer, a laptop computer, a smart phone, etc. Alternatively, the operation and maintenance terminal may also be a software application that can be run in the above electronic devices.
[0134] Among them, the above-mentioned preset risk detection model is a neural network model that is pre-acquired and trained by using a sample knowledge graph based on a sample user group through deep learning.
[0135] Based on the above embodiments, the inheritance relationship data between users and the user authority relationship details table can be used together to automatically detect and determine the risk of unauthorized access in the target user group efficiently and accurately, thereby ensuring the security and reliability of user authorities in the target user group.
[0136] In some embodiments, after establishing a user authority relationship table for a target distributed database, refer to Figure 6 As shown, when the method is implemented specifically, it may also include the following contents:
[0137] S1: receiving a system splitting request for a target distributed cluster of a target distributed database; wherein the target distributed cluster includes a plurality of physical subsystems;
[0138] S2: Responding to the system splitting request, obtaining data objects of the target distributed database and storage information of user data of each physical subsystem in the target distributed cluster;
[0139] S3: According to the user authority relationship detail table and the storage information, determine the data objects of the target distributed database and the system authority relationship table of the user data of each physical subsystem in the target distributed cluster;
[0140] S4: Determine the dependency relationship between physical subsystems according to the system authority relationship table and the user authority relationship detail table;
[0141] S5: Divide the multiple physical subsystems in the target distributed cluster into multiple system groups according to the dependency relationship between the physical subsystems; wherein each system group includes multiple physical subsystems with direct or indirect dependency relationships, and there is no dependency relationship between different system groups.
[0142] In specific implementation, the metadata table of the target distributed database may be queried to obtain data objects of the target distributed database and storage information of user data of each physical subsystem in the target distributed cluster.
[0143] In specific implementation, the permission data of users stored and / or managed by each physical subsystem, as well as data objects about the target distributed database, can be determined based on the system permission relationship table; then, based on the user permission relationship details table, the dependency relationships between the permission data and data objects of different users based on permission implementation can be determined; and then, based on the dependency relationships, the dependency relationships between the corresponding physical subsystems can be determined.
[0144] Based on the above embodiment, the user authority relationship details table and storage information can be used in combination to efficiently and accurately split the complex target distributed cluster into multiple system groups, so that targeted processing can be performed on different system groups to meet related business processing requirements.
[0145] In some embodiments, after dividing the multiple physical subsystems in the target distributed cluster into multiple system groups, the method may further include the following when implemented:
[0146] Receive and respond to a system migration instruction for a target distributed cluster, and perform matching migration operations on multiple system groups in the target distributed cluster.
[0147] During the specific implementation, matching migration strategies can be constructed for different system groups according to their structural characteristics and internal dependencies. Then, based on the corresponding migration order and according to the matching migration strategies, the corresponding system groups can be migrated in batches, thereby safely and stably implementing the migration process of the target distributed cluster.
[0148] As can be seen from the above, the permission data processing method of the distributed database provided by the embodiment of this specification can first obtain the explicit permission data of the user on the target distributed database by querying the metadata table of the target distributed database, and establish the corresponding intermediate table; at the same time, obtain the inheritance relationship data between users; then according to the preset permission parsing processing rules, the intermediate table and the inheritance relationship data between users are used in combination, and the implicit permission data based on inheritance implicit authorization of each user on the target distributed database is determined layer by layer by performing multiple level-by-level permission parsing processes; and according to the implicit permission data, the corresponding implicit association information is determined; then according to the explicit permission data, the implicit permission data, and the implicit association information, a user permission relationship detailed table about the target distributed database is established. Thus, it can be better adapted to the big data scenario with huge data volume and complex permission relationship, and the relevant user permissions of each user on the target distributed database can be determined comprehensively and finely to avoid omissions. Then, based on the above-mentioned user permission relationship detailed table, the dependency relationship between the physical subsystems in the target distributed cluster of the target distributed database can be accurately determined, and further data processing can be realized.
[0149] This specification embodiment provides a server, referring to Figure 7 The server includes a network communication port 701, a processor 702 and a memory 703, and the above structures are connected through internal cables so that each structure can perform specific data interaction.
