Authority management method and device, electronic equipment, readable storage medium and chip

By allocating and managing object roles and permissions in the permission management database, the shortcomings in the division of permission management types and user permission configuration in the existing technology are solved, and flexible and efficient permission control is achieved.

CN120012125APending Publication Date: 2025-05-16CHINA SHIP DEV & DESIGN CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411884485.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the permission management function does not support dividing permission scopes by a certain type, nor can it be configured for the permission scopes between different objects of the same user under the same type.

Method used

The permission management database obtains multiple object information, determines the first object and the second object, assigns the role and permission set corresponding to each object, and in response to the permission adjustment instruction, the associated user and role set is stored in the database.

Benefits of technology

It realizes setting a role type structure tree for any type of objects, supports permission settings for any object in the platform, expands permission control functions, and improves the efficiency and consistency of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012125A_ABST
    Figure CN120012125A_ABST
Patent Text Reader

Abstract

The invention provides an authority management method and device, electronic equipment, a readable storage medium and a chip. The method comprises the steps that multiple pieces of object information are acquired through an authority management database; first objects and second objects are determined according to the object information, and the first objects comprise at least one second object; determining a first role corresponding to each first object; determining a first role set corresponding to the second object; determining a first permission set corresponding to the first role and a second permission set corresponding to the second role; in response to the permission adjustment instruction, determining a user and a second role set corresponding to the permission adjustment instruction; and associatively storing the user and the second role set in an authority management database. According to the method, the role type structure tree belonging to any type of object can be set for the object, and the permission can be set for any object in the platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of ship design, and in particular to a permission management method, device, electronic device, readable storage medium and chip. Background Art

[0002] Currently, the permission management functions on the market do not support dividing permission ranges by a certain type, nor can they configure permission ranges for different objects of the same type for the same user. Summary of the invention

[0003] In view of this, the present invention aims to solve the problem that the permission management function does not support dividing the permission range by a certain type, and cannot configure the permission range between different objects of the same type for the same user.

[0004] Specifically, the present invention is achieved through the following technical solutions:

[0005] An embodiment of the first aspect of the present invention provides a rights management method.

[0006] An embodiment of the second aspect of the present invention provides a rights management device.

[0007] An embodiment of a third aspect of the present invention provides an electronic device.

[0008] An embodiment of a fourth aspect of the present invention provides a readable storage medium.

[0009] An embodiment of the fifth aspect of the present invention provides a chip.

[0010] The permission management method provided by the present invention includes: obtaining multiple object information through a permission management database; determining a first object and a second object according to the object information, wherein the first object includes at least one second object; determining a first role corresponding to each first object, wherein the first role includes at least one second role; determining a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one second role; determining a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; in response to a permission adjustment instruction, determining a user and a second role set corresponding to the permission adjustment instruction, wherein the second role set includes at least one first role and / or at least one second role; and storing the user in association with the second role set in the permission management database.

[0011] In some technical solutions, optionally, determining the first object and the second object based on the object information includes: determining multiple objects and classification information corresponding to each object based on the object information; determining the object whose classification information is a type category as the first object; and determining the object whose classification information is an instance category as the second object.

[0012] In some technical solutions, optionally, determining the first object and the second object based on the object information also includes: determining multiple objects and classification information corresponding to each object based on the object information; determining the object whose classification information is a department category as the first object; and determining the object whose classification information is a position category as the second object.

[0013] In some technical solutions, optionally, determining a first role corresponding to each first object includes: obtaining role information through a permission management database, wherein the role information includes a first role and a second role; determining the first role corresponding to the first object based on the role information; and determining at least one second role based on the role information and the first role.

[0014] In some technical solutions, optionally, determining a first role set corresponding to a second object includes: determining a first object corresponding to the second object; and determining the first role set according to a first role corresponding to the first object.

[0015] In some technical solutions, optionally, determining the first role set corresponding to the second object also includes: determining the first object corresponding to the second object; determining the second role corresponding to the second object; and determining the first role set based on the first role and the second role corresponding to the first object.

[0016] In some technical solutions, optionally, a first permission set corresponding to a first role and a second permission set corresponding to a second role are determined, wherein the first permission set is a subset of the second permission set, including: obtaining first permission information related to the first role and second permission information related to the second role through a permission management database; determining the first permission set corresponding to the first role based on the first permission information; and determining the second permission set corresponding to the second role based on the second permission information.

