Permission control method and device for page object in OFD (Open Forwarding Document)

By using semantic tree files and backup documents for permission control in OFD documents, the omissions and structural complexity problems in the replication process in the prior art are solved, and simplified permission control and system logic are realized.

CN120012166AInactive Publication Date: 2025-05-16AEROSPACE FOXIT SOFTWARE (BEIJING) CO LTD

Patent Information

Application Number
CN202510490157.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, in the permission control of page objects in open-type document OFD, the copying process is prone to omit attributes and data, and the structure is complex and poor maintainability, which changes the structure of the document.

Method used

By obtaining the semantic tree file of the OFD document, when the permission setting operation is detected, the target permission is set, and the object content and permission attributes of the page object are controlled according to the target permissions and backup documents under the semantic node to avoid omissions or errors when copying the complete object.

Benefits of technology

There is no need to copy complex display properties and common drawing parameters, and directly modify the data affected by permissions on the page object, simplifying the system structure and logic, avoiding the needs of location changes and record maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012166A_ABST
    Figure CN120012166A_ABST
Patent Text Reader

Abstract

The invention provides an authority control method and device for a page object in an OFD document, and relates to the technical field of computers.The method comprises the steps that a semantic tree file corresponding to the OFD document is obtained, the semantic tree file comprises at least one semantic node, and the semantic node comprises at least one page object in the OFD document; when a permission setting operation for any semantic node is detected, setting a corresponding target permission for the semantic node; and under the semantic node, according to the target permission and the backup document corresponding to each page object, performing permission control operation on the object content and the object permission attribute of each page object. According to the method, the problem caused by omission or error of copying the complete object is avoided; layer identifiers, direction indexes and the like of the objects do not need to be recorded and maintained, and the system structure and logic are greatly simplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method and device for controlling permissions of page objects in an open format document (OFD). Background Art

[0002] Open Fixed-layout Document (OFD) supports setting the document permission declaration (Permissions) node to achieve application purposes such as document non-proliferation. In order to improve the granularity of permission control, permission control of specific objects in OFD documents has become a research hotspot.

[0003] In the prior art, the object that needs to be controlled in the OFD document is removed from the corresponding page and completely copied to the first page object; at the same time, a second page object corresponding to the object is created, but the content is modified to be visible or operable by the user with limited permissions, and the layer identifier, index identifier, etc. of the object in the page are recorded. After the user opens the OFD document, the reader can decide whether to completely copy the first page object or the second page object and then insert it into the original document for display according to the user role, thereby achieving different display effects and operation effects for different roles.

[0004] However, the above method is prone to omission of attributes and data during copying, has a complex structure, poor understandability and maintainability, and also changes the structure of the document, etc. Therefore, an effective solution is urgently needed to solve the above problems. Summary of the invention

[0005] In view of the above-mentioned defects in the prior art, the present invention provides a method and device for controlling the permissions of page objects in an open format document OFD.

[0006] The present invention provides a method for controlling the permissions of page objects in an open format document OFD, comprising: Acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; When a permission setting operation for any of the semantic nodes is detected, a corresponding target permission is set for the semantic node; Under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, a permission control operation is performed on the object content and the object permission attribute of each of the page objects.

[0007] According to a method for controlling permissions of a page object in an open format document OFD provided by the present invention, the target permission is a hidden permission; Under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the permission control operation is performed on the object content and the object permission attribute of each of the page objects, including: For each of the page objects under the semantic node, the following operations are performed: Creating a backup file for the page object; Under the semantic node, copying the object content and the object permission attributes of the page object to the backup document; Recording the identifier of the backup document as the document identifier corresponding to the page object under the semantic node; According to the target authority, the object content of the page object is hidden under the semantic node, and the object authority attribute of the page object is changed.

[0008] According to a method for controlling the rights of page objects in an open format document OFD provided by the present invention, after performing the rights control operation on the object content and the object rights attribute of each of the page objects, the method further includes: In response to the output class operation on the OFD document: For authorized users, based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, the output operation is performed on the OFD document; For unauthorized users, the output operation is performed on the OFD document based on the semantic tree file.

[0009] According to a method for controlling permissions of page objects in an open format document OFD provided by the present invention, the output type operation is document display and / or document printing; The step of performing the output operation on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers includes: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier, and read the display attribute of the page object from under the semantic node; If not, read the object content and display attributes of the page object from the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0010] According to a method for controlling permissions of page objects in an open format document OFD provided by the present invention, the output type operation is document display and / or document printing; The step of performing the output operation on the OFD document based on the semantic tree file for the unauthorized user includes: For unauthorized users, read the semantic tree file; For any page object contained in each of the semantic nodes in the semantic tree file, read the object content and display attributes of the page object from under the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0011] According to a method for controlling permissions of page objects in an open format document OFD provided by the present invention, the output class operation is semantic tree export; The step of performing the output operation on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers includes: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier and export it; If not, the object content of the page object is read from the semantic node and exported.

[0012] According to a method for controlling permissions of page objects in an open format document OFD provided by the present invention, the output class operation is semantic tree export; The step of performing the output operation on the OFD document based on the semantic tree file for the unauthorized user includes: For each of the semantic nodes in the semantic tree file, read a derived attribute from a node authority attribute of the semantic node; If the derived attribute is reject, skip the semantic node; If the export attribute is allowed, the object content of the page object is read from the semantic node and exported.

[0013] According to a method for controlling the rights of page objects in an open format document OFD provided by the present invention, after performing the rights control operation on the object content and the object rights attribute of each of the page objects, the method further includes: In response to a restore operation of the OFD document by an authorized user, the following operations are performed for each semantic node in the semantic tree file: Clearing the node permission attribute of the semantic node; For any page object included in the semantic node, checking whether the page object has a corresponding document identifier; If so, the object content and permission attributes of the page object in the backup file corresponding to the document identifier are used to replace the object content and permission attributes of the page object under the semantic node, and the document identifier corresponding to the page object under the semantic node is deleted.

[0014] According to a method for controlling permissions of page objects in an open format document OFD provided by the present invention, after the object content and permission attributes of the page object are copied to the backup document under the semantic node, the method further includes: The backup file is encrypted using a key associated with a user, the user being an authorized user or an unauthorized user.

[0015] The present invention also provides a permission control device for page objects in an open format document OFD, comprising: An acquisition module is configured to acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; A setting module, configured to set a corresponding target permission for any of the semantic nodes when a permission setting operation for the semantic nodes is detected; The control module is configured to perform permission control operations on the object content and object permission attributes of each of the page objects under the semantic node according to the target permission and the backup documents corresponding to each of the page objects.

[0016] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for controlling the permissions of page objects in an open format document OFD as described above is implemented.

