Authority management method, device and system and computer readable storage medium

By restricting the permission data rationally during the permission allocation stage, the problem that the permission management system in the existing technology cannot guarantee the rationality of permissions, and the efficiency and security of permission management are achieved.

CN120217326APending Publication Date: 2025-06-27NETSUNION CLEARING CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311810321.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The permission management system in the prior art cannot guarantee the rationality of the permissions between resources, roles and users, resulting in unqualified users or roles being assigned permissions, and the business system fails to cooperate with the audit system for permission auditing, resulting in the audit losing significance.

Method used

In the permission allocation stage, by obtaining permission requests, obtaining the requested permission data, and specifying the permission data according to the permission incompatibility policy, ensuring the rationality of the permission resources, thereby avoiding permission audits after the allocation is completed.

Benefits of technology

By placing reasonable restrictions in the permission allocation stage, we ensure the efficiency and security of permission management, and avoid the problem of non-standard permission allocation and audit failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217326A_ABST
    Figure CN120217326A_ABST
Patent Text Reader

Abstract

The invention discloses an authority management method, device and system and a computer readable storage medium. The method is executed by an authority management system and comprises the steps that an authority request is obtained, and the authority request is used for conducting specified operation on requested authority data; acquiring requested permission data according to the permission request, and performing specified operation on the requested permission data according to a permission incompatibility strategy to obtain an operation result; and generating a response corresponding to the permission request according to the operation result. According to the technical scheme, the reasonability of the permission resources can be limited in the operation stage of the permission data, permission auditing does not need to be carried out after permission allocation is finished, and therefore high efficiency and safety of permission management can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technologies, and in particular, to a method, apparatus, system, and computer-readable storage medium for privilege management. Background Art

[0002] With the rapid development of Internet technologies, most operations need to be completed with the help of software systems. When performing relevant business operations through software systems, it is necessary to review key business operations such as data security and business security. In the case of an increasingly complex enterprise personnel structure and system structure, the industry usually uses a privilege management system to manage privilege data.

[0003] Role Based Access Control (RBAC) is a privilege management mechanism that has been studied extensively and has a relatively mature concept in recent years. Its basic idea is to divide different roles according to different functional positions in the enterprise organizational view, encapsulate the access privileges of system resources in roles, and users indirectly access system resources by being assigned different roles.

[0004] It has been found that the privilege management systems in the prior art cannot ensure the rationality of privileges among resources, roles, and users. To address this problem, an audit system has been designed in the industry, that is, the privilege management system mainly performs privilege allocation, and the audit system mainly performs privilege auditing. The audit system audits whether the business operator and the auditor comply with the specifications.

[0005] It can be seen that the prior art moves the audit of normative conditions backward. Users or roles that do not comply with the specifications can be assigned privileges, but an error will be reported during execution. If the business system does not cooperate with the audit system to perform privilege auditing, the same person can perform operations and audits, and the audit loses its meaning. Summary of the Invention

[0006] The purpose of the embodiments of this application aims to at least solve one of the above technical defects, and particularly provides a method, apparatus, system, and computer-readable storage medium for privilege management to perform normative restrictions on the rationality of privileges during the privilege allocation stage, ensuring the efficiency and security of privilege management.

[0007] The embodiments of this application adopt the following technical solutions:

[0008] In a first aspect, the embodiments of this application provide a method for privilege management, which is executed by a privilege management system. The privilege management method includes:

[0009] Obtain a privilege request, where the privilege request is used to perform a specified operation on the requested privilege data;

[0010] Obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result;

[0011] Generate a response corresponding to the permission request according to the operation result.

[0012] In a second aspect, an embodiment of the present application further provides a permission management device, which is applied to a permission management system. The permission management device includes:

[0013] An acquisition unit, configured to acquire a permission request, where the permission request is used to perform a specified operation on the requested permission data;

[0014] A management unit, configured to obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result;

[0015] A response unit, configured to generate a response corresponding to the permission request according to the operation result.

