Permission data processing method and device, computer equipment and storage medium
By splitting and translating the total calculation unit of the permission policy statement, the problem of low conversion efficiency of permission information between different syntaxes is solved, efficient permission information conversion and management is realized, and storage resource waste is reduced.
Patent Information
- Application Number
- CN202410006803.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, permission information is inefficient in conversion between different syntaxes, and developers need to manually write permission information, resulting in inefficient conversion.
By splitting the first constraint statement, the total computing unit is generated, and the sub-computing unit is translated into the syntax applicable to the second engine using the grammar of the second engine. The idea of division and conquer is adopted, and the computing logic is passed layer by layer to improve conversion efficiency.
It improves the conversion efficiency of permission information between different syntaxes, simplifies the generation and management of permission policy statements, reduces redundant data, and improves the utilization of storage resources.
Smart Images

Figure CN120257940A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and particularly to a method and apparatus for processing permission data, a computer device, a storage medium, and a computer program product. Background Art
[0002] With the development of computer technologies, a permission policy syntax has emerged. The permission policy syntax is a formal language used to describe and define access control rules, and is a special data representation form and syntax rule between human natural language and computer programs. It is usually used in computer systems, networks, and applications to specify the operations that users, roles, or other entities can perform and the resources to which they have access permissions.
[0003] In traditional technologies, if specific permission information needs to be converted from one permission policy syntax to another, developers need to manually write relevant statements under the structure of the new syntax to describe the permission information, resulting in low efficiency in converting permission information between different syntaxes. Summary of the Invention
[0004] Based on this, it is necessary to provide a method and apparatus for processing permission data, a computer device, a computer-readable storage medium, and a computer program product that can improve the efficiency of converting permission information between different syntaxes for the above technical problems.
[0005] This application provides a method for processing permission data, including:
[0006] Obtaining a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of a target permission in a first engine;
[0007] Splitting the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units corresponding to respective condition types in the first constraint condition statement and the logical relationships between the sub-calculation units, the condition types including calculation types and operators corresponding to the calculation types; the sub-calculation unit includes field calculation units corresponding to respective variable fields under the same condition type in the first constraint condition statement and the logical relationships between the field calculation units, the field calculation unit including field information of the variable fields in the first constraint condition statement, and the logical relationship in the total calculation unit is determined based on a logical control word in the first constraint condition statement;
[0008] For any sub-computation unit, through the syntax translator corresponding to the second engine, each field computation unit included in the sub-computation unit is respectively translated into a field constraint condition statement, and based on the logical relationship between the field computation units, the field constraint condition statements corresponding to each field computation unit are combined to obtain the sub-constraint condition statement corresponding to the sub-computation unit;
[0009] Through the syntax translator, based on the logical relationship between the sub-computation units, each sub-constraint condition statement is combined to obtain the second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
[0010] This application also provides a permission data processing device, including:
[0011] An acquisition module, configured to acquire a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of a target permission in a first engine;
[0012] A splitting module, configured to split the first constraint condition statement to generate a total computation unit corresponding to the first constraint condition statement; the total computation unit includes sub-computation units corresponding to each condition type in the first constraint condition statement, as well as the logical relationship between the sub-computation units, the condition type includes a computation type and an operator corresponding to the computation type; the sub-computation unit includes field computation units corresponding to each variable field under the same condition type in the first constraint condition statement, as well as the logical relationship between the field computation units, the field computation unit includes the field information of the variable field in the first constraint condition statement, and the logical relationship in the total computation unit is determined based on the logical control word in the first constraint condition statement;
[0013] A translation module, for any sub-computation unit, through the syntax translator corresponding to the second engine, each field computation unit included in the sub-computation unit is respectively translated into a field constraint condition statement, and based on the logical relationship between the field computation units, the field constraint condition statements corresponding to each field computation unit are combined to obtain the sub-constraint condition statement corresponding to the sub-computation unit;
[0014] The translation module is further configured to, through the syntax translator, based on the logical relationship between the sub-computation units, combine each sub-constraint condition statement to obtain the second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
[0015] The present application also provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned permission data processing method are implemented.
[0016] The present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned permission data processing method are implemented.
[0017] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned permission data processing method are implemented.
[0018] The above-mentioned permission data processing method, device, computer device, storage medium and computer program product obtain a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of the target permission in the first engine; split the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units corresponding to each condition type in the first constraint condition statement, and the logical relationship between the sub-calculation units, and the condition types include calculation types and operators corresponding to the calculation types; the sub-calculation unit includes field calculation units corresponding to each variable field under the same condition type in the first constraint condition statement, and the logical relationship between the field calculation units, and the field calculation unit includes the field information of the variable field in the first constraint condition statement. The logical relationship in the total calculation unit is determined based on the logical control words in the first constraint condition statement; for any sub-calculation unit, through the syntax translator corresponding to the second engine, each field calculation unit included in the sub-calculation unit is translated into a field constraint condition statement, and based on the logical relationship between the field calculation units, the field constraint condition statements corresponding to each field calculation unit are combined to obtain the sub-constraint condition statement corresponding to the sub-calculation unit; through the syntax translator, based on the logical relationship between the sub-calculation units, each sub-constraint condition statement is combined to obtain the second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine. In this way, when translating the constraint condition statement for indicating the effective condition of the target permission from the syntax applicable to the first engine to the syntax applicable to the second engine, first split the first constraint condition statement to generate the total calculation unit corresponding to the constraint condition statement, split the calculation logic in the constraint condition statement, and pass it layer by layer to generate the field calculation unit. The sub-calculation unit is obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. Using the idea of divide and conquer, the total calculation unit not only has the key elements in the first constraint condition statement, but also has the coherence between the elements. Furthermore, through the syntax translator applicable to the second engine, the total calculation unit can be quickly translated into the second constraint condition statement applicable to the second engine, improving the conversion efficiency of permission information between different syntaxes. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 It is an application environment diagram of the permission data processing method in an embodiment;
[0021] Figure 2 It is a schematic flowchart of a method for processing permission data in an embodiment;
[0022] Figure 3 It is a schematic flowchart of permission configuration in an embodiment;
[0023] Figure 4 It is a schematic flowchart of authentication in an embodiment;
[0024] Figure 5 It is a schematic diagram of permission verification through a permission policy matching engine in an embodiment;
[0025] Figure 6 It is a schematic flowchart of permission policy synchronization in an embodiment;
[0026] Figure 7 It is a schematic diagram of the total computing unit generated by the method of this application in an embodiment;
[0027] Figure 8 It is a schematic diagram of the logical relationship in the traditional permission policy syntax in an embodiment;
[0028] Figure 9 It is a schematic diagram of authentication through the method of this application in an embodiment;
[0029] Figure 10 It is a schematic diagram of permission synchronization through the method of this application in an embodiment;
[0030] Figure 11 It is a structural block diagram of a permission data processing device in an embodiment;
[0031] Figure 12 It is an internal structure diagram of a computer device in an embodiment;
[0032] Figure 13 It is an internal structure diagram of a computer device in another embodiment. Detailed implementation manners
[0033] In order to make the purpose, technical solutions and advantages of this application clearer, the following further elaborates on this application in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0034] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing. Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model. It can form a resource pool, be used as needed, and is flexible and convenient. Cloud computing technology will become an important support. The back-end services of technical network systems require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. With the high development and application of the Internet industry, in the future, each item may have its own identification mark and needs to be transmitted to the back-end system for logical processing. Data at different levels will be processed separately, and various industry data requires the support of a powerful system. This can only be achieved through cloud computing.
