Authority automatic control method and device based on decentration and domain division

By adopting a decentralized domain-based permission automatic control method in the Internet of Things system, the problems of coarse granularity, complex code and low development efficiency in the traditional permission verification method are solved, and more fine-grained permission control and higher development efficiency are achieved, providing a more secure and flexible permission management method for the Internet of Things system.

CN119995914APending Publication Date: 2025-05-13WUHAN HONGXIN TECH SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411378176.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Traditional user permission verification methods have problems in IoT systems with coarse granularity of permission control, complex code, and low development efficiency. They cannot effectively prevent attackers from directly accessing the back-end sensitive data interface bypassing the front-end level, resulting in the risk of sensitive data leakage and overprivileged access.

Method used

The permission automatic control method based on decentralization and domain is adopted. By obtaining the system functional interface, setting the permission structure and attribute assignment, obtaining the decentralization attribute and domain attribute, judging user access rights, and automatically adding filtering conditions for domain attributes to the user's database query statement based on the decentralization data.

Benefits of technology

It realizes finer granular permission control, simplifies the writing of permission control code, improves development efficiency, and can flexibly define permission scope and permission code according to business needs, reduces the possibility of human errors, reduces the granularity of permission control, and provides a more secure, flexible and efficient permission management method for IoT systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995914A_ABST
    Figure CN119995914A_ABST
Patent Text Reader

Abstract

The invention provides an automatic authority control method and device based on decentration and domain division, and relates to the technical field of Internet of Things. The method comprises the following steps: acquiring a system function interface, setting a permission structure for the system function interface, and performing attribute assignment on the permission structure to obtain a decentralized attribute and a domain attribute; receiving a user request, mapping the user request to a function interface of a corresponding target module, and obtaining decentration data based on the decentration attribute; judging whether the user has an access permission according to the decentralized data; if yes, associating data field information according to the decentralized data, automatically adding a filtering condition corresponding to a domain attribute for a database query statement of the user according to the domain attribute, and feeding back data in a data field range to the user; and if not, refusing the access. According to the method, compiling of authority control codes is simplified to a great extent, the development efficiency is improved, the possibility of human errors is reduced, the authority control granularity is reduced, and a safer, more flexible and more efficient authority control method is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things, and in particular to a method and device for automatic authority control based on authority and domain division. Background Art

[0002] With the rapid development and widespread application of IoT technology, data security and access control issues in IoT systems have become increasingly prominent. User rights management is an important cornerstone for ensuring data security, preventing sensitive information leakage and unauthorized access. However, traditional user rights verification methods in IoT systems have many limitations and are unable to meet the current complex and changing business needs and security requirements.

[0003] Most traditional user permission verification methods focus on controlling the content displayed on the page; that is, limiting the user's access scope through page URL (Uniform Resource Locator, which is the unique name identifier of each web page, that is, the web address) and menu-level verification.

[0004] However, the permission control granularity of this method is relatively coarse, and it can only perform simple interception at the front-end level, which cannot effectively prevent attackers from bypassing the page and directly requesting the interface to gain unauthorized access. Once an attacker successfully bypasses the front-end verification, he or she can directly access the back-end sensitive data interface, which poses a risk of sensitive data leakage and serious unauthorized behavior, posing a serious threat to system security.

[0005] At present, in order to cope with the above challenges, some methods will strengthen the permission verification by writing additional code; specifically, it is required to write code in each business module to parse the URL, determine the required permissions based on the URL, and call the permission verification function provided by the framework to determine whether the current user has the corresponding permissions. Some methods also prefix the data and aggregate the data resources through prefix matching to obtain all the data within the user's permission range.

[0006] However, since each business module needs to write URL parsing code and permission verification code, it not only leads to code redundancy and significantly increased complexity, but also developers need to frequently write and debug permission verification code during the development process, which reduces development efficiency; especially with the development of IoT business and the addition of new devices, the logic of permission verification needs to be frequently modified and adjusted, and permission requests cannot be processed automatically, resulting in poor flexibility and adaptability. Summary of the invention

[0007] Based on this, it is necessary to provide a permission automatic control method and device based on decentralization and domain division to address the above technical problems, which solves the problems of coarse permission control granularity, complex code, and low development efficiency in existing methods.