[0017] A second aspect of the present invention provides a rights management device, the rights management device comprising:

[0018] An acquisition module is used to acquire multiple object information through a permission management database; a determination module is used to determine a first object and a second object according to the object information, wherein the first object includes at least one second object; the determination module is also used to determine a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one second role; the determination module is also used to determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; the determination module is also used to determine a user and a second role set corresponding to the permission adjustment instruction in response to the permission adjustment instruction, wherein the second role set includes at least one first role and / or at least one second role; a storage module is used to associate the user with the second role set and store it in the permission management database.

[0019] An embodiment of the third aspect of the present invention provides an electronic device, including a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the permission management method in the first aspect.

[0020] An embodiment of the fourth aspect of the present invention provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the permission management method in the first aspect are implemented.

[0021] An embodiment of the fifth aspect of the present invention provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the steps of the permission management method in the first aspect.

[0022] The technical solution provided by the present invention brings at least the following beneficial effects:

[0023] This method can set a role type structure tree for any type of object, and supports setting permissions for any object in the platform, thereby further expanding the platform's permission control function. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0025] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0026] Figure 1A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0027] Figure 2 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0028] Figure 3 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0029] Figure 4 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0030] Figure 5 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0031] Figure 6 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0032] Figure 7 A schematic diagram of a flow chart of a rights management method provided by an embodiment of the present invention;

[0033] Figure 8 A schematic diagram of the structure of a rights management device provided by an embodiment of the present invention;

[0034] Fig. 9 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention;

[0035] Fig.10 A partial model diagram of the rights management method provided by an embodiment of the present invention;

[0036] Fig.11 A schematic diagram of a role type management application interface provided by an embodiment of the present invention;

[0037] Fig.12 A schematic diagram of user roles and department role types provided for an embodiment of the present invention;

[0038] Fig.13 A schematic diagram of a file cabinet management application interface provided by an embodiment of the present invention;

[0039] Fig.14 A schematic diagram of adding roles to a storage object provided by an embodiment of the present invention;

[0040] Fig.15 A schematic diagram of adding a bearer to a role provided by an embodiment of the present invention;

[0041] Fig.16 A rights management operation diagram provided by an embodiment of the present invention.

[0042] The corresponding relationship between the component names and numbers in the figure is as follows:

[0043] 900: authority management device; 901: acquisition module; 902: determination module; 903: storage module; 1000: electronic device; 1109: memory; 1110: processor. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0045] See also Figure 1 The first aspect of the present invention provides a rights management method, comprising the following steps:

[0046] Step S102: obtaining information of multiple objects through a rights management database;

[0047] Step S104: determining a first object and a second object according to the object information, wherein the first object includes at least one second object;

[0048] Step S106: determining a first role corresponding to each first object, wherein the first role includes at least one second role;

[0049] Step S108: determining a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one second role;

[0050] Step S110: Determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set;

[0051] Step S112: In response to the permission adjustment instruction, determining a user and a second role set corresponding to the permission adjustment instruction, wherein the second role set includes at least one first role and / or at least one second role;

[0052] Step S114: associate the user with the second role set and store them in the authority management database.