[0035] The embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, assisted driving, etc.
[0036] The permission data processing method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through the network. For example, the user can set the permission policy syntax through the terminal and send the permission policy syntax to the server for storage. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed on the cloud or other network servers. The terminal 102 can be but is not limited to various personal computers, laptops, smartphones, tablets, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart vehicle-mounted devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and the present application does not limit this.
[0037] Both the terminal and the server can be used alone to execute the permission data processing method provided in the embodiments of the present application. The terminal and the server can also be used in cooperation to execute the permission data processing method provided in the embodiments of the present application.
[0038] For example, the server obtains a first constraint condition statement, which is used to indicate the effective condition of the target permission in the first engine. The server splits the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement. The total calculation unit includes sub-calculation units corresponding to respective condition types in the first constraint condition statement, and the logical relationships between the sub-calculation units. The condition types include calculation types and operators corresponding to the calculation types. The sub-calculation unit includes field calculation units corresponding to respective variable fields under the same condition type in the first constraint condition statement, and the logical relationships between the field calculation units. The field calculation unit includes the field information of the variable field in the first constraint condition statement. The logical relationship in the total calculation unit is determined based on the logical control words in the first constraint condition statement. For any one sub-calculation unit, the server uses the syntax translator corresponding to the second engine to translate each field calculation unit included in the sub-calculation unit into a field constraint condition statement respectively, and combines the field constraint condition statements corresponding to each field calculation unit based on the logical relationship between the field calculation units to obtain a sub-constraint condition statement corresponding to the sub-calculation unit. The server uses the syntax translator to combine each sub-constraint condition statement based on the logical relationship between the sub-calculation units to obtain a second constraint condition statement corresponding to the first constraint condition statement. The second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
[0039] In one embodiment, as Figure 2 shown, a method for processing permission data is provided. Taking the application of this method to a computer device as an example, the computer device can be a terminal or a server. It can be understood that this method can be executed independently by the terminal or the server itself, or can be implemented through the interaction between the terminal and the server. Among them:
[0040] Step S202, obtain a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of the target permission in the first engine.
[0041] Among them, permission refers to allowing or prohibiting certain operations on certain resources under certain conditions. The constraint condition statement is a statement describing the effective condition of the permission and is used to indicate the effective condition of the permission. For example, there is a permission policy scenario where users with application account names "a" or "b" are allowed to view and edit documents in the application. The effective condition of the permission is that the application account name is "a" or "b", and the constraint condition statement is used to indicate this effective condition. The constraint condition statement can be applied to authorization and authentication scenarios.
[0042] The first constraint condition statement is a statement that describes the effective conditions of the target permission and is used to indicate the effective conditions of the target permission in the first engine. The target permission can be various permissions. For example, it can be a permission for the application layer; it can be a permission for the data layer; it can be a permission for cloud resources; and so on. The first constraint condition statement is a constraint condition statement applicable to the first engine, that is, a constraint condition statement recognizable by the first engine. It can be understood that different engines usually have their own supported grammars, and the engine can recognize statements expressed in its own supported grammar.
[0043] Specifically, the computer device obtains the first constraint condition statement applicable to the first engine and translates the first constraint condition statement into the second constraint condition statement applicable to the second engine.
[0044] In one embodiment, the first constraint condition statement is obtained from the permission policy statement corresponding to the target permission in the first engine. The permission policy statement is a statement that describes the target permission through the permission policy grammar. The permission policy grammar is a formal language used to describe and define access control rules, and it is a special data expression form and grammar rule artificially designed between human natural language and computer programs. It is usually used in computer systems, networks, and applications to specify the operations that users, roles, or other entities can perform and the resources to which they have access permissions. The permission policy grammar can express access control rules more clearly, thereby achieving more refined permission management. The main components of the permission policy grammar usually include resource, effect, action, and condition. The resource represents the object that needs to be accessed or operated on, such as a file, a database table, or a cloud machine resource, etc. The effect represents whether it is allowed or prohibited. The action represents the operations and behaviors that are allowed or prohibited to be executed, such as read, write, delete, or modify operations, etc. The condition represents the additional constraint conditions of the access control rule, that is, the constraint condition and the effective condition. The access control rule takes effect only when the constraint condition is met, and it is the module that needs to be calculated in the permission policy grammar. By combining these components, complex permission policies can be created to meet the access control requirements in different scenarios.
[0045] For example, the following permission policy statement can be defined based on the permission policy grammar:
[0046] {
[0047] “effect”: “allow”,
[0048] “action”:
[0049] “read”
[0050] ,
[0051] "resource":
[0052] "All documents of Application A / *"
[0053] ,
[0054] "condition": {
[0055] "string_equal": {
[0056] "name":
[0057] "Zhang San",
[0058] "Li Si",
[0059] "Wang Wu",
[0061] }
[0062] }
[0063] }
[0064] The meaning of the above permission policy statement is to allow Zhang San, Li Si, and Wang Wu to read all documents of Application A.
