Function permission migration method and device of heterogeneous system and medium
By obtaining and configuring the permission allocation carrier relationship and functional permission migration information between heterogeneous systems, the complexity and cost of permission data migration between heterogeneous systems is solved, and efficient, accurate and low-cost permission migration is achieved, reducing the system migration cost and improving security and consistency.
Patent Information
- Application Number
- CN202510094617.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art has high cost, low efficiency and high security risks in the migration of permission data between heterogeneous systems due to complexity and incompatibility between systems, making it difficult to achieve efficient, accurate and low-cost permission migration.
By obtaining the permission allocation carrier relationship between the source system and the target system, configure functional permission migration information, including source value, target value and migration method, replace the carrier value based on the preset carrier matching rules, and perform permission migration based on the functional permission migration information.
Significantly reduce system migration costs, improve the accuracy and consistency of permission migration, provide high flexibility and adaptability, simplify permission migration process, and lower technical thresholds.
Smart Images

Figure CN120012130A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, device and medium for migrating functional permissions in heterogeneous systems. Background Technology
[0002] In today's digital age, the rapid development of information technology has prompted enterprises to frequently upgrade and replace their information systems to adapt to ever-changing business needs and improve system performance and functionality. Data in information systems mainly falls into two categories: business data and access control data.
[0003] Business data has strong business attributes and exhibits relatively small differences across different systems, making its migration and integration relatively convenient during system upgrades. However, the situation is quite different for access control data. Access control data varies significantly across different information systems, and even within the same system, it can present multiple patterns due to organizational structure, business process complexity, or evolution of system architecture.
[0004] Traditional information system upgrades typically focus on upgrading business data, while permission data, due to its complexity and incompatibility with different systems, is often reclassified within the new system. While this approach ensures the new system's permission architecture is compatible with new business processes and organizational structures to some extent, it incurs high costs. Reclassifying permission data requires significant human, time, and technical resources, including in-depth research into the new system's permission model, repeated communication with business departments to determine permission rules, and the manual entry and configuration of permission information in the new system. This not only increases the direct economic cost of upgrading enterprise information systems but may also lead to business delays and indirect economic losses due to lengthy implementation cycles. Furthermore, it increases the possibility of introducing new security risks and management vulnerabilities due to human error.
[0005] Therefore, how to effectively overcome the differences in permission data between heterogeneous systems and achieve efficient, accurate, and low-cost permission migration has become an urgent technical problem to be solved. Summary of the Invention
[0006] This application provides a method, device, and medium for migrating functional permissions in heterogeneous systems, which addresses the following technical problem: how to effectively overcome the differences in permission data between heterogeneous systems and achieve efficient, accurate, and low-cost permission migration.
[0007] In a first aspect, embodiments of this application provide a method for migrating functional permissions in heterogeneous systems. The method includes: obtaining the relationship between permission allocation carriers in a source system and a target system; configuring functional permission migration information based on preset functional migration requirements; wherein the functional migration information includes: a source value, a target value, and a migration method; the source value and the target value respectively represent the identifiers of functional permission objects in the source system and the target system; replacing the source carrier value of the source carrier in the permission allocation carrier relationship with the target carrier value based on preset carrier matching rules; and performing permission migration based on the functional permission migration information and the source carrier after replacing the target carrier value.
[0008] In one implementation of this application, the permission allocation carrier relationship includes: a source carrier permission relationship table, a target carrier permission relationship table, a source carrier table, a target carrier table, a source carrier matching column, a target carrier matching column, a source permission column, and a target permission column; the target permission allocation carrier relationship includes a target carrier table and a target permission table; the source carrier permission relationship table contains the relationship between carriers and functional permissions in the source system; the target carrier permission relationship table is used to store the relationship between carriers and functional permissions in the target system after migration; the source carrier table contains carrier information in the source system, and the target carrier table contains carrier information in the target system; the source carrier matching column and the target carrier matching column contain the correspondence between the source carrier and the target carrier; the source permission column and the target permission column contain permission information in the source system and the target system.
