Authority control method and device
By configuring the graph database access permissions on the ranger and converting them into permission management sub-map, the problem of low efficiency in permission control of graph databases is solved, and safe, reliable and flexible permission management is achieved.
Patent Information
- Application Number
- CN202510175912.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-07-04
AI Technical Summary
The existing graph database lacks flexibility and reliability in data security and permission control, while the traditional permission control is inefficient.
Configure user's graph database access permissions on ranger, generate access policies, and convert them into permission management subgraphs, and use the efficient query performance of graph database for permission authentication.
It improves the permission control efficiency of graph database and realizes safe, reliable and flexible permission management.
Smart Images

Figure CN120257310A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of graph databases, and particularly to a method and device for permission control. Background Art
[0002] A graph database is a database system specifically used for storing and querying graph data. The graph data model consists of entities (Nodes), edges (Edges), and attributes (Properties), and is very suitable for representing and processing complex relationships and connections. Graph databases have a wide range of applications in multiple fields. However, current graph databases do not have good functionality in terms of data security and permission control. Although it has a security control ability based on user passwords, the permission control corresponding to users is fixed in the configuration file, losing the convenient and flexible permission configuration management and the secure and reliable ability. Summary of the Invention
[0003] This application provides a method and device for permission control, which can improve the permission control efficiency of a graph database.
[0004] To achieve the above object, this application provides a method for permission control, which includes:
[0005] Configuring the graph database access permission of a user on ranger to obtain the access policy of the user;
[0006] Converting the access policy of the user into a permission management sub-graph of the user;
[0007] Performing permission authentication on the user based on the permission management sub-graph of the user.
[0008] To achieve the above object, this application also provides an electronic device, which includes a processor; the processor is used to execute instructions to implement the steps of the above method.
[0009] To achieve the above object, this application also provides a computer-readable storage medium, which is used to store instructions / program data, and the instructions / program data can be executed to implement the above method.
[0010] The permission control method of this application configures the access permissions of the graph database for users on Ranger to obtain the access policies of the users; converts the access policies of the users into the user's permission management sub-graphs and updates them into the permission management graph of the graph database; in response to the service requests of the users, performs permission authentication on the users based on the user's permission management sub-graphs. In this way, this application converts the permissions configured by Ranger into permission management sub-graphs, thereby converting the traditional authentication relationship into a graph relationship, so that the subsequent graph database can quickly perform permission authentication on the users by using the efficient graph query performance of itself, improving the permission control efficiency of the graph database, and thus achieving both the security and reliability of the system and its agility and flexibility. Brief Description of the Drawings
[0011] The drawings described herein are used to provide a further understanding of this application, form a part of this application, and the illustrative embodiments and descriptions thereof are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0012] Figure 1 is a schematic flowchart of an implementation manner of the permission control method of this application;
[0013] Figure 2 is a schematic diagram of the permission control method of this application;
[0014] Figure 3 is a schematic flowchart of another implementation manner of the permission control method of this application;
[0015] Figure 4 is a schematic flowchart of an embodiment of the permission control method of this application;
[0016] Figure 5 is a schematic implementation flowchart of an embodiment of the permission control method of this application;
[0017] Figure 6 is a schematic structural diagram of an implementation manner of the electronic device of this application;
[0018] Figure 7 is a schematic structural diagram of an implementation manner of the computer-readable storage medium of this application. Detailed Embodiments
[0019] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application. Additionally, unless otherwise specified (e.g., "or alternatively" or "or in an alternative"), the term "or" as used herein refers to a non-exclusive "or" (i.e., "and / or"). Moreover, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments.
[0020] In the related art, when a graph database is arranged in a Hadoop cluster, Ranger is introduced for permission control. However, the permission control method in this related technology is still the permission management method of traditional databases, with low permission control efficiency.
[0021] Based on this, the present application proposes a permission management method. This permission management method configures the access permissions of the graph database for users on Ranger to obtain the access policies of the users; converts the access policies of the users into the user's permission management sub-graphs and updates them into the permission management graph of the graph database; in response to the user's service request, authenticates the user based on the user's permission management sub-graphs. In this way, the present application converts the permissions configured on Ranger into permission management sub-graphs, thereby converting the traditional authentication relationship into a graph relationship, so that the subsequent graph database can use its own efficient graph query performance to quickly authenticate users using the permission management sub-graphs, improving the permission control efficiency of the graph database, and thus achieving both the security and reliability of the system and its agility and flexibility.