[0065] For the convenience of understanding, the subsequent description of the permission policy statement can be made using the logical language corresponding to the code:
[0066] {
[0067] "Effect": "Allow",
[0068] "Action":
[0069] "Read"
[0070] ,
[0071] "Resource":
[0072] "All resources of Application A documents"
[0073] ,
[0074] "Condition": {
[0075] "string_equal": {
[0076] "Name":
[0077] "Zhang San",
[0078] "Li Si",
[0079] "Wang Wu",
[0081] }
[0082] }
[0083] }
[0084] It can be understood that the target permission in the permission policy statement corresponding to the first engine can be written by professionals on the terminal or obtained by converting the natural language input by the user on the terminal through a tool.
[0085] Step S204: Split the first constraint condition statement to generate the total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units corresponding to each condition type in the first constraint condition statement and the logical relationships between the sub-calculation units. The condition types include calculation types and operators corresponding to the calculation types; the sub-calculation unit includes field calculation units corresponding to each variable field under the same condition type in the first constraint condition statement and the logical relationships between the field calculation units. The field calculation unit includes the field information of the variable field in the first constraint condition statement. The logical relationship in the total calculation unit is determined based on the logical control words in the first constraint condition statement.
[0086] Among them, the permission can take effect only when the constraint conditions indicated by the constraint condition statement are met. The constraint conditions involve calculations, and it is necessary to determine whether the constraint conditions are met through calculations. For example, if the constraint condition is that the application account name is "a" or "b", it is necessary to calculate whether the application account name of the authenticated user is "a" or "b" to determine whether the authenticated user meets the constraint condition.
[0087] The calculation logic expressed by the constraint condition statement involves the condition type, the logical relationship between condition types, the variable fields under the condition type, and the logical relationship between variable fields. A condition type includes a calculation type and an operator corresponding to the calculation type. There are many types of calculation types, including but not limited to calculations of numeric types, string types, array types, and custom types. The calculation type refers to the data type to which the variables used in the calculation belong. For example, string type, numeric type. The operator is used to indicate the arithmetic relationship between the field name and the field value of the variable field under the calculation type. For example, the arithmetic relationships are equal to, not equal to, greater than, less than, greater than or equal to, less than or equal to. The variable field refers to the variable used in the calculation. The variable field under the calculation type refers to the variable belonging to the calculation type. For example, if the calculation type is string type, the variable field under the string type is a variable belonging to the string type, and the variable value is represented by a string; if the calculation type is numeric type, the variable field under the numeric type is a variable belonging to the numeric type, and the variable value is represented by a number. The field information of the variable field refers to the specific information of the variable field, which is used to describe the variable field. The field information of the variable field includes the field name of the variable field, the field value, the arithmetic relationship between the field name and the field value, and the logical relationship between the field values. The logical relationships are AND logical relationship, OR logical relationship, and NOT logical relationship. The calculation type, the operator corresponding to the calculation type, the field information of the variable field, and the logical control word can be identified from the constraint condition statement. The logical relationship is determined by the logical control word. The logical control word is a string that controls the logical relationship.
[0088] The total calculation unit corresponding to the constraint condition statement includes sub-calculation units respectively corresponding to each condition type in the constraint condition statement, and the logical relationship between the sub-calculation units. The sub-calculation unit corresponding to a condition type includes field calculation units respectively corresponding to each variable field under this condition type in the constraint condition statement, and the logical relationship between the field calculation units. The field calculation unit corresponding to a variable field includes the field information of this variable field in the constraint condition statement. The field calculation unit, the sub-calculation unit, and the total calculation unit are in a progressive relationship. The sub-calculation unit is obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units.
[0089] Specifically, in order to translate the first constraint condition statement into other grammars, the computer device can split the first constraint condition statement and split out the elements related to the calculation logic from the first constraint condition statement. The computer device identifies the calculation type, operator, variable field, and logical relationship from the first constraint condition statement. The computer device organically combines the split elements to generate the total calculation unit corresponding to the first constraint condition statement. The computer device generates sub-calculation units from the field information of the same variable field, obtains the field calculation units corresponding to each variable field respectively, combines the field calculation units corresponding to each variable field under the same condition type according to the logical relationship between the variable fields, obtains the sub-calculation units corresponding to each condition type respectively, and combines the sub-calculation units according to the logical relationship between the condition types to obtain the total calculation unit corresponding to the first constraint condition statement.
[0090] In the process of generating the corresponding total calculation unit by splitting the first constraint condition statement, the idea of divide and conquer is adopted. The calculation logic in the first constraint condition statement is split and passed layer by layer. The smallest calculation logic in the first constraint condition statement is split into field calculation units. The sub-calculation units are obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. Adopting the idea of "mutually independent and completely exhaustive", the variable fields in the constraint condition statement are exhausted to generate field calculation units, and the field calculation units are mutually independent. The condition types in the constraint condition statement are exhausted to generate sub-calculation units, and the sub-calculation units are mutually independent.
[0091] Step S206, for any sub-calculation unit, through the grammar translator corresponding to the second engine, each field calculation unit included in the sub-calculation unit is respectively translated into a field constraint condition statement, and based on the logical relationship between the field calculation units, the field constraint condition statements corresponding to each field calculation unit are combined to obtain the sub-constraint condition statement corresponding to the sub-calculation unit.
[0092] Among them, the second engine and the first engine are engines that support different grammars. For example, the first engine is a permission policy engine that supports the permission policy grammar, and the second engine is a rule engine that supports the rule grammar; the first engine is the permission policy engine of the first platform that supports the permission policy grammar of the first platform, and the second engine is the permission policy engine of the second platform that supports the permission policy grammar of the second platform.
[0093] The grammar translator corresponding to the second engine is a translator used to output statements expressed in the grammar adopted by the second engine. The data to be translated is input into the grammar translator corresponding to the second engine, and the grammar translator corresponding to the second engine integrates the data to be translated according to the grammar structure of the grammar adopted by the second engine and outputs the translation result.
[0094] Specifically, the field calculation unit, the sub-calculation unit, and the total calculation unit have a progressive relationship. The sub-calculation unit is obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. For any sub-calculation unit, the computer device first translates the field calculation units therein, and then combines the translation results of the field calculation units based on the logical relationships between the field calculation units to obtain the translation result of the sub-calculation unit. The computer device uses the syntax translator corresponding to the second engine to translate each field calculation unit included in the sub-calculation unit into a field constraint condition statement, and combines the field constraint condition statements corresponding to each field calculation unit based on the logical relationships between the field calculation units to obtain the sub-constraint condition statement corresponding to the sub-calculation unit.
