Permission data access method and device, electronic equipment and storage medium
By partitioning the cache area and dividing the permission data into different cache partitions, the problem of low response speed of permission data query in high concurrency scenarios is solved, and more efficient query efficiency and response speed are achieved.
Patent Information
- Application Number
- CN202510373007.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-06-27
AI Technical Summary
In high concurrency scenarios, existing permission data query systems are difficult to effectively improve response speed, and the full matching and query efficiency of the cache area is low.
By partitioning the cache area, multiple cache partitions are formed, and the permission data is divided into different cache partitions according to the partition rules. Then, when querying, the target cache partition is first positioned, and then a separate query is conducted to avoid full matching of all cache areas.
Reduce the number of data queries, improve the request response speed in high concurrent query scenarios, and improve query efficiency and system reliability.
Smart Images

Figure CN120216557A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of permission data management, and in particular, to a method, apparatus, electronic device, and storage medium for accessing permission data. Background Art
[0002] Permission data refers to data resources that users can access and operate on, such as a specific data table, data field, file, etc. Permission data ensures the security and compliance of data resources. By managing permission data, it is possible to better control users' access to and operations on data resources, further restricting the data scope that users can access and ensuring the accuracy and security of data usage. Summary of the Invention
[0003] This application provides a method, apparatus, electronic device, and storage medium for accessing permission data, which can achieve efficient query of permission data. The technical solution is as follows:
[0004] According to one aspect of this application, there is provided a method for accessing permission data, the method including:
[0005] When receiving an access request for the permission data of a target object, based on the access request, determining a target cache key to be queried;
[0006] Querying a target cache partition that matches the target cache key from multiple cache partitions;
[0007] If there is a target cache partition that matches the target cache key, based on the access request, searching for the target permission data corresponding to the target object in the target cache partition;
[0008] If there is no target cache partition that matches the target cache key, based on the access request, searching for the target permission data corresponding to the target object in a target database.
[0009] According to another aspect of this application, there is provided a permission data access apparatus, the apparatus including:
[0010] A first determination module, configured to, when receiving an access request for the permission data of a target object, based on the access request, determine a target cache key to be queried;
[0011] A first query module, configured to query a target cache partition that matches the target cache key from multiple cache partitions;
[0012] A second query module, configured to, if there is a target cache partition that matches the target cache key, based on the access request, search for the target permission data corresponding to the target object in the target cache partition;
[0013] A third query module, configured to, if there is no target cache partition that matches the target cache key, based on the access request, look up the target permission data corresponding to the target object in a target database.
[0014] According to one aspect of the present application, there is provided an electronic device, including: a processor and a memory storing a program, the program including instructions that, when executed by the processor, cause the processor to execute the permission data access method as described above.
[0015] According to another aspect of the present application, there is provided a non-transitory computer-readable storage medium storing computer instructions, the computer instructions being used to cause a computer to execute the permission data access method as described above.
[0016] According to another aspect of the present application, there is provided a computer program product, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned permission data access method.
[0017] The beneficial effects brought by the technical solution provided by the embodiments of the present application at least include:
[0018] By partitioning the buffer area to obtain multiple cache partitions, when caching permission data into the buffer area, different permission data will be divided into different cache partitions according to the partitioning rules, so that when querying later, the target cache partition where the permission data is cached can be located first according to the access request, and then a single target cache partition can be queried, without having to perform a full match and query on the entire buffer area, which can reduce the number of data queries and improve the request response speed in a high-concurrency query scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features, and advantages of the present application are disclosed. In the drawings:
[0020] Figure 1 A flowchart showing a method for accessing permission data according to an exemplary embodiment of the present application is shown;
[0021] Figure 2 A flowchart showing another method for accessing permission data according to an exemplary embodiment of the present application is shown;
[0022] Figure 3 A flowchart showing another method for accessing permission data according to an exemplary embodiment of the present application is shown;
[0023] Figure 4It is a schematic structural diagram of a permission data access device provided by an embodiment of the present application;
[0024] Figure 5 It shows a structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present application. Detailed implementation manners
[0025] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.
