Authority management method, system and equipment and storage medium

By establishing a mapping relationship between object identification and resource permissions, and using resource encoding to generate target query conditions, the problem of independent maintenance of permission management logic for each business system in SaaS platform-level products is solved, and the power management is lightweight and standardized, and management efficiency and system flexibility are improved.

CN120030570APending Publication Date: 2025-05-23CISDI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510110293.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

During the SaaS platform-level product development process, each sub-business system independently maintains the permission management logic, resulting in complex permission management, low development efficiency, difficulty in quickly querying and setting permission logic, and difficulty in responding to changes in business needs in a timely manner, resulting in high scalability and maintenance costs.

Method used

By establishing a mapping relationship between object identification and resource permissions, quickly determine resource permissions related to object identification, and use resource encoding as an abstract representation of resource permissions query conditions, and generate target query conditions, so that the business system can query and obtain corresponding available resource permissions.

Benefits of technology

It realizes lightweight and standardized permission management, simplifies permission management process, improves management efficiency, enhances the flexibility and scalability of business systems, and adapts to the needs of different business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030570A_ABST
    Figure CN120030570A_ABST
Patent Text Reader

Abstract

The invention provides an authority management method, system and device and a storage medium. The method comprises the following steps: responding to an authority request carrying an object identifier from a service system; a first mapping relation is inquired based on the object identification, available resource permissions are determined, and the first mapping relation comprises a mapping relation between the object identification and the resource permissions; translating according to a resource code of the available resource permission to generate a target query condition, the resource code being an identifier formed by abstracting a query condition based on the resource permission; and enabling the service system to obtain the available resource permission based on the target query condition. Therefore, when the resource code is introduced as the abstract representation of the query condition of the resource permission, the permission management is lighter, the service system can obtain the required resource permission only through simple query, and the permission management efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of software development technology, and in particular to a permission management method, system, device and storage medium. Background Art

[0002] In the process of platform-level product development, the SaaS (Software as a Service) model, as an innovative software delivery method, is gradually becoming the mainstream choice for enterprise information construction. The SaaS model provides software applications as services to users through the Internet, realizes centralized management and on-demand allocation of resources, and greatly reduces the IT (Information Technology) investment and maintenance costs of enterprises. However, with the increasing complexity and diversification of SaaS platforms, the issue of permission management has become one of the key factors restricting its development. In the process of SaaS platform-level product development, it usually involves the permission management of each sub-business system for its own business resources, which is directly related to data security, business compliance and the smoothness of user experience. In the relevant technology, different business systems in the SaaS model have their own operating logic for personnel and resources. The permission management method usually adopted is that each business system maintains an independent set of permission management logic to meet personalized business needs.

[0003] However, the way each system independently maintains the permission management logic is too complicated, which will lead to low development efficiency of the permission management of the business system and make it difficult to quickly query and set the permission logic of the required business. At the same time, with the continuous development of the business, the needs of permission management will continue to change. This decentralized permission management method is difficult to respond to these changes in a timely manner, and there are problems with scalability and high maintenance costs, which in turn affects the stability and reliability of the business system. Summary of the invention

[0004] In order to provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. The summary is not an extensive review, nor is it intended to identify key / critical components or delineate the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.

[0005] In view of the above-mentioned shortcomings of the prior art, the present application discloses a permission management method, system, device and storage medium to solve at least one of the above-mentioned technical problems.

[0006] In a first aspect, the present application provides a permission management method, the method comprising: responding to a permission request carrying an object identifier from a business system, querying a first mapping relationship based on the object identifier to determine available resource permissions, the first mapping relationship including a mapping relationship between the object identifier and resource permissions; querying the first mapping relationship based on the object identifier to determine available resource permissions, the first mapping relationship including a mapping relationship between the object identifier and resource permissions; translating according to a resource code of the available resource permissions to generate a target query condition, the resource code being an identifier abstractly formed based on the query condition of the resource permissions; enabling the business system to obtain the available resource permissions based on the target query condition.