[0095] Step S208, using the syntax translator, combine each sub-constraint condition statement based on the logical relationships between the sub-calculation units to obtain the second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
[0096] Among them, the second constraint condition statement is a statement describing the effective condition of the target permission and is used to indicate the effective condition of the target permission in the second engine.
[0097] Specifically, the field calculation unit, the sub-calculation unit, and the total calculation unit have a progressive relationship. The sub-calculation unit is obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. The computer device uses the syntax translator corresponding to the second engine to combine each sub-constraint condition statement based on the logical relationships between the sub-calculation units to obtain the second constraint condition statement corresponding to the first constraint condition statement. Subsequently, the computer device can send the second constraint condition statement to the second engine for storage or data processing.
[0098] In the above permission data processing method, when translating the constraint condition statement indicating the effective condition of the target permission from the syntax applicable to the first engine to the syntax applicable to the second engine, first split the first constraint condition statement to generate the total calculation unit corresponding to the constraint condition statement, split the calculation logic in the constraint condition statement, and pass it layer by layer to generate the field calculation unit. The sub-calculation unit is obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. Adopting the idea of divide and conquer, the total calculation unit not only has the key elements in the first constraint condition statement but also has the coherence between the elements. Furthermore, through the syntax translator applicable to the second engine, the total calculation unit can be quickly translated into the second constraint condition statement applicable to the second engine, improving the conversion efficiency of permission information between different syntaxes.
[0099] In one embodiment, the first constraint condition statement is the constraint condition statement of the target permission in the permission policy statement corresponding to the first engine. For exampleFigure 3 As shown, the permission data processing method further includes:
[0100] Step S302, receiving a permission configuration request for the first engine; the permission configuration request carries the permission configuration information of the target permission.
[0101] Step S304, identifying the permission effect configuration information from the permission configuration information, and converting the permission effect configuration information into a permission effect statement based on the permission policy syntax corresponding to the first engine; the permission effect statement is used to indicate the effect of the target permission.
[0102] Step S306, identifying the constraint condition configuration information from the permission configuration information, and converting the constraint condition configuration information into a constraint condition statement based on the permission policy syntax corresponding to the first engine; the constraint condition statement is used to indicate the effective condition of the target permission, and the permission policy syntax corresponding to the first engine controls the logical relationship between statements in the constraint condition statement through a preset set of logical control words.
[0103] Step S308, forming a permission policy statement corresponding to the target permission in the first engine by combining the permission effect statement and the constraint condition statement.
[0104] Among them, the permission configuration request is a request for requesting relevant information for configuring permissions. The permission configuration request carries the permission configuration information of the permission. The permission configuration information includes the permission effect configuration information and the constraint condition configuration information. The permission effect configuration information is used to configure the effect information of the permission, and the effect information includes resources (objects that need to be accessed or operated on), effects (allowed or prohibited), and operations (operations and behaviors that are allowed or prohibited to be executed). The constraint condition configuration information is used to configure the constraint conditions (i.e., effective conditions) of the permission.
[0105] The syntax structure of the permission policy syntax corresponding to the first engine controls the logical relationship between statements in the constraint condition statement through a preset set of logical control words, so as to avoid a large number of redundant statements and meet more complex constraint condition configurations. The preset set of logical control words includes multiple logical control words.
[0106] For example, the permission configuration information is that except for users with application account names "a" and "b", others must be within the company's office network to view and edit all documents in Application A. Based on the permission policy syntax corresponding to the first engine, the permission policy statement obtained by converting the permission configuration information is as follows:
[0107] {
[0108] "Effect": "Allowed",
[0109] "Operation":
[0110] "View",
[0111] "Edit"
[0112] ,
[0113] "Resource":
[0114] "All documents of Application A"
[0115] ,
[0116] "Constraints":{
[0117] "string_equal:for_any_value":{
[0118] "Application account name (name)":
[0119] "a",
[0120] "b",
[0122] "Current network (network)":
[0123] "Office network"
[0125] }
[0126] }
[0127] }
[0128] Among them, for_any_value is a logical control word, used to indicate that the logical relationship between the description statements of the two variables of the application account name and the current network is an OR logical relationship.
[0129] It can be understood that without the logical control word, the permission policy statement obtained by converting the permission configuration information is as follows:
[0130] {
[0131] "Effect": "Allow",
[0132] "Operation":
[0133] "View",
[0134] "Edit"
[0135] ,
[0136] "Resource":
[0137] "All documents of Application A"
[0138] ,
[0139] "Constraints":{
[0140] "string_equal:for_any_value": {
[0141] "staffname":
[0142] "a",
[0143] "b",
[0145] }}
[0146] }}
[0147] }}
[0148] {
[0149] "Effect": "Allow",
[0150] "Action":
[0151] "View",
[0152] "Edit"
[0153] ,
[0154] "Resource":
[0155] "All documents of Application A"
[0156] ,
[0157] "Condition": {
[0158] "string_equal": {
[0159] "network":
[0160] "Office network"
[0162] }}
[0163] }}
[0164] }}
[0165] Without logical control words, there will be a large amount of redundant field data in the permission policy syntax, making the syntax structure bloated and wasting device storage resources.
[0166] Specifically, a user can configure the permission configuration information of the target permission on the terminal, thereby triggering the generation of a permission configuration request for the first engine. This permission configuration request is used to request the generation of a permission policy statement corresponding to the target permission in the first engine. The terminal sends the permission configuration request to the computer device. The permission configuration request carries the permission configuration information of the target permission. The computer device converts the permission configuration information into a permission policy statement corresponding to the target permission in the first engine based on the permission policy syntax corresponding to the first engine. Specifically, the permission effect configuration information can be identified from the permission configuration information, and based on the permission policy syntax corresponding to the first engine, the permission effect configuration information is converted into a permission effect statement. The constraint condition configuration information is identified from the permission configuration information, and based on the permission policy syntax corresponding to the first engine, the constraint condition configuration information is converted into a constraint condition statement. The permission effect statement and the constraint condition statement are combined to form a permission policy statement corresponding to the target permission in the first engine.
[0167] The computer device can store the permission policy statement in the first engine. When there is a translation requirement, the constraint condition statement in the permission policy statement corresponding to the target permission in the first engine is used as the first constraint condition statement, and the step of splitting the first constraint condition statement is entered for execution.
