Business data acquisition method and device, electronic equipment and storage medium

By determining the target business and role of the target object, combining the permission correlation table, obtaining the target data acquisition type, and finally obtaining the target business data, the problem of insufficient permission control in complex scenarios is solved, and the precise control and rapid acquisition of data permissions is achieved.

CN120197188APending Publication Date: 2025-06-24ISOFTSTONE SMART DATA TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510253767.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When faced with complex business scenarios and large organizational structures, the existing permission management methods are insufficient in the granularity of permission control and are difficult to adapt to complex needs.

Method used

By determining the target business and target role of the target object, using the preset permission correlation table, the target data acquisition type of the target object is determined, and the target business data is finally obtained, ensuring the accuracy of data permission control.

Benefits of technology

It realizes the rapid acquisition of target business data of target objects, ensures the rationality of data permissions, avoids the occurrence of overprivileges, and improves the efficiency of granting permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197188A_ABST
    Figure CN120197188A_ABST
Patent Text Reader

Abstract

The invention discloses a business data acquisition method and device, electronic equipment and a storage medium. The method comprises the steps of determining a target service corresponding to a target object; determining at least one target role corresponding to the target object according to the target business; determining a target data acquisition type corresponding to the target object according to a preset permission association table and each target role; and determining target business data corresponding to the target business according to the target data acquisition type. By adopting the technical scheme of the invention, the target business data of the target object can be quickly acquired, and the acquired data cannot exceed the authority of the target object in the acquisition process, so that the authority endowing is improved, and the occurrence of an unauthorized behavior is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of permission granting, and particularly to a method, device, electronic device and storage medium for obtaining business data. Background Art

[0002] In the existing technology, permission management is usually an important part of enterprise-level application systems, providing access control to system functions and data. However, with the increase in business complexity and the expansion of system scale, some problems in common permission management methods (such as role-based access control (RBAC) and attribute-based access control (ABAC)) have gradually emerged. For example, the granularity of permission control is insufficient, it is difficult to adapt to large organizational structures, and complex business scenarios cannot be supported. Summary of the Invention

[0003] The present invention provides a method, device, electronic device and storage medium for obtaining business data to solve problems such as insufficient granularity of permission control, difficulty in adapting to large organizational structures, and inability to support complex business scenarios.

[0004] According to one aspect of the present invention, there is provided a method for obtaining business data, the method comprising:

[0005] Determine the target business corresponding to the target object; the target business is the business processed by the target object;

[0006] According to the target business, determine at least one target role corresponding to the target object; the role is used to describe the role that the object needs to play when processing the business;

[0007] According to the preset permission association table and each target role, determine the target data acquisition type corresponding to the target object; the permission association table includes at least one candidate role and the data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of the data that the candidate role is allowed to obtain;

[0008] According to the target data acquisition type, determine the target business data corresponding to the target business.

[0009] According to another aspect of the present invention, there is provided a device for obtaining business data, the device comprising:

[0010] A target business determination module, configured to determine the target business corresponding to the target object; the target business is the business processed by the target object;

[0011] A target role determination module, configured to determine at least one target role corresponding to the target object according to the target business; the role is used to describe the role that the object needs to play when processing the business;

[0012] An acquisition type determination module, configured to determine a target data acquisition type corresponding to a target object according to a preset permission association table and each target role; the permission association table includes at least one candidate role and a data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of the data that the candidate role is allowed to acquire.

[0013] A service data acquisition module, configured to determine target service data corresponding to a target service according to the target data acquisition type.

[0014] According to another aspect of the present invention, there is provided an electronic device, including:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the service data acquisition method of any embodiment of the present invention.

[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the service data acquisition method of any embodiment of the present invention when executed.

[0019] The technical solution of the embodiment of the present invention realizes the rapid acquisition of the target service data of the target object by determining the target service corresponding to the target object; determining at least one target role corresponding to the target object according to the target service; determining the target data acquisition type corresponding to the target object according to the preset permission association table and each target role; and finally determining the target service data corresponding to the target service according to the target data acquisition type, and ensures that the acquired data does not exceed the permissions of the target object during the acquisition process, thereby improving the granting of permissions and avoiding the occurrence of over-authorization behavior.