[0007] In one embodiment of the present application, before querying the first mapping relationship based on the object identifier, it also includes: constructing a resource role table for storing resource roles, each resource role is configured with a role type and a unique role code; constructing a resource permission table for storing resource permissions, each resource permission is configured with a resource type, a resource operation and a unique resource code; constructing a resource subject table for storing subject objects, the subject objects are configured with a unique object identifier and a permission business type, and the resource role associated with the permission business type; constructing a relationship table between the resource roles and the resource permissions, so that the resource role is bound to at least one of the resource permissions.

[0008] In one embodiment of the present application, the resource code according to the available resource permissions is translated to generate a target query condition, including: writing the query condition corresponding to each resource code one by one; constructing a first interface of a translator based on a mapping relationship between the resource code and the query condition, the input of the first interface being the resource code, and the output being the query condition; and inputting the resource code of the available resource permissions into the translator for conversion to obtain the target query condition.

[0009] In one embodiment of the present application, after translating the resource code according to the available resource permissions to generate the target query conditions, it also includes: if a filtering condition is received from the business system, constructing a business query condition based on the filtering condition, the filtering condition includes at least one of the operation type, resource type, operation object, validity period, and level of the resource permissions; encapsulating the target query condition and the business query to obtain the final query condition.

[0010] In one embodiment of the present application, after obtaining the final query condition, the method further includes: screening the available resource permissions according to the final query condition to obtain target resource permissions; and sending the target resource permissions to the business system.

[0011] In one embodiment of the present application, the querying of the first mapping relationship based on the object identifier to determine the available resource permissions includes: querying the first mapping relationship based on the object identifier and the permission business type to confirm the available resource permissions, the permission request also includes the permission business type, and the first mapping relationship also includes the mapping relationship between the object identifier, the permission business type and the resource permissions.

[0012] In one embodiment of the present application, constructing the translator also includes: constructing a second interface of the translator, calling the second interface to return the permission business type of the resource permission corresponding to the object identifier; constructing a third interface of the translator, calling the third interface to return the operation object corresponding to the resource encoding, and the operation object is a collection of resource operations; encapsulating the data returned by the second interface and the third interface in the query condition output by the first interface.

[0013] In a second aspect, the present application provides a permission management system, the system comprising: a response module, for responding to a permission request carrying an object identifier from a business system, querying a first mapping relationship based on the object identifier to determine available resource permissions, the first mapping relationship comprising a mapping relationship between the object identifier and the resource permissions; a permission module, for querying the first mapping relationship based on the object identifier to determine available resource permissions, the first mapping relationship comprising a mapping relationship between the object identifier and the resource permissions; a translation module, for translating according to a resource code of the available resource permissions to generate a target query condition, the resource code being an identifier abstractly formed based on the query condition of the resource permissions; a query module, for enabling the business system to obtain the available resource permissions based on the target query condition.

[0014] In a third aspect, the present application also provides an electronic device comprising: a processor, a memory and a communication bus; the communication bus is used to connect the processor and the memory; the processor is used to execute a computer program stored in the memory to implement the permission management method as described in the above embodiment.

[0015] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor of a computer, the computer executes the method described in the above embodiments.

[0016] Beneficial effects of the present application: The present application proposes a permission management method, system, device and storage medium. By establishing a first mapping relationship between an object identifier and a resource permission, the resource permission related to the object identifier is quickly determined, and the query statement of the resource permission required by the business system is abstracted into a resource code. The business system only needs to maintain the relationship between the resource permission and the resource code, and can translate the resource code to generate a target query statement suitable for the business system. Using the target query condition, the business system can query and obtain the corresponding available resource permission. In this way, permission management is more lightweight. By introducing resource codes as an abstract representation of the query conditions of resource permissions, the management of resource permissions is more standardized and unified, easy to maintain and expand, and can adapt to the needs of different business systems, enhancing the flexibility and scalability of the business system; and the business system can obtain the required resource permissions through simple queries, which simplifies the permission management process and improves management efficiency.

[0017] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0019] Figure 1 is a flowchart of a rights management method shown in an exemplary embodiment of the present application;

[0020] Figure 2 is a schematic diagram of a permission model shown in an exemplary embodiment of the present application;

[0021] Figure 3 is a schematic diagram of a permission framework application shown in an exemplary embodiment of the present application;

[0022] Figure 4 is a schematic diagram of a resource permission usage process shown in an exemplary embodiment of the present application;

[0023] Figure 5 is a block diagram of a rights management system shown in an exemplary embodiment of the present application;

[0024] Figure 6 It is a structural diagram of a computer system suitable for implementing the electronic device of the present application, shown as an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0025] The following will describe the implementation methods of the present application with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for illustrating the present application, not for limiting the scope of protection of the present application.