[0008] In a first aspect, the present invention provides a method for automatic control of permissions based on power division and domain division, the method comprising: Acquire a system function interface, set a permission structure for the system function interface, assign attributes to the permission structure, and obtain authority-based attributes and domain-based attributes; Receiving a user request, mapping the user request to a functional interface of a corresponding target module, and obtaining decentralized data based on the decentralized attribute; Determining whether the user has access rights according to the authority-sharing data; If yes, the data domain information is associated with the decentralized data, and the filtering conditions corresponding to the domain attributes are automatically added to the user's database query statement according to the domain attributes, and the data within the data domain range is fed back to the user; if no, access is denied.

[0009] Furthermore, assigning attributes to the authority structure includes: Defining a permission model, and assigning attributes to the permission structure according to the permission model; The permission model includes one or more of a login identification attribute, a permission code attribute, a region range attribute, and a filtering condition attribute.

[0010] Furthermore, the authority structure includes: a module layer authority structure and an interface layer authority structure.

[0011] Furthermore, assigning attributes to the authority structure also includes: According to the permission model, attribute values ​​are assigned to the module layer permission structure and the interface layer permission structure respectively; Or, only assign attributes to the interface layer permission structure according to the permission model.

[0012] Furthermore, the authority-sharing data includes a target login identifier, a target authority code and a target area range of a target interface that the current user wants to access.

[0013] Further, judging whether the user has access rights according to the authority-sharing data includes: Obtain the user login ID, user authority code and user area range of the current user from the database, and match the user login ID, user authority code and user area range with the target login ID, target authority code and target area range of the target interface to be accessed by the user; If the login IDs of the two are consistent, the current user has the user permission code required to access the data, and the user area range and the target area range intersect, it means that the current user has access rights; otherwise, it means that the current user does not have access rights; If the match fails, it means that the current user does not have access rights.

[0014] Furthermore, associating data domain information according to the decentralized data includes: obtaining the intersection, and associating corresponding data domain information according to the intersection.

[0015] Furthermore, obtaining the database includes: The functional interfaces of all target modules in the system are scanned, and the attributes of the permission structure corresponding to the functional interfaces are cached to obtain a database.

[0016] Furthermore, the domain attributes are filter condition attributes, including specified table names and field names.

[0017] In a second aspect, the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any one of the above methods.

[0018] In general, the present invention provides a method and device for automatic control of permissions based on power division and domain division, which can achieve the following beneficial effects compared with the prior art: The present invention sets a permission structure for the system function interface and assigns attributes to the permission structure, so that when receiving a user request, the access rights are first screened, and then the data domain is screened by adding filtering conditions corresponding to the domain attributes, thereby ensuring that the data fed back to the user is data within the data domain. It avoids writing additional code or performing permission verification by prefixing the data, greatly simplifies the writing of permission control codes, improves development efficiency, and can flexibly define permission ranges and permission codes according to business needs, automatically process request permissions, reduce the possibility of human errors, and reduce the permission control granularity, providing a more secure, flexible and efficient permission management method for the Internet of Things system. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0020] Figure 1It is a method flow diagram of a method and device for automatic authority control based on authority division and domain division provided by the present invention; Figure 2 It is a schematic diagram of organizational information of a method and device for automatic control of authority based on authority division and domain division provided by the present invention; Figure 3 The present invention provides a method and device for automatically controlling permissions based on rights and domains and a schematic diagram of access permission judgment. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in combination with the drawings and embodiments of the present invention. Obviously, the described embodiments are partial embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the scope of protection of the present invention.

[0022] It should be noted that, in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a method, step or system including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such method, step or system. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the existence of other identical elements in the method, step or system including the element.

[0023] In order to solve the problems of coarse permission control granularity, complex code, low development efficiency, etc. in the existing methods, the present invention provides a permission automatic control method and device based on decentralization and domain division, which realizes automatic control of user permissions by configuring a software program that can be applied to a general enabling platform of the Internet of Things, aiming to improve the data security, scalability and development efficiency of the Internet of Things system.

[0024] First, as Figure 1 As shown, the present invention provides a method for automatic control of permissions based on power division and domain division, the method comprising: Step 101: Obtain a system function interface, set a permission structure for the system function interface, assign attributes to the permission structure, and obtain authority attributes and domain attributes.

[0025] As an embodiment of the present invention, assigning attributes to a permission structure includes: defining a permission model, and assigning attributes to the permission structure according to the permission model.