[0026] It should be understood that the steps recorded in the method embodiments of the present application can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this regard.
[0027] The term "including" and its variants used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions executed by these devices, modules or units or their interdependent relationships. It should be noted that the modifications of "one" and "multiple" mentioned in the present application are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly stated otherwise in the context, it should be understood as "one or more". The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0028] The solutions of the present application are described below with reference to the accompanying drawings. The technical solutions provided by the embodiments of the present application are described in detail through specific embodiments and their application scenarios.
[0029] When a user queries a certain resource or file, in order to ensure the data security of the resource or file, the permission data of the user will be queried first to determine whether the user has the permission to query the resource or file. If the user has the query permission, the queried resource or file will be fed back to the user; if the user does not have the query permission, the feedback of the queried resource or file will be refused. In an actual scenario, the query requests for permission data are often highly concurrent, and there are also requirements for the response speed of permission query requests. Therefore, how to improve the reliability and response speed of the permission query system in a highly concurrent scenario is an urgent problem to be solved.
[0030] Please refer to Figure 1 , which shows a flowchart of a method for accessing permission data according to an exemplary embodiment of the present application. This method will be described by taking its application to a permission data management system as an example. As Figure 1 shown, the method includes:
[0031] Step 101, when receiving an access request for the permission data of a target object, based on the access request, determine a target cache key to be queried.
[0032] Among them, the permission data records the resource information that a specific user has permission for, and the permission type for this resource information. The resource information can be the file save path or the file itself, and the permission type can include read and / or write. Optionally, the permission data can also record the role of this specific user, for example, an administrator. Generally, the permission data needs to be stored in a persistent storage system, usually a relational database (such as MySQL or PostgreSQL) or a NoSQL database (such as Redis or Cassandra).
[0033] In a possible implementation, the permission data will first be stored in the target database. In order to facilitate the subsequent high-speed query of the permission data, the permission data will be cached from the target database to the buffer area of the device in advance, so that after receiving an access request for the permission data, the permission data can be directly queried from the buffer area, omitting the steps of finding the permission data from the target database and then caching the permission data from the target database to the buffer area, thereby improving the response speed of the access request.
[0034] By caching permission data in the buffer in advance and directly querying the permission data from the buffer, although the response speed can be accelerated by reducing the caching steps, full matching and full query of the buffer will still greatly affect the query efficiency and response speed in the scenario of high-speed concurrent access requests. To further improve the query efficiency and response speed, the embodiments of the present application partition the buffer to obtain multiple cache partitions, and set partition keys for each cache partition. When caching permission data in the buffer, different permission data will be divided into different cache partitions according to the partitioning rules, so that when querying later, the cache partition where the permission data is cached can be determined first, and then a single cache partition can be queried, which can reduce the number of query matches and accelerate the query efficiency.
[0035] In order to determine the cache partition to be queried according to the access request after receiving the access request for the permission data, the setting rule or partitioning rule of the partition key of the cache partition can be determined by the object identifier or resource identifier. For example, cache partition 1 is used to cache permission data with a user identifier starting with 123, and cache partition 2 is used to cache permission data with a resource identifier starting with files. In a possible implementation manner, in the case of receiving an access request for the permission data of the target object, the target cache key to be queried can be determined based on the information in the access request, and then a single target cache partition can be located according to the target cache key.
[0036] Step 102, query the target cache partition that matches the target cache key from multiple cache partitions.
[0037] After determining the target cache key, the target cache partition that matches the target cache key can be queried from multiple cache partitions, that is, it is determined whether there is a target cache partition in the buffer that stores the permission data indicated by the access request.
[0038] Step 103, if there is a target cache partition that matches the target cache key, based on the access request, find the target permission data corresponding to the target object from the target cache partition.
[0039] If there is a target cache partition that matches the target cache key, it means that the target cache partition in the buffer stores the accessed permission data. The single target cache partition can be directly located, and only the target cache partition is searched based on the access request to obtain the target permission data corresponding to the target object, without performing full matching and query on the entire buffer, which can reduce the number of data queries and improve the request response speed in the high-concurrency query scenario.
