Data permission implementation method, equipment and medium

By introducing the concepts of data dimensions and data dimension values ​​in data permission management, the problem of lack of flexibility in traditional methods is solved, flexible data permission control for complex business scenarios is achieved, and the flexibility and expansion of data permission management is improved.

CN120012163AInactive Publication Date: 2025-05-16SHENZHEN SMARTCITY TECH DEV GRP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510480418.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional data permission management methods lack flexibility and are difficult to meet the needs of complex and changeable business scenarios, especially when data management is required in a specific dimension.

Method used

By receiving data access requests, the user ID and role ID are determined, and the data dimension and data dimension values ​​associated with the user ID and role ID are queried in the preset permission table. Data dimensions are parameters defined based on text data attributes that require permission control. These dimensions and values ​​can determine the user's accessible data range.

Benefits of technology

It realizes flexible filtering and management of text data that requires permission control, improves the expansion and flexibility of data permission management, and can meet the data permission control needs in different specific business scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012163A_ABST
    Figure CN120012163A_ABST
Patent Text Reader

Abstract

The invention discloses a data permission implementation method and device and a medium, and relates to the technical field of data permission management.The method comprises the steps that an externally input data access request is received, a user identifier in the data access request is determined, and a first association relationship corresponding to the user identifier is determined, the first association relationship comprises an association relationship between the user identifier and the role identifier; querying a data dimension value under the data dimension associated with the first association relationship in a preset permission table containing a mapping relationship between the data dimension and the first association relationship, the data dimension being a parameter defined based on the text data attribute needing permission control; and determining an accessible data range corresponding to the data dimension value, searching request data which is matched with the data access request and is in the accessible data range in a preset database, and outputting the request data as accessible data. The flexibility of data authority management is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data authority management, and in particular to methods, devices and media for implementing data authority. Background Art

[0002] In modern information systems, data permission management is a key component to ensure data security and compliant access. With the continuous improvement of the degree of enterprise informatization, the types and quantities of data have increased dramatically, and the demand for data access has become increasingly complex. Traditional methods usually implement data filtering by setting fixed data permission modes for roles, but this method has problems such as solidification of data permission modes and strong coupling with roles, which makes it difficult to meet the needs of complex and changing business scenarios. For example, when data management is required according to specific dimensions such as administrative divisions or projects, the existing data permission modes are often not flexible enough to adapt. In summary, traditional data permission methods lack flexibility. Summary of the invention

[0003] The main purpose of this application is to provide a data permission implementation method, device and medium, aiming to improve the flexibility of data permission management.

[0004] To achieve the above objectives, this application proposes a data permission implementation method, including: Receiving an externally input data access request, determining a user identifier in the data access request, and determining a first association relationship corresponding to the user identifier, wherein the first association relationship includes an association relationship between the user identifier and the role identifier; In a preset permission table including a mapping relationship between a data dimension and a first association relationship, querying a data dimension value under a data dimension associated with the first association relationship, wherein the data dimension is a parameter defined based on a text data attribute for which permission control is required; Determine the accessible data range corresponding to the data dimension value, search for the requested data that matches the data access request and is within the accessible data range in a preset database, and output the requested data as accessible data.

[0005] In one embodiment, in a preset permission table including a mapping relationship between a data dimension and a first association relationship, before the step of querying a data dimension value under a data dimension associated with the first association relationship, the step includes: Determine text data that needs to be subject to permission control according to at least one preset data access scenario, and use parameters defined by attributes of the text data as data dimensions; For any data dimension, use at least one text data of a preset data source to assign a value to the data dimension to obtain at least one data dimension value, wherein the data source includes a custom data source and a preset system data source; A first association relationship between at least one user identifier and a role identifier is determined, and for each first association relationship, a data dimension and a data dimension value are associated on the first association relationship to obtain a preset permission table.

[0006] In one embodiment, the step of determining a first association relationship between at least one user identifier and a role identifier, and associating a data dimension and a data dimension value on each first association relationship to obtain a preset permission table includes: For any one of the multiple user identifiers, determining a first association relationship between the user identifier and the multiple role identifiers; If, among the multiple first association relationships, there is a second association relationship to be associated with the same first data dimension value, then a user group identifier is set; The user group identifier is associated with the first data dimension value and the first data dimension, and all second association relationships are associated with the user group identifier to obtain a preset permission table, wherein the first data dimension is a data dimension of the first data dimension value.

[0007] In one embodiment, the step of associating the user group identifier with the first data dimension value and the first data dimension includes: Check whether there is a subordinate user group ID in the user group ID; If a subordinate user group identifier exists, determining whether the subordinate user group identifier is associated with a data dimension value; If the subordinate user group identifier is associated with a data dimension value, the first data dimension associated with the user group identifier will be updated to be consistent with the data dimension associated with the subordinate user group identifier, and the first data dimension value associated with the user group identifier will be updated to be consistent with the data dimension value associated with the subordinate user group identifier.

[0008] In one embodiment, after associating the data dimension and the data dimension value on the first association relationship to obtain the preset permission table, the following steps are included: When it is detected that a preset trigger condition associated with the first association relationship is satisfied, triggering a permission adjustment rule associated with the trigger condition, wherein the permission adjustment rule is used to re-associate a new data dimension with the first association relationship and / or re-assign a data dimension value of the data dimension; Apply the permission adjustment rule to adjust the data dimension and / or data dimension value associated with the first association relationship in the preset permission table.