[0150] The network communication port 701 can be specifically used to receive a trigger instruction.
[0151] The processor 702 can be specifically used to respond to the trigger instruction, query the metadata table of the target distributed database, and obtain the user's explicit permission data based on SQL explicit authorization on the target distributed database; wherein the explicit permission data includes the user's permission data for the data object of the target distributed database based on SQL explicit authorization; according to the explicit permission data, a corresponding intermediate table is established; and inheritance relationship data between users is obtained; according to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are jointly used to perform multiple level-by-level permission resolution processes to determine the user's implicit permission data based on inheritance implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data for the data object of the target distributed database based on inheritance implicit authorization; according to the implicit permission data, implicit association information about the implicit permission data is determined; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, implicit authorization method; according to the explicit permission data, a user permission relationship detail table about the target distributed database is established.
[0152] The memory 703 may be specifically used to store corresponding instruction programs, as well as intermediate tables, explicit permission data, implicit permission data and other related data.
[0153] Based on the above method, the relevant structural performance of the server can be effectively utilized, the data processing speed of the electronic device can be improved, and the permission data processing of the distributed database can be efficiently implemented.
[0154] In this embodiment, the network communication port 701 can be a virtual port that is bound to different communication protocols so that different data can be sent or received. For example, the network communication port can be a port responsible for web data communication, a port responsible for FTP data communication, or a port responsible for email data communication. In addition, the network communication port can also be a physical communication interface or communication chip. For example, it can be a wireless mobile network communication chip, such as GSM, CDMA, etc.; it can also be a Wifi chip; it can also be a Bluetooth chip.
[0155] In this embodiment, the processor 702 may be implemented in any appropriate manner. For example, the processor may take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) executable by the (micro)processor, a logic gate, a switch, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, etc. This specification does not limit this.
[0156] In this embodiment, the memory 703 may include multiple levels. In a digital system, anything that can store binary data can be a memory; in an integrated circuit, a circuit with a storage function that has no physical form is also called a memory, such as RAM, FIFO, etc.; in a system, a storage device with a physical form is also called a memory, such as a memory stick, TF card, etc.
[0157] The embodiment of the present specification also provides a computer-readable storage medium of the permission data processing method based on the above-mentioned distributed database, wherein the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed, the following are implemented: querying the metadata table of the target distributed database to obtain the explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes the permission data of the user for the data object of the target distributed database based on SQL explicit authorization; according to the explicit permission data, establishing a corresponding intermediate table; and obtaining the inheritance relationship data between users; according to the preset permission parsing processing rules; Then, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processes to determine the user's implicit permission data based on inherited implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data on the data objects of the target distributed database based on inherited implicit authorization; based on the implicit permission data, implicit association information about the implicit permission data is determined; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, implicit authorization method; based on the explicit permission data, implicit permission data, and implicit association information, a user permission relationship detail table about the target distributed database is established.
[0158] In this embodiment, the storage medium includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a cache, a hard disk (HDD), or a memory card. The memory may be used to store computer program instructions. The network communication unit may be an interface for network connection communication set in accordance with the standard specified by the communication protocol.
[0159] In this embodiment, the functions and effects specifically implemented by the program instructions stored in the computer-readable storage medium can be explained in comparison with other implementations and will not be described in detail here.
[0160] The embodiment of the present specification also provides a computer program product, which at least includes a computer program, and when the computer program is executed by a processor, it implements the following method steps: querying the metadata table of the target distributed database to obtain the user's explicit permission data based on SQL explicit authorization on the target distributed database; wherein the explicit permission data includes the user's permission data for the data object of the target distributed database based on SQL explicit authorization; according to the explicit permission data, establishing a corresponding intermediate table; and obtaining inheritance relationship data between users; according to a preset permission resolution processing rule, using the intermediate table and the inheritance relationship data between users, performing multiple level-by-level permission resolution processes to determine the user's implicit permission data based on inheritance implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data for the data object of the target distributed database based on inheritance implicit authorization; according to the implicit permission data, determining implicit association information about the implicit permission data; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, implicit authorization method; according to the explicit permission data, establishing a user permission relationship detail table about the target distributed database.