[0168] In one embodiment, if a permission translation request for the target permission is received, the permission policy statement corresponding to the target permission in the first engine is obtained, and the constraint condition statement in the permission policy statement corresponding to the target permission in the first engine is used as the first constraint condition statement, and the step of splitting the first constraint condition statement is entered for execution.
[0169] Specifically, a permission translation request is a request for translating part or all of a permission policy statement from one syntax to another syntax, that is, from the syntax corresponding to one engine to the syntax corresponding to another engine. A permission translation request can be generated according to business needs. For example, the permission translation request is triggered by a permission policy synchronization request. The permission policy synchronization request is used to request the synchronization of permission policies between different platforms to translate a permission policy statement recognizable by one platform into a permission policy statement recognizable by another platform. For example, before receiving an authentication request, the permission policy statement recognizable by the permission policy engine can be converted into a rule statement recognizable by the rule engine to be ready to respond to the authentication request at any time. For example, the permission translation request is triggered by an authentication request. After receiving the authentication request, the permission policy statement related to the authentication request in the permission policy engine is converted into a rule statement recognizable by the rule engine. For example, the permission translation request is triggered by a permission policy update request. The permission policy update request is used to update the permission policy statement. When the permission policy statement is added, deleted, or modified, the updated permission policy statement is converted into another syntax.
[0170] In the above embodiments, the user can trigger a permission configuration request according to needs. When processing the permission configuration request, based on the permission policy syntax corresponding to the first engine, the permission configuration information configured by the user for the target permission is converted into a permission policy statement that can be recognized and processed by the first engine. The syntax structure of the permission policy syntax corresponding to the first engine controls the logical relationship between statements in the constraint condition statement through a preset set of logical control words, can improve the syntax logic in the constraint condition statement, can avoid a large number of redundant statements in the permission policy syntax, and can meet more complex constraint condition configurations.
[0171] In one embodiment, the first engine is a permission policy engine and the second engine is a rule engine. As Figure 4 shown, obtaining the first constraint condition statement includes:
[0172] Step S402, receiving an authentication request carrying an authentication object identifier.
[0173] Step S404, in the first engine, obtaining the permission policy statement corresponding to the authentication object identifier, and using the constraint condition statement in the permission policy statement as the first constraint condition statement.
[0174] Among them, the first engine is a permission policy engine and the second engine is a rule engine. The permission policy engine is an engine for managing permission policy statements. The permission policy engine can be used to generate permission policy statements, store permission policy statements, and update permission policy statements. The rule engine is an engine for matching and calculating input data. Convert the constraint condition statements that need to be calculated in the permission policy statement into rule statements that can be recognized by the rule engine, input the rule statements and the relevant information of the authentication object into the rule engine for calculation, and the rule engine outputs the authentication result of the authentication object.
[0175] The authentication request is used to request to determine whether the authentication object has the corresponding permission. For example, when a user accesses an application or service, the authentication request can be used to request to determine whether the user has access permission to the accessed application or service, that is, the authentication request can be an authentication request for the application layer. The authentication request can also be used to request to determine whether the user has access permission to specific data in the application or service, and the authentication request can also be used to request to determine whether the user has edit permission to specific data in the application or service, that is, the authentication request can be an authentication request for the data layer.
[0176] The authentication request carries an authentication object identifier. The authentication object identifier is a kind of identifier used to uniquely identify the authentication object. For example, the login account of the authentication object can be used as the authentication object identifier. The permission policy statement corresponding to the authentication object identifier refers to the permission policy statement bound to the authentication object identifier. For example, when authorizing the authentication object identifier, the authentication object identifier and the permission policy statement corresponding to the granted permission can be bound.
[0177] Specifically, in the authentication scenario, query the permission policy statement corresponding to the authentication object identifier from the permission policy engine, convert the queried permission policy statement into a rule statement that the rule engine can recognize, and input the rule statement and the object attribute information corresponding to the authentication object identifier into the rule engine for calculation to quickly determine the authentication result corresponding to the authentication object identifier.
[0178] The computer device receives an authentication request carrying an authentication object identifier. In the permission policy engine, obtain the permission policy statement corresponding to the authentication object identifier, use the constraint condition statement in the permission policy statement as the first constraint condition statement, and translate the first constraint condition statement into a second constraint condition statement that the rule engine can recognize.
[0179] As Figure 4 shown, the permission data processing method further includes:
[0180] Step S406: Obtain the variable field from the first constraint condition statement, and obtain the variable field value of the authentication object identifier on the variable field as the authentication field value of the variable field.
[0181] Step S408: Input the authentication field value of the variable field and the second constraint condition statement into the rule engine for calculation to obtain a calculation result, and determine the authentication result corresponding to the authentication object identifier according to the calculation result.
[0182] Specifically, the computer device receives an authentication request carrying an authentication object identifier. In the permission policy engine, obtain the permission policy statement corresponding to the authentication object identifier, use the constraint condition statement in the permission policy statement as the first constraint condition statement, obtain the variable field from the first constraint condition statement, and obtain the variable field value of the authentication object identifier on the variable field as the authentication field value of the variable field. For example, if the variable field is the user management rank, the variable field value of the authentication object identifier on the variable field is the management rank of the authenticated user corresponding to the authentication object identifier; if the variable field is the used network, the variable field value of the authentication object identifier on the variable field is the network name used by the authenticated user corresponding to the authentication object identifier.
[0183] The computer device inputs the authentication field value of the variable field and the second constraint condition statement into the rule engine for calculation to obtain a calculation result. It can be understood that the second constraint condition statement is a matching rule, and the rule engine calculates whether the authentication field value of the variable field conforms to and satisfies the matching rule, and outputs the calculation result. If the authentication field value of the variable field conforms to and satisfies the matching rule, it is determined that the calculation result is a successful match; if the authentication field value of the variable field does not conform to and does not satisfy the matching rule, it is determined that the calculation result is a failed match.
[0184] Furthermore, the computer device determines the authentication result corresponding to the authentication object identifier according to the calculation result. The action information of the target permission is determined according to the action statement of the permission policy statement corresponding to the authentication object identifier. For example, the action information of the target permission is to allow viewing all documents in the application. If the calculation result is a successful match, it is determined that the authentication result corresponding to the authentication object identifier has the target permission. If the calculation result is a failed match, it is determined that the authentication result corresponding to the authentication object identifier does not have the target permission.