[0009] In one implementation of this application, the migration methods include: no migration, horizontal migration, migration from a source containing all permissions to a target, and migration from a source containing any one permission to a target. No migration means that functional permission objects that do not exist in the target system are not migrated. Horizontal migration means that for functional permission objects whose source system functions and target system functions can directly correspond, the source value is directly replaced with the target value. Migration from a source containing all permissions to a target means that migration is performed only when all source functional permission objects corresponding to the target functional permission object exist in the replacement result. Migration from a source containing any one permission to a target means that migration is performed when any one of the source functional permission objects corresponding to the target functional permission object exists in the replacement result.
[0010] In one implementation of this application, based on a preset carrier matching rule, the source carrier value of the source carrier in the permission allocation carrier relationship is replaced with the target carrier value. Specifically, this includes: reading source carrier information from the source carrier table and determining the key identifier for matching based on the source carrier matching column; reading target carrier information from the target carrier table and determining the corresponding key identifier based on the target carrier matching column; traversing each record in the source carrier permission relationship table, and comparing and locating each source carrier value with the key identifier in the source carrier table; finding the corresponding target carrier value in the target carrier table through the key identifier matching relationship based on the location result; and replacing the source carrier value in that record in the source carrier permission relationship table with the found target carrier value to complete the carrier value replacement operation for all records in the source carrier permission relationship table.
[0011] In one implementation of this application, permission migration is performed based on functional permission migration information and the source carrier after replacing the target carrier value. Specifically, this includes: traversing the source carrier permission relationship table after replacing the target carrier value based on the source value and target value in the functional permission migration information; for each record in the source carrier permission relationship table, if the migration method is no migration, checking whether the target value exists in the target carrier permission relationship table; if not, skipping the record; if the migration method is a horizontal migration, directly replacing the source value in the record with the target value and updating the target carrier permission relationship table; if the migration method is that the source includes all permission target migrations, checking whether all source values associated with the target value already exist in the replaced source carrier permission relationship table; if so, replacing them and updating the target carrier permission relationship table; if the migration method is that the source has any permission target migration, checking whether any source value associated with the target value exists in the replaced source carrier permission relationship table; if so, replacing it and updating the target carrier permission relationship table.
[0012] In one implementation of this application, the method further includes: before replacing the source carrier value of the source carrier in the permission allocation carrier relationship with the target carrier value based on a preset carrier matching rule, creating a backup of the permission allocation carrier relationship; and after performing permission migration based on the functional permission migration information and the source carrier after replacing the target carrier value, rolling back the carrier value of the source carrier in the permission allocation carrier relationship.
[0013] In one implementation of this application, the method further includes: logging the replacement operation during the migration process; wherein the log records include the source carrier value to be replaced, the target carrier value, the corresponding source value, the target value, the migration method, and the operation time.
[0014] In one implementation of this application, the method further includes: providing a visual migration configuration interface and displaying the migration progress in real time during the permission migration process.
[0015] Secondly, embodiments of this application also provide a function permission migration device for a heterogeneous system, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a function permission migration method for a heterogeneous system as described above.
[0016] Thirdly, embodiments of this application also provide a non-volatile computer storage medium for migrating functional permissions in heterogeneous systems, which stores computer-executable instructions. When the computer-executable instructions are executed, a method for migrating functional permissions in heterogeneous systems as described above is implemented.
[0017] The functional permission migration method, device, and medium for heterogeneous systems provided in this application have the following beneficial effects:
[0018] 1. Significantly Reduced System Migration Costs: In traditional methods, when replacing heterogeneous systems, permission data is often re-divided in the new system, requiring significant manpower and time for permission sorting, allocation, and testing. This invention achieves permission migration by dividing permission allocation carriers and functional permission objects, establishing mapping relationships between carriers and between functional permission objects within the system before and after migration. This avoids the cumbersome work of re-dividing permissions, completing permission configuration with minimal implementation cost, significantly reducing the manpower and time costs of system migration, and improving the efficiency of system upgrades and replacements.