[0161] See also Figure 8 As shown, the embodiment of this specification also provides a permission data processing device for a distributed database, which may specifically include the following structural modules:
[0162] The query module 801 may be specifically used to query the metadata table of the target distributed database to obtain the explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes the permission data of the user on the data object of the target distributed database based on SQL explicit authorization;
[0163] The first processing module 802 may be specifically used to establish a corresponding intermediate table according to the explicit permission data; and obtain inheritance relationship data between users;
[0164] The second processing module 803 may be specifically used to perform multiple level-by-level permission resolution processing according to a preset permission resolution processing rule, in combination with the intermediate table and the inheritance relationship data between users, to determine the implicit permission data of the user on the target distributed database based on the inheritance implicit authorization; wherein the implicit permission data includes the permission data of the user on the data object of the target distributed database based on the inheritance implicit authorization;
[0165] The determination module 804 may be specifically used to determine implicit association information about the implicit permission data according to the implicit permission data; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method;
[0166] The establishment module 805 can be specifically used to establish a user authority relationship detail table about the target distributed database according to the explicit authority data, the implicit authority data, and the implicit association information.
[0167] In some embodiments, the data object may include at least one of the following: a schema, a table, a tablespace, a view, etc.;
[0168] Correspondingly, the user permission relationship details table may specifically include at least one of the following: a user permission relationship details table regarding the model of the target distributed database, a user permission relationship details table regarding the table of the target distributed database, a user permission relationship details table regarding the table space of the target distributed database, a user permission relationship details table regarding the view of the target distributed database, etc.
[0169] In some embodiments, when the above-mentioned second processing module 803 is implemented, the current permission parsing process can be performed in the following manner: obtain the last updated intermediate table as the current intermediate table; based on the current intermediate table, determine the user node that does not have a parent node as the current level node; traverse the current intermediate table according to the user identifier and inheritance relationship data corresponding to the node of the current level node, and determine the child nodes of the current level node; determine the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes according to the permission data of the current level node; update the relevant data in the current intermediate table according to the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes; and remove the permission data of the current level node from the current intermediate table to obtain the current updated intermediate table.
[0170] In some embodiments, after obtaining the currently updated intermediate table, the above-mentioned second processing module 803 can also be used for: detecting whether there is a user node without a parent node in the currently updated intermediate table; when it is determined that there is no user node without a parent node in the currently updated intermediate table, ending multiple levels of permission resolution processing; obtaining and determining the user's implicit permission data based on inherited implicit authorization regarding the target distributed database based on the permission data of each current user node.
[0171] In some embodiments, after establishing a user permission relationship detail table for the target distributed database, the device, when implemented, can also be used to: receive a permission recovery request for a target user; wherein the permission recovery request carries at least a user identifier of the target user; respond to the permission recovery request, query the user permission relationship detail table based on the user identifier of the target user, and obtain target permission data directly and indirectly related to the target user; construct a user permission traceability chain graph for the target user based on the target permission data; and perform relevant permission recovery operations based on the user permission traceability chain graph of the target user.
[0172] In some embodiments, after establishing a user authority relationship detail table regarding the target distributed database, the device, when implemented, can also be used to: receive an unauthorized risk detection request regarding a target user group; wherein the unauthorized risk detection request carries at least the group identifier of the target user group; in response to the unauthorized risk detection request, query the inheritance relationship data between users based on the group identifier of the target user group, and determine the user identifiers of multiple users belonging to the target user group; query the user authority relationship detail table based on the user identifiers of the multiple users, and obtain the authority data of the multiple users; construct a target knowledge graph regarding the authority relationship of the target user group based on the authority data of the multiple users; and detect whether the target user group has an unauthorized risk based on the target knowledge graph.