[0053] The permission management method provided by the present invention is used to handle the permission allocation and control of the complex hierarchical relationship between objects, roles, permissions and users in the model. The method first obtains multiple object information through the permission management database, wherein the permission management database is a data storage module for storing and managing all objects, roles and their related permissions. The object information includes information such as object identification (such as object name, used to distinguish each object), object type, object hierarchy and object attributes. Using the object information, multiple objects in the system can be determined, and these objects are divided into two levels: first objects and second objects, wherein the first object is a higher-level object, usually representing a larger classification; the second object is a lower-level object, usually a more specific element under the first object, that is, there is a subordinate or inclusion relationship between the first object and the second object. Different objects form a hierarchical structure of superior-subordinate or parent-child relationships according to the logical organization method. The hierarchical structure enables the system to organize objects in a tree or mesh form, which is conducive to subsequent permission allocation. Next, a corresponding first role is assigned to each first object, and an association relationship between the first object and the first role is established, and each first role also contains at least one second role. It can be understood that roles are related to permissions. Each first role is associated with and contains at least one second role, which forms a hierarchical relationship, indicating that the second role is subordinate to the first role and can inherit all permissions of the first role. The first role is a higher-level role, usually representing a more basic permission, while the second role is a lower-level role, usually having more detailed permissions in addition to the basic permissions. Next, determine the role associated with the second object, that is, determine at least one role corresponding to each second object, that is, the first role set, which may include only the first role, or the first role and at least one second role. It can be understood that the second object is located at the next level of the first object. In addition to inheriting the basic permissions of the first object, the second object may also have detailed permissions, which means that in addition to being associated with the first role, the second object may also be associated with a second role representing a more detailed permission. Therefore, the first role set corresponding to the second object may include only the first role, or may include both the first role and at least one second role. Next, it is necessary to associate the role with the permission and determine the permission set corresponding to each role. The first role is directly associated with a permission set (the first permission set), which represents the operations that the first role can perform. The second role associated with the first role corresponds to a larger permission set (the second permission set), which includes all permissions in the first permission set and may also have additional extended permissions. Therefore, the first permission set is a subset of the second permission set, which means that the second role not only inherits the permissions of the first role, but also may have some more specific or higher permissions added to it.After determining the permission set, after receiving the permission adjustment instruction, it is necessary to assign the corresponding role to the user according to the instruction. When the user is assigned to a role, the user actually has the permission of the object corresponding to the role, which means that the user is directly associated with the object, not just having the role. When actually executing this method, it is only necessary to assign the user to the corresponding role, without setting permissions one by one, which greatly simplifies the permission management process. It should be noted that at least one role corresponding to the user is a second role set, and the second role set can include at least one first role and any number of second roles, which means that the user can control multiple types of objects at the same time, and can also control each instance object. Finally, the user and the role information assigned to them will be recorded in the permission management database in a persistent manner to support the permission allocation, verification, adjustment and maintenance of the system.

[0054] It should be emphasized that, through this design, permission management becomes more flexible and efficient. At the global level, by setting primary permissions for these first objects, a wide range of permission management can be achieved. Since these first objects often contain multiple subordinate objects, namely second objects, when the first object is granted primary permissions, these permissions can be inherited by all its subordinate objects. At the local level, the personalized needs of specific objects can be met by configuring permissions for the second object separately. This flexible permission configuration mechanism ensures that the system can meet the unique needs of each specific object while maintaining the consistency of overall permission management. In addition, the subject of "user" is the user in the platform. In order to facilitate the authorization of all users in an organization, "user" can be a single or multiple user collections, or a certain organizational department. If the undertaker is a certain department, it is assumed that all users under the department have this identity. It should be noted that there is a special type of object, namely the folder object. Because the folder object has a hierarchical structure, the permissions of the folder are also transmitted hierarchically, which is specifically manifested as follows: the permissions of the parent folder can be passed to the child folder, the child folder cannot operate on the passed permissions, and the child file automatically inherits the permissions passed down by the parent folder.

[0055] In general, in traditional permission management methods, permission management is often based on users or roles, directly associated with specific instance objects, and lacks permission control at the object type level, which means that it is impossible to set permission management policies for a certain type of object as a whole, which will make the permission configuration process cumbersome and difficult to maintain. However, this method constructs a role type structure tree based on type objects, and realizes hierarchical and classified management of permissions by classifying roles according to type objects, so that permissions can be set uniformly at the type level, and all instance objects of this type will inherit these permission settings, greatly improving the efficiency and consistency of permission management. Secondly, traditional methods cannot configure the permission range between different objects of the same type for the same user. Once a user is granted permission for a certain type of object, he or she has the same permission for all instance objects of this type, and cannot perform differentiated control for different instance objects. This may lead to excessive or insufficient permissions in actual applications, and cannot meet the needs of refined permission management. This method supports permission control for instance objects and classification objects of the platform, allowing different permission ranges to be set for different instance objects of the same type for the same user, that is, permissions can be configured separately for each instance object. Thirdly, the traditional method usually directly associates roles with permissions, lacks classification and hierarchical management of roles, resulting in a large number of roles and complex management. This method creates a role type structure tree for any type of object on the platform, classifies and manages roles according to type objects, and different types of objects have their own role categories. Roles are closely associated with type objects, and the permission inheritance relationship is clear and unambiguous.