[0019] 2. Improve the accuracy and consistency of permission migration: Different systems have significantly different permission data structures and management models. Manually reclassifying permissions is prone to misunderstandings and operational errors, leading to unreasonable and inconsistent permission allocation. This invention performs permission migration based on clear steps and rules, such as reading the source permission allocation table and replacing the carrier and permission value according to specific matching relationships. Each step is logically rigorous and standardized, effectively ensuring the accuracy and consistency of permission migration. This ensures that the new system's permission settings meet business needs, avoids permission vulnerabilities and abuse risks, and protects data security and normal business operations.
[0020] 3. High Flexibility and Adaptability: The function permission migration settings include four migration methods: No migration, Direct migration, migration from a source containing all permissions to a target (All), and migration from a source containing any one permission to a target (Any). This diverse range of migration methods can handle complex function permission correspondences between different systems. Whether it's a non-existent function, a direct correspondence between the source and target functions, multiple source functions corresponding to a single target function, or a single source function split into multiple target functions, the system can handle these situations flexibly. This makes the invention applicable to various heterogeneous system scenarios, improving the versatility and practicality of the solution.
[0021] 4. Simplified Permission Migration Process and Operational Difficulty: A complete and orderly permission migration process is provided, from setting up permission allocation carrier relationships and function permission migration settings, to reading the source permission allocation table, carrier and permission migration replacement, and finally writing to the target carrier permission relationship table to complete the migration. The steps are clear and easy to operate. Technical personnel only need to follow the established process to configure parameters and perform operations, without needing to understand the complex permission conversion logic, thus lowering the technical threshold and facilitating its promotion and application in enterprises and organizations of different sizes, accelerating the information system upgrade and replacement process. Attached Figure Description
[0022] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0023] Figure 1 A flowchart illustrating a method for migrating functional permissions in a heterogeneous system, as provided in an embodiment of this application;
[0024] Figure 2 This is a schematic diagram of the internal structure of a function permission migration device for a heterogeneous system provided in an embodiment of this application. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0026] This application provides a method, device, and medium for migrating functional permissions in heterogeneous systems, which addresses the following technical problem: how to effectively overcome the differences in permission data between heterogeneous systems and achieve efficient, accurate, and low-cost permission migration.
[0027] The technical solutions proposed in the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0028] Figure 1 This is a flowchart illustrating a method for migrating functional permissions in a heterogeneous system, as provided in an embodiment of this application. Figure 1 As shown in the figure, the functional permission migration method for a heterogeneous system provided in this application embodiment specifically includes the following steps:
[0029] Step 101: Obtain the relationship between the permission allocation carriers of the source system and the target system.
[0030] In one embodiment of this application, the permission allocation carrier relationship includes: a source carrier permission relationship table, a target carrier permission relationship table, a source carrier table, a target carrier table, a source carrier matching column, a target carrier matching column, a source permission column, and a target permission column; the target permission allocation carrier relationship includes a target carrier table and a target permission table; the source carrier permission relationship table contains the relationship between carriers and functional permissions in the source system; the target carrier permission relationship table is used to store the relationship between carriers and functional permissions in the target system after migration; the source carrier table contains carrier information in the source system, and the target carrier table contains carrier information in the target system; the source carrier matching column and the target carrier matching column contain the correspondence between the source carrier and the target carrier; the source permission column and the target permission column contain permission information in the source system and the target system.
[0031] In one embodiment, suppose a large chain enterprise is upgrading its information system. The original sales management system (source system) adopts a simple user-permission direct association mode, while the newly introduced enterprise resource planning system (ERP, target system) adopts the RBAC (role-based access control) mode. Furthermore, the new system has reorganized and divided its functional modules. Under these circumstances, permission migration work is carried out.