[0009] In one embodiment, when it is detected that a preset trigger condition associated with the first association relationship is met, before the step of triggering a permission adjustment rule associated with the trigger condition, the step includes: If it is detected that the association relationship is associated with a preset time interval, and the current time is within the time interval, it is determined that the preset trigger condition associated with the first association relationship is satisfied.

[0010] In one embodiment, when it is detected that a preset trigger condition associated with the first association relationship is met, before the step of triggering a permission adjustment rule associated with the trigger condition, the step includes: If it is detected that the association relationship is associated with a preset project and the project reaches a preset progress milestone, it is determined that a preset trigger condition associated with the first association relationship is satisfied.

[0011] In one embodiment, the step of obtaining the preset permission table further includes: The first association relationship and the second association relationship summarized in the preset permission table; Generate an association view of the first association relationship and the second association relationship, and output the association view, wherein the association view is used to query and manage user identifiers, role identifiers, user group identifiers, data dimensions and data dimension values ​​according to the first association relationship and the second association relationship.

[0012] In addition, to achieve the above-mentioned purpose, the present application also proposes a data permission implementation device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the data permission implementation method as described above.

[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data permission implementation method as described above are implemented.

[0014] In addition, to achieve the above-mentioned purpose, the present application also provides a product, which is a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the data permission implementation method as described above are implemented.

[0015] One or more technical solutions proposed in this application have at least the following technical effects: The present application receives an external input data access request, obtains the user ID and role ID in the data access request; queries the data dimension and data dimension value associated with the user ID and role ID in the preset permission table. By introducing the concept of data dimension, it can meet the use scenario that requires data management according to a specific dimension. The data dimension is defined according to the attribute of the text data that needs to be controlled by permission. The request data that matches the data access request is searched in the preset database, and the request data in the request data that meets the data dimension value in the data dimension is used as accessible data, and the accessible data is output to the outside. The text data that needs to be controlled by permission can be filtered through the data dimension and the data dimension value, so that the user ID and role ID associated with the data dimension and the data dimension value have the permission to see the text data, thereby improving the scalability of data permission management. In summary, the present application can flexibly meet the data permission control requirements in different specific business scenarios, and improve the flexibility of data permission management. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0018] Figure 1 This is a flowchart of the first embodiment of the method for implementing data permissions for this application; Figure 2 This is a schematic diagram of the data dimensions for the data permission implementation method of this application; Figure 3 This is a scenario diagram of the method for implementing data permissions for this application; Figure 4 This is a schematic diagram of the module structure of the data permission implementation device of the present application embodiment; Figure 5 Schematic diagram of the device structure of the hardware operating environment involved in the data permission implementation method in the embodiment of the present application.

[0019] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0020] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0021] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0022] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of realizing the above functions, a terminal system, etc. The following takes the system as an example to illustrate this embodiment and the following embodiments.

[0023] Based on this, this embodiment provides a data permission implementation method, referring to Figure 1 , Figure 1 This is a flowchart of the data permission implementation method of this application. The data permission implementation method includes steps S10 to S30: Step S10, receiving an externally input data access request, determining a user identifier in the data access request, and determining a first association relationship corresponding to the user identifier, wherein the first association relationship includes an association relationship between the user identifier and the role identifier; Step S20, in a preset permission table including a mapping relationship between a data dimension and a first association relationship, querying a data dimension value under a data dimension associated with the first association relationship, wherein the data dimension is a parameter defined based on a text data attribute that needs to be subject to permission control; Step S30, determining the accessible data range corresponding to the data dimension value, searching a preset database for request data that matches the data access request and is within the accessible data range, and outputting the request data as accessible data.

[0024] When the system receives an external data access request, it parses the request to extract the user ID. Next, the system determines which role IDs are associated with this user ID by querying the pre-built association table. These associations are defined as first associations. Each user ID can be associated with one or more role IDs, depending on the system's permission design.

[0025] With the first association determined, the system looks in the preset permissions table, which records the mapping between data dimensions and the first association. Data dimensions are parameters defined based on text data attributes, such as time range, department name, etc. By matching the first association, the system is able to identify the specific value under a specific data dimension. For example, if a role is limited to viewing data for a specific department, the value of the data dimension will be the name of the department.

[0026] After finding the data dimension values, the system then determines the accessible data range represented by these values. This means calculating the boundaries of the data that users can access based on their associated roles. The system then searches the preset database for all data that meets the data access request and is within the accessible data range determined above. Ultimately, the data that meets the conditions will be returned to the request initiator as accessible data.

[0027] In this process, the principle is to use pre-established rules and mappings to dynamically limit user access rights. The system processes the logical connections between user identification, role identification, data dimensions, and accessible data ranges to ensure that only authorized data is provided to the requester. This mechanism not only enhances security, but also improves data management efficiency.

[0028] In order to optimize this process, a more fine-grained mapping can be implemented between data dimensions and associations, making permission control more flexible and accurate. In addition, introducing a cache mechanism to speed up the retrieval of frequently accessed data dimension values, or using a distributed architecture to process large-scale data sets are possible improvements.

[0029] Furthermore, in order to optimize the application of this embodiment, more data dimensions, such as geographic location, time period, etc., can be introduced in the actual deployment to adapt to more diverse business needs. In addition, it is also possible to consider implementing a dynamic data dimension value update mechanism so that the system can promptly reflect the latest business changes, such as adding new projects or adjusting department structures. Such a design not only simplifies authority management, but also reduces maintenance costs, ensuring the continuous optimization and development of the system. For new needs that may arise in the future, it is only necessary to update the data dimensions and their values ​​accordingly to ensure the flexibility and scalability of the system.