[0185] It can be understood that the first constraint condition statement and the second constraint condition statement are used to indicate the effective conditions of the target permission, that is, in which cases the variable values of the variables in the constraint conditions of the target permission are effective. If the authentication field value of the variable field satisfies the constraint conditions of the target permission, it can be determined that the authentication object identifier has the target permission, and the authentication object identifier passes the authentication for the target permission; if the authentication field value of the variable field does not satisfy the constraint conditions of the target permission, it can be determined that the authentication object identifier does not have the target permission, and the authentication object identifier fails to pass the authentication for the target permission.
[0186] In one embodiment, the syntax recognizable by the permission policy engine may be the permission policy syntax. The syntax recognizable by the rule engine may be the syntax executable by a computer program. For example, the syntax recognizable by the rule engine may be a logical expression. The authentication field value of the variable field and the second constraint condition statement are input into the rule engine for logical calculation, and the calculation result is output. The calculation result includes a logical value representing true or false. If the calculation result is a logical value representing true, the authentication result is that the authentication object identifier has the target permission; if the calculation result is a logical value representing false, the authentication result is that the authentication object identifier does not have the target permission.
[0187] In the above embodiment, when performing authentication based on an authentication request, the constraint condition statement describing the calculation logic in the permission policy statement corresponding to the authentication object identifier in the permission policy engine is converted into a constraint condition statement recognizable and calculable by the rule engine. The variable field value of the authentication object identifier on the variable field and the second constraint condition statement are input into the rule engine for calculation. The rule engine can quickly output the calculation result, and then based on the calculation result, the authentication result of the authentication object identifier can be quickly determined.
[0188] In one embodiment, obtaining the permission policy statement corresponding to the authentication object identifier includes:
[0189] Obtaining a plurality of permission policy statements bound to the authentication object identifier; removing duplicates and integrating the plurality of permission policy statements to obtain a comprehensive permission policy statement corresponding to the authentication object identifier; using the constraint condition statement in the comprehensive permission policy statement as the first constraint condition statement.
[0190] Among them, removing duplicates and integrating means removing duplicates and then merging.
[0191] Specifically, when obtaining the permission policy statement corresponding to the authentication object identifier, the computer device can obtain a plurality of permission policy statements bound to the authentication object identifier and merge the plurality of permission policy statements, that is, remove duplicates and integrate the plurality of permission policy statements to obtain a comprehensive permission policy statement corresponding to the authentication object identifier, and use the constraint condition statement in the comprehensive permission policy statement as the first constraint condition statement.
[0192] In the above embodiment, obtaining the permission policy statement bound to the authentication object identifier, removing duplicates and integrating the plurality of permission policy statements to obtain a comprehensive permission policy statement corresponding to the authentication object identifier, and using the constraint condition statement in the comprehensive permission policy statement as the first constraint condition statement. Removing duplicates and integrating the plurality of permission policy statements can further remove duplicate data, reduce the amount of data to be translated, improve the subsequent translation efficiency, and thus contribute to improving the authentication efficiency.
[0193] In one embodiment, permission verification is implemented through a permission policy engine (which can also be referred to as a permission policy matching engine). Refer to Figure 5 , in the permission policy engine, load the permission policy statement generated based on the permission policy syntax (i.e., obtain the permission policy statement), then optimize and integrate the permission policy statement (i.e., remove duplicates and integrate the permission policy statement), and then process the calculation module in the optimized and integrated permission policy statement (i.e., process the constraint condition statement in the optimized and integrated permission policy statement). When processing the constraint condition statement, specifically, split the constraint condition statement, and generate the total calculation unit corresponding to the constraint condition statement based on the split result. Then, through the syntax translator corresponding to the rule engine, convert the total calculation unit corresponding to the constraint condition statement into an executable statement of the rule engine, and input the converted rule statement into the rule engine. When authentication is required, extract the variables in the calculation module (i.e., extract the variables in the constraint condition statement), obtain the attribute information of the authenticated user on the variables, input the attribute information of the authenticated user on the variables into the rule engine, and the rule engine calculates the attribute information of the user on the variables and the rule statement, and determines the permission verification result (i.e., the authentication result) according to the calculation result output by the rule engine.
[0194] For example, the constraint condition statement is as follows:
[0195] {
[0196] "condition": {
[0197] "string_euqal: for_any_value": {
[0198] "staffname":
[0199] "a",
[0200] "b"
[0201] ,
[0202] "network":
[0203] "A-WiFi"
[0205] }
[0206] }
[0207] }
[0208] Convert the constraint condition statement into a rule statement. The rule statement is (staffname == "a" || staffname == "b") or network == "Tencent-WiFi". Extract the variables staffname and network from the constraint condition statement, obtain the values of the authenticated user on staffname and network, input the values of the authenticated user on staffname and network and this rule statement into the rule engine for calculation, and determine the authentication result of the authenticated user according to the calculation result output by the rule engine.
[0209] In one embodiment, the first engine is the permission policy engine of the first platform, and the second engine is the permission policy engine of the second platform. As Figure 6 shown, obtain the first constraint condition statement, including:
[0210] Step S602, receive a permission policy synchronization request for the first platform and the second platform.
[0211] Step S604, obtain the first permission policy statement from the permission policy engine of the first platform, and use the constraint condition statement in the first permission policy statement as the first constraint condition statement.
[0212] Among them, the first engine and the second engine are permission policy engines for different platforms. The first engine is the permission policy engine for the first platform, and the second engine is the permission policy engine for the second platform. For example, the first engine is a permission policy engine that configures permission policies through the permission policy syntax of this application, and the second engine is a permission policy engine for a cloud platform. For example, the first engine is the permission policy engine for cloud platform A provided by Company A, and the second engine is the permission policy engine for cloud platform B provided by Company B.
[0213] A permission policy synchronization request is a request used to request the synchronization of permission policy statements between permission policy engines on different platforms, that is, to request the translation of permission policy statements recognizable by the permission policy engine of the first platform into permission policy statements recognizable by the permission policy engine of the second platform. For example, Company X applies for cloud servers on cloud platform A and cloud platform B to store the company's business data. Then, Company X needs to synchronize the access control rules (i.e., permission policies) of the business data between cloud platform A and cloud platform B.