[0032] In obtaining the permission allocation carrier relationship between the source and target systems, the technical team first extracts relevant information from the source system database to construct a permission allocation carrier relationship data structure. For example, the source carrier permission relationship table records the association between user IDs and various functional permissions, such as user "U001" having permissions such as "view sales reports" and "modify customer information"; the source carrier table stores detailed information about all users, including user ID, name, department, etc.; the source carrier matching column may be set to "user ID" for subsequent matching operations. From the target system, the team obtains the target carrier permission relationship table (which is empty at this time and used to store migration results), the target carrier table (containing role information in the new system, such as roles "sales specialist" and "sales manager" and their related attributes), the target carrier matching column (also using "role ID" as the matching key identifier), the source permission column (a set of permission identifiers in the source system), and the target permission column (a set of permission identifiers in the target system).
[0033] Step 102: Configure function permission migration information based on preset function migration requirements.
[0034] In one embodiment of this application, the function migration information includes: a source value, a target value, and a migration method. The source value and the target value represent the identifiers of the function permission objects in the source system and the target system, respectively. The migration methods include: no migration, horizontal migration, source including all permissions target migration, and source having any one permission target migration. Specifically, no migration means that function permission objects that do not exist in the target system are not migrated; horizontal migration means that for function permission objects whose functions in the source system and target system can directly correspond, the source value is directly replaced with the target value; source including all permissions target migration means that migration is performed only when all source function permission objects corresponding to the target function permission object exist in the replacement result; source having any one permission target migration means that migration is performed when any one of the source function permission objects corresponding to the target function permission object exists in the replacement result.
[0035] In one embodiment, when configuring function permission migration information based on preset function migration requirements, the enterprise's business experts and technical personnel jointly analyze the functional modules of the source and target systems to determine the correspondence between function permission objects. For example, the "View Sales Reports" function in the source system corresponds to the "Sales Analysis - Report Viewing" function in the target system. Since the two functions directly correspond, the migration method is "Straight Migration". The "Modify Customer Information" function in the source system is split into two functions in the target system: "Modify Basic Customer Information" and "Modify Sensitive Customer Information". These two functions require different permission controls, so the "Modify Customer Information" function is selected using the "Migrate from any source with any permission to the target" method. This information is organized into a function permission migration information table, clearly defining the source value, target value, and migration method for each function permission object.
[0036] Step 103: Based on the preset carrier matching rules, replace the source carrier value of the source carrier in the permission allocation carrier relationship with the target carrier value.
[0037] In one embodiment of this application, after configuring function permission migration information based on preset function migration requirements, the source carrier value of the source carrier in the permission allocation carrier relationship is replaced with the target carrier value based on preset carrier matching rules.
[0038] Specifically, source carrier information is read from the source carrier table, and the key identifier used for matching is determined based on the source carrier matching column; target carrier information is read from the target carrier table, and the corresponding key identifier is determined based on the target carrier matching column; each record in the source carrier permission relationship table is traversed, and for each source carrier value, it is compared and located with the key identifier in the source carrier table; based on the location result, the corresponding target carrier value is found in the target carrier table through the matching relationship of the key identifier; the source carrier value in the record of the source carrier permission relationship table is replaced with the found target carrier value to complete the carrier value replacement operation for all records in the source carrier permission relationship table.
[0039] In one embodiment, when replacing the source carrier value of the source carrier in the permission allocation carrier relationship with the target carrier value based on a preset carrier matching rule, the technician uses a pre-written program script to execute the operation according to the rule. Information for each user is read from the source carrier table, and a key identifier is determined based on the source carrier matching column (user ID); information for each role is read from the target carrier table, and a key identifier is determined based on the target carrier matching column (role ID). Each record in the source carrier permission relationship table is traversed. For example, for the permission record corresponding to user "U001", "U001" is compared with the user ID in the source carrier table to locate the user's detailed information. Then, according to the matching rule, the target role corresponding to user "U001" is found in the target carrier table through the correspondence of the key identifier. Assuming the role corresponding to "U001" in the new system is "Sales Specialist" (role ID "R001"), the source carrier value "U001" in that record in the source carrier permission relationship table is replaced with "R001". This process is repeated until the carrier value replacement operation for all records in the source carrier permission relationship table is completed.
