Application permission establishment method and application permission establishment system
By introducing application permission establishment methods and systems in the data center, and automatically judge and grant data permissions, the problems of high time costs and data security risks caused by relying on manual audits in the existing technology are solved, and efficient and secure data permission management is achieved.
Patent Information
- Application Number
- CN202311533424.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-05-16
AI Technical Summary
The establishment of data permissions in existing data centers mainly relies on manual audits, resulting in high time costs and increased data security risks, and lack of automated and systematic solutions.
Provides a method and system for establishing application permissions. The data processing module determines whether the permission exists in the permissions table. If it exists, it will be automatically granted, otherwise it will be reviewed by the audit committee.
It realizes automated and systematic data permission management, reduces labor costs, improves data security, and promotes the company's digital transformation.
Smart Images

Figure CN120012120A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an application authority establishment method and an application authority establishment system, and in particular to an automated and systematic application authority establishment method and an application authority establishment system. Background Art
[0002] With the increase in information technology and confidentiality requirements, highly confidential data is usually stored in the company's internal data center, such as order information, financial information, and procurement information. Employees belonging to different units or different levels may have different data scopes that can access these highly confidential data. Therefore, based on information security issues, the data center must establish a permission mechanism to regulate the data permissions that different employees can access.
[0003] However, the establishment of data permissions in current data centers is mainly based on manual review. Generally speaking, the review committee first collects each employee's requirements for data permissions, and then determines the data permissions that each employee can access. In addition to increasing time costs, such a complicated permission establishment method also exposes the company to data security risks.
[0004] In this situation, how to automate and systematize the application permission establishment method and application permission establishment system and accelerate the digital transformation of the industry has become one of the goals that the industry is striving for. Summary of the invention
[0005] One of the main purposes of the present invention is to provide an application permission establishment method and an application permission establishment system to solve the above-mentioned problem.
[0006] The present invention provides an application permission establishment method, comprising: requesting a first permission; determining whether the first permission exists in a plurality of application permissions in a permission summary table; obtaining the first permission when the first permission exists in the plurality of application permissions in the permission summary table; and reviewing the first permission when the first permission does not exist in the plurality of application permissions in the permission summary table.
[0007] The present invention provides an application permission establishment system, comprising: a user interface, used to request a first permission; a storage module, used to store a permission summary table; and a data processing module, coupled to the user interface and the storage module, used to perform the following steps: determining whether the first permission exists in a plurality of application permissions in a permission summary table; when the first permission exists in the plurality of application permissions in the permission summary table, obtaining the first permission; and when the first permission does not exist in the plurality of application permissions in the permission summary table, reviewing the first permission through the user interface. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 A schematic diagram of a system for establishing application permissions according to an embodiment of the present invention.
[0009] Figure 2 , Figure 3 , Figure 4 Schematic diagram of the process of the method for establishing application authority in different embodiments of the present invention.
[0010] Figure 5 A schematic diagram of an application permission establishment system processing a purchasing system permission according to an embodiment of the present invention.
[0011] Component number description
[0012] 1. Application Permissions Establishment System
[0013] 2, 3, 4 Process
[0014] 10 User Interface
[0015] 20 Storage Modules
[0016] 30 Data processing module
[0017] 50 User Rights Table
[0018] 52. Summary of permissions
[0019] S200-S208, S300-S310, S400-S408 Steps DETAILED DESCRIPTION
[0020] Certain words are used in the specification and subsequent patent applications to refer to specific components. It should be understood by those with ordinary knowledge in the field that hardware manufacturers may use different terms to refer to the same component. This specification and subsequent patent applications do not use differences in names as a way to distinguish components, but use differences in the functions of components as the criteria for distinction. The term "including" mentioned throughout the specification and subsequent patent applications is an open term and should be interpreted as "including but not limited to". In addition, the term "coupled" is used here to include any direct and indirect electrical connection means. Therefore, if the text describes a first device coupled to a second device, it means that the first device can be directly electrically connected to the second device, or indirectly electrically connected to the second device through other devices or connection means.