[0214] Specifically, the computer device can receive a permission policy synchronization request for the first platform and the second platform, obtain the first permission policy statement from the permission policy engine of the first platform, use the constraint condition statement in the first permission policy statement as the first constraint condition statement, and translate the first constraint condition statement into a second constraint condition statement recognizable by the permission policy engine of the second platform.
[0215] As Figure 6 shown, the permission data processing method further includes:
[0216] Step S606, generating a second permission policy statement based on the second constraint condition statement, and storing the second permission policy statement in the permission policy engine of the second platform.
[0217] Specifically, after obtaining the second constraint condition statement, the computer device can generate a second permission policy statement based on the second constraint condition statement. For example, using the permission effect statement in the first permission policy statement as the first permission effect statement, through the syntax translator corresponding to the second engine, convert the first permission effect statement into a second permission effect statement, and combine the second permission effect statement and the second constraint condition statement to form the second permission policy statement. The computer device can store the second permission policy statement in the permission policy engine of the second platform. Subsequently, the permission policy engine of the second platform can perform authentication based on the second permission policy statement.
[0218] In the above embodiment, the method of this application can also be used for the synchronization of permission policies on different platforms, with stronger generality.
[0219] In one embodiment, splitting the first constraint condition statement to generate the total calculation unit corresponding to the first constraint condition statement includes:
[0220] Identify the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement; the operator is used to indicate the operation relationship between the field name and the field value of the variable field under the calculation type.
[0221] Combine the identified calculation type and the operator corresponding to the calculation type into a condition type, and determine the logical relationship between condition types, the logical relationship between variable fields under the condition type, and the logical relationship between variable field values of the variable fields based on the identified logical control word; for any one condition type, generate a field calculation unit corresponding to the variable field based on the field information of the variable fields under the same condition type in the first constraint condition statement, determine the logical relationship between the field calculation units based on the logical relationship between the variable fields, and form a sub-calculation unit corresponding to the condition type by combining each field calculation unit and the logical relationship between the field calculation units; the field calculation unit corresponding to the variable field includes the logical relationship between the variable field values of the variable field; determine the logical relationship between the sub-calculation units based on the logical relationship between the condition types, and form the total calculation unit corresponding to the first constraint condition statement by combining each sub-calculation unit and the logical relationship between the sub-calculation units.
[0222] Among them, the calculation type refers to the data type to which the variables used in the constraint condition belong. For example, the string type, the numeric type. The operator is used to indicate the operation relationship between the field name and the field value of the variable field under the calculation type. The operator can be represented by a string. For example, equal represents equal; greater_than represents greater than; and so on. The logical control word is used to indicate the logical relationship, and the logical control word can be represented by a string. Further, in order to improve the recognition accuracy, different levels of logical control words can use different strings to represent the same logical relationship. For example, the AND logical relationship between condition types is represented by the string A, the AND logical relationship between variable fields is represented by the string B, and the AND logical relationship between variable field values is represented by the string C.
[0223] Specifically, when splitting the first constraint condition statement, the computer device identifies the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement. For example, the calculation type, the operator corresponding to the calculation type, and the logical control word can be identified from the first constraint condition statement through string matching. It can be understood that if a calculation type is identified at two positions in the first constraint condition statement, two calculation types are obtained.
[0224] The computer device combines the recognized calculation types and the operators corresponding to the calculation types into conditional types. The computer device determines the logical relationships between conditional types, the logical relationships between variable fields under conditional types, and the logical relationships between variable field values of variable fields based on the recognized logical control words. For example, the logical relationships between conditional types are determined based on the logical control words recognized between conditional types, the logical relationships between variable fields under the same conditional type are determined based on the logical control words recognized between variable fields under the same conditional type, and the logical relationships between variable field values of the same variable field are determined based on the logical control words recognized between variable field values of the same variable field.
[0225] For any one conditional type, the computer device generates a field calculation unit corresponding to the variable field based on the field information of the variable fields under the same conditional type in the first constraint condition statement, and obtains the field calculation units corresponding to the respective variable fields under the same conditional type. That is, in the field operation unit, there is only one variable field, indicating that the field operation unit only calculates this one variable field, and other variable fields will be calculated in other field operation units. Moreover, in the field operation unit, there is only one operator. Furthermore, the logical relationships between field calculation units are determined based on the logical relationships between variable fields, and the respective field calculation units and the logical relationships between field calculation units are combined into a sub-calculation unit corresponding to the conditional type. That is, the sub-calculation unit includes multiple different field calculation units, and the operators and calculation types corresponding to the respective field calculation units within the sub-calculation unit are the same. For example, "string equality calculation" will be placed in the same sub-calculation unit for calculation processing, "number greater than calculation" will be placed in the same sub-calculation unit for calculation processing, and "number equality calculation" will be placed in the same sub-calculation unit for calculation processing. The logical relationships between different field calculation units are also included within the sub-calculation unit.
[0226] Finally, the logical relationships between sub-calculation units are determined based on the logical relationships between conditional types, and the respective sub-calculation units and the logical relationships between sub-calculation units are combined into a total calculation unit corresponding to the first constraint condition statement.
[0227] In the above embodiments, the total calculation unit includes sub-calculation units corresponding to respective condition types and the logical relationships between the sub-calculation units. The sub-calculation unit includes field calculation units corresponding to respective variable fields under the same calculation type and operator and the logical relationships between the field calculation units. The field calculation unit includes the field information of the variable field. In this way, placing the field information of a variable field in the same field calculation unit and placing variable fields with the same calculation type and operator in the same sub-calculation unit can ensure translation efficiency and accuracy, avoid translation chaos, and also facilitate subsequent calculations during permission verification, improving calculation efficiency.
[0228] In one embodiment, identifying the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement includes:
[0229] Identifying the calculation type from the first constraint condition statement through respective calculation type subclasses under the calculation type base class to obtain each calculation type in the first constraint condition statement; identifying the operator from the first constraint condition statement through respective operator subclasses under the operator base class to obtain each operator in the first constraint condition statement; determining the operator corresponding to each calculation type respectively based on the positions of the calculation type and the operator in the first constraint condition statement; identifying the logical control word from the first constraint condition statement through respective logical control word subclasses under the logical control word base class to obtain each logical control word in the first constraint condition statement.