[0017] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the method for controlling the permissions of a page object in an open format document OFD as described in any one of the above is implemented.

[0018] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method for controlling the permissions of a page object in an open format document OFD as described above is implemented.

[0019] The method and device for controlling the permissions of page objects in an open format document OFD provided by the present invention obtains a semantic tree file corresponding to the OFD document, the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; when a permission setting operation for any of the semantic nodes is detected, the corresponding target permission is set for the semantic node; under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and object permission attribute of each of the page objects are subjected to permission control operations. The present invention does not need to copy complex and numerous display attributes, and further does not need to process the public drawing parameters referenced by them, which avoids the problem caused by omission or error in copying the complete object; the present invention does not need to remove the original page object, but directly modifies the data affected by the permission on the page object, so that the position of the page object does not change, and does not need to record and maintain the layer identification, direction index, etc. of the object, which greatly simplifies the system structure and logic. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 This is one of the flow charts of the permission control method for page objects in the open format document OFD provided by the present invention.

[0022] Figure 2 It is a flowchart of the permission setting provided by the present invention.

[0023] Figure 3 It is a flowchart of document display provided by the present invention.

[0024] Figure 4 It is a schematic diagram of the document printing process provided by the present invention.

[0025] Figure 5 It is a flowchart of the semantic tree export provided by the present invention.

[0026] Figure 6 It is a schematic diagram of the process of restoring a document provided by the present invention.

[0027] Figure 7 This is the second flow chart of the permission control method for page objects in the open format document OFD provided by the present invention.

[0028] Figure 8It is a structural schematic diagram of a permission control device for page objects in an open format document OFD provided by the present invention.

[0029] Fig. 9 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0031] Combine the following Figure 1-Figure 9 The present invention describes a method and device for controlling permissions of page objects in an open format document (OFD).

[0032] First, the relevant contents of the present invention are briefly described.

[0033] In the OFD standard "GB / T 33190-2016 Electronic Document Storage and Exchange Format - Layout Document" supports the setting of document permission declaration nodes to achieve application purposes such as document non-proliferation, for example, whether editing (Edit), whether adding or modifying annotations (Annot), whether exporting (Export) and other permissions are allowed.

[0034] However, the permissions set are for the entire layout document. It is not possible to control permissions for specific objects in the layout file, such as the name or gender of a patient in a medical record. It is also not possible to flexibly set different permissions for different scenarios and users. For example, doctors, nurses, or managers have different permissions for medical records. In real life, there are a large number of scenarios that require different permissions for different users, and the control granularity also needs to be more detailed. Therefore, how to implement permission control for OFD page objects is a technical problem that needs to be solved urgently.

[0035] In the prior art, the principle of controlling the permissions of OFD objects is as follows: for objects that require permission control (such as text objects), remove them from the corresponding page and completely copy them to a specific data backup file. This object is called the "first page object". At the same time, create a "second page object" corresponding to the object, but modify the content to be visible or operable by users with limited permissions, for example, the content becomes , InPrintable changes to true, etc., and records the layer ID (Identifier) ​​of the object in the page. It may also be necessary to record the index ID of the object in the layer. After the user opens the OFD document, the reader can decide whether to completely copy the first page object or the second page object and then insert it into the original document for display based on the user role, thereby achieving different display and operation effects for different roles, such as normal plain text or Such as alternative text, ability to print or not print, and other operation permissions.

[0036] However, the above solution has the following shortcomings: 1) It is difficult to delete the object from the page and completely copy it to a specific data backup file, or to completely copy it from the data backup file back to the original page. It is easy to miss properties and data during copying. The reason is that the copy operation is performed on the memory object. When the object has complex properties, such as clipping area, pattern (Patten) / shading (Shadding) fill, etc., these properties are constructed from several other sub-objects, and there may be complex relationships between sub-objects (such as multiple intersections / unions). Therefore, it is difficult to completely copy the object. These properties are used to control the display of the object. Copying errors or data omissions will cause display errors. In fact, it is precisely because direct copying is difficult or error-prone that existing layout document engines basically do not provide complete copying of objects. Some engines use counting technology to simulate or avoid complete copying of objects.

[0037] 2) The rendering effect of page objects is not only affected by their own properties, but also by the drawing parameters of public resources if the objects reference these parameters. When an object is removed and copied back from a backup location, even if the object's own attribute data is completely copied, if the reference to the public parameters is omitted, the drawing effect will be incorrect.

[0038] 3) When copying an object from a data backup file back to the original page, it is difficult to guarantee the position of the object. The existing technology uses the method of recording the layer ID of the original object to ensure that the layer of the object remains unchanged when writing back, but it cannot guarantee that the index (that is, the position) of the object in multiple object sequences in the same layer remains unchanged. For example, in the original page, a text object is before an image object in the same layer, and the text can be displayed normally. When it is removed and inserted into the page again, its index value in the object sequence has been lost. If it is inserted to the end, the text will be blocked and cannot be displayed after the image. In addition, the existing technology adds the index of the recorded object or the ID of the previous object, and the subsequent restoration of the position by index / previous object ID is still very fragile. Once the user edits the page, such as adding / deleting objects, the recorded index value or ID may become invalid.

[0039] 4) The existing technical structure is relatively complex. The system needs to maintain the ID of the original page object (the object is removed, but the ID is still recorded in the semantic tree), the first page object (the copy of the original page object), and the second page object (copy and construct the object that is changed by permission restrictions, such as the plain text becomes " ", etc.), and their mapping relationships; as well as layer IDs, possible object indexes, etc., which make the system structure more complex and difficult to understand and maintain.

[0040] 5) The existing technology removes the objects with set permissions from the original page (and copies them to a custom data backup file), which changes the structure of the document. One bad consequence is that when the document is viewed with other standard OFD readers, these objects no longer exist and the area where they are located becomes blank. A more reasonable effect is that when the document is viewed with a standard OFD reader, the objects still exist, but they become visible to restricted users, such as text becomes ; or the text can still be seen but cannot be printed, etc.

[0041] 6) The encryption of the specific data backup file in the prior art is independent of the encryption strategy of the system as a whole for OFD, which may lead to inconsistency between the encryption strategy of the data backup file and the encryption strategy of the overall OFD, or increase the cost of maintaining such consistency.

[0042] Figure 1 FIG. 1 is one of the flow charts of the permission control method for page objects in an open format document OFD provided by the present invention, such as Figure 1 As shown, the method includes steps 101 to 103.

[0043] Step 101: Acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document.

[0044] It should be noted that the permission control method for page objects in an open format document OFD provided by the present invention is applicable to the scenario of permission control of page objects in an OFD document. The executor of the method may be a permission control device for page objects in an open format document OFD, such as an electronic device, or a control module in the permission control device for page objects in the open format document OFD for executing the permission control method for page objects in the open format document OFD.