[0026] It should be noted that the permission model can be defined in the form of defining annotations. The permission model includes one or more of a login identification attribute, a permission code attribute, a region range attribute, and a filter condition attribute.

[0027] The decentralized attributes include login identification attribute, permission code attribute, and area range attribute.

[0028] The login flag attribute is used to indicate whether the user needs to log in.

[0029] The permission code attribute is used to indicate whether the corresponding specific data has a permission code; corresponding permission codes can be defined for users to perform operations such as adding, deleting, modifying, and querying data according to system functions.

[0030] The area scope attribute is used to identify the area scope of the user or accessed data, as well as the method for calculating the permission scope; the area scope is the organizational information corresponding to the domain management model. Figure 2 As shown, the domain management model may be a pre-built three-level domain management model of organization, role, and user.

[0031] As an embodiment, the construction of the three-level domain management model includes: Create an organization node; the organization node supports multiple levels, and each organization node can have multiple subordinate organization nodes; Create a role node for the organization node; each role node can specify a role type, and there are multiple role types, such as: administrator, general manager, employee, etc. Each organization node can create multiple role nodes of different types and bind data domains to the organization node; in the IoT system, according to business needs, the data domain can be a device, a cell, a device set, etc. In this example, a single device can be used as the minimum granularity of the data domain; Create a new user and bind the user to the role node. It should be noted that each role node can be bound to multiple users, and each user can also be bound to multiple role nodes. Assign permissions to roles. Permissions are identified by defined permission code attributes. Each role can be assigned multiple permissions.

[0032] It should be noted that the constructed three-level domain management structure and the assigned permissions are stored in the database.

[0033] The domain attribute is a filter condition attribute, including a specified table name and / or field name.

[0034] The filter condition attribute is used to indicate the relevant query information of the database required to filter the data, that is, the filtering method of the data domain, such as table name, field name, table comment, field type, etc. You can specify multiple filter conditions according to the actual needs of the system.

[0035] For example, define an annotation class @Authority, which includes four attributes: login identification attribute (login), authority code attribute (authKey), area scope attribute (scopeHandler), and filter condition attribute (scopeFilter).

[0036] It should be noted that the permission structure may include a module layer permission structure and an interface layer permission structure. The permission structure is set for each functional interface of the Internet of Things system according to the permission model. In other words, the module layer permission structure and / or the interface layer permission structure are annotated according to the permission model.

[0037] For example, use the @Authority annotation on the authority structure (Controller class or its method) to specify the required authority. The annotation on the class is used as the default value, and the annotation on the method takes precedence; if the annotation is defined on the method, it directly overrides the annotation on the class.

[0038] When assigning values ​​to the four attributes in the permission structure, If login is set to true, it means that you need to log in to access this method; if login is set to false, it means that you can access this method without logging in.

[0039] The authKey is assigned the corresponding permission code, which can be pre-defined according to business needs, such as whether alarm data can be read or written.

[0040] The scopeHandler is assigned a specific method for calculating the scope of permissions. This method is a member of the current Controller class and is implemented according to the business logic. The method return value is a collection of organizational structure IDs, indicating the scope of permissions required for the current request. The method parameters are the same as the current request processing method parameters, and direct parameter mapping is supported, for example, "{orgId}", "{orgId1,orgId2}", "{orgId1,org.orgId}", "{orgId1,org.getOrgId()}". If the scope is empty or the parameters are not provided, the final calculation result is empty and the scope of permissions is ignored.

[0041] scopeFilter is assigned to the filtering method of the data domain, which can include the database table name and the field name used for filtering.

[0042] As a specific embodiment, when the permission annotation contains four attributes, namely: whether user login is required to access the interface data, what permissions are required, the area calculation method, and the data filtering method, the permission model can be defined as: @Authority(login=true,authKey==INorthDataService.AUTH_MODIFY_KEY,scopeHandler="getOrgId",scopeFilter={@Authority.ScopeFilter(table="alarm_record",field="device_id"),@Authority.ScopeFilter(table = "device_product",field="device_id")}) public String doSomething(HttpServletResponse response, @RequestParamString arg1, @RequstParam Integer arg2) { … } private int[] getOrgId(HttpServletResponse response, String arg2,Integer arg2){ … } Further, attributes are assigned to the module layer authority structure and the interface layer authority structure respectively according to the authority model; or, attributes are assigned to the interface layer authority structure according to the authority model.