[0040] Step 104, if there is no target cache partition that matches the target cache key, based on the access request, find the target permission data corresponding to the target object from the target database.
[0041] If there is no target cache partition that matches the target cache key, it means that the permission data has not been cached in the cache area. It is necessary to search for the target permission data corresponding to the target object from the target database based on the access request. After the target permission data is found, it is also necessary to load the target permission data into the corresponding target cache partition, and then verify the access request based on the target permission data.
[0042] In summary, the embodiment of the present application provides a method for accessing permission data: by partitioning the cache area, multiple cache partitions are obtained. When caching permission data into the cache area, different permission data will be divided into different cache partitions according to the partitioning rules, so that when querying later, the target cache partition where the permission data is cached can be located first according to the access request, and then a single target cache partition can be queried, without having to perform a full-scale matching and query on the entire cache area, which can reduce the number of data queries and improve the request response speed in a high-concurrency query scenario.
[0043] When partitioning the cache area, there are two partitioning methods. One is to partition according to the object identifier, for example, the user ID, and the other is to partition according to the resource identifier, for example, the file storage path. Correspondingly, when locating the target cache partition where the target permission data is stored, the target cache key can be determined according to the object identifier or resource identifier carried in the access request.
[0044] Please refer to Figure 2 , which shows a flowchart of another method for accessing permission data according to an exemplary embodiment of the present application. This method will be described by taking its application to a permission data management system as an example. As Figure 2 shown, this method includes:
[0045] Step 201, determine the partition keys of multiple cache partitions based on multiple object identifiers or multiple resource identifiers.
[0046] In a possible implementation, after dividing the cache area into multiple cache partitions, the hash value of the object identifier (for example, the user ID) or resource identifier (resource path) can be selected as the partition key of each cache partition, and the permission data is sliced according to the partition key to initially design the cache structure of the cache area. Step 202, in the case of receiving an access request for the permission data of the target object, if the access request carries the object identifier of the target object, determine the target cache key to be queried based on the object identifier.
[0047] When receiving an access request for the permission data of a target object, the information carried in the access request can be obtained. If the object identifier of the target object is carried in the access request, the target cache key to be queried can be determined based on the hash value of the object identifier. Whether the object identifier or the resource identifier is carried in the access request is determined by different application scenarios. For example, if all permissions of a certain object need to be queried, the object identifier of the object is carried in the access request; if it is necessary to query whether a certain object has permissions for a specific resource, the resource identifier of the specific resource will be carried in the access request.
[0048] Step 202, when receiving an access request for the permission data of a target object, if the object identifier of the target object is carried in the access request, determine the target cache key to be queried based on the object identifier.
[0049] When receiving an access request for the permission data of a target object, the target cache key to be queried can be determined based on the information carried in the access request. If the object identifier of the target object is carried in the access request, the target cache key to be queried can be determined based on the hash value of the object identifier.
[0050] Step 203, when receiving an access request for the permission data of a target object, if the resource identifier of the resource to be viewed by the target object is carried in the access request, determine the target cache key to be queried based on the resource identifier.
[0051] Optionally, if the resource identifier of the resource to be viewed by the target object is carried in the access request, the target cache key to be queried can be determined based on the hash value of the resource identifier.
[0052] Step 204, determine the cache partition corresponding to the target partition key that matches the target cache key as the target cache partition.
[0053] After determining the target cache key, since the partition keys of each cache partition are also determined by the object identifier or the resource identifier, the cache partition corresponding to the target partition key that matches the target cache key can be determined as the target cache partition.
[0054] Step 205, if there is a target cache partition that matches the target cache key and the object identifier of the target object is carried in the access request, search for the target permission data corresponding to the target object in the target cache partition based on the object identifier.
[0055] Since the information carried in the access request is different, after determining that there is a target cache partition that matches the target cache key, the query key used to search for the target permission data in the target cache partition is also different. Specifically, if the object identifier of the target object is carried in the access request, directly search for the target permission data that matches the object identifier in the target cache partition according to the object identifier.