[0045] Specifically, when different scenarios or users of different roles need to perform permission control on page objects in an OFD document, the user uses the OFD document reader to open the OFD document and enters text content in the OFD document reader. The OFD document reader pops up at least one semantic tree template corresponding to the text content. The user selects the corresponding semantic tree template and imports the semantic tree template into the OFD document; wherein, the page object includes at least one of the following: text, picture, path.

[0046] Then, the OFD document is parsed to obtain a semantic tree file, which includes multiple semantic nodes. In practical applications, the obtained OFD document is parsed to obtain a semantic tree file (semantic tree XML file), which includes multiple semantic nodes, such as an official document style node, a header node, a body node, a colophon node, multiple copy-to agency nodes, and an issuing agency and issuing date nodes; wherein the issuing agency and issuing date nodes include an issuing agency node and an issuing date node.

[0047] Step 102: When a permission setting operation for any of the semantic nodes is detected, a corresponding target permission is set for the semantic node.

[0048] Specifically, the target permissions are used to perform corresponding permission control operations on each page object contained in the semantic node. The target permissions include but are not limited to at least one of the following groups: invisible, unprintable, and unextractable; invisible, printable, and unextractable; invisible, unprintable, and extractable; invisible, printable, and extractable; visible, unprintable, and unextractable; visible, unprintable, and extractable; visible, unprintable, and extractable; visible, unprintable, and extractable; visible, printable, and unextractable; visible, printable, and extractable.

[0049] In actual applications, when a permission setting operation for a semantic node is detected, the corresponding target permission can be set for the semantic node. For example, the page object associated with the "file level" node is "special", and the "file level" node is set with invisible, printable, and extractable permissions. The page object "special" corresponding to the invisible permission can be replaced by an alternative text, for example, the alternative text is " ". By setting the corresponding target permissions for the semantic nodes, when the permission control operation corresponding to the target permissions is performed on the page object, the permissions of the page object are controlled, and the detailed management of the page object permissions is achieved to improve the user experience.

[0050] Step 103: Under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, perform permission control operations on the object content and object permission attributes of each of the page objects.

[0051] Specifically, it should be noted that the permission attributes of the semantic node are set: when an authorized user sets permissions for a semantic node, these permissions are represented by two parts: one is the (node ​​permission) attribute of the semantic node, including "plaintext / ciphertext", represented by "ClearText=true / false"; "printable / non-printable", represented by "InPrintable=false / true", "exportable / non-exportable", represented by "Extractable=true / false", etc. The second is the attributes of the (multiple) page objects contained under the semantic node, for example, "OriginalObjID" represents the backup file ID corresponding to the page object, which stores the original content data of the object. When the semantic node is not set with permissions, these attributes of the semantic node do not exist.

[0052] All data of the page object contained in the semantic node is divided into three parts. The first part is the content data of the object (object content), such as the string (TextCode) and CGTransform of the text object (CGTransform is used to describe the index of the character in the embedded font, which is closely related to the content of the text); the second part is the general attribute data of the object (display attributes), such as the font, font size, line width, color, position, transparency, drawing parameter resource set, whether it can be printed, bounding rectangle, rotation matrix, text direction, reading direction, horizontal scaling ratio, gradient / axial / radial / Gouraud filling, and complex filling effects such as clipping area, Shadding / Pattern, etc. The third part is the attributes related to object permissions (object permission attributes), preferably, specifically refers to the "InPrintable" attribute, indicating whether the page object is not printable.

[0053] In actual applications, permission control operations corresponding to the target permissions can be performed on each page object based on the target permissions: first, the object content and object permission attributes are copied to the backup document, and then permission control operations are performed on the object content and object permission attributes based on the target permissions.

[0054] For example, the object content "Special" and the object permission attribute "InPrintable=true" of the page object "Special" can be copied to the backup file, and then based on the target permission, the object content "Special" can be changed to " ”, change “InPrintable=true” to “InPrintable=false”.

[0055] The method for controlling the permissions of page objects in an open format document OFD provided by the present invention obtains a semantic tree file corresponding to the OFD document, the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; when a permission setting operation for any of the semantic nodes is detected, the corresponding target permission is set for the semantic node; under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and object permission attribute of each of the page objects are subjected to permission control operations. The present invention does not need to copy complex and numerous display attributes, and further does not need to process the public drawing parameters referenced by them, which avoids the problem caused by omission or error in copying the complete object; the present invention does not need to remove the original page object, but directly modifies the data affected by the permission on the page object, so that the position of the page object does not change, and does not need to record and maintain the layer identification, direction index, etc. of the object, which greatly simplifies the system structure and logic.

[0056] In one or more optional embodiments of the present invention, the target permission is a hidden permission; accordingly, under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and the object permission attribute of each of the page objects are subjected to permission control operations, including: For each of the page objects under the semantic node, the following operations are performed: Creating a backup file for the page object; Under the semantic node, copying the object content and the object permission attributes of the page object to the backup document; Recording the identifier of the backup document as the document identifier corresponding to the page object under the semantic node; According to the target authority, the object content of the page object is hidden under the semantic node, and the object authority attribute of the page object is changed.

[0057] Specifically, the hidden permission includes ciphertext and / or non-printable.

[0058] In actual applications, when the page objects contained in the semantic node are designated as ciphertext or non-printable, two operations are performed: construct a specific backup file to store the object content of the page objects with set permissions, copy the object content and object permission attributes of all page objects under the semantic node to the backup document, and record the document identifier; modify the object content and object permission attributes of the page objects under the semantic node according to the content of the target permissions.

[0059] For example, for a text object set as ciphertext, its content string is replaced with a specified replacement character (such as " ", etc.), and delete its CGTransform to ensure that the replacement characters are effective. For objects set to be non-printable, set their "InPrintable" property to true.

[0060] In one or more optional embodiments of the present invention, the target permission is a display permission; accordingly, under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and the object permission attribute of each of the page objects are subjected to permission control operations, including: According to the display permission, setting the ciphertext attribute of the semantic node to deny; For each of the page objects under the semantic node, the object content and permission attributes of the page object in the backup file corresponding to the document identifier are used to replace the object content and permission attributes of the page object under the semantic node.

[0061] Specifically, the display permission includes plain text and / or printable.

[0062] In actual applications, when the page object contained in the semantic node is specified to be changed from ciphertext to plaintext, or the printing permission is changed from non-printable to printable, the page object under the semantic node must have a corresponding backup document, and the backup document stores the original object content of the page object. At this time, you should: set the ciphertext attribute of the semantic node, that is, the ChiperText attribute, to deny (false); then copy the object content and object permission attributes in the backup document back to the object content and permission attributes of the page object under the semantic node.