[0173] In some embodiments, after establishing a user authority relationship detail table regarding the target distributed database, the device can also be used, when implemented, to: receive a system split request regarding a target distributed cluster of the target distributed database; wherein the target distributed cluster includes multiple physical subsystems; in response to the system split request, obtain data objects regarding the target distributed database of each physical subsystem in the target distributed cluster, and storage information of user data; based on the user authority relationship detail table and the storage information, determine a system authority relationship table regarding data objects regarding the target distributed database of each physical subsystem in the target distributed cluster, and user data; based on the system authority relationship table and the user authority relationship detail table, determine dependencies between physical subsystems; based on the dependencies between physical subsystems, divide multiple physical subsystems in the target distributed cluster into multiple system groups; wherein each system group includes multiple physical subsystems with direct or indirect dependencies, and there are no dependencies between different system groups.
[0174] In some embodiments, after dividing multiple physical subsystems in the target distributed cluster into multiple system groups, the device can also be used to: receive and respond to system migration instructions for the target distributed cluster, and perform matching migration operations on multiple system groups in the target distributed cluster.
[0175] It should be noted that the units, devices or modules described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. For the convenience of description, the above devices are described separately by functions divided into various modules. Of course, when implementing this specification, the functions of each module can be implemented in the same or more software and / or hardware, or the modules that implement the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0176] As can be seen from the above, the permission data processing device for the distributed database provided by the embodiment of this specification can be well adapted to the big data scenario with huge data volume and complex relationships, and comprehensively and finely determine the user's relevant user permissions on the target distributed database to avoid omissions. Subsequently, the dependency relationship between the physical subsystems in the target distributed cluster of the target distributed database can be more accurately determined, and relevant data processing such as permission recovery, unauthorized detection, system migration, etc. can be accurately implemented.
[0177] In a specific scenario example, the distributed database permission data processing method provided in this specification can be used to implement efficient acquisition and application of implicit permissions applicable to a large commercial bank distributed database. The specific implementation process can be found in the following content.
[0178] In this scenario example, considering that large commercial bank systems have a large number of systems and complex data dependencies between systems, the corresponding distributed databases have a large number of database users and complex permissions for users. The metadata table of the database records information such as database users, tables, and tablespaces. For example, metadata can record information such as the owner of the table, the user's default tablespace, and permissions explicitly granted by the user through SQL. However, it is worth noting that the permissions obtained by users by inheriting user groups are not recorded in the metadata table, so it is impossible to accurately obtain accurate information about which users can access a table, and it is also impossible to quickly associate the relationship between tables, users, and systems.
[0179] Based on the above situation, during emergency work, system operation and maintenance personnel may encounter a situation where a user cannot access a certain table and cannot query relevant information in time, resulting in delayed recovery of the fault; a user may have write permissions to other users' tablespaces, resulting in a large amount of data being mistakenly written into the tablespace, thereby creating the risk of insufficient capacity; it is even difficult to quickly sort out the upstream and downstream systems related to the current system in terms of cluster construction and system migration.
[0180] Based on the existing methods, the user permissions of the distributed database of large commercial banks are given in the form of the database's own metadata table, and the permission information given is the permissions granted through SQL display, ignoring the permissions indirectly obtained through user inheritance. The relevant permission information is only recorded in the table from the user dimension. The permission-related information is recorded in the form of a database table.
[0181] In order to solve the above problems, the applicant proposed a method for efficiently acquiring and applying implicit permissions suitable for distributed databases of large commercial banks. First, by reading and analyzing the relevant metadata tables, the users, databases, tablespaces, tables, views, etc. of all physical subsystems in a cluster can be associated; and the inheritance relationship between users can be traced layer by layer; and then the permissions owned by users can be passed layer by layer. All permission details are written into the database table in the form of a daily job, and the permission traceability relationship and the dependency relationship between physical subsystems are given in a visual way. The overall processing process can be referred to Fig. 9 As shown, it includes: metadata table reading; explicit permission (for example, explicit permission data) parsing; implicit permission (for example, implicit permission data) parsing.
[0182] Specifically, the metadata table of the above database records the information related to the permissions of users and modes, tablespaces, tables, and views, but the recorded information related to permissions is explicitly granted through SQL, and does not effectively record the permissions indirectly obtained by users through inheritance. Therefore, in this solution, the metadata table is first read to parse out the permissions explicitly granted through SQL, and the results are recorded in the intermediate table.