[0030] For example, suppose that in a project management system, user Zhang San has the role of "Project Administrator" and has management rights to Project A. When Zhang San tries to view the project list, the system extracts his user index as the user ID and the role he plays as the role ID from his request. Then, the system searches the background for the data dimensions that Zhang San can access as a "project administrator", such as the project dimension, and the corresponding dimension value, that is, Project A. Next, the system searches the database that stores all project information, and only selects the information belonging to Project A to provide to Zhang San. The advantage of this is that even if the business scenario is complex and changeable, the data access rules can be flexibly adjusted, avoiding the problem of a sharp increase in the number of roles in traditional solutions, while improving the efficiency of permission configuration.

[0031] For ease of understanding, this embodiment can be divided into three steps: The first step is to determine the user's identity and its associated role, that is, to receive the user's access request (such as querying a sales report), first extract the user identifier (such as user ID, account number) in the request, and then find the "role" corresponding to this user (such as "ordinary employee", "department manager", "administrator"). The "first association relationship" here is the mapping of user ID → role ID (for example: user A's role is "department manager"). The user's permission level can be quickly located through the role, because the role is the middle layer of permission management (avoid directly configuring permissions for each user individually to improve management efficiency).

[0032] The second step is to query the accessible data dimension values ​​through the preset permission table.

[0033] The preset permission table is a pre-defined mapping table, which contains the relationship between "role → data dimension → dimension value". For example, as shown in Table 1: Table 1

[0034] The query process is to find all the data dimension values ​​corresponding to the role (such as "sales department" and "marketing department") in the permission table based on the user role obtained in the first step (such as "department manager"). These values ​​determine which attribute conditions the data that the user can access must meet. A role can have multiple data dimensions.

[0035] The third step is to determine the accessible scope and filter the data.

[0036] According to the data dimension value in the second step (assuming that the user has the department dimension and the time dimension, and the department's accessible data range is "Sales Department", and the time's accessible data range is "2024"), it is converted into the database query condition (for example: Department = Sales Department and Time ≥ 2024-01-01).

[0037] In the database, find data that meets both conditions: 1. Meets the user's original request (that is, the "sales report" that the user wants to query in the first step); 2. Is within the accessible range (the department of the report is "sales department" and the time is within 2024).

[0038] Return the filtered data to the user to ensure that the user can only see the data within their permissions.

[0039] For example, suppose the role of user "Zhang San" (user ID: 001) is "Sales Department Employee" (role ID: R02). The permission table stipulates that "R02" can only access data with "Department = Sales Department" and "Data Status = Reviewed"; Zhang San initiates a request to query "2024 sales data". The system first confirms that his role is "R02". In the permission table, it is found that the dimension values ​​corresponding to R02 are "Department = Sales Department" and "Status = Reviewed". The system filters out the data with Department = Sales Department, Status = Reviewed, Time = 2024 from the database and returns it to Zhang San, while data from other departments or unreviewed data will be filtered out.

[0040] This embodiment receives an external input data access request, obtains the user identifier and role identifier in the data access request; queries the data dimension and data dimension value associated with the user identifier and the role identifier in a preset permission table. By introducing the concept of data dimension, it can meet the use scenario that requires data management according to a specific dimension. The data dimension is defined according to the attribute of the text data that needs to be controlled by permission. The request data matching the data access request is searched in the preset database, and the request data in the request data that meets the data dimension value in the data dimension is used as accessible data, and the accessible data is output to the outside. The text data that needs to be controlled by permission can be filtered through the data dimension and the data dimension value, so that the user identifier and role identifier associated with the data dimension and the data dimension value have the permission to see the text data, thereby improving the scalability of data permission management. In summary, this embodiment can flexibly meet the data permission control requirements in different specific business scenarios, and improve the flexibility of data permission management.

[0041] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the first embodiment can be referred to the above description, and will not be repeated hereafter. On this basis, the step S20 also includes steps A10 to A30: Step A10, determining text data that needs to be subject to permission control according to at least one preset data access scenario, and using parameters defined by attributes of the text data as data dimensions; Step A20: for any data dimension, assign a value to the data dimension using at least one text data of a preset data source to obtain at least one data dimension value, wherein the data source includes a custom data source and a preset system data source; Step A30, determining a first association relationship between at least one user identifier and a role identifier, and for each first association relationship, associating a data dimension and a data dimension value on the first association relationship to obtain a preset permission table.

[0042] In this embodiment, the system first determines the text data that needs to be controlled by permission through preset data access scenarios. These scenarios can be specific situations of user operations, such as querying sales records or browsing project documents. For each selected piece of text data, its attributes are defined as parameters, which are data dimensions used to describe and limit the access scope of the data. For example, time period, department name, etc. can be used as data dimensions.

[0043] Next, for each data dimension, the system uses at least one text data in the preset data source to assign values. The data sources here are divided into custom data sources and system preset data sources. Custom data sources allow administrators to enter specific values ​​according to business needs, while system data sources provide pre-configured values. Through this process, each data dimension obtains one or more specific data dimension values. For example, if the data dimension is "department", the possible data dimension values ​​include "marketing department" and "research and development department".

[0044] The system then determines the first association between the user ID and the role ID. This association means that each user ID can correspond to one or more role IDs, indicating which roles the user has. Then, for each first association, the system links it with the previously determined data dimension and data dimension value to build a preset permission table. This table records in detail which users (through roles) can access which data (through text data) under what conditions (through data dimension values).