[0063] For example, for a text object, copy the text content (TextCode) and CGTransform in the corresponding backup document back to the page object, and replace the object content and object permission attributes in the page object under the semantic node. For printing permissions, the printing attribute "InPrintable" of the semantic node should be set to false, and then the InPrintable of the page object should be set to false.

[0064] In one or more optional embodiments of the present invention, the target permission is a semantic tree export permission; accordingly, under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and the object permission attribute of each of the page objects are subjected to permission control operations, including: According to the semantic tree export permission, the export attribute of the semantic node is set to allow.

[0065] In one or more optional embodiments of the present invention, the target permission is a semantic tree non-export permission; accordingly, under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the object content and the object permission attribute of each of the page objects are subjected to permission control operations, including: According to the semantic tree non-export permission, the export attribute of the semantic node is set to deny.

[0066] In actual applications, the export attribute of the semantic node is set to determine whether it is exportable: simply set Extractable to true or false on the semantic node.

[0067] It should be noted that in the embodiment of the present invention, when the "plaintext / ciphertext" attribute of the page object is set, the "Visible" attribute of the page object is not changed. Visible / invisible means that the content of the page object can be displayed / cannot be displayed, which is different from only switching the object content between plaintext and ciphertext (switching to For example, if the "Visible" attribute of a page object in the original OFD document is false, the page object itself is invisible. The embodiment of the present invention only modifies the object content of the page object. After the object content is switched to ciphertext, the page object is still invisible. For example, the text object cannot see the " " character, because its Visible property is false. However, for the "Printable / Non-printable" setting, this property will not cause ambiguity, and the "InPrintable" property of the page object can be directly modified / replaced to achieve the intention. For example, if the "InPrintable" property of a page object in the original document is false (or there is no InPrintable property, the default value is false), that is, the page object itself is printable, after the user sets it to "Non-printable", its "InPrintable" will be set to true; conversely, if the "InPrintable" property of a page object in the original document is true, that is, the page object itself is not printable, after the user sets it to "Printable", the "InPrintable" of the page object will be set to false.

[0068] For example, see Figure 2 , Figure 2This is a flowchart of the permission setting provided by the present invention: first, the node permission attribute of the semantic node is set to determine whether it is set to ciphertext or unprintable: if so, a backup document is constructed, and the object content and object permission attributes of the page object under the semantic node are copied to the backup document, that is, the object content and object permission attributes are copied to the backup document, and then the object content and object permission attributes of the page object under the semantic node are modified, that is, the object content and object permission attributes of the page object are modified; if not, continue to determine whether it is changed from plain text or right unprintable to printable. If it is changed from plain text or right unprintable to printable, the object content of the page object is read from the backup document corresponding to the document identifier and restored to the object content of the page object under the semantic node, that is, the object content is read from the backup document and restored to the page object, and the object permission attributes of the page object are read from the backup document corresponding to the document identifier and restored to the object permission attributes of the page object under the semantic node, that is, the InPrintable attribute is updated. If it is not changed from plain text or right unprintable to printable, then end.

[0069] In one or more optional embodiments of the present invention, after performing the permission control operation on the object content and the object permission attribute of each of the page objects, the method further includes: In response to the output class operation on the OFD document: For authorized users, based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, the output operation is performed on the OFD document; For unauthorized users, the output operation is performed on the OFD document based on the semantic tree file.

[0070] Specifically, output operations include document display, document printing, and semantic tree export.

[0071] In actual applications, when a user performs output operations on an OFD document, different logical output operations are performed on the OFD document for different users: for authorized users, output operations are performed on the OFD document together according to the backup documents corresponding to the semantic nodes and the record document identifiers; for unauthorized users, there is no need for the backup documents corresponding to the document identifiers, and only the output operations are performed on the OFD document according to the semantic nodes. In this way, different users can have different output operations.

[0072] In one or more optional embodiments of the present invention, the output operation is document display and / or document printing; the output operation is performed on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, including: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier, and read the display attribute of the page object from under the semantic node; If not, read the object content and display attributes of the page object from the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0073] In practical applications, see Figure 3 , Figure 3 It is a flowchart of document display provided by the present invention: when displaying an OFD document, the embodiment of the present invention does not adopt the method of modifying the content of the OFD page object to achieve the change of the display effect; instead, the object content is kept unchanged, and when the rendering engine displays a certain page object, the correct content of the page object is obtained in real time according to the user role and transmitted to the display engine, so that the content of the OFD document can be guaranteed to remain unchanged after the permission is set, and does not change with different display conditions. The specific method is that when rendering the object, the conventional properties of the page object are first obtained according to the normal process, including the referenced public drawing parameter data, that is, the display properties are obtained when rendering the page object, and then the page content is obtained according to the role of the current user, that is, whether the user is an authorized user. If it is an authorized user, ignore the ChiperText attribute of the semantic node (each authorization restriction is only for unauthorized users, and the authorized user must have the authority to see the plain text), that is, ignore the ChiperText attribute, and check whether each page object contained in the semantic node has a corresponding document identifier, that is, determine whether there is a backup document. If there is, the object content (plain text) in the backup document corresponding to the document identifier is read, and together with the display attributes of the page object read under the semantic node, a complete page object is formed, and handed over to the rendering engine for rendering and display, that is, the object content in the backup document and the display attributes of the page object are read for rendering; if there is no corresponding document identifier, it means that the page object under the semantic node has not been set with permissions, and the object content of the page object under the semantic node is still the original plain text. At this time, the object content and display attributes of the page object under the semantic node are read for display, that is, the object content and display attributes of the page object are read for rendering. In this way, the authorized user must see the original text (plain text). In this way, different effects can be displayed according to the user role and plain text / cipher text settings. This effect change occurs dynamically in the rendering engine, rather than relying on modifying the document content. The document content itself does not change.

[0074] See also Figure 4 , Figure 4It is a flowchart of document printing provided by the present invention. When printing a page object, the display attribute is obtained to determine whether the user is an authorized user. If it is an authorized user, the InPrintable attribute of the semantic node is ignored (each authorization restriction is only for unauthorized users, and the authorized user must have printing authority), that is, the InPrintable attribute is ignored; check whether each page object contained in the semantic node has a corresponding document identifier, that is, determine whether there is a backup document. If so, the object content (plain text) in the backup document corresponding to the document identifier is read, and together with the display attribute of the page object read under the semantic node, a complete page object is formed, which is handed over to the printing engine for printing, that is, the object content of the backup document and the display attribute of the page object are read for printing; if there is no corresponding document identifier, it means that the page object under the semantic node has not been set with permissions, and the object content of the page object under the semantic node is still the original plain text. At this time, the object content and display attribute of the page object under the semantic node are read for printing, that is, the object content and display attribute of the page object are read for printing. In this way, the content printed by the authorized user must be the original text (plain text).