[0021] In an embodiment, the computing device may adopt at least one of the following examples: central processor unit (CPU), graphics processing unit (GPU), microcontroller (MCU), application processor (AP), field programmable gate array (FPGA), application specific integrated circuit (ASIC), digital signal processor (DSP), system-on-a-chip (SOC), deep learning accelerator. However, the present invention is not limited to these examples.
[0022] Please refer to Figure 1 , Figure 1 Schematic diagram of an application permission establishment system 1 according to an embodiment of the present invention. The application permission establishment system 1 can be configured in a data center to collect user requirements or applications for data permissions, and automatically and systematically allow users to obtain data permissions. The application permission establishment system 1 includes a user interface 10, a storage module 20, and a data processing module 30. The user requests multiple data permissions through the user interface 10. The user interface 10 can be an application programming interface (API). The user's request will be converted into a data format of the data center through the application programming interface. The conversion of the application programming interface is well known to those skilled in the art and will not be repeated here. It should be noted that, for the sake of clarity, the following embodiments are all based on the user requesting a first permission as an example, but are not limited to this. The storage module 20 is used to store a permission summary table, which records a plurality of application permissions, which are application permissions that the user has obtained or application permissions that are preset to be obtained. The data processing module 30 is coupled to the user interface 10 and the storage module 20, and is used to execute an application permission establishment method to determine whether the user can obtain the first permission based on a plurality of application permissions in the permission summary table.
[0023] The application permission establishment method of the application permission establishment system 1 can be summarized into a process 2, such as Figure 2 Process 2 includes the following steps:
[0024] Step S200: Start.
[0025] Step S202: Determine whether the first permission exists in a plurality of application permissions in the permission list.
[0026] Step S204: When the first permission exists in a plurality of application permissions in the permission list, the first permission is obtained.
[0027] Step S206: When the first permission does not exist in the plurality of application permissions in the permission summary table, review the first permission through the user interface.
[0028] Step S208: End.
[0029] According to process 2, in step S202, when the user requests multiple data permissions through the user interface 10, the data processing module 30 determines whether the first permission exists in the multiple application permissions in the permission list. In step S204, when the first permission exists in the multiple application permissions in the permission list, that is, the first permission is an application permission that the user can obtain or has obtained, the data processing module 30 allows the user to obtain the first permission. On the contrary, in step S206, when the first permission does not exist in the multiple application permissions in the permission list, the data processing module 30 cannot allow the user to automatically obtain the first permission. Therefore, other mechanisms are needed to review whether the user can obtain the first permission. For example, when the first permission does not exist in the multiple application permissions in the permission list, the data processing module 30 sends the first permission to a review committee, which can be composed of the user's supervisor, etc. The members of the review committee can review the first permission through the user interface 10.
[0030] In one embodiment, reviewing the first permission through the user interface can be summarized as a process 3, such as Figure 3 Process 3 includes the following steps:
[0031] Step S300: Start.
[0032] Step S302: Determine whether the first permission exists in the plurality of application permissions in the permission list. If yes, execute step S304. If no, execute step S306.
[0033] Step S304: Obtain the first authority.
[0034] Step S306: Determine whether the first permission has passed the review. If yes, execute step S304. If no, execute step S308.
[0035] Step S308: Stop obtaining the first permission.
[0036] Step S310: End.
[0037] For detailed descriptions of steps S302 and S304 and their derivative changes, please refer to the above description, which will not be repeated here. In step S306, after receiving the user's request for the first permission, the member of the review committee reviews the first permission through the user interface 10. When the first permission fails to pass the review, the data processing module 30 cannot allow the user to obtain the first permission. On the contrary, when the first permission passes the review, the data processing module 30 allows the user to obtain the first permission. It should be noted that there is no first permission in the multiple application permissions in the permission summary table, so the data processing module 30 can add the first permission to the permission summary table, so that when the user requests the first permission again in the future, the permission establishment system 1 can automatically pass the request for the first permission without going through the review committee. In one embodiment, when the application permission establishment system 1 is initially established, there may be no data permissions in the permission summary table, so each of the multiple data permissions applied by the user will go through step S306, and some of the multiple data permissions will be added to the permission summary table after passing the review of the review committee.