[0045] For ease of understanding, let's take a specific example. In the school grade management system, first, based on the two preset data access scenarios of "teachers viewing and entering grades" and "students viewing grades", the text data to be controlled for permission is determined to be student grade information, which contains attributes such as student name, course name, and grade score, and they are defined as data dimensions. Next, use the grade table in the grade management system as the data source to assign values ​​to each data dimension. The values ​​of the student name dimension are "Xiao Ming" and "Xiao Hong", etc.; the values ​​of the course name dimension are "mathematics", "Chinese", "English", etc.; the values ​​of the grade score dimension are "80 points", "90 points", "75 points", etc. Finally, determine the association relationship between users and roles (the first association relationship), such as "U001" is "teacher" "R001", "U002" is "student" "R002", and build a preset permission table on this basis. Teachers can associate all student names, course names, and grade scores; assuming that the student is Xiao Ming, he can only associate his own name, the selected "mathematics" and "Chinese" course names, and the corresponding "80 points" and "90 points" grades.

[0046] For example, refer to Figure 2, data dimension has four attributes, namely name, code, data structure and data source. Name and code refer to a certain characteristic of the data that needs to be controlled by permission. The data structure determines whether the data is a list structure or a tree hierarchical structure. The data source is customized or obtained from other data sources. A data dimension value can have N data dimension values. Data dimension values ​​have three attributes, namely name, code and description. The code of the data dimension value refers to the specific data value when the user filters the data permissions. For example, if the data dimension is a project, then the value is the specific project code.

[0047] Furthermore, in order to optimize the application of this embodiment, more complex data dimension combinations can be introduced in the specific implementation to adapt to multi-dimensional permission control requirements. In addition, an automated dimension value update mechanism can be developed to promptly reflect changes in the organizational structure or the addition of new projects. This design not only improves the flexibility of permission configuration, but also simplifies the management process and reduces maintenance costs. In response to new business needs that may arise in the future, data dimensions and their values ​​can be dynamically adjusted to respond quickly and ensure the scalability and adaptability of the system.

[0048] The method provided in this embodiment achieves accurate and flexible permission control by associating user roles with specific text data access conditions. This method can not only effectively protect sensitive information, but also support complex and changing business needs, and improve the security and efficiency of data management and access.

[0049] In a feasible implementation manner, step A30 further includes steps A301 to A303: Step A301, for any one of the multiple user identifiers, determining a first association relationship between the user identifier and multiple role identifiers; Step A302: if there is a second association relationship to be associated with the same first data dimension value among the multiple first association relationships, then set a user group identifier; Step A303, associating the user group identifier with the first data dimension value and the first data dimension, and associating all second association relationships with the user group identifier to obtain a preset permission table, wherein the first data dimension is the data dimension of the first data dimension value.

[0050] In this embodiment, the system first determines, for each of the multiple user identifiers, a first association relationship between the user identifier and the multiple role identifiers. This first association relationship represents the connection between users and the roles they can play. For example, a user may have the roles of "administrator" and "editor" at the same time.

[0051] Next, the system checks these first associations to find out whether there are multiple users associated with the same first data dimension value. The first data dimension value here is a specific value specific to a data dimension, such as "Marketing Department" under the data dimension "Department Name". If there is a situation where multiple users are associated with the same first data dimension value, the system will create a user group ID to represent these users. The purpose of the user group ID is to simplify management by grouping multiple users with the same permissions together.

[0052] Then, the system associates this user group ID with the first data dimension value mentioned above and its corresponding data dimension. This step means that through the user group ID, all grouped users now have common access rights to a specific data dimension value. In addition, all secondary associations (i.e., those first associations that were originally independently associated with the same data dimension value) are now redirected to the user group ID. Finally, after these operations, the system generates a preset permission table, which records the mapping relationship between the user group ID, data dimension and its value.

[0053] In terms of optimization implementation, intelligent analysis tools can be introduced to automatically identify which users should be classified into the same user group ID, thereby reducing manual intervention. Distributed database technology can also be used to store and quickly retrieve permission tables to improve the system's response speed. For large organizations, regular review of user groups and permission settings helps maintain the effectiveness and security of permission configuration.

[0054] For example, refer to Figure 3 , the access subject and user group ID, the access subject and role ID, and the role ID and user group ID are all n-to-n relationships. Data permissions, that is, data dimensions and data dimension values, are bound to the association relationship between the access subject and role ID or the role ID and user group ID.

[0055] For ease of understanding, let’s use the school score management system as an example: Step A301: Assume that there are multiple student IDs (user IDs) in the system, such as "2024001", "2024002" and "2024003". These students have all chosen the "Mathematics Improvement Class" (which can be regarded as a role identification). The system determines the association relationship between each student ID and the "Mathematics Improvement Class" role (i.e., the first association relationship), indicating that these students belong to this class.

[0056] Step A302: In the system, "Course Name" is a data dimension (first data dimension), under which there is a specific value "Advanced Mathematics" (first data dimension value). It is found that the first associations corresponding to the three student numbers "2024001", "2024002" and "2024003" (all belong to "Mathematics Advanced Class") need to be associated with the course data "Advanced Mathematics" (that is, there is a second association to be associated), so the system sets a user group identifier for them, such as "Advanced Mathematics Elective Group".

[0057] Step A303: The system associates the "Advanced Mathematics Elective Group" (user group ID) with the "Course Name" (first data dimension) and its value "Advanced Mathematics" (first data dimension value), and binds all the second associations corresponding to "2024001", "2024002", and "2024003" (i.e., they belong to the "Mathematics Improvement Class" and need to access the "Advanced Mathematics" course) to the "Advanced Mathematics Elective Group". In the final preset permission table, students in the "Advanced Mathematics Elective Group" (associated by the user group ID) have the permission to access the score data of "Course Name" as "Advanced Mathematics", which clearly reflects the permission association between user groups and data dimensions and dimension values.