[0056] Fig.16 It is an operation diagram for permission configuration within the platform. Instance objects and classification objects are stored in containers, and their permissions are granted to roles. Roles are associated with users, thus completing the permission configuration for classifications and instances.

[0057] The following is an example of how to configure permissions on a storage object:

[0058] Step 1: The developer creates a permission management model in the model structure tree of the ontology management application (App), which mainly describes the relationship between roles, role types, storage containers (folders and file cabinets), storage locations (object storage locations, classification storage locations) and permission control tables. The model diagram is attached. Fig.10 .

[0059] Step 2: To implement the function of classifying and managing role types, developers develop a "Role Type Management" App. This App can build a role type structure tree for any type of object, create a unique type role under this type, and support the nesting and permission inheritance of type roles. See the attached Fig.11; For example, create a role type of "Reviewer" under the "Design Document" type object, and create a role type of "Designer" under the "Product" type object.

[0060] Step 3. The role type under "Administrative Department" is special. Its scope of authority is related to the organizational structure. Therefore, the developer develops the "User Role" module in the "User Management" App. Its main function is to associate the role under "Administrative Department" with the department object and create the role of the department. The scope of authority of the department role is the department to which it belongs. See attached. Fig.12 In addition, the role type created based on the administrative department type object is special. It is specifically used to describe the roles under the organizational structure, such as the director and section chief under the department. Their authority is within the department, so it is necessary to further develop the user role module in conjunction with the "User Management" App in the platform. The roles created by the administrative department type object need to be associated with the department object and converted into department roles. The authority of the department role is within the department.

[0061] Step 4: In order to centrally authorize objects within the platform, develop a "File Cabinet Management" App, see attached Fig.13 This App is similar to the resource manager. The storage structure is divided into file cabinets and folders. The storage structure supports self-nesting. Any instance object and classification object in the platform can be stored in the storage container, such as project type (classification) A, file (instance) B, etc. Roles and role bearers are added to the storage objects to complete the permission configuration of the storage objects. See the attached Fig.14 , Attachment Fig.15 , and the authorization is completed. In addition, configure permissions in the file cabinet management. For the categories or objects stored in the file cabinet, add the role that needs to configure permissions and the person who bears the role; and the permission list shows all the methods of the category or object. Check Allow or Deny to configure the access rights of the role.

[0062] In some embodiments, optionally, Figure 2 As shown, determining the first object and the second object according to the object information includes:

[0063] Step S1042: determining multiple objects and classification information corresponding to each object according to the object information;

[0064] Step S1044: Determine that the object whose classification information is the type category is the first object;

[0065] Step S1046: Determine that the object whose classification information is the instance category is the second object.

[0066] In this embodiment, the system first receives and parses the input object information, which may include the object's attributes, categories, hierarchical relationships, and other related data information. Based on these parsing results, multiple objects and their corresponding classification information can be determined. Specifically, the system will traverse all the parsed objects and extract the classification information of each object, where the classification information is used to describe the category type to which the object belongs, and is usually divided into two categories: type category and instance category. Type category objects represent a class of abstract entities with similar attributes and functional characteristics, such as "user type", "document type" or "device type"; while instance category objects are specific and operable entity instances, such as specific object instances pointing to a certain type, such as a specific user account, a specific document file, or a specific device. Through this distinction, the system can achieve macro-level permission settings for all types of objects in the permission management process, while performing micro-level permission control on specific instance objects. Specifically, the system can create a unified permission template for each type of object, set the default permission range of the type of object, and these permissions will be automatically applied to all instance objects under the type to ensure the efficiency of macro-level permission management. At the same time, the system allows personalized permission configuration for instance objects, and achieves refined control over instance objects through inherited type permissions and added additional permissions.

[0067] In some embodiments, optionally, Figure 3 As shown, determining the first object and the second object according to the object information also includes:

[0068] Step S1043: determining multiple objects and classification information corresponding to each object according to the object information;

[0069] Step S1045: determining that the object whose classification information is a department category is the first object;

[0070] Step S1047: Determine that the object whose classification information is the position category is the second object.