[0016] In a third aspect, an embodiment of the present application further provides a permission management system, where the permission management system includes:

[0017] A memory, storing computer-executable instructions;

[0018] A processor, when the computer-executable instructions are executed, causes the processor to execute a permission management method.

[0019] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, where the computer-readable storage medium stores one or more programs, and when the one or more programs are executed by a permission management system including multiple application programs, the permission management system is caused to execute a permission management method.

[0020] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects:

[0021] When the requested permission data is obtained in the embodiment of the present application, a specified operation is performed on the requested permission data according to the permission incompatibility policy, so that the rationality of permission resources can be restricted during the operation stage of permission data, without the need to perform permission auditing after the permission allocation is completed, thereby ensuring the efficiency and security of permission management. Description of the Drawings

[0022] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0023] Figure 1 It is a flowchart of a permission management method shown in an embodiment of the present application;

[0024] Figure 2 It is a schematic structural diagram of a permission management device shown in an embodiment of the present application;

[0025] Figure 3 It is a schematic structural diagram of a permission management system shown in an embodiment of the present application. Detailed implementation manners

[0026] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0027] The technical solutions provided in each embodiment of the present application will be described in detail below in conjunction with the drawings.

[0028] The embodiment of the present application provides a permission management method. As Figure 1 shown, a flowchart of a permission management method in an embodiment of the present application is provided. The permission management method at least includes the following steps S110 to step S130:

[0029] Step S110, obtain a permission request, where the permission request is used to perform a specified operation on the requested permission data.

[0030] The permission management method of the embodiments of the present application is executed by a permission management system. The permission management system is a system based on the RBAC mechanism, which abstracts the member objects in permission management into three entities: users, roles, and resources. Among them, resources can be understood as the objects to which permissions are applied. For a certain business system, the resources are specifically the permission functions of the business system. Taking a software system as an example, from the perspective of data usage, resources may include configuration resources, query resources, audit resources, etc.; from the perspective of data display, for example, in a business view, resources usually show a tree structure, usually including system-level resources, menu-level resources, and button-level resources. Users can be understood as the owners of permissions, and can be personnel such as institutional administrators, institutional leaders, and institutional members. For roles, on the one hand, it can be understood as relatively stable powers in permission management or different roles divided according to responsibility functions. Each role can perform certain functions, and roles are directly associated with functions. Each role may be associated with multiple functions; on the other hand, a role is a set of permissions, and a role is associated with at least one resource. Specifically, a role is a bridge between users and resources, and a user can obtain the permissions of all resources under a certain role by possessing that role.

[0031] According to the above three entities involved in the permission management system, the permission data of the embodiments of the present application includes the data corresponding to each entity, that is, the permission data includes at least user data, role data, and resource data. Among them, user data may include user attribute data, and user attribute data is used to create user data, such as including user personal information such as user name, gender, and age. Role data may include role attribute data, and role attribute data is used to create role data, such as including role codes (role codes are unique in the system and are generally strings composed of English, numbers, and symbols), role names, role descriptions, and other data. Resource data includes resource attribute data, and resource attribute data is used to create resource data, and may include resource codes, resource names, resource types, and resource descriptions.

[0032] In addition, a permission request may be a request for a specified operation on permission data issued by a target object. The target object may be a user, intelligent machine management, or a developer, etc. The permission data may be data in a database, such as user data in a user database, role data in a role database, or resource data in a resource database. The permission request may be a data query request for querying the database, or a data deletion request for deleting the database. Of course, the permission request may also be any request for permission management such as a data modification request or a data creation request. The embodiments of the present application do not make special limitations on this.

[0033] Step S120, obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result.

[0034] The privilege incompatibility policy in the embodiments of the present application means that mutually exclusive resources cannot be allocated to the same user or the same role, and mutually exclusive roles cannot be allocated to the same user. For example, in some scenarios, the operation privilege and the approval privilege are mutually exclusive resources. In practical applications, it is possible to determine whether there is a mutually exclusive relationship between resources according to business specifications.