[0043] Among them, the interface layer permission structure takes precedence over the module layer permission structure. The module layer permission structure can be used as the default permission, that is, when the attributes of the interface layer permission structure are assigned, the interface layer permission structure is used as the permission first, and the unassigned attributes default to the module layer permission structure; when the attributes of the interface layer permission structure are not assigned, the attribute values ​​of the module layer permission structure are directly used.

[0044] For example, the target module includes four interfaces, A, B, C, and D. For interface B, interface B includes the interface layer permission structure (BJ) and the module layer permission structure (BM). If BJ only assigns the filter condition attribute (BJG), and BM assigns the login identification attribute (BMD), the permission code attribute (BMM), the area range attribute (BMQ), and the filter condition attribute (BMG), then when the user accesses, the attributes of interface B are BJG, BMD, BMM, and BMQ. If BJ assigns the filter condition attribute (BJG) and the permission code attribute (BJM), and BM assigns the login identification attribute (BMD), the permission code attribute (BMM), the area range attribute (BMQ), and the filter condition attribute (BMG), then when the user accesses, the attributes of interface B are BJG, BMD, BJM, and BMQ.

[0045] Step 102: Receive a user request, map the user request to a functional interface of a corresponding target module, and obtain decentralized data based on decentralized attributes.

[0046] It should be noted that the system includes multiple modules. When a user wants to access a target module, all functional interfaces of the target module can be obtained, and the decentralized data of the current user can be obtained according to the decentralized attributes of the corresponding functional interfaces of the target module.

[0047] The authority data includes the target login identification, target permission code and target area range of the target interface that the current user wants to access. The domain data includes user filtering conditions.

[0048] For example, if the attributes of interface B are BJG, BMD, BMM, and BMQ, then the weighting attributes are BMD, BMM, and BMQ, and the domain attribute is BJG, corresponding to the weighting data and domain data of the current user. If the attributes of interface B are BJG, BMD, and BJM, then the weighting attributes are BMD and BJM, and the domain attribute is BJG, corresponding to the weighting data and domain data of the current user.

[0049] When a user requests a functional interface, the permission interceptor obtains the target login ID and target permission code based on the attributes of the permission structure of the target interface; in addition, if the area range attribute is preset, the parameters are parsed from the user request to obtain the target area range to which the current user belongs, that is, the organization information.

[0050] For example, when the target interface receives a user request, it maps the request to the processing class and method of the corresponding target module and obtains the permission attribute from the cache. If the scopeHandler is specified, the parameters are parsed from the request, and the scopeHandler method is called to calculate the permission scope and form a permission structure.

[0051] Step 103: Determine whether the user has access rights based on the decentralized data; if so, associate the data domain information based on the decentralized data, automatically add filtering conditions corresponding to the domain attributes to the user's database query statement based on the domain attributes, and feed back the data within the data domain range to the user; if not, deny access.

[0052] It should be noted that the granularity of domain division can be determined according to business needs, for example, by device or by community / suburb. If the domain is divided by device, the device is bound to the organization of the domain management model, each device is bound to an organization, and each organization can be bound to multiple devices. When a user accesses, the bound device set can be associated according to the organization set to which the user belongs. When filtering data, the device set is automatically added to the database query statement as a filtering condition.

[0053] Among them, the automatic adding method can be: intercepting the database query statements of each business module, searching the database query statements according to the table name specified by the filter condition in the permission configuration, and if a matching table name is found, automatically adding the field name specified in the filter condition to the database query statement.

[0054] As an embodiment of the present invention, determining whether a user has access rights based on decentralized data may include: obtaining the user login identification, user permission code and user area range of the current user from a database, and matching the user login identification, user permission code and user area range with the target login identification, target permission code and target area range of the target interface that the user wants to access, respectively; if the two login identifications are consistent, the current user has the user permission code required to access the data, and the user area range and the target area range have an intersection, it means that the current user has access rights; otherwise, it means that the current user does not have access rights; if the match is unsuccessful, it means that the current user does not have access rights.

[0055] More specifically, the user login identification, user authority code and user area range are respectively matched with the target login identification, target authority code and target area range of the target interface that the user wants to access; the three can be matched at the same time, or the user login identification, user authority code can be matched with the target login identification and target authority code first, and then it is determined whether the user area range and the target area range have an intersection; but in any case, only when all three conditions are met can the verification pass, indicating that the current user has access rights.