[0022] Specifically, as Figure 1 shown, a permission management method of an implementation manner proposed by the present application specifically includes the following steps. It should be noted that the following step numbers are only used for simplified description and are not intended to limit the execution order of the steps. Each step of this implementation manner can be arbitrarily changed in the execution order without violating the technical idea of the present application.
[0023] S101: Configure the access permissions of the graph database for users on Ranger to obtain the access policies of the users.
[0024] Optionally, the permission management method of the present application can, when a user registers, first configure the access permissions of the graph database for the user on Ranger to obtain the access policies of the user, so as to subsequently convert the access policies of the user into the user's permission management sub-graphs, and then directly use the user's permission management sub-graphs to authenticate the user during subsequent authentication to improve the permission control efficiency of the graph database.
[0025] Among them, the graph database access permission data of the user can be obtained from the Ranger component of the Hadoop cluster to obtain the access policy of the user.
[0026] Among them, for the graph database, the graph database access permission data of the user may include information about the graphs accessible to the user, and / or the operation permissions of the user for the accessible graphs, and / or the points, edges, and / or attributes accessible to the user for the accessible graphs, etc.
[0027] S102: Convert the access policy of the user into a user's permission management sub-graph.
[0028] After obtaining the access policy of the user, the access policy of the user can be converted into a user's permission management sub-graph.
[0029] In one implementation, when the user registers or the user's permission information is updated, the user configures the graph database access permission of the user through the Ranger component. After the configuration is completed, the access policy of the configured user can be obtained immediately. In this way, the configuration of the user's permission management sub-graph can be performed based on the access policy of the user obtained immediately.
[0030] Among them, by binding the traversal of the graph corresponding to the user, the access policy of the user can be updated to the permission management graph to update the user's permission management sub-graph in the permission management graph. Among them, the user's permission management sub-graph refers to the permission management content related to the user in the permission management graph, which can be independent (such as the sub-graph obtained by dividing the permission management graph), or non-independent (that is, the permission management graphs of multiple users can be integrated with each other). More preferably, the user's permission management sub-graph is independent. In this way, when performing permission authentication later, a graph query can be directly performed in the user's permission management sub-graph for permission authentication, so as to improve the permission authentication efficiency. As described above, the user's permission management sub-graph can be non-independent. In this way, when performing permission authentication later, a graph query can be performed on the permission management graph through a graph traversal statement, and the user can be authenticated for permission during the graph query process by querying the permission management content related to the user in the permission management graph.
[0031] In another implementation, the latest permission policy can be obtained from Ranger at preset intervals, and the configuration of the user's permission management sub-graph can be performed based on the obtained access policy of the user. Here, the preset interval can be set according to the actual situation and is not limited here. In a specific example, the JansGraphManager layer of the janusgraph server obtains the latest permission policy from the Ranger center every 10 seconds, binds the traversal of the graph corresponding to the user, and updates the permission policy to the permission management graph.
[0032] Among them, the user's permission management sub-graph is as Figure 2 shown, including user entities, business graph entities, permission management entities, and the edges between these entities. Among them, the grid-filled entity is the user entity, whose label T.label name can be user, and its attribute userName can be the user name (such as Li Si); among them, the horizontal-line-filled entity is the business graph entity; the T.label attribute represents the label name of the business graph entity, which can be graph; the attribute graphName represents the graph name; among them, the directed graph from the user to the access entities (business graph, business data point, business data edge, business data attribute) represents that the user has the right to access these permission entities, and the label name T.label of this permission authorization relationship is fixed as hasGrant, and the attribute readOnlyStrategy represents whether there is only read-only permission; among them, the gray part represents the permission management entity of the business point, and the entity label T.label name is fixed as vertex, and the attribute labelName represents what kind of business data point (such as Automobile in the following figure); similarly, in the permission management graph of business data edges and business data attributes, the corresponding entity label T.label names are fixed as edge and property respectively, and the attribute labelName represents what kind of business data edges and business data attributes. In short, a permission management graph represents that a certain user has the right to access certain business graphs, certain business points, certain business edges, and certain business attributes, so that business graphs, points, edges, attributes, etc. with high confidentiality can be managed, improving the data security of users.
[0033] Based on the above settings of the permission management sub-graph, during conversion, the points, edges, and their attributes in the permission management sub-graph can be set using each permission data information in the user's access policy to achieve the conversion from the user's access policy to the user's permission management sub-graph.