[0035] When receiving a privilege request for performing a specified operation on privilege data sent by a target object, the requested privilege data can be obtained according to the privilege request, and then the specified operation is performed on the privilege data according to the privilege incompatibility policy. If a situation of resource mutual exclusion or role mutual exclusion occurs during the process of performing the specified operation on the privilege data, or if there is resource mutual exclusion or role mutual exclusion in the privilege data after the operation, the privilege management system generates an operation failure result; otherwise, an operation success result is generated.

[0036] Step S130: Generate a response corresponding to the privilege request according to the operation result.

[0037] After obtaining the operation result through the foregoing steps, a response corresponding to the operation result can be generated. By feeding back the response to the target object, the target object can learn about the processing situation of the requested privilege data.

[0038] As Figure 1 It can be seen from the privilege management method shown that in the embodiments of the present application, when the requested privilege data is obtained, the specified operation is performed on the requested privilege data according to the privilege incompatibility policy. In this way, the rationality of privilege resources can be restricted during the operation stage of the privilege data, and there is no need to perform privilege auditing after the privilege allocation is completed, thereby ensuring the efficiency and security of privilege management.

[0039] As described above, the privilege data in the embodiments of the present application includes resource data, role data, and user data. The following separately introduces the specific implementation steps of performing a specified operation on each type of privilege data according to the privilege incompatibility policy.

[0040] 1) The requested privilege data is resource data

[0041] In some embodiments of the present application, when the requested privilege data is resource data, the specific steps of performing the specified operation on the requested privilege data according to the privilege incompatibility policy in step S120 above include:

[0042] Determine the resource type of the requested resource data;

[0043] According to the resource type and the privilege incompatibility policy, perform resource incompatibility configuration on the requested resource data.

[0044] As described above, in terms of data usage, the resource types in the embodiments of the present application include, for example, configuration resources, query resources, and audit resources. Configuration resources refer to resources related to the operation policies of system functions, which generally need to be configured manually. For example, they include configurations such as instruction triggering, addition, modification, deletion, enabling, and disabling. Query resources are mainly used to query certain configurations, such as viewing system configurations, system records, etc. Audit resources are mainly used to audit configuration operations to ensure the correctness and compliance of configuration operations. Of course, in actual application scenarios, corresponding resource types can be set for the permission resources of the system according to business requirements, and the present application does not make special restrictions on this.

[0045] When it is necessary to create resource data or modify existing resource data, the target object can edit a resource data creation request or a resource data modification request through the permission management interface provided by the permission management system and running on the terminal device, so that the edited request carries resource attribute data and sends it to the server of the permission management system. In this way, the server of the permission management system can obtain the resource attribute data according to the resource data creation request, create new resource data based on the resource attribute data, or obtain the resource attribute data according to the resource data modification request, and modify the resource data to be modified in the resource database based on the resource attribute data.

[0046] Taking the creation of new resource data as an example, the resource data creation request carries resource attribute data. First, the resource type is set for the new resource data according to the resource type in the resource attribute data, and then, based on the resource type and the permission incompatibility policy, resource incompatibility configuration is performed on the new resource data.

[0047] In some possible application scenarios of this embodiment, performing resource incompatibility configuration on the requested resource data according to the resource type and the permission incompatibility policy specifically includes:

[0048] Determine whether the resource type is a preset resource type;

[0049] If it is a preset resource type, then configure incompatible resource attributes for the requested resource data;

[0050] If it is not a preset resource type, then configure incompatible resource attributes for the requested resource data or do not configure incompatible resource attributes for the requested resource data.