[0056] Step 206, if there is a target cache partition that matches the target cache key and the resource identifier of the resource to be viewed by the target object is carried in the access request, based on the resource identifier, search for the target permission data corresponding to the target object in the target cache partition.
[0057] If the resource identifier of the resource to be viewed by the target object is carried in the access request, then based on the resource identifier, search for the target permission data that matches the resource identifier in the target cache partition to determine whether the target object is included in the target permission data. If it is included, it means that the target object has access permission to the resource to be viewed.
[0058] Optionally, if there is no target cache partition that matches the target cache key, based on the access request, search for the target permission data corresponding to the target object in the target database.
[0059] If there is no target partition key that matches the target cache key, that is, the target permission data has not been cached to the target cache partition yet, it is necessary to directly search for the target permission data that matches the object identifier in the target database according to the object identifier or resource identifier carried in the access request, or search for the target permission data that matches the resource identifier in the target database.
[0060] Optionally, after querying the target permission data from the target database, it is also necessary to determine the target cache key based on the hash value of the object identifier or resource identifier, so as to load the target permission data into the target cache partition corresponding to the target partition key that matches the target cache key.
[0061] In this embodiment, by presetting the relationship between the partition keys of each cache partition and the object identifier or resource identifier carried in the access request, after receiving the access request, the target cache partition can be located according to the object identifier or resource identifier carried in the access request, so as to achieve fast query of the cache area.
[0062] Since the cache partitions are pre-divided according to experience, in the actual caching and querying process, there may be more or less data cached in some cache partitions, or the access volume of the cache partitions is large, thus affecting the query speed or query performance of the cache partitions. In order to make the division of the cache partitions more suitable for the actual caching and querying requirements, this embodiment also provides a way to dynamically adjust the cache partitions.
[0063] Please refer to Figure 3 , which shows a flowchart of another method for accessing permission data according to an exemplary embodiment of the present application. This method is described by taking its application to a permission data management system as an example. As Figure 3 shown, this method includes:
[0064] Step 301: Obtain the partition status information of multiple cache partitions. The partition status information includes the amount of cached data, the number of access requests, and the request response time for each cache partition.
[0065] In a possible implementation, during the actual caching and querying process, the device can collect the partition status information of each cache partition in real time. For example, the amount of cached data, the number of access requests, and the request response time (or the range of request response times) for each cache partition, so as to determine whether it is necessary to adjust the existing multiple cache partitions based on this partition status information and how to adjust.
[0066] Step 302: Dynamically adjust multiple cache partitions based on the partition status information.
[0067] If the amount of cached data indicates that the data volume of a certain cache partition is too large, this may lead to a decline in the access performance of accessing this cache partition; if the amount of cached data indicates that the data volume of a certain cache partition is too small, this may lead to a waste of cache resources in the cache partition. In both cases, it is necessary to dynamically adjust multiple cache partitions based on the partition status information to balance each cache partition.
[0068] When dynamically adjusting cache partitions, there are mainly two adjustment methods according to the partition status information. One is to merge partitions, corresponding to the case where the amount of cached data is relatively small, and the other is to split partitions, corresponding to the case where the amount of cached data is relatively large. Correspondingly, in an exemplary example, step 302 may include step 302A and step 302B.
[0069] Step 302A: If the amount of cached data of at least two cache partitions is lower than the first data volume threshold, perform a partition merging operation on the at least two cache partitions to obtain updated multiple cache partitions.
[0070] If the amount of cached data of at least two cache partitions is lower than the first data volume threshold, it means that the partition utilization rate of the at least two cache partitions is relatively low. To avoid wasting cache partition resources, the partition merging operation can be performed on multiple cache partitions with relatively small amounts of cached data to merge multiple cache partitions into a new cache partition, thereby increasing the amount of cached data in the new cache partition. After the partition merging, the number of cache partitions will be reduced to obtain updated multiple cache partitions.
[0071] Exemplarily, the first data volume threshold can be 50% of the cache partition capacity.