[0026] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the form, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0027] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.

[0028] See also Figure 1 , is a flowchart of a rights management method shown in an exemplary embodiment of the present application. Figure 1 As shown, in an exemplary embodiment, the rights management method includes at least steps S110 to S130, which are described in detail as follows:

[0029] Step S110, in response to a permission request carrying an object identifier from a business system, query a first mapping relationship based on the object identifier to determine available resource permissions, wherein the first mapping relationship includes a mapping relationship between the object identifier and the resource permissions.

[0030] Specifically, the permission framework responds to the permission request of the business system, and the permission framework is constructed based on the permission model of four data tables: resource role table, resource permission table, resource subject table and relationship table. Among them, constructing the permission model includes: constructing a resource role table for storing resource roles, each resource role is configured with a role type and a unique role code; constructing a resource permission table for storing resource permissions, each resource permission is configured with a resource type, resource operation and a unique resource code; constructing a resource subject table for storing subject objects, the subject objects are configured with a unique object identifier and permission business type, and resource roles associated with the permission business type; constructing a relationship table between resource roles and resource permissions, so that the resource role is bound to at least one resource permission, and the permission model is composed based on the definition of the resource role table, resource permission table, resource subject table and relationship table.

[0031] In one embodiment of the present application, the subject object is an object that uses resources, that is, an object that has specific resource permissions. The object types include users, applications, organizations, etc. The business permission types include permissions of different business types, which can be adjusted according to actual business needs, such as business systems, menus, resource roles, and pages, etc. The resource role is a further abstraction of the resource permissions owned by the subject object, representing a collection of resource permissions. The role types of resource roles include administrators, visitors, advanced applications, etc. A subject object can be defined as multiple resource roles. For example, when the object identifier of the subject object is ID=1, it can be queried that its object type is employee, and the permission business types of employee 1 include business system A and business system B. Its resource role in business system A is administrator, and its resource role in business system B is visitor. In addition, the resource types of resource permissions include at least menu resources, button resources, data resources, and space resources. Resource operations include at least editing, querying, and deleting. Each operation type in resource permissions can be used as an operation permission, and resource types and resource permissions can define resource types and resource operations in the form of enumeration types. Each resource type or resource operation corresponds to an enumeration constant.

[0032] In one embodiment of the present application, a resource code is a custom identifier used to represent one or more resource permissions, and is abstracted from a query condition of at least one resource permission, where the query condition is an SQL (Structured Query Language) query condition for querying resource permissions. The resource code may be a string, a number, or another type of representation. For example, "123456" is defined as a resource code. The resource code "123456" may represent one resource permission or a collection of multiple resource permissions. "all" may also be defined as a resource code to represent all resource permissions.

[0033] In one embodiment of the present application, the permission model is an improved version of the role-based access control (RBAC) permission model, in which the query of resource permissions is abstracted into a coded form (i.e., resource coding), making permission management more lightweight. When developing a business system, relevant technical personnel only need to maintain the relationship between resource permissions and resource coding to obtain the required resource permissions quickly and easily. In addition, the permission framework built based on the permission model is also more lightweight, and the business system can verify and manage resource permissions by interacting with the permission framework and the data table defined in the access permission model.

[0034] See also Figure 2 , is a schematic diagram of a permission model shown in an exemplary embodiment of the present application. Figure 2 As shown, through four data tables, the main object (i.e. Figure 2 The object in the resource role has a resource role, and the resource role (i.e. Figure 2 The role in the resource has resource permissions through resource encoding (i.e. Figure 2 The resource permission is the permission to operate a resource on a resource.

[0035] In one embodiment of the present application, the permission framework can be implemented in conjunction with the MyBatis framework (i.e., a persistence layer framework), or in conjunction with other frameworks that can implement the same type of functionality to enhance the flexibility and efficiency of permission management. For example, in the permission framework, complex queries are executed to verify resource permissions. The MyBatis framework enables dynamic construction or custom SQL query conditions to filter out the required resource permissions, thereby meeting the business needs of different business systems.