[0075] It should be noted that the embodiment of the present invention separates the logic of printing and plain text / cipher text. For example, if an object is set to display cipher text and can be printed, unauthorized users can print it, but can only print out the password. This is more in line with the convention and principle of "what you see is what you get".

[0076] In one or more optional embodiments of the present invention, the output type operation is document display and / or document printing; The step of performing the output operation on the OFD document based on the semantic tree file for the unauthorized user includes: For unauthorized users, read the semantic tree file; For any page object contained in each of the semantic nodes in the semantic tree file, read the object content and display attributes of the page object from under the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0077] In practical applications, see Figure 3 :If the user is an unauthorized user, the object content and display attributes of the page object are fixedly read from the semantic tree file for rendering. In this way, different display effects can be displayed according to the user role and plaintext / ciphertext settings. This effect change occurs dynamically in the rendering engine, rather than relying on modifying the document content. The document content itself does not change.

[0078] It should be noted that, at this time, regardless of whether the page object in the semantic node has a ChiperText attribute and whether the value of the ChiperText attribute is true or false, the object content and display attributes of the page object are fixedly read for rendering. If the ChiperText attribute is not set, it means that the semantic node / page object has not been set with the permission of plaintext / ciphertext. At this time, the object content of the page object under the semantic node is the original data (plaintext), and the displayed effect is plaintext. If ChiperText=true, it means that the semantic node / object is set to display ciphertext. At this time, the object content of the page object under the semantic node has been modified to ciphertext when the permission is set, and the displayed object content is ciphertext. If there is a ChiperText attribute and ChiperText=false, it means that the semantic node was first set to display ciphertext (ChiperText=true) and then changed to display plaintext (ChiperText=false). At this time, the object content of the page object under the semantic node has been modified to plaintext when the permission was last set, and the displayed object content is plaintext.

[0079] See also Figure 4 When printing OFD documents, if the user is not authorized, the object content and display properties of the page object are fixedly read for printing.

[0080] It should be noted that, at this time, regardless of whether the page object in the semantic node has an InPrintable attribute and whether the value of the InPrintable attribute is true or false, the object content and display attributes of the page object are fixedly read for printing.

[0081] In one or more optional embodiments of the present invention, the output operation is semantic tree export; the output operation is performed on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, including: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier and export it; If not, the object content of the page object is read from the semantic node and exported.

[0082] In practical applications, see Figure 5 , Figure 5It is a flowchart of the semantic tree export provided by the present invention: traverse each semantic node in the semantic tree file, that is, traverse the semantic nodes, and make a judgment in combination with the role of the current user, that is, judge whether the user is an authorized user. If it is an authorized user, ignore the "Exprotable" attribute and ChiperText attribute of the semantic node (each authorization restriction is only for unauthorized users, and authorized users must have export authority), that is, ignore the Exprotable and ChiperText attributes, and see whether each page object contained in the semantic node has a corresponding document identifier, that is, judge whether there is a backup document. If so, read the object content (plain text) of the backup document corresponding to the document identifier for export, that is, read the object content of the backup document for export; if not, read the object content of the page object under the semantic node (plain text at this time) for export, that is, read the object content of the page object for export. In this way, according to the user role and export settings, it can be achieved that part of the content of unauthorized users can be exported and part of the content cannot be exported; for the exportable part, some objects export plain text, and some objects export ciphertext.

[0083] In one or more optional embodiments of the present invention, the output type operation is semantic tree export; the performing the output type operation on the OFD document based on the semantic tree file for the unauthorized user includes: For each of the semantic nodes in the semantic tree file, read a derived attribute from a node authority attribute of the semantic node; If the derived attribute is reject, skip the semantic node; If the export attribute is allowed, the object content of the page object is read from the semantic node and exported.

[0084] In practical applications, see Figure 5 : When exporting the semantic tree, each semantic node in the semantic tree file will be traversed, that is, the semantic nodes will be traversed, and a judgment will be made in combination with the role of the current user, that is, whether the user is authorized. For unauthorized users, the export attribute of the semantic node is first judged, that is, whether the Exprotable attribute is false. If it is false, the semantic node is skipped and not exported; otherwise, the object content of the page object under the semantic node is read for export, that is, the object content of the page object is read for export. Note that at this time, regardless of whether there is a ChiperText attribute and whether the value of the ChiperText attribute is true or false, the object content of the page object is read for export. In this way, according to the user role and export settings, it can be achieved that part of the content can be exported for unauthorized users and part of the content is not exported; for the exportable part, some objects are exported in plain text, and some objects are exported in cipher text.

[0085] In one or more optional embodiments of the present invention, after performing the permission control operation on the object content and the object permission attribute of each of the page objects, the method further includes: In response to a restore operation of the OFD document by an authorized user, the following operations are performed for each semantic node in the semantic tree file: Clearing the node permission attribute of the semantic node; For any page object included in the semantic node, checking whether the page object has a corresponding document identifier; If so, the object content and permission attributes of the page object in the backup file corresponding to the document identifier are used to replace the object content and permission attributes of the page object under the semantic node, and the document identifier corresponding to the page object under the semantic node is deleted.

[0086] In practical applications, see Figure 6 , Figure 6 This is a flowchart of document recovery provided by the present invention: an authorized user can restore the OFD document with set permissions to its original state. The specific method is to traverse each semantic node in the semantic tree file, that is, traverse the semantic nodes, and for each semantic node traversed: if the semantic node has a semantic permission attribute, such as ChiperText, InPrintable, Extractable, etc., delete it, that is, delete the semantic permission attribute; determine whether the page object under the semantic node has a corresponding document identifier, that is, determine whether there is a backup document, and if so, copy the object content and object permission attribute of the backup page object corresponding to the document identifier to the corresponding page object under the semantic node to replace the corresponding data, that is, restore the object content in the backup document to the page object, and delete the document identifier corresponding to the page object recorded under the semantic node, that is, delete the recorded document ID; if not, end. In this way, while ensuring the efficiency of document recovery, the accuracy of recovery can also be improved.

[0087] In one or more optional embodiments of the present invention, after copying the object content and permission attributes of the page object to the backup document under the semantic node, the method further includes: The backup file is encrypted using a key associated with a user, the user being an authorized user or an unauthorized user.