[0072] Optionally, after performing the partition merging operation, in order to avoid incorrect mapping relationships between the pre-established object identifiers or resource identifiers and their corresponding hash values and the partition keys, the mapping relationships are updated as follows: after performing the partition merging operation, obtain the first partition keys of at least two cache partitions before merging and the second partition key of the cache partition after merging, and set a target mapping relationship for the first partition keys and the second partition key, so that the hash values that were originally mapped to the cache partitions before merging can be mapped to the cache partition after merging according to this target mapping relationship, ensuring the normal operation of searching and caching after the cache partition is updated.
[0073] Step 302B, if the cached data volume of at least one cache partition is higher than the second data volume threshold, or if the access request volume of at least one cache partition is greater than the access volume threshold, or if the request response time of at least one cache partition is greater than the preset time threshold, perform a partition splitting operation on each of the at least one cache partition to obtain multiple updated cache partitions.
[0074] If the cached data volume of a cache partition is large, or the access request volume of the cache partition is too large, or the request response time of the cache partition is long, these problems will all affect the access performance of the cache partition. To improve the access performance of the cache partition, if the cached data volume of at least one cache partition is higher than the second data volume threshold, or if the access request volume of at least one cache partition is greater than the access volume threshold, or if the request response time of at least one cache partition is greater than the preset time threshold, perform a partition splitting operation on each of the at least one cache partition. After the partition splitting, the number of partitions of the cache partition can be increased, thus obtaining multiple updated cache partitions.
[0075] Exemplarily, the second data volume threshold can be 70% of the cache partition capacity; the access volume threshold can be 1000 times; the preset time threshold can be 2s.
[0076] Optionally, after the partition splitting operation, there are two partition splitting methods. One method will increase the number of cache partitions, and the other method will not increase the number of cache partitions. Specifically, if the cached data volume of at least one cache partition is higher than the second data volume threshold, perform a partition splitting operation on the cached data in each of the at least one cache partition to obtain multiple updated cache areas. That is to say, when the cached data volume in the cache partition is relatively large, the cached data volume exceeding the second data volume threshold can be divided into other existing cache partitions, so as to obtain multiple updated cache partitions. Exemplarily, if the original cache partitions are: cache partition A, cache partition B, and cache partition C, according to the first type of partition splitting judgment condition (the cached data volume is greater than the second data volume threshold), it is determined that cache partition B needs to be split, and the cached data volume exceeding the second data volume threshold in cache partition B is divided into cache partition A and / or cache partition C.
[0077] Another situation is: if the access request volume of at least one cache partition is greater than the access volume threshold, or, if the request response time of at least one cache partition is greater than the preset time threshold, split each of the at least one cache partition into multiple sub-cache partitions to obtain multiple updated cache partitions. That is to say, if the access performance of the existing cache partition is poor, directly split the existing cache partition into multiple sub-cache partitions, so as to obtain multiple updated cache partitions. Exemplarily, if the original cache partitions are: cache partition A, cache partition B, and cache partition C, according to the partition splitting judgment condition, it is determined that cache partition B needs to be split into cache partition B1, cache partition B2, and cache partition B3; then the multiple updated cache partitions are: cache partition A, cache partition B1, cache partition B2, cache partition B3, and cache partition C.
[0078] In this embodiment, by monitoring the partition status information of each cache partition, it is possible to timely determine whether there are problems with the existing cache partition division, and after meeting the preset partition merging conditions or partition splitting conditions, perform partition merging or partition splitting operations on the existing cache partitions, so as to dynamically adjust the number of cache partitions, so as to further ensure the access performance of the cache partitions on the basis of meeting fast query and caching.
[0079] Please refer to Figure 4 , which is a schematic structural diagram of a permission data access device provided by an embodiment of the present application. Exemplarily, as Figure 4 shown, the device 400 includes:
[0080] A first determination module 401, configured to determine a target cache key to be queried based on the access request when receiving an access request for permission data of a target object;
[0081] The first query module 402 is configured to query, from multiple cache partitions, a target cache partition that matches the target cache key;
[0082] The second query module 403 is configured to, if there is a target cache partition that matches the target cache key, based on the access request, find target permission data corresponding to the target object from the target cache partition;
[0083] The third query module 404 is configured to, if there is no target cache partition that matches the target cache key, based on the access request, find the target permission data corresponding to the target object from a target database.