[0183] During the parsing process, if there is too much metadata information and a single process takes a long time to execute, you can use multi-process development to complete the processing if computing resources permit.
[0184] For specific implicit permission parsing, please refer to Fig.10As shown. The resolution result of display permissions has been written into the intermediate table. The information recorded in the intermediate table is the display permissions of the user on the mode, tablespace, table, and view. Before the implicit permission resolution, the inheritance relationship between users is first obtained according to the relevant metadata table. The inheritance relationship can be multiple inheritance. Multiple inheritance includes two meanings. The first meaning means that user A directly inherits user B and user C; the second meaning means that user A inherits user B, and user B inherits C.
[0185] The original inheritance relationship between users is equivalent to a network structure. After sorting, the relationship between nodes is converted into Figure 2 For the hierarchical relationship in Figure 2 The first layer of nodes in the layer have no parent nodes, so the permissions they have can be passed to their direct child nodes.
[0186] Among them, the permission parsing process is the process of code execution, so the permission relationship details table is written into the table once after the code execution is completed. During the execution process, each time a node is parsed, its permission information is stored in the memory and will not be updated to the permission relationship details table in time. However, it can also be understood that there is also a permission relationship details table in the memory, which is dynamically updated as the program runs. After the program runs, the permission relationship details table in the memory is written into the database table.
[0187] Based on the above characteristics, multi-level permission transfer can be performed in the following manner (for example, multiple level-by-level permission parsing processes):
[0188] (1) The explicit permissions of all users of the current metadata cluster are recorded in the intermediate table, so users without parent users (e.g., parent nodes) are marked in the current metadata cluster user set. The set of these users is called the first-level node (e.g., the current level node).
[0189] (2) Traverse the users in the first-level nodes one by one and find all the sub-users (e.g., child nodes) of the current user. The intermediate table records the permissions of each user on the schema, tablespace, table, and view. These four types of permissions are copied to each sub-user in batches. At the same time, each permission is marked with information such as the authorizer and authorization method.
[0190] (3) When all the node users of the first layer have completed the permission transfer according to step (2), all the nodes of this layer are removed from the current metadata cluster user set.
[0191] (4) Repeat step (1) and mark the users without parent users. The set of these users is called the second-layer nodes.
[0192] (5) Repeat step (2) to transfer the permissions of each user in the second-layer node to all its sub-users in turn.
[0193] (6) Repeat step (3) to remove the users in the second-layer nodes from the current metadata cluster user set.
[0194] (7) Repeat steps (4)-(6) until all users are removed from the current metadata cluster user set.
[0195] After the above permission parsing process, the relevant results can be put into the library table as follows:
[0196] (1) A table of user and mode permission relationships (for example, a table of user permission relationships for the target distributed database mode): This table records the user's permissions on the mode, the permission type, and the user who authorized the permission and the authorization method. This table can be used to quickly query which modes a user has permissions for; it can also be used to quickly query which users can access or write to a mode.
[0197] (2) A table detailing the relationship between user and tablespace permissions (for example, a table detailing the relationship between user permissions on the tablespace of the target distributed database): This table records the user's permissions on the tablespace, the permission type, and the user who authorized the permission and the authorization method. This table can be used to quickly query which tablespaces a user has permissions on; it can also be used to quickly query which users can access or write to a tablespace.
[0198] (3) User and table permission relationship details table (for example, user permission relationship details table for target distributed database tables): This table records the user's permissions on the table, records the permission type, marks who is the authorized user of the permission, and the authorization method. Through this table, you can quickly query which tables a user has permissions for; you can also quickly query which users can access or write to a table.
[0199] (4) User and view permission relationship details table (for example, user permission relationship details table for views of the target distributed database): This table records the user's permissions on the view, records the permission type, marks who is the authorized user of the permission, and the authorization method. Through this table, you can quickly query which views a user has permissions for; you can also quickly query which users can access a view.
[0200] (5) Table-based physical subsystem dependency table: Each data entry in the table records the data dependency relationship between two physical subsystems and the number of dependency tables.