[0040] Step 104: Perform permission migration based on the function permission migration information and the source carrier after replacing the target carrier value.
[0041] In one embodiment of this application, after replacing the source carrier value of the source carrier in the permission allocation carrier relationship with the target carrier value based on the preset carrier matching rules, permission migration is performed based on the function permission migration information and the source carrier after replacing the target carrier value.
[0042] Specifically, based on the source and target values in the function permission migration information, the source carrier permission relationship table after replacing the target carrier value is traversed. For each record in the source carrier permission relationship table, if the migration method is no migration, the target value is checked to see if it exists in the target carrier permission relationship table. If it does not exist, the record is skipped. If the migration method is a horizontal migration, the source value in the record is directly replaced with the target value, and the target carrier permission relationship table is updated. If the migration method is that the source includes all permission target migrations, all source values associated with the target value are checked to see if they already exist in the replaced source carrier permission relationship table. If so, they are replaced and updated in the target carrier permission relationship table. If the migration method is that the source has any permission target migration, any source value associated with the target value is checked to see if it exists in the replaced source carrier permission relationship table. If it exists, it is replaced and updated in the target carrier permission relationship table.
[0043] In one embodiment, when performing permission migration based on function permission migration information and the source carrier after replacing the target carrier value, the system iterates through the source carrier permission relationship table after replacing the target carrier value according to the source value and target value in the function permission migration information. For each record: if the migration method is "no migration", for example, there is an obsolete "old inventory count" function in the source system that does not exist in the target system, the system checks whether the target value (corresponding to the function identifier that does not exist in the target system) is in the target carrier permission relationship table. If it does not exist, the record is skipped; if the migration method is "horizontal migration", such as the "view sales report" function, the source value (source system "view sales report" function identifier) in the record is directly replaced with the target value (target system "sales analysis - report view" function identifier), and the updated record is written to the target carrier permission relationship table; if the migration method is "source includes all permission target migration", assuming the target system's "complex sales data" function is included in the target carrier permission relationship table, the system will perform the following steps: The "Analysis" function corresponds to multiple functions in the source system, such as "In-depth Sales Data Mining" and "Multi-dimensional Sales Data Analysis." The system checks whether all source values associated with the target value exist in the replaced source carrier permission relationship table. If they all exist, the system replaces and updates the target carrier permission relationship table. If the migration method is "Migration of any one permission target from the source," for example, the target system's "Customer Basic Information Modification" function corresponds to the source system's "Modify Customer Information" function (this function is split), the system checks whether any source value associated with the target value (the "Modify Customer Information" function identifier) exists in the replaced source carrier permission relationship table. If it exists, the system replaces and updates the target carrier permission relationship table.
[0044] In one embodiment of this application, to ensure data security and operational traceability during the entire migration process, the following auxiliary steps are also performed: Before replacing the carrier value based on the preset carrier matching rules, the system automatically creates a backup of the permission allocation carrier relationship, completely copying the current permission allocation carrier relationship data of the source system and the target system to a backup storage area. After the permission migration is completed based on the functional permission migration information and the source carrier after replacing the target carrier value, if there is a need to restore to the state before migration (such as when data anomalies are found after migration), the system can roll back the carrier value of the source carrier in the permission allocation carrier relationship, and overwrite the current data with the backup data. At the same time, the system logs each replacement operation during the migration process, and the recorded content includes the replaced source carrier value (such as "U001"), the target carrier value (such as "R001"), the corresponding source value (such as the "View Sales Report" function identifier), the target value (such as the "Sales Analysis - Report View" function identifier), the migration method (such as "Simplified Migration"), and the operation time.