[0084] Optionally, the first determination module 401 is further configured to:
[0085] If an object identifier of the target object is carried in the access request, based on the object identifier, determine the target cache key to be queried;
[0086] If a resource identifier of a resource to be viewed by the target object is carried in the access request, based on the resource identifier, determine the target cache key to be queried;
[0087] The second query module is further configured to:
[0088] If the object identifier of the target object is carried in the access request, based on the object identifier, find the target permission data corresponding to the target object from the target cache partition;
[0089] If the resource identifier of the resource to be viewed by the target object is carried in the access request, based on the resource identifier, find the target permission data corresponding to the target object from the target cache partition.
[0090] Optionally, the apparatus further includes:
[0091] A second determination module, configured to determine partition keys of the multiple cache partitions based on multiple object identifiers or multiple resource identifiers;
[0092] The first query module 402 is further configured to:
[0093] Determine, as the target cache partition, a cache partition corresponding to a target partition key that matches the target cache key.
[0094] Optionally, the apparatus further includes:
[0095] A first acquisition module, configured to acquire partition status information of the multiple cache partitions, where the partition status information includes the amount of cached data, the access request volume, and the request response time of each cache partition;
[0096] An adjustment module, configured to dynamically adjust the multiple cache partitions based on the partition status information.
[0097] Optionally, the adjustment module is further configured to:
[0098] If the amount of cached data of at least two cache partitions is lower than a first data volume threshold, perform a partition merging operation on the at least two cache partitions to obtain an updated multiple cache partitions;
[0099] If the amount of cached data of at least one cache partition is higher than a second data volume threshold, or, if the access request volume of the at least one cache partition is greater than an access volume threshold, or, if the request response time of the at least one cache partition is greater than a preset time threshold, perform a partition splitting operation on each of the at least one cache partitions to obtain the updated multiple cache partitions.
[0100] Optionally, the apparatus further includes:
[0101] A second acquisition module, configured to, after performing the partition merging operation, acquire a first partition key of the at least two cache partitions before merging and a second partition key of the merged cache partition;
[0102] A setting module, configured to set a target mapping relationship for the first partition key and the second partition key.
[0103] Optionally, the adjustment module is further configured to:
[0104] If the amount of cached data of the at least one cache partition is higher than the second data volume threshold, perform a partition splitting operation on the cached data in each of the at least one cache partitions to obtain the updated multiple cache partitions;
[0105] If the access request volume of the at least one cache partition is greater than the access volume threshold, or, if the request response time of the at least one cache partition is greater than the preset time threshold, split each of the at least one cache partitions into multiple sub-cache partitions to obtain the updated multiple cache partitions.
[0106] An exemplary embodiment of the present application further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the permission data access method according to the embodiment of the present application.
[0107] An exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the permission data access method according to the embodiment of the present application.
[0108] An exemplary embodiment of the present application further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the permission data access method according to the embodiment of the present application.
[0109] Referring to Figure 5 , a block diagram of an electronic device 500 that can be a server or a client of the present application will now be described. It is an example of a hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer devices, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described herein and / or claimed.
[0110] As Figure 5 shown, the electronic device 500 includes a computing unit 501, which can execute various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0111] Multiple components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, an output unit 507, a storage unit 508, and a communication unit 509. The input unit 506 can be any type of device capable of inputting information into the electronic device 500. The input unit 506 can receive input digital or character information and generate key signal inputs related to the user settings and / or function controls of the electronic device. The output unit 507 can be any type of device capable of presenting information and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 508 can include, but is not limited to, a magnetic disk and an optical disk. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0112] The computing unit 501 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above. For example, in some embodiments, Figure 1 , Figure 2 , Figure 3 the methods shown can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 500 via the ROM 502 and / or the communication unit 509. In some embodiments, the computing unit 501 can be configured to execute Figure 1 , Figure 2 , Figure 3 the methods shown in any other suitable manner (e.g., by means of firmware).