[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0022] Figure 1 It is a flowchart of a method for obtaining service data provided in Embodiment 1 of the present invention;

[0023] Figure 2 It is a flowchart of another method for obtaining service data provided in Embodiment 2 of the present invention;

[0024] Figure 3 It is a schematic structural diagram of a service data acquisition device provided in Embodiment 3 of the present invention;

[0025] Figure 4 It is a schematic structural diagram of an electronic device for implementing the service data acquisition method of the embodiments of the present invention. Detailed implementation manners

[0026] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] Embodiment 1

[0029] Figure 1 For Embodiment 1 of the present invention, a flowchart of a method for obtaining service data is provided. This embodiment is applicable to quickly obtaining target service data and avoiding the situation of obtaining data irrelevant to the target service data. This method can be executed by a service data acquisition device, which can be implemented in the form of hardware and / or software, and the service data acquisition device can be configured in an electronic device with data processing capabilities. As Figure 1 shown, the method includes:

[0030] S110. Determine the target business corresponding to the target object.

[0031] The target business is the business processed for the target object.

[0032] The target object can be the object that needs to process the target business. The target business can be the business that the target object needs to process.

[0033] When the target object processes the business, it will first determine the specific content of the business that the target object needs to process, that is, determine the target business.

[0034] In an actual organization, such as an enterprise or a department, etc., there will be multiple businesses involved. At this time, the determination of the target business can be through the direct assignment of business assignment personnel, or can be pre-assigned according to the actual work content of different positions.

[0035] S120. According to the target business, determine at least one target role corresponding to the target object.

[0036] A role is used to describe the role that an object needs to play when processing a business.

[0037] When processing a business, the specific work content that may need to be processed in different businesses is different. For example, when calculating the electricity bill of a user, it includes multiple steps such as measuring the electricity consumption of the electric energy meter and statistics based on the electricity consumption. Therefore, different roles will be set according to the actual work content.

[0038] In different target businesses, the same object may need to play multiple roles at the same time. For example, it may be necessary to measure the electricity consumption of the electric energy meter and statistics based on the electricity consumption at the same time.

[0039] For different businesses, it is necessary to generate or match roles according to the processing content during actual processing. Roles can be administrators, ordinary users, data analysts, etc.

[0040] Optionally, the determination of the role includes:

[0041] Determine at least one candidate business;

[0042] According to each candidate business, determine at least one role.

[0043] When generating roles, to ensure the accuracy of role generation, it is necessary to generate according to the responsibilities and requirements of the candidate business in actual work. Therefore, it is necessary to first determine the existing candidate businesses and determine the roles according to the actual work content of each candidate business.

[0044] S130. According to the preset permission association table and each target role, determine the target data acquisition type corresponding to the target object.

[0045] The permission association table contains at least one candidate role and the data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of the data that the candidate role is allowed to acquire.

[0046] After obtaining the role, since the content processed by each role has been clarified, the data type of the business data corresponding to each role can be determined in advance, and a permission association table can be generated according to the corresponding relationship between the role and the business data type. After determining the target role, the target data acquisition type corresponding to the target role can be determined by comparing the target role with the candidate roles in the permission association table.

[0047] S140. Determine the target business data corresponding to the target business according to the target data acquisition type.

[0048] After determining the target data acquisition type that needs to be acquired, the corresponding target business data can be directly acquired.

[0049] According to the technical solution of the embodiment of the present invention, by determining the target business corresponding to the target object; according to the target business, determining at least one target role corresponding to the target object; according to the preset permission association table and each target role, determining the target data acquisition type corresponding to the target object; finally, according to the target data acquisition type, determining the target business data corresponding to the target business, the rapid acquisition of the target business data of the target object is realized, and during the acquisition process, it is ensured that the acquired data does not exceed the permission of the target object, thereby improving the granting of permissions and avoiding the occurrence of over-authorization behavior.

[0050] Embodiment II

[0051] Figure 2 This is a flowchart of another method for acquiring business data provided by the embodiment of the present invention. Based on the above embodiment, the process after determining the target business corresponding to the target object in the foregoing embodiment is further optimized. This embodiment can be combined with various alternative solutions in one or more of the above embodiments. As Figure 2 shown, the method for acquiring business data in this embodiment may include the following steps:

[0052] S210. Determine the target business corresponding to the target object.

[0053] S220. Determine the target object permission of the target object according to the target business.

[0054] In addition to the method of using roles to acquire business data in Embodiment I, it can also be acquired through the permissions of the target object.

[0055] Since the operations handled by different objects may vary to some extent, different objects will be granted different permissions according to their specific operations.

[0056] Therefore, after clarifying the target operation corresponding to the target object, the specific operation that the target object needs to handle is also clarified, and then the target object permissions required to handle this specific operation can be determined.

[0057] Regarding how to determine the target object permissions of the target object according to the target operation, it can be generated in advance according to the actual operation or the hierarchical relationship between each candidate object.