[0034] In a specific example, when a user first sets permissions through Ranger, information about the graphs accessible to the user in the access policy can be used to establish user entities and the edges between the user entities and the graph entities accessible to the user, and the attributes of the above edges can be set based on the user's operation permissions for the accessible graphs; edges can also be established between the user entity and the access entities such as point entities, edge entities, and / or attribute entities accessible to the user through the points, edges, and / or attributes accessible to the user in the access policy, and their edge attributes can be set.
[0035] In another specific example, when a user sets permissions through Ranger for non - the first time, or after the user sets permissions through Ranger for the first time and converts to generate a user permission management sub - graph, if it is necessary to update the user permission management sub - graph through the user's current access policy, the differences between the user's current access policy and the access policy corresponding to the current user permission management sub - graph can be determined, and then the current user permission management sub - graph can be updated based on these differences.
[0036] S103: Perform permission authentication on the user based on the user's permission management sub - graph.
[0037] After obtaining the user's permission management sub - graph by configuring the user's permissions based on the above steps, if a service request from the user is received, in response to the user's service request, permission authentication can be performed on the user based on the user's permission management sub - graph.
[0038] Optionally, the graph traversal statement of the graph database can be used to traverse the user's permission management sub - graph to query the specific permissions of the user on the graph currently accessed by the user; based on the specific permissions of the user on the graph currently accessed by the user, it is confirmed whether the user's service request exceeds the permissions. If it exceeds the permissions, the request is rejected; otherwise, the statement of the request is executed and the result is returned.
[0039] Among them, using the graph traversal statement of the graph database to traverse the user's permission management sub - graph to query the specific permissions of the user on the graph currently accessed by the user; and based on the specific permissions of the user on the graph currently accessed by the user to confirm whether the user's service request exceeds the permissions, these steps can include: using the graph traversal statement of the graph database to traverse the user's permission management sub - graph to query whether the user has the permission to access the data in the graph currently accessed by the user; if so, continue to determine whether the user's service request conforms to the permission scope of the data in the graph currently accessed by the user; if it conforms, the user's service request does not exceed the permissions, otherwise it exceeds the permissions.
[0040] For example, the user's service request is a request to rewrite the business Figure 1 but based on the user's permission management sub - graph, it is confirmed that the user Figure 1Only read-only permissions, so the user's service permissions exceed the permissions.
[0041] It can be understood that the types of service requests are not restricted. For example, they can be access requests, query requests, and / or write requests, etc.
[0042] In this implementation, the permission control method configures the user's access permissions to the graph database on Ranger to obtain the user's access policy; converts the user's access policy into the user's permission management sub-graph, and updates it to the permission management graph of the graph database; in response to the user's service request, performs permission authentication on the user based on the user's permission management sub-graph. In this way, this application converts the permissions configured by Ranger into the permission management sub-graph, so that the subsequent graph database can use its own efficient graph query performance to quickly use the permission management sub-graph to perform permission authentication on the user, improving the permission control efficiency of the graph database.
[0043] Based on the above implementation of the permission control method, this application also provides another implementation of the permission control method. Specifically, as Figure 2 shown, a specific implementation of the permission control method proposed by this application specifically includes the following steps. It should be noted that the following step numbers are only used for simplified description and are not intended to limit the execution order of the steps. Each step of this implementation can be arbitrarily changed in the execution order without violating the technical idea of this application.
[0044] S201: Create a Kerberos user and issue a key file; configure the user's access permissions to the graph database on Ranger to obtain the user's access policy.
[0045] Optionally, in the permission control method, when the user registers and / or logs in for the first time, a Kerberos user can be created and a key file (such as a keytab file) can be issued, so that the subsequent user can perform user identity authentication based on the downloaded key file.
[0046] In one example, as Figure 4 shown, when the user registers and / or logs in for the first time, a kerberos user can be created on the big data console and the keytab file can be downloaded, and the permissions for this user to access JanusGraph can be configured on Ranger (specifically, it can include permission information such as whether there are permissions to access certain graphs, vertices, edges, and attributes, and / or whether there are only read-only permissions, etc.).
[0047] S202: Convert the user's access policy into the user's permission management sub-graph.
[0048] Specifically, refer to step S102, which will not be elaborated here.
[0049] S203: In response to the user's service request, perform user authentication based on the user's key file.