[0036] In one embodiment of the present application, the first mapping relationship can be determined by the resource role table, resource permission table, resource subject table and relationship table. First, the matching resource role under the same subject object is determined according to the object identifier, and then all resource permissions bound to the resource role are used as available resource permissions.

[0037] In one embodiment of the present application, since the subject object represented by the same object identifier may include multiple business permission types, in order to refine the screening and avoid the business system from obtaining unavailable resource permissions, it is also possible to combine the permission business type query, including: querying the first mapping relationship based on the object identifier and the permission business type to determine the available resource permissions, the permission request also includes the permission business type, and the first mapping relationship also includes the mapping relationship between the object identifier, the permission business type and the resource permission.

[0038] Step S120 , translating according to the resource code of the available resource authority to generate a target query condition, where the resource code is an identifier abstractly formed based on the query condition of the resource authority.

[0039] Specifically, a query condition corresponding to each resource code is written; a first interface of a translator is constructed based on a mapping relationship between resource codes and query conditions, the input of the first interface is the resource code, and the output is the query condition; the resource code of the available resource authority is input into the translator for conversion to obtain a target query condition.

[0040] In one embodiment of the present application, the translator is an abstract class exposed to the outside, which is used by the business party to set the conversion rules according to the required business logic, and the logic of permission code translation is abstracted. The first interface of the translator is constructed, that is, the first interface is implemented in this abstract class to translate the resource code into the query condition.

[0041] In one embodiment of the present application, the conversion rules of the first interface are configured, including: based on MyBatis-Plus (i.e., a persistence layer framework) or other frameworks with related functions, a query condition constructor is constructed according to the resource code, which is used to construct a query condition mapped to each resource code, and the query condition is a WHERE statement in the SQL query condition, which is used to query the resource authority corresponding to the resource code; the query condition constructor is encapsulated as a condition consumption function, so that each query condition is encapsulated as an independent condition consumption function, and stored in a mapping with the resource code as the key, which is a mapping relationship between the resource code and the condition consumption function.

[0042] In one embodiment of the present application, taking the MyBatis-Plus framework as an example, a LambdaQueryWrapper is created. <t>The object is the query condition builder, and then LambdaQueryWrapper <t>Object encapsulation as Consumer <LambdaQueryWrapper <t>>Conditional consumption function, and stored in a map with resource identifier as key, i.e. Map <R,Consumer<LambdaQueryWrapper <t>>>. Map is a mapping, its key is R, which is the resource code, and its value is Consumer <LambdaQueryWrapper <t>>Consumer is a conditional consumption function, which is a function interface that accepts a LambdaQueryWrapper <t>The object is used as a parameter and operations are performed on it (such as adding query conditions). T usually represents the entity class type in the database, and the query conditions corresponding to the resource code are for the entity class of type T (such as the class of resource permissions).

[0043] Through the above method, the resource code is translated into a query statement by a translator to abstract the logic of permission code translation and decouple it from the external business system. In this way, technical personnel in different business systems do not need to worry about how the resource code is translated by maintaining the relationship between resource codes and resource permissions. They only need to repeatedly call the interface of the same translator to generate the query statement of the required resource permissions based on the resource code. The query statement can be used to quickly query or configure the resource permissions required by the business system, which helps to reduce the complexity of permission management, improve the maintainability of the code, and realize lightweight management of resource permissions.

[0044] Specifically, since the translator is decoupled from the business system, new interfaces can be added without modifying the existing code to implement new functions, which increases the flexibility and scalability of authority management. Based on this, the interface of the translator can also include: constructing a second interface of the translator, calling the second interface to return the authority business type of the object identifier corresponding to the resource authority; constructing a third interface of the translator, calling the third interface to return the operation object corresponding to the resource encoding, and the operation object is a collection of resource operations; encapsulating the data returned by the second interface and the third interface in the query conditions output by the first interface. In this way, when it is necessary to query the operation object and the business authority type, it is only necessary to call the interface of the translator, making the authority management more lightweight.