[0201] (6) Table of permissions between physical subsystems and tables: records which physical subsystems can access and write to a table. When a table has data quality problems or data delays, the affected downstream systems can be quickly analyzed to provide support for emergency decision-making.
[0202] In addition to storing permission data in the database table for detailed query, this scenario example also provides a visual display method to facilitate developers and operation and maintenance personnel to more intuitively analyze the permission transfer path. Fig.11 As shown. And to provide decision support for the splitting of metadata clusters in data centers, please refer to Fig.12 shown.
[0203] In specific implementation, when it is known that a user has certain permissions on a table, the permissions of the user can be traced back to the authorized user layer by layer. Fig.11 As shown in the figure, the user in the first column on the left is the user for whom permission tracing is to be performed. There are three direct parent users who grant permissions to him, one of which is authorized by explicit SQL, and the other two are implicitly authorized by inheritance. These three direct parent users are authorized by inheritance and SQL respectively. The two users in the third column are the top-level authorized users, generally database super users or owners of the current table. The transfer path of permissions can be clearly seen from the figure. When a user's permissions are to be revoked, a decision can be made quickly based on the permission tracing chain diagram. Similarly, the permission tracing of users for modes, tablespaces, and views is similar, so I will not go into details here.
[0204] In actual production, the number of physical subsystems contained in a metadata cluster ranges from a few to hundreds. When there are many systems in a cluster and the amount of data is increasing, the cluster load is high, and computing resources, storage resources, etc. will not be able to meet the healthy and stable operation of the systems in the cluster. In this case, it is necessary to consider cluster splitting or moving individual systems out of the current cluster. Specifically, whether it is cluster splitting or system relocation, the important consideration is the upstream and downstream dependencies of the system. The most important dependency is data dependency, and the most direct manifestation of data dependency is the system's dependency on the table. Fig.12 The diagram briefly shows the dependency relationship between systems in a cluster, where the arrows on the curve point to the dependent party, and the numbers on the curve indicate the number of dependent tables. The diagram uses dotted lines to frame three subsets (i.e., three system groups). The systems within the set have direct or indirect dependencies on each other, while there are no dependencies between sets. In theory, these three sets can be split into three clusters to improve the computing efficiency of the cluster. If a system is moved out of the current cluster, the upstream data dependency of the system can be clarified based on the dependency relationship in the diagram, and its downstream system can be reminded to make corresponding data dependency changes.
[0205] The physical subsystem is a combination of hardware (database, operating system, network, storage, etc.) that completes a specific functional module and the code and software deployed on it. As mentioned above, the user permission relationship details table will record which tables, tablespaces, modes (schemas), etc. a user has which permissions. Each physical subsystem will have corresponding tables, tablespaces, modes (schemas), and users. For example, user1 has read and write permissions on table tbl1, user1 belongs to system sys1, and tbl1 belongs to system sys2 (this relationship is locked when a new user and table are created, and it can also be obtained in the relevant table. In short, the relationship between users, tables, tablespaces and physical subsystems is determined and can be queried from the table). Then it can be said that system sys1 has a dependency on system sys2, and sys1 needs to rely on sys2 to complete the relevant functions [Table-based physical subsystem dependency table]. Similarly, sys1 has read and write permissions on table tbl1, which can form a [physical subsystem to table permission relationship table].
[0206] Specifically, regarding the division of metadata clusters: a metadata cluster contains metadata for many systems. When each system completes a specific function (the underlying logic is to add, delete, modify, and query related tables and perform related operations), it must use some tables. When accessing the table, the metadata information will be read first. If the amount of metadata is too much and the access frequency is too high, the load on the metadata cluster will be high, resulting in low execution efficiency. Therefore, when the amount of metadata is too much, some systems need to be split out of the current cluster, and the split systems cannot have dependencies on other systems. This can be determined based on the [Table-based Physical Subsystem Dependency Table]. Otherwise, after migration, the related functions will not be usable or failures will occur.