[0058] In an alternative solution, before determining the target object permissions of the target object according to the target operation, it further includes steps A1 - A2:

[0059] Step A1: Determine the hierarchical relationship between each candidate object.

[0060] Step A2: According to the hierarchical relationship, establish an object permission tree and assign object permissions to each node in the object permission tree; each node in the object permission book is a candidate object, and the parent node is the superior of the child node.

[0061] Regarding the determination of the object permissions of an object, an object permission book can be established through the hierarchical relationship between each candidate object. In the object permission book, the permissions of the parent node should be greater than or equal to those of the child node. The permissions of each node can be assigned manually or by other means.

[0062] Optionally, before determining the target object permissions of the target object according to the target operation, it further includes:

[0063] Determine at least one candidate business data and assign data permissions to each candidate business data.

[0064] For each candidate business data, data permissions also need to be assigned according to the sensitivity of the data.

[0065] Regarding objects and business data, in addition to considering permissions, the dimension issue also needs to be considered. The reason is that the importance degree of the same data is different in positions of different dimensions.

[0066] For example, taking cleaners as an example, there are cleaner A and cleaner B. Cleaner A is responsible for cleaning the warehouse, and cleaner B is responsible for cleaning the public area. Since the warehouse is more important than the public area, if only divided by permissions, it may lead to cleaner A being unable to reach the warehouse for cleaning work. Therefore, it is necessary to divide the business data into dimensions, generate labels such as finance, human resources, logistics, and operation and maintenance, and also divide the objects into dimensions. When determining business data, it is determined by weight within the same dimension.

[0067] S230. Determine the target business data permissions corresponding to the target object according to the preset permission mapping relationship and the target object permissions.

[0068] The permission mapping relationship is used to describe the corresponding relationship between object permissions and business data permissions.

[0069] After determining the target object permissions, the target business data permissions corresponding to the target object can be found in the permission mapping relationship.

[0070] In an alternative solution, to determine the target business data according to the target business data permissions, it includes steps B1 - B2:

[0071] Step B1. Determine the candidate business data permissions of each candidate business data.

[0072] Step B2. For each candidate business data, if the candidate business data permissions are less than or equal to the target business data permissions, then determine this candidate business data as the target business data permissions.

[0073] When determining the target business data through the target business data permissions, it is necessary to first determine the candidate business data permissions of each candidate business data.

[0074] By comparing the business data permissions, find the candidate business data permissions whose candidate business data permissions are less than or equal to the target business data permissions from each candidate business data, and use them as the target business data permissions.

[0075] Optionally, when the target business of the target object changes, the mapping ratio between business permissions and object permissions can be adjusted.

[0076] S240. Determine the target business data according to the target business data permissions.

[0077] According to the technical solution of the embodiment of the present invention, by determining the target business corresponding to the target object; according to the target business, determining the target object permissions of the target object; according to the preset permission mapping relationship and the target object permissions, determining the target business data permissions corresponding to the target object; and finally determining the target business data according to the target business data permissions, it realizes the rapid acquisition of the target business data, and ensures that while acquiring the target business data, business data exceeding the permissions of the target object will not be acquired.

[0078] Embodiment III

[0079] Figure 3The embodiment of the present invention provides a structural block diagram of a service data acquisition device. This embodiment is applicable to quickly acquire target service data and avoid the situation of acquiring data irrelevant to the target service data. The service data acquisition device can be implemented in the form of hardware and / or software, and can be configured in an electronic device with data processing capabilities. As Figure 3 shown, the service data acquisition device of this embodiment may include: a target service determination module 310, a target role determination module 320, an acquisition type determination module 330, and a service data acquisition module 340. Among them:

[0080] The target service determination module 310 is used to determine the target service corresponding to the target object; the target service is the service processed by the target object;

[0081] The target role determination module 320 is used to determine at least one target role corresponding to the target object according to the target service; the role is used to describe the role that the object needs to play when processing the service;

[0082] The acquisition type determination module 330 is used to determine the target data acquisition type corresponding to the target object according to a preset permission association table and each target role; the permission association table includes at least one candidate role and the data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of the data that the candidate role is allowed to acquire;

[0083] The service data acquisition module 340 is used to determine the target service data corresponding to the target service according to the target data acquisition type.

[0084] Based on the above embodiment, optionally, after the target service determination module 310, it further includes:

[0085] The object permission acquisition module is used to determine the target object permission of the target object according to the target service;

[0086] The data permission determination module is used to determine the target service data permission corresponding to the target object according to a preset permission mapping relationship and the target object permission; the permission mapping relationship is used to describe the corresponding relationship between the object permission and the service data permission;

[0087] The target data determination module is used to determine the target service data according to the target service data permission.