[0051] From the perspective of the rationality of permissions among resources, roles, and users, for example, some business regulations stipulate that the resource operation behavior and review behavior of certain resources should not be performed by the same user. Accordingly, the configuration - type resources directly associated with the resource operation behavior can be regarded as the preset resource type, and the review - type resources directly associated with the review behavior can be regarded as the incompatible resource attributes of the configuration - type resources. Then, when the requested resource data is a configuration - type resource, the incompatible resource attribute can be forcibly set for this resource data, and the review - type resources mutually exclusive to this resource data can be used as the values of the incompatible resource attributes. At this time, the resource attribute data of the requested resource data includes the incompatible resource attribute. When the requested resource data is not a configuration - type resource, such as a query - type resource or a review - type resource, the incompatible resource attribute can be used as an optional attribute, that is, it can be determined according to the actual business situation whether to set the incompatible resource attribute for the query - type resource or the review - type resource. When it can be determined according to the actual business situation that there are incompatible resources for the query - type resource or the review - type resource, the incompatible resources can be set for the query - type resource or the review - type resource at this time. When it can be determined according to the actual business situation that there are no incompatible resources for the query - type resource or the review - type resource, there is no need to set the incompatible resource attribute for the query - type resource or the review - type resource at this time. In this way, the permission management system can quickly detect whether incompatible resources are assigned to a role or a user by restricting the most basic data (i.e., resource data).

[0052] It should be noted that in the actual application scenario, when configuring incompatible resources for the resource data of the preset resource type, one resource data can correspond to more than one incompatible resource. For example, when a certain operation of the resource data may require multi - step review or multi - department collaborative review, the incompatible resources of this resource data are multiple at this time.

[0053] Specifically, in some possible implementation solutions of this application scenario, if it is a preset resource type, configuring the incompatible resource attribute for the requested resource data specifically includes:

[0054] If the requested resource data is a configuration - type resource, obtain the incompatible resource data of the resource data from the review - type resources. Specifically, all review - type resources mutually exclusive to the resource data are used as the incompatible resource data;

[0055] Configure the incompatible resource attribute for the requested resource data according to the obtained incompatible resource data.

[0056] It should be noted that an implementation manner of resource incompatible configuration for resource data is shown in an embodiment of the present application. In other embodiments of the present application, when the requested resource data is a preset resource type, an association relationship can also be established between the resource data and its incompatible resource data. When the requested resource data is not a preset resource type, there is no such association relationship for the resource data. In this way, it is possible to determine whether the resource data has incompatible resources by whether there is an association relationship for the resource data.

[0057] After the creation of new resource data or the modification of existing resource data is completed, the permission management system generates a result indicating that the data creation or modification is successful, and generates a corresponding response based on the result of the data creation or modification success and feeds it back to the permission management interface at the front end of the permission management system. In this way, the target object can obtain the operation result of the current resource data according to the response fed back by the permission management system.

[0058] The method for managing resource data in the above embodiments of the present application can be applied to the transformation of existing resource databases (or resource data sets), and is also applicable to the construction of new resource databases (resource data sets). Adding incompatible resource attributes to the configuration type resource data in the resource database (or resource data set) can prevent the possibility of the same person operating and the same person auditing from the data source.

[0059] 2) The requested permission data is role data

[0060] In some embodiments of the present application, when the requested permission data is role data, the above step S120 performs a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result, which specifically includes:

[0061] Obtain all the resource data associated with the requested role data;

[0062] Perform resource incompatibility detection on all the resource data to obtain a detection result, where the detection result includes resource compatibility or resource incompatibility;

[0063] If the detection result is resource compatibility, the operation result is operation success; if the detection result is resource incompatibility, the operation result is operation failure.

[0064] When it is necessary to create character data or modify existing character data, the target object can edit a character data creation request or a character data modification request through a permission management interface running on a terminal device, so that the edited request carries character attribute data and is sent to the server of the permission management system. In this way, the server of the permission management system can obtain the character attribute data according to the character data creation request, create new character data according to the character attribute data, or obtain the character attribute data according to the character data modification request, and modify the character data to be modified in the character database according to the character attribute data.

[0065] Taking the creation of new character data as an example, the character data creation request carries character attribute data. All resource data associated with the character data can be obtained according to the character description in the character attribute data, and then it is judged whether there are incompatible resources among all the associated resource data. If the relationship between two resource data is mutually exclusive, the detection result is that the resources are incompatible. If the relationship between any two resource data is not mutually exclusive, the detection result is that the resources are compatible.