[0113] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when executed by the processor or controller, the program codes cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0114] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0115] As used in the present application, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., a disk, an optical disc, a memory, a programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0116] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0117] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0118] A computer system can include clients and servers. The clients and servers are generally far apart from each other and typically interact through a communication network. The client - server relationship is created by computer programs that run on the respective computers and have a client - server relationship with each other.
Claims
1. A method for accessing permission data, characterized in that: The method comprises: In case of receiving an access request to the permission data of the target object, determining the target cache key to be queried based on the access request; Querying a target cache partition matching the target cache key from multiple cache partitions; If the target cache partition matching the target cache key exists, based on the access request, searching the target cache partition for target permission data corresponding to the target object; If the target cache partition matching the target cache key does not exist, based on the access request, the target permission data corresponding to the target object is searched from the target database.
2. The method according to claim 1, characterized in that The determining, based on the access request, a target cache key to be queried includes: If the access request carries the object identifier of the target object, determining the target cache key to be queried based on the object identifier; If the access request carries a resource identifier of the target object to be viewed, based on the resource identifier, determining the target cache key to be queried; The step of searching the target permission data corresponding to the target object from the target cache partition based on the access request includes: If the access request carries the object identifier of the target object, searching the target permission data corresponding to the target object from the target cache partition based on the object identifier; If the access request carries the resource identifier of the target object to be viewed, the target permission data corresponding to the target object is searched from the target cache partition based on the resource identifier.
3. The method according to claim 2, characterized in that The method further comprises: Determining partition keys of the plurality of cache partitions based on a plurality of object identifiers or a plurality of resource identifiers; The step of querying a target cache partition matching the target cache key from multiple cache partitions includes: A cache partition corresponding to a target partition key matching the target cache key is determined as the target cache partition.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Acquire partition status information of the plurality of cache partitions, the partition status information including the amount of cached data, the amount of access requests, and the request response time of each of the cache partitions; Based on the partition status information, the multiple cache partitions are dynamically adjusted.
5. The method according to claim 4, characterized in that The dynamically adjusting the plurality of cache partitions based on the partition status information includes: If there are at least two cache partitions whose cached data amounts are lower than the first data amount threshold, performing a partition merging operation on the at least two cache partitions to obtain a plurality of updated cache partitions; If the cached data volume of at least one cache partition is higher than the second data volume threshold, or the access request volume of at least one cache partition is greater than the access volume threshold, or the request response time of at least one cache partition is greater than the preset time threshold, a partition splitting operation is performed on each of the at least one cache partition to obtain the updated multiple cache partitions.
6. The method according to claim 5, characterized in that The method further comprises: After performing the partition merging operation, obtaining the first partition key of the at least two cache partitions before merging, and the second partition key of the cache partition after merging; A target mapping relationship is set for the first partition key and the second partition key.
7. The method according to claim 5, characterized in that If the cached data amount of at least one cache partition is higher than the second data amount threshold, or the access request amount of at least one cache partition is greater than the access amount threshold, or the request response time of at least one cache partition is greater than the preset time threshold, a partition splitting operation is performed on each of the at least one cache partition to obtain the updated multiple cache partitions, including: If the cached data amount of the at least one cache partition is higher than the second data amount threshold, performing a partition splitting operation on the cached data in each of the at least one cache partition to obtain the updated multiple cache partitions; If the access request volume of at least one cache partition is greater than the access volume threshold, or the request response time of at least one cache partition is greater than the preset time threshold, each of the at least one cache partition is split into multiple sub-cache partitions to obtain the updated multiple cache partitions.
8. A permission data access device, characterized in that: The device comprises: A first determination module is used to determine a target cache key to be queried based on a request for accessing permission data of a target object when receiving the request; A first query module, configured to query a target cache partition matching the target cache key from multiple cache partitions; A second query module is configured to search the target permission data corresponding to the target object from the target cache partition based on the access request if there is a target cache partition matching the target cache key; The third query module is used to search the target permission data corresponding to the target object from the target database based on the access request if there is no target cache partition matching the target cache key.
9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, enable the processor to execute the permission data access method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable the computer to execute the rights data access method according to any one of claims 1-7.