[0207] Based on the above scenario examples, the permission data processing method of the distributed database provided in this specification is verified. Through the SQL explicitly granted permission parsing table, the implicit permissions inherited by the user are passed layer by layer, and finally a user permission detail table is generated; by tracing the user's permissions to the mode / tablespace / table / view in a visual form, a permission traceability link diagram is generated. Through this link diagram, omissions can be avoided when reclaiming user permissions; the dependency relationship diagram between systems at the metadata cluster level is generated through the permission detail data, and the dependency relationship and dependency strength between systems in the cluster can be intuitively judged from the diagram, providing decision support for metadata cluster splitting and system relocation. Thus, user permission information query in multiple dimensions can be provided, and various permissions owned by users on modes, tablespaces, tables and views can be queried. At the same time, which users have access rights to them can also be queried from the perspective of modes, tablespaces, tables and views; at the same time, a visual interface can be provided to trace a specific permission and provide all relevant users on its upstream and downstream links, so as to facilitate the subsequent system correlation analysis of metadata cluster dimensions.
[0208] Although the present specification provides method operation steps as described in the embodiments or flow charts, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps, and does not represent a unique execution order. When the device or client product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or device including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or device. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or device including the elements. The first, second, etc. words are used to represent the name, and do not represent any particular order.
[0209] Those skilled in the art also know that, in addition to implementing the controller in a purely computer-readable program code, the controller can be made to implement the same function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered as a hardware component, and the devices for implementing various functions included therein can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules for implementing the method and structures within the hardware component.
[0210] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer-readable storage media including storage devices.
[0211] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that the present specification can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present specification can essentially be embodied in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a mobile terminal, a server, or a network device, etc.) to execute the methods described in each embodiment of the present specification or some parts of the embodiments.
[0212] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. This specification can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc.
[0213] Although the present specification is described through embodiments, those skilled in the art will appreciate that there are many modifications and changes to the present specification without departing from the spirit of the present specification, and it is intended that the appended claims include these modifications and changes without departing from the spirit of the present specification.
Claims
1. A method for processing authority data of a distributed database, characterized in that: include: Querying the metadata table of the target distributed database to obtain explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes permission data of the user on the data object of the target distributed database based on SQL explicit authorization; According to the explicit permission data, a corresponding intermediate table is established; and inheritance relationship data between users is obtained; According to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processing to determine the user's implicit permission data on the target distributed database based on inheritance implicit authorization; wherein the implicit permission data includes the user's permission data on the data object of the target distributed database based on inheritance implicit authorization; According to the implicit permission data, implicit association information about the implicit permission data is determined; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method; A user permission relationship detail table of a target distributed database is established based on explicit permission data, implicit permission data, and implicit association information.
2. The method according to claim 1, characterized in that The data object includes at least one of the following: a schema, a table, a tablespace, and a view; Correspondingly, the user permission relationship details table includes at least one of the following: a user permission relationship details table regarding the model of the target distributed database, a user permission relationship details table regarding the table of the target distributed database, a user permission relationship details table regarding the table space of the target distributed database, and a user permission relationship details table regarding the view of the target distributed database.
3. The method according to claim 1, characterized in that According to the preset permission resolution processing rules, the intermediate table and the inheritance relationship data between users are used together to perform multiple level-by-level permission resolution processing, including: According to the preset permission resolution processing rules, the current permission resolution processing is performed in the following manner: Get the last updated intermediate table as the current intermediate table; Based on the current intermediate table, a user node that does not currently have a parent node is determined as the current level node; According to the user ID and inheritance relationship data corresponding to the node of the current level node, traverse the current intermediate table to determine the child nodes of the current level node; According to the permission data of the current level node, the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes are determined; According to the permission data of the child nodes of the current level node and the permission inheritance information between the current level node and the child nodes, the relevant data in the current intermediate table is updated; and the permission data of the current level node is removed from the current intermediate table to obtain the updated intermediate table of the current time.
4. The method according to claim 3, characterized in that After obtaining the updated intermediate table for the current time, the method further includes: Check whether there is a user node without a parent node in the intermediate table after the current update; When it is determined that there is no user node without a parent node in the intermediate table after the current update, the multiple level-by-level authority resolution processes are terminated; Obtain and determine the user's implicit permission data based on inherited implicit authorization on the target distributed database according to the permission data of each current user node.