[0088] Based on the above embodiment, optionally, before the object permission acquisition module, it further includes:

[0089] Determine the superior-subordinate relationship of each candidate object;

[0090] Establish an object permission tree according to the superior-subordinate relationship, and assign object permissions to each node in the object permission tree; each node in the object permission book is a candidate object, and the parent node is the superior of the child node.

[0091] Based on the above embodiments, optionally, before the object permission acquisition module, it further includes:

[0092] Determine at least one candidate business data, and assign data permissions to each candidate business data.

[0093] Based on the above embodiments, optionally, the target data determination module includes:

[0094] Determine the candidate business data permissions of each candidate business data;

[0095] For each candidate business data, if the candidate business data permission is less than or equal to the target business data permission, then determine that the candidate business data is the target business data permission.

[0096] Based on the above embodiments, optionally, the determination of the role includes:

[0097] Determine at least one candidate business;

[0098] Determine at least one role according to each candidate business.

[0099] The business data acquisition device provided by the embodiments of the present invention can execute the business data acquisition method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0100] Embodiment 4

[0101] Figure 4 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0102] Such as Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as read-only memory (ROM) 12, random access memory (RAM) 13, etc. The memory stores computer programs executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 12 or the computer programs loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0103] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0104] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the business data acquisition method.

[0105] In some embodiments, the business data acquisition method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the business data acquisition method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the business data acquisition method in any other appropriate way (e.g., by means of firmware).

[0106] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.

[0107] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0108] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0109] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0110] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0111] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0112] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0113] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for acquiring business data, characterized in that: include: Determine the target business corresponding to the target object; The target business is the business processed by the target object; Determine, according to the target business, at least one target role corresponding to the target object; Roles are used to describe the roles that an object needs to play when processing business; Determine the target data acquisition type corresponding to the target object according to the preset permission association table and each target role; The permission association table includes at least one candidate role and a data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of data that the candidate role is allowed to acquire; According to the target data acquisition type, target business data corresponding to the target business is determined.

2. The method according to claim 1, characterized in that After determining the target business corresponding to the target object, it also includes: Determining target object permissions of the target object according to the target business; Determine the target business data permission corresponding to the target object according to the preset permission mapping relationship and the target object permission; the permission mapping relationship is used to describe the corresponding relationship between the object permission and the business data permission; The target business data is determined according to the target business data authority.

3. The method according to claim 2, characterized in that Before determining the target object rights of the target object according to the target business, the method further includes: Determine the hierarchical relationship between each candidate; According to the superior-subordinate relationship, an object permission tree is established, and object permissions are granted to each node in the object permission tree; each node in the object permission book is a candidate object, and the parent node is the superior of the child node.

4. The method according to claim 3, characterized in that Before determining the target object rights of the target object according to the target business, the method further includes: At least one candidate business data is determined, and data authority is granted to each candidate business data.

5. The method according to claim 2, characterized in that: Determine the target business data according to the target business data authority, including: Determine the candidate business data permissions for each candidate business data; For each candidate business data, if the permission of the candidate business data is less than or equal to the permission of the target business data, the candidate business data is determined to be the permission of the target business data.

6. The method according to claim 1, characterized in that Determination of roles, including: determining at least one candidate business; At least one role is determined based on each candidate business.

7. A business data acquisition device, characterized in that: include: A target business determination module is used to determine the target business corresponding to the target object; The target business is the business processed by the target object; A target role determination module, used to determine at least one target role corresponding to the target object according to the target business; Roles are used to describe the roles that an object needs to play when processing business; An acquisition type determination module, used to determine the target data acquisition type corresponding to the target object according to a preset permission association table and each target role; The permission association table includes at least one candidate role and a data acquisition type corresponding to each candidate role; the data acquisition type is used to describe the data type of data that the candidate role is allowed to acquire; The business data acquisition module is used to determine the target business data corresponding to the target business according to the target data acquisition type.

8. The device according to claim 7, characterized in that After the target business determination module, it also includes: An object authority acquisition module, used to determine the target object authority of the target object according to the target business; A data authority determination module is used to determine the target business data authority corresponding to the target object according to a preset authority mapping relationship and the target object authority; the authority mapping relationship is used to describe the correspondence between the object authority and the business data authority; The target data determination module is used to determine the target business data according to the target business data authority.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the business data acquisition method according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the business data acquisition method according to any one of claims 1 to 6 when executed.