[0071] In this embodiment, the way to classify objects is also to traverse all the objects obtained by parsing, extract the classification information of each object and classify them, but when the classification information of the object is a department category, the object is the first object; when the classification information of the object is a position category, the object is the second object. It should be noted that the role types created based on department type objects are special. These role types are specifically used to describe specific roles under the organization, such as department director, section chief, etc. The authority scope of these roles is limited to the department to which they belong, thereby ensuring the refinement of authority management and the isolation of authority between departments. It can be understood that strictly limiting the authority scope of the department role to the department to which it belongs can ensure that the role authority is consistent with the dynamic changes of the organizational structure. Specifically, if the category corresponding to the storage object is a department category, and the role corresponding to it is a department role, then its role bearer will not change with the change of the storage object; and when the category corresponding to the storage object is a type, then its role bearer will be dynamically adjusted according to the change of the storage object, thereby adapting to the dynamic changes of the organizational structure.

[0072] In some embodiments, optionally, Figure 4 As shown, determining a first role corresponding to each first object includes:

[0073] Step S1062: Acquire role information through the authority management database, wherein the role information includes a first role and a second role;

[0074] Step S1064: determining a first role corresponding to the first object according to the role information;

[0075] Step S1066: Determine at least one second role based on the role information and the first role.

[0076] In this embodiment, the role information includes multiple levels of role definitions, wherein the first role is usually a high-level or basic role responsible for defining a wide range of permissions; and the second role is a sub-role or a specific responsibility role based on the first role, with more detailed and limited permissions. After obtaining the role information, the system determines the first role corresponding to the first object according to the role information, and associates it with the role information in the permission management database by matching the attributes or category information of the first object, and identifies the most suitable first role, usually the first role represents. After determining the first role, the system further determines at least one second role according to the role information and the first role. The second role is further refined according to the category corresponding to the first role to adapt to the specific responsibility requirements or operation scope, and the appropriate second role is automatically or manually assigned by analyzing the role type of the first role. For example, based on the first role of "document manager", the system can assign second roles such as "reviewer" according to specific needs. These second roles inherit the basic permissions of the "document manager" and have their own specific operation permissions to meet the needs of different functions.

[0077] In some embodiments, optionally, Figure 5 As shown, determining a first role set corresponding to the second object includes:

[0078] Step S1082: Determine the first object corresponding to the second object;

[0079] Step S1084: Determine a first role set according to the first role corresponding to the first object.

[0080] In this embodiment, the corresponding first object can be determined through the attributes or association information of the second object, and this process is usually implemented through relationship mapping or predefined association rules in an association database. For example, after the system receives the information of the second object "design drawing", it determines that the corresponding first object is "design document" through its type attribute. If the permissions of the second object are only inherited from the permissions of the first object, the role associated with the second object is the same as the role associated with the first object, and no new role is additionally associated, that is, it does not have more subdivided permissions. At this time, the first role set corresponding to the second object only includes the first role corresponding to the first object.

[0081] In some embodiments, optionally, Figure 6 As shown, determining the first role set corresponding to the second object also includes:

[0082] Step S1081: Determine the first object corresponding to the second object

[0083] Step S1083: Determine the second role corresponding to the second object

[0084] Step S1085: Determine a first role set according to the first role and the second role corresponding to the first object.

[0085] In this embodiment, the corresponding first object can be determined through the attributes or association information of the second object. This process is usually implemented through relationship mapping or predefined association rules in an association database. After determining the first object, the system further processes the role assignment of the second object. If the permissions of the second object are not only inherited from the permissions of the first object, but also need to have additional subdivided permissions, the system will adopt a dual role association strategy. Specifically, in addition to inheriting the role associated with the first object, the second object will also be associated with additional second roles based on its own responsibilities and needs. These second roles are used to grant specific permissions to the second object to meet its needs in specific responsibilities. Therefore, at this time, all roles associated with the second object, that is, the first role set, include both the first role and the second role.

[0086] In some embodiments, optionally, Figure 7 As shown, a first permission set corresponding to a first role and a second permission set corresponding to a second role are determined, wherein the first permission set is a subset of the second permission set, including:

[0087] Step S1102: acquiring first permission information related to the first role and second permission information related to the second role through a permission management database;

[0088] Step S1104: Determine a first permission set corresponding to the first role according to the first permission information;

[0089] Step S1106: Determine a second permission set corresponding to the second role according to the second permission information.