[0058] Furthermore, in order to optimize the application of this embodiment, a dynamic permission adjustment mechanism can be considered in actual deployment, so that when the organizational structure changes, the data dimensions and dimension values ​​under the user group identification can be quickly updated without having to modify the specific permission configuration of each user one by one. In addition, an intelligent recommendation algorithm can be developed to automatically recommend appropriate user group identification and permission settings based on the user's behavior pattern, thereby simplifying the administrator's workload.

[0059] This implementation improves the efficiency and flexibility of permission management. By using user group identifiers, the workload of repeatedly configuring the same permissions is reduced, and permission adjustment is made more convenient. At the same time, it ensures that only authorized users can access specific data, enhancing the security of the system and the level of data protection. In addition, this approach also supports more refined permission control and adapts to complex changes in business needs.

[0060] In a feasible implementation manner, step A303 further includes steps A304 to A306: Step A304, detecting whether there is a subordinate user group identifier in the user group identifier; Step A305: if the subordinate user group identifier exists, determine whether the subordinate user group identifier is associated with a data dimension value; Step A306, if the subordinate user group identifier is associated with a data dimension value, the first data dimension associated with the user group identifier is updated to be consistent with the data dimension associated with the subordinate user group identifier, and the first data dimension value associated with the user group identifier is updated to be consistent with the data dimension value associated with the subordinate user group identifier.

[0061] In this embodiment, the system first detects whether the user group identifier contains a subordinate user group identifier. The user group identifier mentioned here is an identifier used to represent a group of users with the same authority, while the subordinate user group identifier refers to a more detailed user group belonging to a certain user group.

[0062] If the existence of subordinate user group IDs is detected, the system will then check whether these subordinate user group IDs are associated with data dimension values. Data dimension values ​​are specific values ​​for a data dimension, such as "North China" under the data dimension "Region". This step is to confirm whether the subordinate user groups have been configured with specific access rights.

[0063] When it is found that the subordinate user group identifier is indeed associated with a data dimension value, the system will perform a permission update operation. Specifically, the first data dimension and the first data dimension value associated with the user group identifier will be updated to be consistent with the data dimension and its value associated with the subordinate user group identifier. This means that the original permission settings of the upper user group will be adjusted to reflect the more detailed permission requirements of the subordinate user group.

[0064] For ease of understanding, a department (such as the marketing department) can be used as a user group ID, and different teams within it (such as the advertising team) can be subordinate user group IDs. If the marketing department (user group ID) originally has access to sales data in all regions, but its subordinate advertising team (subordinate user group ID) is only authorized to access data in the North China region, then the marketing department's permissions will be updated to be limited to the North China region.

[0065] In this process, the principle is to organize user groups through a hierarchical structure and allow different permissions to be set for user groups at different levels. This not only simplifies permission management, but also supports fine-grained permission control. Through this mechanism, the system can flexibly respond to changes in the internal structure of the organization and business needs.

[0066] To optimize this process, automated tools can be introduced during the detection and update process to automatically identify permissions that need to be updated and perform the corresponding changes. In addition, the permission settings of user groups and subordinate user groups can be reviewed regularly to ensure that they still meet the latest business rules and security requirements.

[0067] The main benefit of this approach is that it enhances the flexibility and accuracy of permission management. It allows permissions to be precisely configured according to the organizational hierarchy, reducing the workload of manually adjusting permissions. At the same time, this approach improves the adaptability of the system and can quickly respond to organizational structure changes or new business needs. In this way, the system not only ensures data security, but also improves user experience and work efficiency.

[0068] Based on the first or second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first or second embodiment can be referred to the above description, and will not be described in detail later. Step A30 also includes steps B10 to B20: Step B10: when it is detected that a preset trigger condition associated with the first association relationship is met, triggering a permission adjustment rule associated with the trigger condition, wherein the permission adjustment rule is used to re-associate a new data dimension with the first association relationship and / or re-assign a data dimension value of the data dimension; Step B20: Apply the permission adjustment rule to adjust the data dimension and / or data dimension value associated with the first association relationship in the preset permission table.

[0069] In this embodiment, the system monitors whether the first association relationship meets the preset trigger condition. The "first association relationship" here refers to the association between the user ID and the role ID, and the "trigger condition" is a pre-set event or state change, such as the time reaching a certain node, the completion of a specific business process, etc. When these trigger conditions are met, the system will activate the associated permission adjustment rules.

[0070] The permission adjustment rule is used to update the first association relationship. Specifically, it can re-associate a new data dimension with the first association relationship, or re-assign the data dimension value of the existing data dimension. By applying the permission adjustment rule, the user's access rights can be dynamically changed to adapt to different business needs or security policies.

[0071] Once the trigger condition is met, the system will modify the preset permission table according to the preset permission adjustment rule. This process includes checking and updating the data dimension and / or its value involved in the first association relationship.

[0072] For ease of understanding, let's take a specific example. If the preset trigger condition is position transfer, then if an employee is transferred from the sales department to the marketing department, the permission adjustment rule will update the data dimension associated with the employee's role to "marketing department" and adjust the data scope that the employee can access accordingly.

[0073] In terms of specific implementation methods, an automated workflow engine can be introduced to monitor trigger conditions and automatically execute permission adjustment rules. This can not only improve efficiency but also reduce human errors. In addition, using machine learning algorithms to predict future permission requirements and prepare for adjustments in advance is also an innovative optimization method. Regularly reviewing permission adjustment records to ensure that all changes are reasonable and necessary will also help maintain the security of the system.