[0045] In addition, to facilitate operation for technical and business personnel, the system provides a visual migration configuration interface. In this interface, technical personnel can intuitively view and configure parameters such as permission allocation carrier relationships and functional permission migration information. During the permission migration process, the visual interface displays the migration progress in real time, allowing users to understand the real-time status of the migration through progress bars and status prompts. Information such as the number of functional permissions already migrated, the remaining number to be migrated, and whether any errors have occurred during the migration process can be promptly identified and resolved, ensuring the smooth completion of the permission migration. Through the above detailed implementation steps, this chain enterprise successfully migrated functional permissions from the old sales management system to the new ERP system, reducing migration costs while ensuring the accuracy and flexibility of permission migration, and improving the management efficiency and security of the enterprise information system.
[0046] The above are embodiments of the method proposed in this application. Based on the same inventive concept, embodiments of this application also provide a function permission migration device for heterogeneous systems, the structure of which is as follows: Figure 2 As shown.
[0047] Figure 2 This is a schematic diagram of the internal structure of a function permission migration device for a heterogeneous system, provided as an embodiment of this application. Figure 2 As shown, the device includes:
[0048] At least one processor 201;
[0049] And a memory 202 that is communicatively connected to at least one processor;
[0050] The memory 202 stores instructions executable by at least one processor, which are executed by at least one processor 201 to enable at least one processor 201 to:
[0051] Obtain the relationship between the permission allocation carriers of the source system and the target system;
[0052] Based on preset function migration requirements, configure function permission migration information; wherein, function migration information includes: source value, target value and migration method;
[0053] The source value and target value represent the identifiers of the functional permission objects in the source system and target system, respectively.
[0054] Based on the preset carrier matching rules, the source carrier value of the source carrier in the permission allocation carrier relationship is replaced with the target carrier value;
[0055] Permission migration is performed based on the functional permission migration information and the source carrier after replacing the target carrier value.
[0056] Some embodiments of this application provide corresponding to Figure 1 A non-volatile computer storage medium for function permission migration in heterogeneous systems, storing computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0057] Obtain the relationship between the permission allocation carriers of the source system and the target system;
[0058] Based on preset function migration requirements, configure function permission migration information; wherein, function migration information includes: source value, target value and migration method;
[0059] The source value and target value represent the identifiers of the functional permission objects in the source system and target system, respectively.
[0060] Based on the preset carrier matching rules, the source carrier value of the source carrier in the permission allocation carrier relationship is replaced with the target carrier value;
[0061] Permission migration is performed based on the functional permission migration information and the source carrier after replacing the target carrier value.
[0062] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for IoT devices and media are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0063] The systems, media, and methods provided in this application are one-to-one correspondences. Therefore, the systems and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be repeated here.
[0064] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0065] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0066] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0067] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0068] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0069] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0070] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0071] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0072] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for migrating functional permissions of a heterogeneous system, characterized in that: The method comprises: Obtain the authority allocation carrier relationship between the source system and the target system; Based on the preset function migration requirements, configure function permission migration information; wherein the function migration information includes: source value, target value and migration mode; the source value and the target value represent the identifiers of the function permission objects in the source system and the target system respectively; Based on a preset carrier matching rule, replacing a source carrier value of a source carrier in the authority allocation carrier relationship with a target carrier value; Based on the function permission migration information and the source carrier after replacing the target carrier value, permission migration is performed.
2. According to the method for migrating functional permissions of a heterogeneous system according to claim 1, it is characterized in that: The authority allocation carrier relationship includes: a source carrier authority relationship table, a target carrier authority relationship table, a source carrier table, a target carrier table, a source carrier matching column, a target carrier matching column, a source authority column, and a target authority column; the target authority allocation carrier relationship includes a target carrier table and a target authority table; The source carrier authority relationship table includes the relationship between carriers and functional authorities in the source system; The target carrier authority relationship table is used to store the relationship between the carrier and the functional authority in the target system after migration; The source carrier table contains carrier information in the source system, and the target carrier table contains carrier information in the target system; The source carrier matching column and the target carrier matching column contain a corresponding relationship between a source carrier and a target carrier; The source permission column and the target permission column contain permission information in the source system and the target system.