[0088] In actual applications, most existing OFD readers have the function of encrypting and decrypting OFD documents. They will encrypt / decrypt all files in OFD documents except for individual files such as ofd.xml and document.xml. And because this encryption and decryption is not in the OFD specification, different OFD readers cannot decrypt each other's encrypted OFD documents. As a result, different OFD readers will only display each other's encrypted OFD documents as blank when opening them.

[0089] The original content of the page objects of the OFD document with permission set as mentioned above is stored in a backup file, so the backup file needs to be encrypted to prevent unauthorized users from seeing the plain text by directly opening the XML in the OFD document. In the prior art, the encryption and decryption of the backup file is independent of the encryption and decryption of the OFD document itself. The embodiment of the present invention combines the permission setting with the encryption and decryption of the OFD document. For the OFD document with permission set, it is considered that the user has performed more refined control (semantic node level or page object level control) on the page objects of the OFD document according to his or her needs, rather than simply encrypting the entire document so that other readers cannot display it at all (the entire document is displayed as blank), or not encrypting the entire document so that other readers can fully display the original content.

[0090] In this regard, the encryption strategy of OFD is adjusted in the embodiment of the present invention as follows: if the semantic node of the OFD document has been set with permissions, only the backup file storing the object content is encrypted, and the rest of the files are not encrypted. The password / certificate and algorithm used for encryption and decryption use the password / certificate mechanism in the OFD document encryption mechanism, that is, the key associated with the authorized user.

[0091] Since the page objects in the OFD document will not be removed from the page, and the object content and object permission attributes in the page object will be replaced with the permission content corresponding to the unauthorized user when the permission is set, when the OFD document is viewed with other standard OFD readers, the effect is consistent with what the unauthorized user sees, rather than being completely blank, and the object printing permission is also consistent with the permission of the unauthorized user.

[0092] Combine the following Figure 7 , the permission control method of page objects in the open format document OFD provided by the present invention is further explained.

[0093] See also Figure 7 , Figure 7 This is the second flow chart of the permission control method for page objects in the open format document OFD provided by the present invention.

[0094] For an OFD document that contains multiple pages with various objects such as text and pictures, permission control needs to be performed on the OFD document to ensure that users with different roles (authorized users and unauthorized users) can see and operate content at different levels.

[0095] 1) Permission setting, which includes node permission attribute setting of semantic nodes and object permission setting of page objects.

[0096] Node permission attribute settings for semantic nodes.

[0097] For example, a semantic node represents part of the confidential information of an enterprise, and the authorized user sets permissions for the semantic node. The semantic node attributes are set as follows: "Plain text / Cipher text": Set "ChiperText" to "true", indicating that the content under the semantic node is cipher text; "Printable / Non-printable": Set "InPrintable" to "true", indicating that the content under the semantic node is not printable; "Exportable / Non-exportable": Set "Extractable" to "false", indicating that the content under the node is not exportable.

[0098] The semantic node contains a text object, and the "OriginalObjID" attribute of the semantic node is set to "100", indicating that the original content data (object content) of the page object is stored in the backup document (document ID is "100").

[0099] Page object data analysis. The data contained in the page object is divided into three parts, taking the above text object as an example: Object content: The string (TextCode) of the text object is "Enterprise Core Technical Information", and its CGTransform records the index of the character in the embedded font, which is used to accurately display the text; display attributes (general attribute data): for example, the font is Songti, the font size is 12, the color is black, the position is the upper left corner of the page (X=10, Y=20), etc.; object permission attributes: The "InPrintable" attribute is set to "true", indicating that the text object cannot be printed.

[0100] The object is set to be ciphertext or non-printable. For example, if the above text object is set to be ciphertext and non-printable, the following operations are performed: a data backup file "BackupFile_100" is constructed, and the content data ("Corporate Core Technology Information" and the corresponding CGTransform) and permission-related attributes ("InPrintable=true") of the text object are copied to the first page object (ID is "100"); the content data of the page object is modified, and the text content is replaced with " ” and remove its CGTransform, while setting the “InPrintable” property to “true”.

[0101] The object permission settings for page objects are described by setting the object to be plain text or printable, and setting whether the semantic node can be exported.

[0102] Object is set to plain text or printable operation: Assuming that the subsequent authorized user changes the semantic node from ciphertext to plain text, and the printable permission changes from non-printable to printable: set the "ChiperText" attribute of the semantic node to "false"; copy the text content ("Corporate Core Technology Information") and CGTransform in the backup document (document ID is "100") back to the page object, and replace the " "; Set the "InPrintable" attribute of the semantic node to "false", and the "InPrintable" attribute value of the page object is also set to "false".

[0103] Set whether the semantic node is exportable: Authorized users can directly set the "Extractable" attribute on the semantic node to "true", indicating that the node is exportable.

[0104] 2) Document display (set to ciphertext).

[0105] Determine whether the user is an authorized user.

[0106] If it is an authorized user, it will be displayed according to the operation process of unauthorized users: when the authorized user opens the OFD document, the rendering engine first obtains the display properties of the page object (such as font, font size, etc.) according to the normal process. Since the user is an authorized user, the "ChiperText" property of the semantic node is ignored, and it is found that the text object has a corresponding backup document (document ID is "100"), then the object content in the backup document (plain text "Corporate Core Technology Information") and the object properties of the page object are read together to form a complete object data, which is handed over to the rendering engine for rendering and display. The authorized user sees the original text.

[0107] If the user is not an authorized user, the display will be displayed according to the unauthorized user operation process: when an external unauthorized person tries to open the OFD document, the rendering engine also obtains the general attribute data first. Since the user is an unauthorized user, the object content of the page object is fixedly read (" ”) and display attributes, and the displayed object content is ciphertext.

[0108] 3) Document printing (taking the setting of ciphertext + printable as an example).

[0109] Determine whether the user is an authorized user.

[0110] If it is an authorized user, it will print according to the operation process of unauthorized users: the authorized user clicks the print button, and the print engine starts working. Because it is an authorized user, the "InPrintable" attribute of the node is ignored, and it is found that the text object has a corresponding backup document (document ID is "100"), so the object content in the backup document (plain text "Corporate Core Technology Information") is read together with the display attributes of the page object to form a complete object data, which is handed over to the print engine for printing, and the printed content is the original text.

[0111] If the user is not an authorized user, the printing will be performed according to the unauthorized user operation process: If an unauthorized user tries to print the document, the print engine will read the InPrintable attribute of the page object and the object content (" ”) and display properties for printing. Currently, InPrintable is false, which means it can be printed, but only the ciphertext can be printed.

[0112] 4) Export the semantic tree (taking the setting of ciphertext + non-exportable as an example).

[0113] Determine whether the user is an authorized user.