[0074] The main benefit of this approach is that it enhances the flexibility and responsiveness of permission management. It allows the system to dynamically adjust user permissions based on actual conditions, ensuring the timeliness and accuracy of permission configuration. At the same time, through automated mechanisms, it reduces the need for manual operations and improves work efficiency. This approach also supports more complex business scenarios and ensures the security and compliance of internal information in the organization.

[0075] In a feasible implementation manner, step B10 also includes step B101 before step B10: Step B101: If it is detected that the association relationship is associated with a preset time interval, and the current time is within the time interval, it is determined that a preset trigger condition associated with the first association relationship is satisfied.

[0076] In this embodiment, the system checks whether the first association is associated with a preset time interval. The "first association" here refers to the connection between the user identifier and the role identifier, and the "preset time interval" is one or more pre-set time ranges, such as a specific date period or working time period. If the current time falls within this preset time interval, the system determines that the preset trigger condition of the association is met.

[0077] Specifically, when the system detects that a first association contains a preset time interval, it will compare the current time with the time interval. For example, if there is a role that is only valid between 9:00 and 17:00 on weekdays, the system will check whether the current time meets this condition during this time period every day. If the current time is indeed within the specified time interval, the system will confirm that the preset trigger condition has been met. The purpose of this step is to ensure that the associated permission adjustment rules will only be activated within the specified time range.

[0078] Next, the principle is to dynamically control the effectiveness of permissions by using time as a trigger. This approach allows organizations to flexibly manage user access rights in different time periods based on actual business needs and security policies. For example, some sensitive data may only be accessible during working hours to reduce the risk of data leakage during non-working hours.

[0079] In order to optimize this process, intelligent scheduling algorithms can be introduced to predict high-load periods and prepare resources in advance to ensure the immediacy of permission adjustments and system performance. In addition, a distributed timed task system is used to improve the time synchronization accuracy in a multi-server environment to ensure that all nodes can accurately perform permission adjustments. At the same time, the setting and actual use of time intervals are regularly reviewed to ensure their rationality and effectiveness.

[0080] This embodiment enhances the time sensitivity of permission management. It can accurately control the validity period of user permissions and improve the security and flexibility of the system. Through this mechanism, organizations can dynamically adjust user access rights according to different business scenarios and security requirements to ensure secure access to information, while also improving user experience and work efficiency.

[0081] In a feasible implementation manner, step B10 also includes step B102 before step B10: Step B102: If it is detected that the association relationship is associated with a preset project and the project reaches a preset progress milestone, it is determined that a preset trigger condition associated with the first association relationship is satisfied.

[0082] In this embodiment, the system checks whether the first association is associated with a preset project and whether the project has reached a preset progress milestone. The "first association" here refers to the connection between the user ID and the role ID, the "preset project" is a pre-specified business or work project, and the "progress milestone" is a key node or phased goal set during the project execution. When the system detects that a project has reached these preset progress milestones, it is considered that the preset trigger condition of the first association is met.

[0083] Specifically, the system first confirms whether one or more preset items are included in the first association. For example, suppose there is a project manager role whose permissions may be associated with specific construction projects. Next, the system evaluates the current progress status of these projects and checks whether they have reached the preset progress milestones. If a project does achieve the predetermined goals, such as completing the preliminary design phase or passing the mid-term review, the system determines that the preset trigger conditions have been met. The purpose of this process is to ensure that the relevant permission adjustment rules will only be activated when the project reaches a certain progress.

[0084] In terms of principle application, this method takes advantage of the progress control in project management to dynamically influence the permission configuration. It allows organizations to flexibly adjust user access rights based on the actual progress of the project. For example, in the early stages of a project, team members may be limited to viewing planning documents, but as the project advances and reaches certain milestones, they may be granted more operational permissions, such as editing design drawings or accessing financial reports.

[0085] In order to optimize this process, automated tools and intelligent analysis algorithms can be introduced to automatically track project progress and compare it with preset milestones, so as to trigger permission adjustments in a timely manner. In addition, combined with a real-time notification mechanism, administrators can be reminded to conduct permission review immediately when the project reaches an important milestone to ensure the timeliness and accuracy of permission changes. At the same time, project milestone settings and actual progress are reviewed regularly to ensure that permission adjustments always meet the latest business needs and security policies. Furthermore, in addition to time and project progress, more types of trigger conditions can be introduced, such as specific business events such as financial approval processes and contract signing. Once these events occur, the system will automatically execute the corresponding permission adjustment rules. This not only improves the flexibility of permission management, but also makes permission configuration closer to actual business logic. In order to facilitate the use of non-technical personnel, an intuitive and easy-to-use permission configuration interface is designed, allowing users to easily define complex permission rules. Different data dimensions, dimension values, and operation permissions can be selected by dragging and dropping graphical tools to reduce the possibility of misoperation. Each permission adjustment should be recorded in detail, including the time, reason, and specific content involved. This helps with post-event review and problem troubleshooting, and also provides management with a more transparent permission management system.

[0086] This embodiment enhances the dynamics and accuracy of rights management. It can flexibly adjust user rights according to the actual progress of the project, improving the adaptability and security of the system. This approach not only supports complex business scenarios, but also ensures secure access to information, improves work efficiency and user experience. Through this mechanism, organizations can more effectively manage resource access and promote the smooth progress of projects.