3. The method for migrating functional permissions of a heterogeneous system according to claim 2, characterized in that: The migration modes include: no migration, horizontal migration, migration of the source including all permission targets, and migration of the source including any one permission target; The "non-migration" means that the functional permission objects that do not exist in the target system will not be migrated; The migration means directly replacing the source value with the target value for the function permission objects that can directly correspond to the source system function and the target system function; The source includes all rights target migration means that the migration is performed only when all source function rights objects corresponding to the target function rights object exist in the replacement result; The source has any one permission target migration means that when any one of the source function permission objects corresponding to the target function permission object exists in the replacement result, the migration is performed.
4. The method for migrating functional permissions of a heterogeneous system according to claim 3, characterized in that: Based on a preset carrier matching rule, the source carrier value of the source carrier in the authority allocation carrier relationship is replaced with the target carrier value, specifically including: Read the source carrier information from the source carrier table, and determine the key identifier for matching based on the source carrier matching column; Read the target carrier information from the target carrier table, and determine the corresponding key identifier according to the target carrier matching column; Traverse each record in the source carrier authority relationship table, and for each source carrier value, compare and locate it with the key identifier in the source carrier table; According to the positioning result, the corresponding target carrier value is found in the target carrier table through the matching relationship of the key identifier; Replace the source carrier value in the record in the source carrier authority relationship table with the found target carrier value to complete the carrier value replacement operation for all records in the source carrier authority relationship table.
5. The method for migrating functional permissions of a heterogeneous system according to claim 4, characterized in that: Based on the function permission migration information and the source carrier after replacing the target carrier value, permission migration is performed, specifically including: Based on the source value and the target value in the functional authority migration information, traverse the source carrier authority relationship table after replacing the target carrier value; For each record in the source carrier authority relationship table, if the migration mode is not to migrate, check whether the target value exists in the target carrier authority relationship table, if not, skip the record; If the migration method is horizontal migration, directly replace the source value in the record with the target value and update the target carrier's permission relationship table; If the migration method is source including all permissions target migration, check whether all source values associated with the target value already exist in the replaced source carrier permission relationship table. If so, replace them and update them to the target carrier permission relationship table; If the migration method is that the source has any permission target migration, check whether any source value associated with the target value exists in the source carrier permission relationship table after replacement. If so, replace it and update it to the target carrier permission relationship table.
6. A method for migrating functional permissions of a heterogeneous system according to claim 5, characterized in that: The method further comprises: Before replacing the source carrier value of the source carrier in the rights allocation carrier relationship with the target carrier value based on a preset carrier matching rule, creating a rights allocation carrier relationship backup; After the authority migration is performed based on the function authority migration information and the source carrier after replacing the target carrier value, the carrier value of the source carrier in the authority allocation carrier relationship is rolled back.
7. A method for migrating functional permissions of a heterogeneous system according to claim 6, characterized in that: The method further comprises: Log the replacement operation during the migration process; wherein the log record includes the replaced source carrier value, target carrier value, corresponding source value, target value, migration method and operation time.
8. The method for migrating functional permissions of a heterogeneous system according to claim 7, characterized in that: The method further comprises: Provides a visual migration configuration interface and displays the migration progress in real time during the permission migration process.
9. A functional permission migration device for a heterogeneous system, characterized in that: The device comprises: at least one processor; and, a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a function permission migration method for a heterogeneous system as described in any one of claims 1-8.
10. A non-volatile computer storage medium for functional permission migration of heterogeneous systems, storing computer executable instructions, characterized in that: When the computer executable instructions are executed, a method for migrating functional permissions of a heterogeneous system as described in any one of claims 1 to 8 is implemented.