[0090] In this embodiment, first, the system obtains the first permission information related to the first role and the second permission information related to the second role through the permission management database. As the core storage module of permission control, the permission management database contains all roles in the system and their corresponding permission information. The first permission information and the second permission information correspond to permission definitions of different levels or categories, respectively. Usually, the first role is a basic role with basic permissions, while the second role is an extended role with more or higher-level permissions. After obtaining the permission information, the system determines the first permission set corresponding to the first role according to the first permission information. Specifically, the system extracts all permissions associated with the first role by querying the role and permission association table in the permission management database, and summarizes them to form a first permission set, which covers all basic permissions required by the first role. Subsequently, the system determines the second permission set corresponding to the second role according to the second permission information. Similarly, the system extracts all permission identifiers associated with the second role by querying the role and permission association table in the permission management database, and summarizes them to form a second permission set. Since the first permission set is a subset of the second permission set, the second role not only inherits all basic permissions of the first role, but also has additional subdivided permissions to meet the needs of higher levels or specific responsibilities.

[0091] like Figure 8 As shown, the second aspect of the present invention provides a control device 900, including: an acquisition module 901, used to acquire multiple object information through a permission management database; a determination module 902, used to determine a first object and a second object according to the object information, wherein the first object includes at least one second object; the determination module 902 is also used to determine a first role corresponding to each first object, wherein the first role includes at least one second role; the determination module 902 is also used to determine a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one second role; the determination module 902 is also used to determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; the determination module 902 is also used to determine a user and a second role set corresponding to the permission adjustment instruction in response to a permission adjustment instruction, wherein the second role set includes at least one first role and / or at least one second role; the storage module 903 is used to associate the user with the second role set and store it in the permission management database.

[0092] like Fig. 9As shown, the third aspect of the present invention provides an electronic device 1000, including a processor 1110, a memory 1109, and a program or instruction stored in the memory 1109 and executable on the processor 1110. When the program or instruction is executed by the processor 1110, the various processes of the embodiment of the above-mentioned permission management method are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0093] Among them, the processor 1110 is used to obtain multiple object information through the permission management database; determine the first object and the second object according to the object information, wherein the first object includes at least one second object; determine a first role corresponding to each first object, wherein the first role includes at least one second role; determine a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one second role; determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; in response to a permission adjustment instruction, determine a user and a second role set corresponding to the permission adjustment instruction, wherein the second role set includes at least one first role and / or at least one second role; and associate the user with the second role set and store it in the permission management database.

[0094] Optionally, the processor 1110 is further configured to determine, based on the object information, multiple objects and classification information corresponding to each object; determine an object whose classification information is a type category as a first object; and determine an object whose classification information is an instance category as a second object.

[0095] Optionally, the processor 1110 is further configured to determine multiple objects and classification information corresponding to each object based on the object information; determine an object whose classification information is a department category as a first object; and determine an object whose classification information is a position category as a second object.

[0096] Optionally, the processor 1110 is further configured to obtain role information through a rights management database, wherein the role information includes a first role and a second role; determine the first role corresponding to the first object according to the role information; and determine at least one second role according to the role information and the first role.

[0097] Optionally, the processor 1110 is further configured to determine a first object corresponding to the second object; and determine a first role set according to a first role corresponding to the first object.

[0098] Optionally, the processor 1110 is further configured to determine a first object corresponding to the second object; determine a second role corresponding to the second object; and determine a first role set according to the first role and the second role corresponding to the first object.

[0099] Optionally, processor 1110 is further used to obtain first permission information related to the first role and second permission information related to the second role through a permission management database; determine a first permission set corresponding to the first role based on the first permission information; and determine a second permission set corresponding to the second role based on the second permission information.

[0100] The fourth aspect of the present invention provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the embodiment of the above-mentioned permission management method are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0101] The methods may be implemented in a variety of different ways depending on the specific features and / or example applications. For example, the methods may be implemented by a combination of hardware, firmware, and / or software. For example, in a hardware implementation, the processor may be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, electronic devices, other device units for performing the above functions, and / or combinations thereof.

[0102] A computer readable storage medium may be a tangible device that can retain and store instructions for use by an instruction execution device. A computer readable storage medium may be an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above devices, but is not limited thereto. A non-exhaustive list of more specific examples of computer readable storage media includes: portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory card, floppy disk, encoding mechanical device (such as a punch card or a groove with a raised structure with instructions recorded) and any suitable combination of the above devices. The computer readable storage medium used herein should not be understood as a transmission signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium, or an electrical signal transmitted through a wire, etc.