[0087] In a feasible implementation, the data authority implementation method includes steps C10 to C20: Step C10, summarizing the first association relationship and the second association relationship in the preset permission table; Step C20, generating an association view of the first association relationship and the second association relationship, and outputting the association view, wherein the association view is used to query and manage user identifiers, role identifiers, user group identifiers, data dimensions and data dimension values ​​according to the first association relationship and the second association relationship.

[0088] In this embodiment, the system summarizes the first association relationship and the second association relationship in the preset permission table. The first association relationship here refers to the connection between the user ID and the role ID, and the second association relationship refers to the association between the user group ID and the data dimension and its value. By integrating these relationships together, the system can fully reflect the user's permission settings.

[0089] Next, the system generates an association view, which comprehensively displays the first association relationship and the second association relationship, and is used to query and manage user IDs, role IDs, user group IDs, data dimensions, and data dimension values. The role of the association view is to provide an intuitive interface so that administrators can easily view and adjust permission configurations at different levels. For example, an administrator can quickly find a user's role and the data dimensions and values ​​that the role can access through the association view.

[0090] In specific operations, the system first extracts all the associated first and second relationship information from the preset permission table. Then, it organizes this information into a format that is easy to understand and operate, creating an association view. The association view not only includes static data display, but also supports dynamic query functions, allowing administrators to find specific permission configurations based on different filtering conditions. For example, if you want to know the access rights of all employees in a department, the administrator can filter by department in the association view.

[0091] In terms of principle application, this method utilizes the concepts of data visualization and centralized management. By building an associated view, the system achieves one-stop management and monitoring of permission configuration and simplifies the complex permission structure. This not only improves the efficiency of permission management, but also enhances the transparency and controllability of the system. For example, when it is necessary to audit the permission settings of a project, the associated view provides auditors with a clear permission distribution map for easy inspection and verification.

[0092] In order to optimize this process, intelligent search and filtering tools can be introduced to help administrators locate specific permission records more quickly. In addition, the use of graphical interface design makes the associated view more user-friendly and reduces the learning cost. At the same time, regularly updating and maintaining the content of the associated view to ensure its accuracy and timeliness helps to maintain the effectiveness of permission management. Furthermore, the introduction of intelligent permission recommendation function allows the system to automatically suggest appropriate permission configurations based on historical data and similar cases. For example, when a new project manager joins, the system will recommend a set of preset permission combinations based on the permission setting mode of previous project managers, including data dimensions and their dimension values ​​for accessing specific projects. This not only simplifies the configuration process, but also reduces the possibility of human errors. The system has a permission conflict detection function that can automatically identify and prompt potential permission conflicts or redundancies during the configuration process. For example, if two different roles grant the same user different operation permissions for the same resource, the system will remind the administrator that there may be a conflict. In addition, the system can also provide optimization suggestions to help administrators simplify the permission structure and improve management efficiency.

[0093] This embodiment improves the visualization and usability of permission management. It provides administrators with an intuitive and powerful tool for querying and adjusting complex permission configurations, reducing the need for manual operations. This approach not only simplifies the permission management process, but also improves work efficiency and ensures the security and accuracy of permission settings. Through associated views, organizations can better control internal resource access and promote smooth business operations.

[0094] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the data permission implementation method of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0095] This application also provides a data permission implementation device, please refer to Figure 4 , the data authority implementation device includes: The input module 10 receives an external data access request, determines a user identifier in the data access request, and determines a first association relationship corresponding to the user identifier, wherein the first association relationship includes an association relationship between the user identifier and the role identifier; The query module 20 queries a data dimension value under the data dimension associated with the first association relationship in a preset permission table including a mapping relationship between the data dimension and the first association relationship, wherein the data dimension is a parameter defined based on a text data attribute that needs to be subject to permission control; The output module 30 determines the accessible data range corresponding to the data dimension value, searches for the request data that matches the data access request and is within the accessible data range in a preset database, and outputs the request data as accessible data.

[0096] The data permission implementation device provided by the present application adopts the data permission implementation method in the above embodiment, which can improve the flexibility of data permission management. Compared with the prior art, the beneficial effects of the data permission implementation device provided by the present application are the same as the beneficial effects of the data permission implementation method provided by the above embodiment, and other technical features in the data permission implementation device are the same as the features disclosed in the above embodiment method, which will not be repeated here.

[0097] The present application provides a data permission implementation device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data permission implementation method in the above-mentioned embodiment one.

[0098] Reference below Figure 5, which shows a schematic diagram of the structure of a data authority implementation device suitable for implementing the embodiment of the present application. The data authority implementation device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The data permission implementation device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0099] like Figure 5 As shown, the data authority implementation device may include a processing device 1001 (such as a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the data authority implementation device are also stored. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the data rights implementation device to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a data rights implementation device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or provided instead.

[0100] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0101] The data permission implementation device provided by the present application adopts the data permission implementation method in the above embodiment, which can improve the flexibility of data permission management. Compared with the prior art, the beneficial effects of the data permission implementation device provided by the present application are the same as the beneficial effects of the data permission implementation method provided by the above embodiment, and the other technical features in the data permission implementation device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.

[0102] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0103] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0104] The present application provides a medium, which is a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the data permission implementation method in the above-mentioned embodiment.

[0105] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM: Random Access Memory), a read-only memory (ROM: Read Only Memory), an erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency: Radio Frequency), etc., or any suitable combination of the above.

[0106] The above-mentioned computer-readable storage medium may be included in the data authority implementation device; or it may exist independently without being assembled into the data authority implementation device.