[0045] In one embodiment of the present application, a third interface of the translator is constructed, that is, the third interface is implemented in this abstract class, and the third interface can be combined with MyBatis-Plus (i.e., a persistence layer framework) or other frameworks with related functions to define a service interface, which defines resource operations associated with the operation object and also provides the ability to construct SQL query conditions on the operation object so that the third interface returns the operation object. Among them, the resource operations related to the operation object can be extended to the IServi ce provided by MyBatis-Plus. <t>In this way, the operation object of the resource permission corresponding to a resource code can be queried by calling the third interface, which provides a very unified and standardized way without having to worry about the implementation details of the underlying database.

[0046] In one embodiment of the present application, the second interface defines a mapping relationship between an object identifier and a permission service type, wherein the input is the object identifier and the output is the permission service type. Alternatively, the second interface returns the permission service type according to the object identifier or resource code in a manner similar to the third interface.

[0047] Step S130: enabling the business system to obtain available resource permissions based on the target query condition.

[0048] In an embodiment of the present application, taking the example that business system A has a database of storage resources, each resource is distinguished by a unique resource ID (identifier), and for different personnel using the business system, each person has an object ID in the business system, and it is necessary to manage the resource permissions for viewing and deleting each resource. Thus, the business system establishes two database tables. One is the personnel table: storing the basic information of personnel, and the key field is the personnel ID (for example, personnel ID 111); the other is the resource table, storing the basic information of resources, and the key fields include the resource ID (for example, resource ID 123456). Then, according to business requirements, tables related to rights management are constructed, including the resource role table, the resource permission table, the resource subject table, and the relationship table. For example, in the resource role table, a resource role with a role code of 1 is stored, and its role type is an administrator; in the resource subject table, a subject object with an object code of 111 is stored, its business permission type is business system A, and the associated role code is 1; in the resource permission table, a resource permission with a resource code of 123456 is stored, corresponding to the resource with the resource ID 123456. Also, according to requirements, the resource code can be defined as a character for multiple resources, such as 234, and this resource permission includes operation types such as viewing and deleting; in the relationship table, the corresponding relationship between the role code 1 and the resource code 123456 is recorded. Secondly, in order to implement the query function of resource permissions, three interfaces of an abstract class (i.e., the translator) also need to be constructed. Among them, one interface returns the business permission type of business system A, one interface feeds back the operation object of the entity class being the personnel table (such as IService<Personnel Table>), and another interface is used to return the consumption function for constructing and executing the query conditions (such as Consumer<LambdaQueryWrapper<Personnel Table>>), and then the query conditions are returned. Finally, through the personnel ID and the resource ID, the resource permissions for a certain person to view or delete a certain resource can be queried through the translator. For example, to query whether Zhang San has the consumption permission for book 123456, only by combining IService<Personnel Table> and the resource code 123456, generating a query statement through the translator, and based on the query statement, the resource permissions of the person corresponding to Zhang San's personnel ID can be queried.

[0049] Specifically, because only partial resource permissions are required during the development or maintenance of the business system, it is necessary to filter the available resource permissions, including: if a filtering condition from the business system is received, then based on the filtering condition, a business query condition is constructed. The filtering condition includes at least one of the operation type, resource type, operation object, validity period, and level of the resource permission; the target query condition and the business query are encapsulated to obtain the final query condition; the available resource permissions are filtered according to the final query condition to obtain the target resource permissions; the target resource permissions are sent to the business system.

[0050] In one embodiment of the present application, the business query condition corresponding to the filtering condition can be implemented by creating a new interface for returning the added business query based on the translator.

[0051] In one embodiment of the present application, taking the available resource permissions including the resource permissions of four data numbered 1, 2, 3 and 4 as an example, the business system can set filtering conditions, such as setting the validity period of the data as the filtering condition. First, construct a business query condition for querying whether the data corresponding to the resource permissions are within the validity period. If the data numbered 1 and 2 in the resource permissions are expired, the data numbered 1 and 2 are filtered, and only the data 3 and 4 are retained. Then, the filtering condition is also set as the operation type, such as deletion, and then construct a query for querying whether the available resource permissions have the operation type of deletion. If so, the resource permissions have the resource permissions to delete the data numbered 3 and 4, and use them as the target resource permissions.