[0066] In some possible implementation solutions of this embodiment, performing a resource incompatibility detection on all the resource data to obtain a detection result specifically includes:

[0067] Obtaining target resource data with incompatible resource attributes according to the resource attribute data of the resource data;

[0068] Performing a matching detection on the target resource data and all the resource data. If the matching is successful, a detection result of resource incompatibility is obtained. If the matching is unsuccessful, a detection result of resource compatibility is obtained.

[0069] In some embodiments of the present application, when the obtained detection result is that the resources are compatible, the method further includes:

[0070] Setting an incompatible role identifier for the character data.

[0071] In practical applications, there may be a situation of role mutual exclusion between certain roles. Role mutual exclusion may include the following three situations:

[0072] The first situation is that the functions associated with the role are mutually exclusive;

[0073] The second situation is that the resources associated with the role are mutually exclusive;

[0074] The third situation is that the functions associated with the role are mutually exclusive, and the resources associated with the role are also mutually exclusive.

[0075] To avoid assigning role data with mutually exclusive relationships to the same user, in this embodiment, when it is determined that the relationship between all resource data associated with the role data is not mutually exclusive, an incompatible role identifier is further set for the role data. For example, it can be pre-agreed that incompatible roles have the same identifier. Then, when a user applies for role data, if the two applied roles have the same incompatible role identifier, the application will not be approved. In this way, the rationality and compliance of permission allocation can be further ensured.

[0076] The method for managing role data in the above embodiments of this application can be applied to the transformation of existing role databases (or role data sets), and is also applicable to the construction of new role databases (role data sets). On the one hand, it can perform permission rationality detection on the resource data associated with role data, and ensure the rationality and compliance of role permissions during the permission allocation process; on the other hand, adding an incompatible role identifier to role data can further ensure the rationality and compliance of role permissions.

[0077] 3) The requested permission data is user data

[0078] In some embodiments of this application, when the requested permission data is user data, the above step S120 performs a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result, specifically including:

[0079] Obtain all role data associated with the requested user data and the resource data associated with each role data;

[0080] Perform an incompatibility detection on the all role data and the all resource data to obtain a detection result, where the detection result includes compatibility or incompatibility between data;

[0081] If the detection result is compatibility between data, the operation result is operation success; if the detection result is incompatibility between data, the operation result is operation failure.

[0082] When it is necessary to create user data or modify existing user data, the target object can edit a user data creation request or a user data modification request through the permission management interface running on the terminal device, and send the edited request to the server of the permission management system. In this way, the server of the permission management system can apply for role data for the new user data according to the user data creation request, or modify the roles of the user data to be modified in the user database according to the user data modification request.

[0083] For creating new user data, the user data creation request is used to apply for new role data for the user data, and determine whether there is a role incompatibility between the applied role data and the role data already associated with the user data, or whether there is a resource incompatibility between the resource data associated with the applied role data and the resource data already associated with the user data. If there is a role incompatibility and / or a resource incompatibility, the detection result is data incompatibility; otherwise, the detection result is data compatibility.

[0084] In some possible implementation solutions of this embodiment, incompatibility detection is performed on all the role data and all the resource data to obtain a detection result, which specifically includes:

[0085] Obtain target role data with incompatible role identifiers, and determine whether there are incompatible roles between the target role data according to the incompatible role identifiers. If there are incompatible roles, the detection result is data incompatibility; otherwise, further obtain target resource data with incompatible resource attributes, and perform a matching detection on the target resource data and all the resource data. If the matching is successful, the detection result is data incompatibility; if the matching is not successful, the detection result is data compatibility.

[0086] When the detection result is data incompatibility, generate a response indicating operation failure; when the detection result is data compatibility, generate a response indicating operation success, so that the target object can determine whether the operation on the user data is successful according to the response feedback by the permission management system.

[0087] As can be seen from the above embodiments of this application, the permission management method of this application can constrain the created role data and user data during the permission allocation phase. For example, it is not allowed to create role data with incompatible resources, and applications for user data with incompatible roles or incompatible resources are not approved. The permission management system can constrain operations that do not conform to business specifications or are unreasonable, improving the permission management efficiency of the permission management system, and can provide assistance to the business system to facilitate self-inspection and self-examination of the permissions of the business system.