[0038] On the other hand, the review committee can use the application permission establishment system 1 to actively change (add, update and reduce) the permission list and the user's permission range. For example, the review committee members review a second permission among the multiple application permissions in the permission list through the user interface 10. When the second permission passes the review, the permission list is maintained; when the second permission fails the review, the second permission in the permission list is deleted. In addition, if the second permission is the same as the first permission requested or obtained by the user, the first permission is stopped or revoked.
[0039] Furthermore, different users may have different scopes of authority and their corresponding authority tables, and their requested data authorities may also be different. In order to more effectively manage the scope of authority of users, in another embodiment, the present invention may further add an automatic deletion of data authority function so that there will not be too many data authorities in the authority table to cause information security problems. The automatic deletion of data authority function can be summarized as a process 4, such as Figure 4 Process 4 includes the following steps:
[0040] Step S400: Start.
[0041] Step S402: Determine whether to delete a third permission in the permission list.
[0042] Step S404: When the third permission is not requested for a critical time, the third permission is deleted from the permission list.
[0043] Step S406: When the third permission is requested, maintain the third permission in the permission list.
[0044] Step S408: End.
[0045] For detailed description of process 4 and its derivative changes, please refer to the above description and will not be repeated here. It should be noted that process 4 is a different embodiment of the present invention, and those skilled in the art can make different modifications accordingly, without limitation to this. For example, when the third permission has not been requested for a critical time, the data processing module 30 deletes the third permission in the permission list and at the same time reclaims the data permission that the user has obtained that is the same as the third permission. For example, the data processing module 30 can first determine whether the third permission is a data permission that the user has obtained. If so, process 4 is not executed. If not, process 4 is started.
[0046] Finally, for the actual operation of the application permission establishment system 1, please refer to Figure 5 . Figure 5 The schematic diagram of the permission establishment system 1 for processing the permissions of a purchasing system according to an embodiment of the present invention is shown. A permission summary table 52 and a user permission table 50 are stored in the storage module 20. The permission summary table 52 records the data permissions that the user can obtain, which includes a purchase requisition list, an inventory list, and a work list. The user permission table 50 records the data permissions that the user currently has, which includes an inventory list. In one embodiment, when a user requests data permissions for a purchase requisition list through the user interface 10, the data processing module 30 determines that the data permissions for the purchase requisition list are included in the data permissions recorded in the permission summary table 52, so the user can automatically obtain the data permissions for the purchase requisition list. In other words, the data processing module 30 will add the data permissions for the purchase requisition list to the user permission table 50. It should be noted that if Figure 5 As shown, the user can request to modify the user rights table 50, and the review committee can modify the authority table 52. In addition, the data authority range of the authority table 52 will be greater than or equal to the data authority range of the user rights table 50. In another embodiment, the review committee can delete the data authority of the inventory list in the authority table 52 (not shown). Figure 5 ), the data processing module 30 determines that the data permission of the inventory list in the user authority table 50 no longer exists in the authority total table 52, so the data processing module 30 deletes the data permission of the inventory list in the user authority table 50 accordingly.
[0047] It should be noted that the application permission establishment system 1 is an embodiment of the present invention, and a person with ordinary knowledge in the art can combine, modify or change the above-mentioned embodiments according to the spirit of the present invention, but is not limited thereto. All of the above descriptions, steps, and / or processes (including recommended steps) can be implemented by hardware, software, firmware (i.e., a combination of hardware devices and computer instructions, the data in the hardware devices are read-only software data), electronic systems, or a combination of the above devices. Hardware may include analog, digital and hybrid circuits (i.e., microcircuits, microchips or silicon chips). Electronic systems may include system on chip (SoC), system in package (SiP), computer module (CoM) and computer system. The process steps and embodiments of the present invention may exist in the form of program code or instructions and be stored in the storage module 20. The storage module 20 may be a computer-readable recording medium, and the storage module 20 may include a read-only memory (ROM), a flash memory (Flash Memory), a random-access memory (RAM), a subscriber identity module (SIM), a hard disk or a CD-ROM / DVD-ROM / BD-ROM, but is not limited thereto. The above-mentioned processes and embodiments may be compiled into program codes or instructions and stored in the storage module 20. The data processing module 30 may be used to read and execute the program codes or instructions stored in the storage module 20 to implement all the aforementioned steps and functions.