[0056] As an example, Figure 3 As shown, the user login identification and user authority code of the current user are obtained from the database, and the user login identification and user authority code are matched with the target login identification and target authority code of the target interface to be accessed by the corresponding user.

[0057] For example, the permission interceptor obtains the list of organizations to which the current user belongs and the list of permission codes corresponding to the roles to which the current user belongs from the database, and matches them with the target login identifier and target permission code of the target interface that the corresponding user wants to access. More specifically, the permission interceptor matches the obtained permission structure with the permission structure that has been assigned to the current user and stored in the database. If the permission code in the permission structure is included in the permissions assigned to the user, and the organization ID in the permission structure is included in the set of regional identifiers where the user is located, the match is successful. Among them, the regional identifier of the upper-level organization in a multi-level organization includes the regional identifier of the lower-level organization. If the user matches successfully, the request is allowed to continue processing, otherwise an error message of insufficient authority is returned.

[0058] If the match is successful, the user area range to which the current user belongs is obtained from the database to determine whether the user area range and the target area range have an intersection. If there is an intersection, it means that the current user has access rights; otherwise, it means that the current user does not have access rights; If the match fails, it means that the current user does not have access rights.

[0059] It should be noted that when there is an intersection, it means that the current user has access rights, and the data domain information is associated with the authority data. Specifically, the intersection is first obtained, and the corresponding data domain information is associated with the intersection; then, the filtering conditions corresponding to the domain attributes are automatically added to the user's database query statement based on the domain attributes. In other words, the permission interceptor filters the data domain according to the preset filtering conditions, and can specify the table name and field name of the database, and automatically add the filtering conditions corresponding to the domain attributes to the database query statement, thereby ensuring that the data fed back to the user is within the data domain range.

[0060] Furthermore, obtaining the database includes: when the target module is initialized, scanning the functional interfaces of all target modules in the system, and caching the attributes of the authority structure corresponding to the functional interface to obtain the database.

[0061] For example, at startup, scan all Controller interface classes, and for each class, determine whether it has the @Authority annotation; if so, obtain the annotation attributes and cache them, then traverse each method, if there is an @Authority annotation, obtain the attributes, parse out the method corresponding to the scopeHandler, cache it, and overwrite the attributes of the class annotation.

[0062] As a specific embodiment, when a user needs to obtain the historical alarm records of the system, First, preset the permission model for the method of obtaining historical alarm records, that is, assign attributes: login-login required, authkey-alarm data readable permission, scopeHandler-method name that identifies the acquisition area, custom acquisition method, scopeFilter-specify filtering conditions; at this time, you can obtain the user's area and all permissions based on the user's organization and role.

[0063] Then, when the user accesses the interface, the interceptor determines whether the user has access rights based on one or more of the three attributes: login, authkey, and scopeHandler. Among them, login and authkey can directly determine whether there is access rights, and the judgment method of scopeHandler is: when the area set to which the user belongs intersects with the area set calculated by the interface, it means that the user has access rights.

[0064] Finally, for users with access permissions, when the functional interface is querying database data, the interceptor automatically adds filtering conditions to the database query statement based on the table name and field name specified in scopeFilter to ensure that the returned data is within the user's permission range. It should be noted that when adding a filter condition, the specified database table is filtered according to the specified field name. For example, if the filter field is the device ID, the device ID set associated with the area to which the user belongs is obtained.

[0065] In a second aspect, the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any one of the above methods.

[0066] As an embodiment, the device includes a permission preset unit, a permission management unit, a permission allocation unit and a permission judgment unit which are connected in sequence.

[0067] The permission preset unit is used to define the permission model, obtain the system function interface, set the permission structure for the system function interface according to the permission model, and assign attributes to the permission structure. It is also used to specify the calculation method of the area range, the filtering conditions of the data domain, and build a three-level domain management structure.

[0068] The permission management unit is used to scan the functional interfaces of all target modules and cache the attributes of the permission structure of each functional interface into the database. When a user accesses a functional interface, the required permission code is automatically obtained, and the parameters are parsed from the user request to obtain the organization information to which the visited user belongs based on the preset area range.

[0069] The authority allocation unit specifies organizations and roles for users according to the pre-built three-level domain management structure and stores them in the database.