[0114] If you are an authorized user, you can export the semantic tree according to the unauthorized user operation process. The export program traverses each semantic node of the semantic tree file. Since you are an authorized user, you ignore the "Exprotable" attribute and "ChiperText" attribute of the node. If you find that the text object has a corresponding backup document (document ID is "100"), you can read the object content in the backup document (plain text "Enterprise Core Technology Information") for export.

[0115] If the user is not an authorized user, the semantic tree is exported according to the unauthorized user operation process: when an unauthorized person tries to export the semantic tree, the export program first determines the "Exprotable" attribute of the semantic node. Since the "Extractable" attribute of the semantic node is "false", the semantic node is skipped and not exported.

[0116] 5) Restore the original document.

[0117] Authorized users choose to restore the OFD document with permissions set to its original state: traverse the semantic tree nodes, find the semantic node with permissions set before, and delete the permission attributes such as "ChiperText", "InPrintable", and "Extractable"; the text object under the semantic node has a corresponding backup document (ID is "100"), copy the object content ("Enterprise Core Technical Information") and object permission attributes ("InPrintable=false") in the backup document to the corresponding page object to replace the corresponding data; delete the document ID ("100") corresponding to the page object recorded under the semantic node.

[0118] 6) Combine with the encryption and decryption and roles of the existing OFD documents, that is, combine with the existing OFD.

[0119] Because the OFD document has semantic permissions set, only the backup document "BackupFile_100" storing the object content and object permission attributes of the page object is encrypted, and the rest of the files are not encrypted. The password / certificate and algorithm used for encryption and decryption reuse the password / certificate mechanism in the current OFD document encryption mechanism. When other standard OFD readers view the OFD document, the effect they see is the same as that seen by unauthorized users, that is, text objects are displayed as " ", the object printing permissions are also consistent with those of unauthorized users.

[0120] When setting permissions, the embodiment of the present invention needs to construct a specific backup document for storing a copy of the page object for which permissions are set. Only simple object content and object permission attributes need to be copied, and there is no need to copy complex and numerous display attributes, and further, there is no need to process the public drawing parameters referenced by them, which avoids the problem caused by omission or error in copying the complete object in the prior art. After this step, the original object content (plain text) and the original value of the object permission attribute are always saved in the backup document.

[0121] The embodiment of the present invention does not remove the original page object, but directly modifies the data affected by the permission on the original page object. When a page object is designated as ciphertext, for example, the text object content is converted into ciphertext (replaced with " " and other replacement characters) or vice versa. In this way, the position of the original page object remains unchanged, and there is no need to record and maintain the layer ID, direction index, etc. of the object, which greatly simplifies the system structure and logic.

[0122] For OFD readers of other standards, the embodiment of the present invention does not reduce the content of the original OFD document, but only modifies the data of some objects (mainly converting plain text into ciphertext), and adds some content that is not within the OFD specification (mainly specific backup documents). The standard OFD reader parses the document normally according to the OFD standard and ignores the added non-standard content, while the page object has been rewritten to an effect that is visible to unauthorized users (the content data of the page object may remain in plain text or may be converted into ciphertext (such as " ”, etc.), so when a standard OFD reader opens the OFD document, the result is what an unauthorized user can see, and the operations are what an unauthorized user can perform, instead of leaving it blank.

[0123] The embodiment of the present invention combines the document encryption and decryption and roles widely supported in the existing OFD readers with the semantic permission setting and improves the former. On the one hand, the existing encryption and decryption logic is reused, including the rules for opening documents and setting various "permissions of permissions" for different roles, the management of keys / certificates and algorithm support, etc.; on the other hand, the rough strategy of "OFD documents are either fully encrypted, resulting in other readers only seeing blank pages, or not encrypted at all, other readers can see all plain texts and perform all operations without restrictions" in the prior art is improved, so that other standard OFD readers can obtain the same permissions as unauthorized users to see the content and operations.

[0124] The permission control device for page objects in the open layout document OFD provided by the present invention is described below. The permission control device for page objects in the open layout document OFD described below and the permission control method for page objects in the open layout document OFD described above can be referenced to each other.

[0125] Figure 8 : is a schematic diagram of the structure of the permission control device for page objects in the open format document OFD provided by the present invention, such as Figure 8 As shown, the device comprises: An acquisition module 801 is configured to acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; A setting module 802 is configured to set a corresponding target permission for any of the semantic nodes when a permission setting operation for the semantic nodes is detected; The control module 803 is configured to perform permission control operations on the object content and object permission attributes of each of the page objects under the semantic node according to the target permission and the backup document corresponding to each of the page objects.

[0126] Optionally, the target permission is a hidden permission; The control module 803 is specifically configured as follows: For each of the page objects under the semantic node, the following operations are performed: Creating a backup file for the page object; Under the semantic node, copying the object content and the object permission attributes of the page object to the backup document; Recording the identifier of the backup document as the document identifier corresponding to the page object under the semantic node; According to the target authority, the object content of the page object is hidden under the semantic node, and the object authority attribute of the page object is changed.

[0127] Optionally, the device further includes a first response module configured to: In response to the output class operation on the OFD document: For authorized users, based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, the output operation is performed on the OFD document; For unauthorized users, the output operation is performed on the OFD document based on the semantic tree file.

[0128] Optionally, the output operation is document display and / or document printing; The first response module is specifically configured as follows: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier, and read the display attribute of the page object from under the semantic node; If not, read the object content and display attributes of the page object from the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0129] Optionally, the output operation is document display and / or document printing; The first response module is specifically configured as follows: For unauthorized users, read the semantic tree file; For any page object contained in each of the semantic nodes in the semantic tree file, read the object content and display attributes of the page object from under the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

[0130] Optionally, the output class operation is semantic tree export; The first response module is specifically configured as follows: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier and export it; If not, read the object content of the page object from the semantic node and export it; Optionally, the output class operation is semantic tree export; The first response module is specifically configured as follows: For each of the semantic nodes in the semantic tree file, read a derived attribute from a node authority attribute of the semantic node; If the derived attribute is reject, skip the semantic node; If the export attribute is allowed, the object content of the page object is read from the semantic node and exported.

[0131] Optionally, the device further includes a second response module configured to: In response to a restore operation of the OFD document by an authorized user, the following operations are performed for each semantic node in the semantic tree file: Clearing the node permission attribute of the semantic node; For any page object included in the semantic node, checking whether the page object has a corresponding document identifier; If so, the object content and permission attributes of the page object in the backup file corresponding to the document identifier are used to replace the object content and permission attributes of the page object under the semantic node, and the document identifier corresponding to the page object under the semantic node is deleted.

[0132] Optionally, the device further includes an encryption module configured to: The backup file is encrypted using a key associated with a user, the user being an authorized user or an unauthorized user.