[0048] In summary, the application permission establishment method and application permission establishment system of the present invention can automatically and systematically process the user's data permission request and manage the user's permission scope. The review committee can review and change the user's permission scope through the application permission establishment method and application permission establishment system of the present invention. In this way, compared with the previous technology, the present invention can reduce labor costs and accelerate the company's digital transformation.
[0049] The above description is only a preferred embodiment of the present invention. All equivalent changes and modifications made according to the scope of the patent application of the present invention should fall within the scope of the present invention.
Claims
1. A method for establishing application permissions, characterized in that: The method comprises executing the following steps using a computing device: Requesting a first permission; Determining whether the first permission exists in a plurality of application permissions in a permission summary table; When the first permission exists in the plurality of application permissions in the permission summary table, obtaining the first permission; as well as When the first permission does not exist in the plurality of application permissions in the permission summary table, the first permission is reviewed.
2. The method for establishing application permissions according to claim 1, characterized in that: Also included: When the first permission passes the review, obtaining the first permission and adding the first permission to the plurality of application permissions in the permission summary table; as well as When the first permission fails to pass the review, the acquisition of the first permission is stopped.
3. The method for establishing application permissions according to claim 1, characterized in that: Also included: Reviewing a second permission among the plurality of application permissions in the permission summary table; When the second authority passes the review, maintaining the authority summary list; as well as When the second permission fails to pass the review, the second permission in the permission summary table is deleted.
4. The method for establishing application permissions according to claim 3, characterized in that: The step of deleting the second permission in the permission summary table further includes: If the second permission is the same as the first permission, stop obtaining or revoke the first permission.
5. The method for establishing application permissions according to claim 1, characterized in that: Also included: Determine whether to delete a third permission in the permission list; When the third permission is not requested for a critical time, deleting the third permission in the permission summary table; as well as When the third permission is requested, the third permission in the permission list is maintained.
6. An application permission establishment system, characterized in that: Contains: A user interface, used to request a first permission; A storage module, used to store a permission list; and A data processing module, coupled to the user interface and the storage module, is used to perform the following steps: Determining whether the first permission exists in a plurality of application permissions in a permission summary table; When the first permission exists in the plurality of application permissions in the permission summary table, obtaining the first permission; as well as When the first permission does not exist in the plurality of application permissions in the permission summary table, the first permission is reviewed through the user interface.
7. The application permission establishment system according to claim 6, characterized in that: The data processing module also performs the following steps: When the first permission passes the review, obtaining the first permission and adding the first permission to the plurality of application permissions in the permission summary table; as well as When the first permission fails to pass the review, the acquisition of the first permission is stopped.
8. The application permission establishment system according to claim 6, characterized in that: The data processing module also performs the following steps: Reviewing a second permission among the plurality of application permissions in the permission summary table through the user interface; When the second authority passes the review, maintaining the authority summary list; as well as When the second permission fails to pass the review, the second permission in the permission summary table is deleted.
9. The application permission establishment system according to claim 8, characterized in that: The step of deleting the second permission in the permission summary table further includes: If the second permission is the same as the first permission, stop obtaining or revoke the first permission.
10. The application permission establishment system according to claim 6, characterized in that: The data processing module also performs the following steps: Determine whether to delete a third permission in the permission list; When the third permission is not requested for a critical time, deleting the third permission in the permission summary table; as well as When the third permission is requested, the third permission in the permission list is maintained.