[0088] This application embodiment also provides a permission management device, as Figure 2 shown, which provides a structural schematic diagram of a permission management device in this application embodiment. The permission management device 200 of this embodiment is applied to a permission management system. The permission management device 200 includes an acquisition unit 210, a management unit 220, and a response unit 230;

[0089] The acquisition unit 210 is configured to acquire a permission request, and the permission request is used to perform a specified operation on the requested permission data;

[0090] The management unit 220 is configured to obtain the requested permission data according to the permission request, and perform specified operations on the requested permission data according to the permission incompatibility policy to obtain an operation result;

[0091] The response unit 230 is configured to generate a response corresponding to the permission request according to the operation result.

[0092] In some embodiments of the present application, the requested permission data includes resource data. The management unit 220 is specifically configured to determine the resource type of the requested resource data; according to the resource type and the permission incompatibility policy, perform resource incompatibility configuration on the requested resource data.

[0093] In some embodiments of the present application, the management unit 220 is further specifically configured to determine whether the resource type is a preset resource type; if it is a preset resource type, configure an incompatible resource attribute for the requested resource data; if it is not a preset resource type, configure an incompatible resource attribute for the requested resource data or not configure an incompatible resource attribute for the requested resource data.

[0094] In some embodiments of the present application, the resource type includes configuration resources, query resources, and audit resources. The preset resource type is configuration resources. The management unit 220 is further specifically configured to, if the requested resource data is configuration resources, obtain the incompatible resource data of the resource data from the audit resources; configure an incompatible resource attribute for the requested resource data according to the obtained incompatible resource data.

[0095] In some embodiments of the present application, the requested permission data includes role data. The management unit 220 is specifically configured to obtain all the resource data associated with the requested role data; perform resource incompatibility detection on the all resource data to obtain a detection result, where the detection result includes resource compatibility or resource incompatibility; if the detection result is resource compatibility, the operation result is operation success; if the detection result is resource incompatibility, the operation result is operation failure.

[0096] In some embodiments of the present application, the management unit 220 is further configured to set an incompatible role identifier for the role data when the obtained detection result is resource compatibility.

[0097] In some embodiments of the present application, the requested permission data includes user data. The management unit 220 is specifically configured to obtain all role data associated with the requested user data and resource data associated with each role data; perform an incompatibility detection on the all role data and the all resource data to obtain a detection result, where the detection result includes compatibility or incompatibility between the data; if the detection result is compatibility between the data, the operation result is successful; if the detection result is incompatibility between the data, the operation result is failed.

[0098] It can be understood that the above permission management device can implement each step of the permission management method provided in the foregoing embodiments. The relevant explanations of the permission management method are applicable to the permission management device and will not be elaborated herein.

[0099] Figure 3 is a schematic structural diagram of a permission management system in an embodiment of the present application. Please refer to Figure 3 , at the hardware level, the permission management system includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (Random-Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory, etc. Of course, the permission management system may also include other hardware required for other services.

[0100] The processor, network interface, and memory can be interconnected through an internal bus, and the internal bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 3 only a bidirectional arrow is used in

[0101] The memory is used to store programs. Specifically, the program may include program codes, and the program codes include computer operation instructions. The memory may include a memory and a non-volatile memory, and provide instructions and data to the processor.

[0102] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a permission management device at the logical level. The processor executes the program stored in the memory and executes the permission management method, specifically performing the following steps:

[0103] Obtain a permission request, where the permission request is used to perform a specified operation on the requested permission data;

[0104] Obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result;

[0105] Generate a response corresponding to the permission request according to the operation result.

[0106] The method executed by the permission management device disclosed in the above embodiments of the present application Figure 1 can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or by instructions in software form. The above processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being completed by the hardware decoding processor, or by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above permission management method.

[0107] The permission management system can also execute Figure 1 the method executed by the permission management device in Figure 1The functions of the embodiments shown are not elaborated in the embodiments of the present application herein.