[0133] Fig. 9 An example of a physical structure diagram of an electronic device is shown in FIG. Fig. 9As shown, the electronic device may include: a processor 910, a communication interface 920, a memory 930 and a communication bus 940, wherein the processor 910, the communication interface 920 and the memory 930 communicate with each other through the communication bus 940. The processor 910 may call the logic instructions in the memory 930 to execute the permission control method of the page object in the open layout document OFD, the method comprising: obtaining a semantic tree file corresponding to the OFD document, the semantic tree file comprising at least one semantic node, the semantic node comprising at least one page object in the OFD document; when a permission setting operation for any of the semantic nodes is detected, setting a corresponding target permission for the semantic node; under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, performing a permission control operation on the object content and the object permission attribute of each of the page objects.

[0134] In addition, the logic instructions in the above-mentioned memory 930 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0135] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the permission control method for page objects in an open format document OFD provided by the above methods, the method including: obtaining a semantic tree file corresponding to the OFD document, the semantic tree file including at least one semantic node, and the semantic node containing at least one page object in the OFD document; when a permission setting operation for any of the semantic nodes is detected, setting a corresponding target permission for the semantic node; under the semantic node, performing permission control operations on the object content and object permission attributes of each of the page objects according to the target permission and the backup documents corresponding to each of the page objects.

[0136] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it is implemented to execute the permission control method of page objects in an open format document OFD provided by the above methods, the method comprising: obtaining a semantic tree file corresponding to the OFD document, the semantic tree file comprising at least one semantic node, the semantic node containing at least one page object in the OFD document; when a permission setting operation for any of the semantic nodes is detected, setting a corresponding target permission for the semantic node; under the semantic node, performing a permission control operation on the object content and object permission attributes of each of the page objects according to the target permission and the backup documents corresponding to each of the page objects.

[0137] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0138] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for controlling the permissions of page objects in an open format document OFD, characterized in that: include: Acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; When a permission setting operation for any of the semantic nodes is detected, a corresponding target permission is set for the semantic node; Under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, a permission control operation is performed on the object content and the object permission attribute of each of the page objects.

2. The permission control method for page objects in an open format document OFD according to claim 1, characterized in that: The target permission is a hidden permission; Under the semantic node, according to the target permission and the backup document corresponding to each of the page objects, the permission control operation is performed on the object content and the object permission attribute of each of the page objects, including: For each of the page objects under the semantic node, the following operations are performed: Creating a backup file for the page object; Under the semantic node, copying the object content and the object permission attributes of the page object to the backup document; Recording the identifier of the backup document as the document identifier corresponding to the page object under the semantic node; According to the target authority, the object content of the page object is hidden under the semantic node, and the object authority attribute of the page object is changed.

3. The permission control method for page objects in an open format document OFD according to claim 2, characterized in that: After the permission control operation is performed on the object content and the object permission attribute of each of the page objects, the method further includes: In response to the output class operation on the OFD document: For authorized users, based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers, the output operation is performed on the OFD document; For unauthorized users, the output operation is performed on the OFD document based on the semantic tree file.

4. The method for controlling the permissions of page objects in an open format document OFD according to claim 3, characterized in that: The output operation is document display and / or document printing; The step of performing the output operation on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers includes: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier, and read the display attribute of the page object from under the semantic node; If not, read the object content and display attributes of the page object from the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

5. The method for controlling the permissions of page objects in an open format document OFD according to claim 3 or 4, characterized in that: The output operation is document display and / or document printing; The performing the output operation on the OFD document based on the semantic tree file for the unauthorized user includes: For unauthorized users, read the semantic tree file; For any page object contained in each of the semantic nodes in the semantic tree file, read the object content and display attributes of the page object from under the semantic node; An output operation is performed on the page object according to the object content and the display attribute of the page object.

6. The method for controlling the permissions of page objects in an open format document OFD according to claim 3, characterized in that: The output class operation is semantic tree export; The step of performing the output operation on the OFD document for the authorized user based on the semantic tree file and the backup documents corresponding to all the recorded document identifiers includes: For authorized users, read the semantic tree file; For any page object included in each of the semantic nodes in the semantic tree file, checking whether the page object has a corresponding document identifier; If yes, then read the object content of the page object from the backup file corresponding to the document identifier and export it; If not, the object content of the page object is read from the semantic node and exported.

7. The method for controlling the permissions of page objects in an open format document OFD according to claim 3 or 4, characterized in that: The output class operation is semantic tree export; The performing the output operation on the OFD document based on the semantic tree file for the unauthorized user includes: For each of the semantic nodes in the semantic tree file, reading a derived attribute from a node authority attribute of the semantic node; If the derived attribute is reject, skip the semantic node; If the export attribute is allowed, the object content of the page object is read from the semantic node and exported.

8. The method for controlling the permissions of page objects in an open format document OFD according to claim 2, characterized in that: After the permission control operation is performed on the object content and the object permission attribute of each of the page objects, the method further includes: In response to a restore operation of the OFD document by an authorized user, the following operations are performed for each semantic node in the semantic tree file: Clearing the node permission attribute of the semantic node; For any page object included in the semantic node, checking whether the page object has a corresponding document identifier; If so, the object content and permission attributes of the page object in the backup file corresponding to the document identifier are used to replace the object content and permission attributes of the page object under the semantic node, and the document identifier corresponding to the page object under the semantic node is deleted.

9. The method for controlling the permissions of page objects in an open format document OFD according to claim 2, characterized in that: After the object content and permission attributes of the page object are copied to the backup document under the semantic node, the method further includes: The backup file is encrypted using a key associated with a user, the user being an authorized user or an unauthorized user.

10. A permission control device for page objects in an open format document OFD, characterized in that: include: An acquisition module is configured to acquire a semantic tree file corresponding to an OFD document, wherein the semantic tree file includes at least one semantic node, and the semantic node includes at least one page object in the OFD document; A setting module, configured to set a corresponding target permission for any of the semantic nodes when a permission setting operation for the semantic nodes is detected; The control module is configured to perform permission control operations on the object content and object permission attributes of each of the page objects under the semantic node according to the target permission and the backup documents corresponding to each of the page objects.

Citation Information

Patent Citations

  • A document desensitization system and method based on big data

    CN109284631A

  • Desensitization processing method and device for sensitive data in electronic document

    CN113204949A

  • Electronic document sharing control method and system based on data extraction

    CN115310108A

  • Authority control method and device for OFD (Open Forwarding Detection) object of open format document

    CN117251833A

  • Data desensitization method, device and equipment and readable storage medium

    CN118194349A

Cited By

  • AI enterprise management document automatic filing system based on semantic analysis

    CN122364167A

  • AI enterprise management document automatic filing system based on semantic analysis

    CN122364167B