[0052] In one embodiment of the present application, the filtering conditions may also be paging query and joint table query, etc., which may be expanded according to actual needs.

[0053] See also Figure 3 , is a schematic diagram of a permission framework application shown in an exemplary embodiment of the application. Figure 3 As shown, the permission framework constructed according to the permission management method provided in this application creates a permission center, which can be deployed in a microservice manner or introduced into a development project (business system) through an SDK (Software Development Kit). Figure 3 In this example, the SaaS platform of the platform base user center domain resource center is used as an example. The type of resource object (i.e., subject object) under this platform is the business system. Business system A and business system B access the permission center deployed in the microservice mode to call the permission center to implement permission management. Business system C directly introduces the permission center deployed in the SDK mode to call the permission center. In this way, the permission framework does not need to rely on too much middleware, and the lightweight deployment allows developers to access it quickly and conveniently.

[0054] See also Figure 4 , is a schematic diagram of a resource permission usage process shown in an exemplary embodiment of the present application. Figure 4 As shown, first, the permission center is called, and the object ID (object code) and the business permission type are taken as input parameters to determine the resource role corresponding to the business permission type under the object code, so as to query the resource code bound to the resource role, and regard all resource permissions corresponding to the resource code as available resource permissions; then, the resource code is converted into a target query condition by a translator, and the business query condition is further encapsulated on the basis of the target query condition to obtain the operable data of the available resource permissions, that is, the operation type related data of the available resource permissions, wherein, if a business query condition of at least one operation type is encapsulated, the operable data of the available resource permissions is screened, and the available resource permissions including the same operation type as the business query condition are taken as the target permissions, and the operation permissions for executing the same operation type in the available resource permissions are sent to the business system.

[0055] Through the above method, a permission center is created based on the permission framework. Developers only need to maintain the permission control logic of their own business. By configuring the binding rules between resource codes and resource permissions, their own permission logic can be quickly and efficiently connected to the permission center. Through the resource coding translator of the permission center, query statements for resource permissions are generated. Developers can quickly query and set the permission logic of the required business based on the provided queries.

[0056] See also Figure 5 , is a block diagram of a rights management system shown in an exemplary embodiment of the present application. Figure 5 As shown, in an exemplary embodiment, the rights management system includes at least a rights query module 510, a code translation module 520 and an acquisition module 530, which are described in detail as follows:

[0057] The permission query module 510 is used to respond to the permission request carrying the object identifier from the business system, query the first mapping relationship based on the object identifier, and determine the available resource permissions, where the first mapping relationship includes a mapping relationship between the object identifier and the resource permissions;

[0058] A code translation module 520 is used to translate the resource code of the available resource authority to generate a target query condition, where the resource code is an identifier abstractly formed based on the query condition of the resource authority;

[0059] The acquisition module 530 is used to enable the business system to acquire available resource permissions based on the target query condition.

[0060] It should be noted that the permission management system provided in the above embodiment and the permission management method provided in the above embodiment belong to the same concept, wherein the contents of the operations performed by each module have been described in detail in the method embodiment and will not be repeated here.

[0061] The permission management method and system provided in the present application have the following advantages: First, permission management is more lightweight. By introducing resource coding as an abstract representation of the query conditions of resource permissions, the management of resource permissions is more standardized and unified, easy to maintain and expand, and can adapt to the needs of different business systems, thereby enhancing the flexibility and scalability of the business system. Second, the business system can obtain the required resource permissions through simple queries, thereby simplifying the permission management process and improving management efficiency.

[0062] The present application also provides an electronic device, comprising: a processor, a memory and a communication bus; the communication bus is used to connect the processor and the memory; the processor is used to execute a computer program stored in the memory to implement the permission management method as in the above embodiment.

[0063] See also Figure 6 , shows a schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application. It should be noted that, Figure 6 The computer system 600 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0064] like Figure 6 As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage part 608 to the random access memory (RAM) 603, such as executing the method in the above embodiment. In the RAM 603, various programs and data required for system operation are also stored. The CPU 601, ROM 602 and RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0065] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 609 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read therefrom is installed into the storage section 608 as needed.