[0108] The embodiments of the present application also propose a computer-readable storage medium that stores one or more programs. The one or more programs include instructions that, when executed by a permission management system including multiple application programs, can cause the permission management system to execute Figure 1 the method executed by the permission management device in the embodiments shown, and specifically execute the following steps:

[0109] Obtain a permission request, where the permission request is used to perform a specified operation on the requested permission data;

[0110] Obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result;

[0111] Generate a response corresponding to the permission request according to the operation result.

[0112] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0113] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the specified functions in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0114] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the specified functions in Figure 1 one or more flows and / or blocks Figure 1The functions specified in one or more boxes.

[0115] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in one Figure 1 one process or more processes and / or boxes Figure 1 step of the functions specified in one box or more boxes.

[0116] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0117] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.

[0118] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0119] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the said element.

[0120] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0121] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A permission management method, which is executed by a permission management system, wherein, The described permission management method includes: Obtaining a permission request, where the permission request is used to perform a specified operation on the requested permission data; Obtaining the requested permission data according to the permission request, and performing a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result; Generating a response corresponding to the permission request according to the operation result.

2. The privilege management method according to claim 1, wherein The requested permission data includes resource data. The performing a specified operation on the requested permission data according to the permission incompatibility policy includes: Determining the resource type of the requested resource data; Performing resource incompatibility configuration on the requested resource data according to the resource type and the permission incompatibility policy.

3. The permission management method according to claim 2, wherein, The performing resource incompatibility configuration on the requested resource data according to the resource type and the permission incompatibility policy includes: Determining whether the resource type is a preset resource type; If it is a preset resource type, then configuring incompatible resource attributes for the requested resource data; If it is not a preset resource type, then configuring incompatible resource attributes for the requested resource data or not configuring incompatible resource attributes for the requested resource data.

4. The permission management method according to claim 3, wherein, The resource type includes configuration type resources, query type resources, and audit type resources. The preset resource type is configuration type resources. The if it is a preset resource type, then configuring incompatible resource attributes for the requested resource data includes: If the requested resource data is a configuration type resource, then obtaining the incompatible resource data of the resource data from the audit type resources; Configuring incompatible resource attributes for the requested resource data according to the obtained incompatible resource data.

5. The privilege management method according to claim 1, wherein, The requested permission data includes role data. The performing a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result includes: Obtaining all the resource data associated with the requested role data; Performing resource incompatibility detection on all the resource data to obtain a detection result, where the detection result includes resource compatibility or resource incompatibility; If the detection result is resource compatibility, then the operation result is operation success; if the detection result is resource incompatibility, then the operation result is operation failure.

6. The privilege management method according to claim 5, wherein, When the obtained detection result is resource compatibility, the method further includes: Setting an incompatible role identifier for the role data.

7. The privilege management method according to claim 1, wherein The requested permission data includes user data. The performing a specified operation on the requested permission data according to the permission incompatibility policy to obtain an operation result includes: Obtaining all the role data associated with the requested user data and the resource data associated with each role data; Performing incompatibility detection on all the role data and all the resource data to obtain a detection result, where the detection result includes data compatibility or data incompatibility; If the detection result is data compatibility, then the operation result is operation success; if the detection result is data incompatibility, then the operation result is operation failure.

8. A permission management device, which is applied to a permission management system, wherein, The permission management device includes: An obtaining unit, configured to obtain a permission request, where the permission request is used to perform a specified operation on the requested permission data; A management unit, configured to obtain the requested permission data according to the permission request, and perform a specified operation on the requested permission data according to a permission incompatibility policy to obtain an operation result; A response unit, configured to generate a response corresponding to the permission request according to the operation result.

9. A permission management system, wherein, The permission management system includes: A memory, storing computer-executable instructions; A processor, when the computer-executable instructions are executed, causing the processor to execute the permission management method according to any one of claims 1 to 7.

10. A computer-readable storage medium, the computer-readable storage medium storing one or more programs, which when executed by a permission management system including a plurality of application programs, cause the permission management system to execute the permission management method according to any one of claims 1 to 7.