[0103] The processor is the processor in the electronic device in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0104] The fifth aspect of the present invention provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the embodiments of the above-mentioned permission management method, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0105] Although this specification includes many specific implementation details, these should not be interpreted as limiting the scope of any invention or the scope of protection claimed, but are mainly used to describe the features of the specific embodiments of specific inventions. Certain features described in multiple embodiments in this specification may also be implemented in combination in a single embodiment. On the other hand, the various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although the features may work as above in certain combinations and even initially claim protection, one or more features from the claimed combination may be removed from the combination in some cases, and the claimed combination may point to a sub-combination or a variation of a sub-combination.

[0106] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring that these operations be performed in the particular order shown or performed sequentially, or requiring that all illustrated operations be performed to achieve the desired results. In some cases, multitasking and parallel processing may be advantageous. In addition, the separation of various system modules and components in the above-described embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product, or packaged into multiple software products.

[0107] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired results. In some implementations, multitasking and parallel processing may be advantageous.

[0108] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0109] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A rights management method, characterized in that: include: Obtain information about multiple objects through the rights management database; Determine a first object and a second object according to the object information, wherein the first object includes at least one of the second objects; Determining a first role corresponding to each of the first objects, wherein the first role includes at least one second role; Determine a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one of the second roles; Determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; In response to a permission adjustment instruction, determining a user and a second role set corresponding to the permission adjustment instruction, wherein the second role set includes at least one of the first roles and / or at least one of the second roles; The user is associated with the second role set and stored in the authority management database.

2. The rights management method according to claim 1, characterized in that: The determining the first object and the second object according to the object information includes: Determine, according to the object information, a plurality of objects and classification information corresponding to each of the objects; Determine that the object of the type category of the classification information is the first object; Determine that the classification information is an object of an instance category as the second object.

3. The rights management method according to claim 1, characterized in that: The determining the first object and the second object according to the object information further includes: Determine, according to the object information, a plurality of objects and classification information corresponding to each of the objects; Determine that the object whose classification information is a department category is the first object; The object whose classification information is determined to be a position category is the second object.

4. The rights management method according to claim 1, characterized in that: The determining a first role corresponding to each of the first objects includes: Acquire role information through a rights management database, wherein the role information includes the first role and the second role; Determining a first role corresponding to the first object according to the role information; At least one second role is determined according to the role information and the first role.

5. The rights management method according to claim 1, characterized in that: The determining the first role set corresponding to the second object includes: determining a first object corresponding to the second object; The first role set is determined according to the first role corresponding to the first object.

6. The rights management method according to claim 1, characterized in that: The determining of the first role set corresponding to the second object further includes: determining a first object corresponding to the second object; determining a second role corresponding to the second object; The first role set is determined according to the first role and the second role corresponding to the first object.

7. The rights management method according to claim 1, characterized in that: The determining a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set, includes: Acquire, through a rights management database, first rights information associated with the first role and second rights information associated with the second role; Determine, according to the first permission information, a first permission set corresponding to the first role; A second permission set corresponding to the second role is determined according to the second permission information.

8. A rights management device, characterized in that: include: An acquisition module is used to obtain information of multiple objects through a rights management database; a determination module, configured to determine a first object and a second object according to the object information, wherein the first object includes at least one of the second objects; The determining module is further configured to determine a first role corresponding to each of the first objects, wherein the first role includes at least one second role The determining module is further configured to determine a first role set corresponding to the second object, wherein the first role set includes the first role or the first role set includes the first role and at least one of the second roles; The determining module is further configured to determine a first permission set corresponding to the first role and a second permission set corresponding to the second role, wherein the first permission set is a subset of the second permission set; The determination module is further configured to determine, in response to the permission adjustment instruction, a user and a second role set corresponding to the permission adjustment instruction, wherein the second role set includes at least one of the first roles and / or at least one of the second roles; A storage module is used to associate the user with the second role set and store them in the authority management database.

9. An electronic device, characterized in that: It comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the rights management method as described in any one of claims 1 to 7.

10. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the rights management method according to any one of claims 1 to 7 are implemented.

11. A chip, characterized in that: The chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the rights management method according to any one of claims 1 to 7.