[0066] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 609, and / or installed from a removable medium 611. When the computer program is executed by a central processing unit (CPU) 601, various functions defined in the system of the present application are executed.

[0067] The present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor of a computer, the computer executes the rule engine configuration method for early warning as described above. The computer-readable storage medium may be included in the electronic device described in the above embodiment, or may exist independently without being assembled into the electronic device.

[0068] It should be noted that the computer-readable medium shown in the embodiment of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared or semiconductor system, system or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, system or device. A computer program contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0069] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0070] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.

[0071] The above embodiments are merely illustrative of the principles and effects of the present application, and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.< / t> < / t> < / t> < / t> < / t> < / t> < / t>

Claims

1. A rights management method, characterized in that: The method comprises: In response to a permission request carrying an object identifier from a business system, query a first mapping relationship based on the object identifier to determine available resource permissions, wherein the first mapping relationship includes a mapping relationship between the object identifier and the resource permissions; Translate the resource code of the available resource authority to generate a target query condition, wherein the resource code is an identifier abstractly formed based on the query condition of the resource authority; The business system is enabled to obtain the available resource authority based on the target query condition.

2. The rights management method according to claim 1, characterized in that: Before querying the first mapping relationship based on the object identifier, the method further includes: Constructing a resource role table for storing resource roles, each of the resource roles is configured with a role type and a unique role code; Constructing a resource permission table for storing resource permissions, each resource permission is configured with a resource type, a resource operation and the resource code, and the resource code is associated with at least one resource permission; Constructing a resource subject table for storing subject objects, wherein the subject objects are configured with a unique object identifier and a permission business type, and the resource role associated with the permission business type; A relationship table between the resource roles and the resource permissions is constructed so that the resource role is bound to at least one of the resource permissions.

3. The rights management method according to claim 2, characterized in that: The resource code according to the available resource authority is translated to generate a target query condition, including Compile the query condition corresponding to each resource code; Building a first interface of a translator based on a mapping relationship between the resource code and the query condition, wherein the input of the first interface is the resource code and the output is the query condition; The resource code of the available resource authority is input into the translator for conversion to obtain the target query condition.

4. The rights management method according to any one of claims 1 to 3, characterized in that: After translating the resource code according to the available resource authority to generate the target query condition, the method further includes: If a filtering condition is received from the business system, a business query condition is constructed based on the filtering condition, wherein the filtering condition includes at least one of the operation type, resource type, operation object, validity period, and level of the resource authority; The target query condition and the business query are encapsulated to obtain a final query condition.

5. The rights management method according to claim 4, characterized in that: After obtaining the final query condition, the method further includes: The available resource permissions are screened according to the final query condition to obtain target resource permissions; The target resource authority is sent to the business system.

6. The rights management method according to claim 1, characterized in that: The querying the first mapping relationship based on the object identifier to determine the available resource authority includes: The first mapping relationship is queried based on the object identifier and the permission business type to confirm the available resource permission, the permission request also includes the permission business type, and the first mapping relationship also includes the mapping relationship between the object identifier, the permission business type and the resource permission.

7. The rights management method according to claim 3, characterized in that: Constructing the translator also includes: Constructing a second interface of the translator, and calling the second interface to return the permission business type of the resource permission corresponding to the object identifier; Constructing a third interface of the translator, calling the third interface to return an operation object corresponding to the resource encoding, wherein the operation object is a collection of resource operations; The data returned by the second interface and the third interface are encapsulated in the query condition output by the first interface.

8. A rights management system, characterized in that: The system comprises: A permission query module, configured to respond to a permission request carrying an object identifier from a business system, query a first mapping relationship based on the object identifier to determine available resource permissions, wherein the first mapping relationship includes a mapping relationship between the object identifier and the resource permissions; A code translation module, used for translating the resource code of the available resource authority to generate a target query condition, wherein the resource code is an identifier abstractly formed based on the query condition of the resource authority; An acquisition module is used to enable the business system to acquire the available resource authority based on the target query condition.

9. An electronic device, characterized in that: include: processor, memory, and communications bus; The communication bus is used to connect the processor and the memory; The processor is configured to execute the computer program stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and the computer program is used to make a computer execute the method according to any one of claims 1 to 7.