5. The method according to claim 1, characterized in that After establishing the user authority relationship detail table for the target distributed database, the method further includes: Receiving a permission recovery request for a target user; wherein the permission recovery request carries at least a user identifier of the target user; In response to the permission recovery request, query the user permission relationship table according to the user identifier of the target user to obtain the target permission data directly and indirectly related to the target user; Based on the target permission data, build a user permission traceability chain diagram for the target user; According to the user permission tracing chain diagram of the target user, relevant permission recovery operations are performed.
6. The method according to claim 1, characterized in that After establishing the user authority relationship detail table for the target distributed database, the method further includes: Receiving an unauthorized risk detection request for a target user group; wherein the unauthorized risk detection request carries at least a group identifier of the target user group; In response to the unauthorized risk detection request, query the inheritance relationship data between users according to the group identifier of the target user group, and determine the user identifiers of multiple users belonging to the target user group; According to the user IDs of multiple users, query the user authority relationship detail table to obtain the authority data of multiple users; Based on the permission data of multiple users, a target knowledge graph about the permission relationship of the target user group is constructed; Based on the target knowledge graph, detect whether the target user group has the risk of unauthorized access.
7. The method according to claim 1, characterized in that After establishing the user authority relationship detail table for the target distributed database, the method further includes: Receiving a system split request for a target distributed cluster of a target distributed database; wherein the target distributed cluster includes a plurality of physical subsystems; In response to the system splitting request, obtaining data objects of the target distributed database and storage information of user data of each physical subsystem in the target distributed cluster; According to the user authority relationship details table and the storage information, determine the data objects of the target distributed database and the system authority relationship table of the user data of each physical subsystem in the target distributed cluster; Determine the dependency relationship between physical subsystems based on the system authority relationship table and user authority relationship detail table; According to the dependency relationship between the physical subsystems, multiple physical subsystems in the target distributed cluster are divided into multiple system groups; wherein each system group includes multiple physical subsystems with direct or indirect dependency relationship, and there is no dependency relationship between different system groups.
8. The method according to claim 7, characterized in that After dividing the multiple physical subsystems in the target distributed cluster into multiple system groups, the method further includes: Receive and respond to a system migration instruction for a target distributed cluster, and perform matching migration operations on multiple system groups in the target distributed cluster.
9. A permission data processing device for a distributed database, characterized in that: include: A query module, used to query the metadata table of the target distributed database, and obtain the explicit permission data of the user on the target distributed database based on SQL explicit authorization; wherein the explicit permission data includes the permission data of the user on the data object of the target distributed database based on SQL explicit authorization; The first processing module is used to establish a corresponding intermediate table according to the explicit permission data; and obtain inheritance relationship data between users; The second processing module is used to perform multiple level-by-level permission parsing processes according to a preset permission parsing processing rule, jointly using the intermediate table and the inheritance relationship data between users, and determine the user's implicit permission data based on inheritance implicit authorization on the target distributed database; wherein the implicit permission data includes the user's permission data on the data object of the target distributed database based on inheritance implicit authorization; A determination module, used to determine implicit association information about the implicit authority data according to the implicit authority data; wherein the implicit association information includes: implicit authorizer identification, implicit authorization type, and implicit authorization method; A module is established to establish a user authority relationship detail table about a target distributed database according to explicit authority data, implicit authority data, and implicit association information.
10. A computer-readable storage medium, characterized in that: Computer instructions are stored thereon, and when the instructions are executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Access right processing method, apparatus and system for database
CN106407757A
Usage authorization method and device for database resources
CN116611093A
Method and apparatus for restricting access to a database according to user permissions
US20030187848A1
System and method for SQL server resources and permissions analysis in identity management systems
US20220050835A1
Cited By
Database management method and device based on multiple security mechanisms, equipment and medium
CN120632855A
Database management method and device based on multiple security mechanisms, equipment and medium
CN120632855B