[0070] The permission judgment unit matches the permission result obtained by the permission management unit with the permission of the user in the database. If the match is successful, the request is allowed to continue processing, otherwise an error message of insufficient permission is returned. At the same time, the permission judgment unit can also associate the data domain information according to the organization information in the permission structure, and automatically add query conditions to the query statement in combination with the preset filtering conditions to ensure that the data returned is within the data domain range.

[0071] It should be noted that other technical features of the device are consistent with the technical solution of the above method and will not be described in detail here.

[0072] In summary, the present invention performs power division and domain division calculations through annotations, which can be used not only on classes but also in class methods. When a user obtains data through an access method, it can automatically determine whether the user has permission based on the configuration in the annotation and return the data domain with permission, without the need for each business layer to use code to implement power division and domain division respectively. This greatly simplifies the writing of permission control codes and improves development efficiency. At the same time, it can flexibly define permission ranges and permission codes according to business needs, automatically process permission requests, reduce the possibility of human errors, and reduce the granularity of permission control, providing a more secure, flexible and efficient permission management method for the Internet of Things system.

[0073] It should be noted that, for the above-mentioned various embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, and according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0074] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. In the several embodiments provided in this application, it should be understood that the disclosed method or system can be implemented in other ways. For example, the embodiments described above are only schematic, such as the division of the units, which is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0075] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0076] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0077] The above is only an exemplary embodiment of the present disclosure, and the scope of the present disclosure cannot be limited thereto. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure here, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any modification, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field not recorded in the present disclosure. The description and examples are regarded as exemplary only, and the scope and spirit of the present disclosure are defined by the claims.

[0078] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0079] It will be easily understood by those skilled in the art that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A permission automatic control method based on power division and domain division, characterized in that: The method comprises: Acquire a system function interface, set a permission structure for the system function interface, assign attributes to the permission structure, and obtain authority-based attributes and domain-based attributes; Receiving a user request, mapping the user request to a functional interface of a corresponding target module, and obtaining decentralized data based on the decentralized attribute; Determining whether the user has access rights according to the authority-sharing data; If yes, the data domain information is associated according to the decentralized data, and the filtering conditions corresponding to the domain attributes are automatically added to the user's database query statement according to the domain attributes, and the data within the data domain range is fed back to the user; if no, access is denied.

2. The automatic permission control method based on power division and domain division according to claim 1 is characterized in that: Assigning attributes to the authority structure includes: Defining a permission model, and assigning attributes to the permission structure according to the permission model; The permission model includes one or more of a login identification attribute, a permission code attribute, a region range attribute, and a filtering condition attribute.

3. The automatic permission control method based on power division and domain division according to claim 1 or 2 is characterized in that: The authority structure includes: a module layer authority structure and an interface layer authority structure.

4. The automatic permission control method based on power division and domain division according to claim 3 is characterized in that: Assigning attributes to the authority structure also includes: According to the permission model, attribute values ​​are assigned to the module layer permission structure and the interface layer permission structure respectively; Or, only assign attributes to the interface layer permission structure according to the permission model.

5. The automatic permission control method based on power division and domain division according to claim 2 is characterized in that: The authority-sharing data includes a target login identifier, a target authority code and a target area range of a target interface that the current user wants to access.

6. The automatic authority control method based on authority division and domain division according to claim 5 is characterized in that: Judging whether the user has access rights according to the authority-sharing data includes: Obtain the user login ID, user authority code and user area range of the current user from the database, and match the user login ID, user authority code and user area range with the target login ID, target authority code and target area range of the target interface to be accessed by the user; If the login IDs of the two are consistent, the current user has the user permission code required to access the data, and the user area range and the target area range intersect, it means that the current user has access rights; otherwise, it means that the current user does not have access rights; If the match fails, it means that the current user does not have access rights.

7. The automatic authority control method based on authority division and domain division according to claim 6 is characterized in that: Associating data domain information according to the decentralized data includes: obtaining the intersection, and associating corresponding data domain information according to the intersection.

8. The automatic authority control method based on authority division and domain division according to claim 6 is characterized in that: The acquisition of the database includes: Scan the functional interfaces of all target modules in the system, and cache the attributes of the permission structure corresponding to the functional interfaces to obtain a database.

9. The automatic permission control method based on power division and domain division according to claim 1 is characterized in that: The domain attributes are filter condition attributes, including specified table names and field names.

10. A computer device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 9.