[0050] When the user's service request is obtained, user authentication can be performed based on the user's key file.
[0051] Among them, the previously issued key file to the user or relevant information in the key file can be obtained from the user's client, and user authentication is performed based on the key file or relevant information in the key file. Among them, the kerberos center can perform user authentication based on the key file or relevant information in the key file.
[0052] If the user authentication in step S203 passes based on the user's key file, then proceed to step S205; otherwise, proceed to step S204.
[0053] S204: Deny the user access to the graph database.
[0054] If the user authentication fails, the user will be denied access to the graph database.
[0055] S205: Perform permission authentication on the user based on the user's permission management sub-graph.
[0056] If the user authentication passes, permission authentication can be performed on the user based on the user's permission management sub-graph.
[0057] Among them, the specific steps of permission authentication can refer to step S103 and will not be elaborated here.
[0058] In an example, as Figure 4 and Figure 5 shown, if the kerberos authentication in step S203 passes, the user's service request will reach the permission interceptor AllowListAuthorizer layer of the graph database (janusgraph) for request permission control of the user's gremlin statement; among them, check whether the user has the overall permission to access the graph, and check whether there is a corresponding traversal; finally, the specific permissions of the user on the graph can be quickly queried through the permission management graph using the gremlin statement, and then compare the request of the gremlin statement. When it does not meet the permissions declared in the permission management graph, the request is rejected; when it meets the permissions declared in the permission management graph, the statement requested by the user is directly executed and the result is returned.
[0059] In this embodiment, the permission control method can combine the characteristics of the graph database and the mature identity authentication and permission management solutions of Kerberos and Ranger. Among them, identity authentication is based on Kerberos, and permission policy configuration and management are based on Ranger. JanusGraph pulls the Ranger policy every 10 seconds, converts it into a small graph for permission management. When a user request comes, the Gremlin statement in the request can be converted into permission authentication of the small graph for permission management. Through the Gremlin statement of the small graph for permission, it can be quickly identified whether the user has access permission, improving the data security and the flexibility and convenience of permission management of the graph database.
[0060] This application also provides a permission management device, which includes:
[0061] A policy configuration module, configured to configure the graph database access permission of a user on Ranger to obtain the access policy of the user;
[0062] A conversion module, configured to convert the access policy of the user into a sub-graph for the user's permission management;
[0063] An authentication module, configured to perform permission authentication on the user based on the sub-graph for the user's permission management.
[0064] Among them, the authentication module can be used to traverse the sub-graph for the user's permission management through the graph traversal statement of the graph database to query the specific permissions of the user on the graph currently being accessed; confirm whether the service request of the user exceeds the permissions based on the specific permissions of the user on the graph currently being accessed; if it exceeds the permissions, reject the service request; otherwise, execute the statement of the service request and return the result.
[0065] The conversion module can be used to bind the graph traversal corresponding to the user, and update the access policy of the user to the sub-graph for the user's permission management in the permission management graph;
[0066] The authentication module can be used to query whether there is a graph traversal corresponding to the user and the graph currently being accessed; if so, query the specific permissions of the user on the graph currently being accessed through the graph traversal statement.
[0067] The conversion module can be used to obtain the current access policy of the user from the Ranger center at preset intervals; bind the graph traversal corresponding to the user, and update the current access policy to the sub-graph for the user's permission management in the permission management graph.
[0068] The above-mentioned permission control device may further include a creation module and an identity authentication module. Among them, the creation module can be used to create Kerberos users and distribute key files; the identity authentication module can be used to, in response to a service request of the user, perform identity authentication of the user based on the key file of the user; if the identity authentication is passed, the subsequent step of performing permission authentication on the user based on the permission management sub-graph of the user is executed; if the identity authentication fails, the user is refused access to the graph database.
[0069] Among them, if the identity authentication is passed, the service request of the user will reach the permission interceptor of the graph database, so as to execute the step of performing permission authentication on the user based on the permission management sub-graph of the user through the permission interceptor.
[0070] Among them, the access policy includes whether the user has permissions to access certain graphs, nodes, edges, and / or attributes, and / or whether the user only has read-only permissions.
[0071] Please refer to Figure 6 , Figure 6 is a schematic structural diagram of an embodiment of the electronic device of the present application. The electronic device 20 includes a processor 22, and the processor 22 is used to execute instructions to implement the above method. For the specific implementation process, please refer to the description of the above embodiment, which will not be repeated here.