[0107] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the data authority implementation device, the data authority implementation device: Receiving an externally input data access request, determining a user identifier in the data access request, and determining a first association relationship corresponding to the user identifier, wherein the first association relationship includes an association relationship between the user identifier and the role identifier; In a preset permission table including a mapping relationship between a data dimension and a first association relationship, querying a data dimension value under a data dimension associated with the first association relationship, wherein the data dimension is a parameter defined based on a text data attribute for which permission control is required; Determine the accessible data range corresponding to the data dimension value, search for the requested data that matches the data access request and is within the accessible data range in a preset database, and output the requested data as accessible data.

[0108] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0109] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0110] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.

[0111] The readable storage medium provided in this application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned data permission implementation method, and can improve the flexibility of data permission management. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the data permission implementation method provided in the above-mentioned embodiment, and will not be described in detail here.

[0112] The present application also provides a product, which is a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the data permission implementation method as described above are implemented.

[0113] The computer program product provided by this application can improve the flexibility of data authority management. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as the beneficial effects of the data authority implementation method provided by the above embodiment, which will not be repeated here.

[0114] The above are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A method for implementing data permissions, characterized in that: The data authority implementation method includes: Receiving an externally input data access request, determining a user identifier in the data access request, and determining a first association relationship corresponding to the user identifier, wherein the first association relationship includes an association relationship between the user identifier and a role identifier; In a preset permission table including a mapping relationship between a data dimension and a first association relationship, querying a data dimension value under a data dimension associated with the first association relationship, wherein the data dimension is a parameter defined based on a text data attribute for which permission control is required; Determine the accessible data range corresponding to the data dimension value, search a preset database for request data that matches the data access request and is within the accessible data range, and output the request data as accessible data.

2. The data authority implementation method according to claim 1, characterized in that: The step of querying the data dimension value under the data dimension associated with the first association relationship in the preset permission table including the mapping relationship between the data dimension and the first association relationship includes: Determine text data that needs to be subject to permission control according to at least one preset data access scenario, and use parameters defined by attributes of the text data as data dimensions; For any data dimension, use at least one text data of a preset data source to assign a value to the data dimension to obtain at least one data dimension value, wherein the data source includes a custom data source and a preset system data source; A first association relationship between at least one of the user identifiers and the role identifier is determined, and for each of the first association relationships, the data dimension and the data dimension value are associated on the first association relationship to obtain the preset permission table.

3. The data authority implementation method according to claim 2, characterized in that: The step of determining a first association relationship between at least one of the user identifiers and the role identifier, and associating the data dimension and the data dimension value on the first association relationship for each of the first association relationships to obtain the preset permission table comprises: For any one of the plurality of user identifiers, determining a first association relationship between the user identifier and the plurality of role identifiers; If, among the plurality of the first association relationships, there is a second association relationship to be associated with the same first data dimension value, setting a user group identifier; The user group identifier is associated with the first data dimension value and the first data dimension, and all the second association relationships are associated with the user group identifier to obtain the preset permission table, wherein the first data dimension is the data dimension of the first data dimension value.

4. The data authority implementation method according to claim 3, characterized in that: The step of associating the user group identifier with the first data dimension value and the first data dimension comprises: Detecting whether there is a subordinate user group identifier in the user group identifier; If a subordinate user group identifier exists, determining whether the subordinate user group identifier is associated with a data dimension value; If the subordinate user group identifier is associated with a data dimension value, the first data dimension associated with the user group identifier is updated to be consistent with the data dimension associated with the subordinate user group identifier, and the first data dimension value associated with the user group identifier is updated to be consistent with the data dimension value associated with the subordinate user group identifier.

5. The data authority implementation method according to claim 2, characterized in that: After the step of associating the data dimension and the data dimension value on the first association relationship to obtain the preset permission table, the following steps are included: When it is detected that a preset trigger condition associated with the first association relationship is met, triggering a permission adjustment rule associated with the trigger condition, wherein the permission adjustment rule is used to re-associate a new data dimension with the first association relationship and / or re-assign a data dimension value of the data dimension; The permission adjustment rule is applied to adjust the data dimension and / or data dimension value associated with the first association relationship in the preset permission table.

6. The data authority implementation method according to claim 5, characterized in that: Before the step of triggering the permission adjustment rule associated with the triggering condition when it is detected that the preset triggering condition associated with the first association relationship is met, the method includes: If it is detected that the association relationship is associated with a preset time interval and the current time is within the time interval, it is determined that a preset trigger condition associated with the first association relationship is satisfied.

7. The data authority implementation method according to claim 5, characterized in that: Before the step of triggering the permission adjustment rule associated with the triggering condition when it is detected that the preset triggering condition associated with the first association relationship is met, the method includes: If it is detected that the association relationship is associated with a preset project and the project reaches a preset progress milestone, it is determined that a preset trigger condition associated with the first association relationship is satisfied.

8. The data authority implementation method according to claim 3, characterized in that: The step of obtaining the preset permission table also includes: The first association relationship and the second association relationship summarized in the preset permission table; Generate an association view of the first association relationship and the second association relationship, and output the association view, wherein the association view is used to query and manage the user identifier, role identifier, user group identifier, data dimension and data dimension value according to the first association relationship and the second association relationship.

9. A data authority implementation device, characterized in that: The data authority implementation device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the data authority implementation method as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the data authority implementation method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • User authorization management system and method

    CN107506658A

  • Data range control method and device based on combination and storage medium

    CN109885609A

  • Access control method and device

    CN115017484A

  • Data authority management method and device, equipment and storage medium

    CN116756768A