[0072] The processor 22 can also be called a CPU (Central Processing Unit, central processing unit). The processor 22 may be an integrated circuit chip with signal processing capabilities. The processor 22 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor 22 can also be any conventional processor, etc.
[0073] The electronic device 20 may further include a memory 21 for storing instructions and data required for the operation of the processor 22.
[0074] The processor 22 is used to execute instructions to implement the method provided by any embodiment of the above method of the present application and any non-conflicting combination.
[0075] Among them, the electronic device of the present application can be a confusion control system.
[0076] Please refer to Figure 7 , Figure 7This is a schematic structural diagram of the computer-readable storage medium in the embodiments of the present application. The computer-readable storage medium 30 of the embodiments of the present application stores instructions / program data 31, and when the instructions / program data 31 are executed, the methods provided by any one of the embodiments of the permission control method of the present application and any non-conflicting combination are implemented. In one embodiment, the instructions / program data 31 may form a program file and be stored in the above storage medium 30 in the form of a software product, so that a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor can execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium 30 includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, or terminal devices such as computers, servers, mobile phones, and tablets.
[0077] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.
[0078] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0079] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitations, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, commodity or device including the element.
[0080] The above are only the implementation manners of this application, and do not thus limit the patent scope of this application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of this application, or directly or indirectly applied in other related technical fields, shall similarly be included within the patent protection scope of this application.
Claims
1. A permission control method, characterized in that, The method includes: Configuring the access permission of the user's graph database on Ranger to obtain the access policy of the user; Converting the access policy of the user into the user's permission management sub-graph; Performing permission authentication on the user based on the user's permission management sub-graph.
2. The permission control method according to claim 1, characterized in that The performing permission authentication on the user based on the user's permission management sub-graph includes: Traversing the user's permission management sub-graph through the graph traversal statement of the graph database to query the specific permissions of the user on the graph currently being accessed; Based on the specific permissions of the user on the graph currently being accessed, confirming whether the service request of the user exceeds the permissions; if it exceeds the permissions, rejecting the service request; otherwise, executing the statement of the service request and returning the result.
3. The permission control method according to claim 2, characterized in that The converting the access policy of the user into the user's permission management sub-graph includes: Binding the graph traversal corresponding to the user and updating the access policy of the user to the user's permission management sub-graph in the permission management graph; The traversing the user's permission management sub-graph through the graph traversal statement of the graph database to query the specific permissions of the user on the graph currently being accessed includes: Querying whether there is a graph traversal corresponding to the user and the graph currently being accessed; If there is, querying the specific permissions of the user on the graph currently being accessed through the graph traversal statement.
4. The authority control method according to claim 3, wherein The method further includes: Obtaining the current access policy of the user from the Ranger center at preset intervals; Binding the graph traversal corresponding to the user and updating the current access policy to the user's permission management sub-graph in the permission management graph.
5. The permission control method according to claim 1, wherein The method further includes: creating a Kerberos user and issuing a key file; Before performing permission authentication on the user based on the user's permission management sub-graph, it includes: In response to the service request of the user, performing identity authentication on the user based on the key file of the user; If the identity authentication is passed, performing the step of performing permission authentication on the user based on the user's permission management sub-graph; If the identity authentication fails, rejecting the user from accessing the graph database.
6. The authority control method according to claim 5, wherein The if the identity authentication is passed, performing the step of performing permission authentication on the user based on the user's permission management sub-graph includes: If the identity authentication is passed, the service request of the user will reach the permission interceptor of the graph database to perform the step of performing permission authentication on the user based on the user's permission management sub-graph through the permission interceptor.
7. The authority control method according to claim 1, wherein The access policy includes whether the user has permissions to access certain graphs, vertices, edges, and / or attributes, and / or whether the user has only read-only permissions.
8. A permission control device, characterized in that, The device includes: A policy configuration module for configuring the access permission of the user's graph database on Ranger to obtain the access policy of the user; A conversion module for converting the access policy of the user into the user's permission management sub-graph; An authentication module, configured to perform permission authentication on the user based on the user's permission management sub-graph.
9. An electronic device, characterized in that, The electronic device includes a processor; the processor is configured to execute instructions to implement the steps of the method according to any one of claims 1-8.
10. A computer-readable storage medium having a program and / or instructions stored thereon, characterized in that, When the program and / or instructions are executed, the steps of the method according to any one of claims 1-8 are implemented.