[0230] Among them, the calculation type base class is a base class created based on the general recognition logic among various calculation types. The calculation type subclass is a class inherited from the calculation type base class. One calculation type subclass is used to identify one calculation type. The calculation type subclass inherits the general recognition logic of the calculation type base class and also includes the individual recognition logic of a calculation type. For example, defining the general recognition position of the calculation type in the calculation type base class and defining the individual recognition string of the calculation type in the calculation type subclass.
[0231] The operator base class is a base class created based on the general recognition logic among various operators. The operator subclass is a class inherited from the operator base class. One operator subclass is used to identify one operator. The operator subclass inherits the general recognition logic of the operator base class and also includes the individual recognition logic of an operator. For example, defining the general recognition position of the operator in the operator base class and defining the individual recognition string of the operator in the operator subclass.
[0232] The base class of logical control words is a base class created based on the common recognition logic among various logical control words. The subclass of logical control words is a class that inherits from the base class of logical control words. A subclass of logical control words is used to recognize a type of logical control word. The subclass of logical control words inherits the common recognition logic of the base class of logical control words and also includes the personalized recognition logic of a type of logical control word. For example, the common recognition position of logical control words is defined in the base class of logical control words, and the personalized recognition string of logical control words is defined in the subclass of logical control words.
[0233] Specifically, the factory method pattern (i.e., the factory class method) is a creational design pattern. Its main role is to separate the code for creating products from the code for actually using products, and it can expand the code for product creation without affecting other code. Through the factory method pattern, the calculation type, the operator corresponding to the calculation type, and the logical control word are recognized from the first constraint condition statement. Through each calculation type subclass under the base class of calculation types, where a calculation type subclass is used to recognize a type of calculation type, the calculation types in the first constraint condition statement are recognized, and each calculation type in the first constraint condition statement is obtained. Through each operator subclass under the base class of operators, where an operator subclass is used to recognize a type of operator, the operators in the first constraint condition statement are recognized, and each operator in the first constraint condition statement is obtained. Furthermore, based on the positions of the calculation type and the operator in the first constraint condition statement, the operator corresponding to each calculation type is determined. For example, the operator adjacent to the recognized calculation type is used as the operator corresponding to the calculation type. Through each logical control word subclass under the base class of logical control words, where a logical control word subclass is used to recognize a type of logical control word, the logical control words in the first constraint condition statement are recognized, and each logical control word in the first constraint condition statement is obtained.
[0234] After recognizing the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement, the elements used in the sub - calculation unit and the field calculation unit are generated by loading the recognized calculation type, the operator corresponding to the calculation type, and the logical control word. That is, the elements used in the sub - calculation unit and the field calculation unit are generated by instantiating the recognized calculation type, the operator corresponding to the calculation type, and the logical control word. After instantiation, the data is loaded into the memory for real - time use.
[0235] In the above - mentioned embodiments, through each calculation type subclass under the base class of calculation types, the calculation types in the first constraint condition statement can be quickly and accurately recognized. Through each operator subclass under the base class of operators, the operators in the first constraint condition statement can be quickly and accurately recognized. Through each logical control word subclass under the base class of logical control words, the logical control words in the first constraint condition statement can be quickly and accurately recognized. This helps to quickly generate the total calculation unit corresponding to the first constraint condition statement.
[0236] In one embodiment, the permission data processing method further includes:
[0237] Inherit the calculation type base class to obtain the first subclass to be configured corresponding to the custom calculation type; add the recognition logic corresponding to the custom calculation type to the first subclass to be configured to obtain the calculation type subclass corresponding to the custom calculation type.
[0238] Inherit the operator base class to obtain the second subclass to be configured corresponding to the custom operator; add the recognition logic corresponding to the custom operator to the second subclass to be configured to obtain the operator subclass corresponding to the custom operator.
[0239] Among them, the custom calculation type is a calculation type customized according to business needs. The custom operator is a calculation type customized according to business needs.
[0240] Specifically, in addition to pre-establishing the calculation type subclasses corresponding to common calculation types, it is also possible to extend the calculation type subclasses corresponding to custom calculation types according to business needs. When extending the calculation type subclasses corresponding to custom calculation types, inherit the calculation type base class to obtain the first subclass to be configured corresponding to the custom calculation type. The first subclass to be configured inherits the general recognition logic in the calculation type base class, and then add the recognition logic corresponding to the custom calculation type to the first subclass to be configured to obtain the calculation type subclass corresponding to the custom calculation type. Subsequently, the custom calculation type can be recognized and loaded through the calculation type subclass corresponding to the custom calculation type.
[0241] In addition to pre-establishing the operator subclasses corresponding to common operators, it is also possible to extend the operator subclasses corresponding to custom operators according to business needs. When extending the operator subclasses corresponding to custom operators, inherit the operator base class to obtain the first subclass to be configured corresponding to the custom operator. The first subclass to be configured inherits the general recognition logic in the operator base class, and then add the recognition logic corresponding to the custom operator to the first subclass to be configured to obtain the operator subclass corresponding to the custom operator. Subsequently, the custom operator can be recognized and loaded through the operator subclass corresponding to the custom operator.
[0242] For example, if the business needs to add a custom calculation type "ip", the extension method is to inherit the calculation type base class when using the permission policy engine, rewrite the inherited recognition method according to the recognition logic of the "ip" calculation type, obtain the calculation type subclass corresponding to the custom calculation type "ip", complete the extension of the "ip" calculation type, and then the permission policy engine can recognize and load the "ip" calculation type through the calculation type subclass corresponding to the custom calculation type "ip".
[0243] In the above embodiments, the service can extend the calculation type subclass corresponding to the custom calculation type through the calculation type base class as needed, and extend the operator subclass corresponding to the custom operator through the operator base class, which can improve the scalability and generality of the permission policy syntax.
[0244] In one embodiment, based on the identified logical control words, determining the logical relationships between condition types, the logical relationships between variable fields under a condition type, and the logical relationships between variable field values of variable fields, includes:
[0245] When a first preset logical control word is identified in the first constraint condition statement, determining that the logical relationship between condition types is a logical relationship opposite to the first default logical relationship; when the first preset logical control word is not identified in the first constraint condition statement, determining that the logical relationship between condition types is the first default logical relationship;
[0246] When a second preset logical control word is identified in the first constraint condition statement, determining that the logical relationship between variable fields under a condition type is a logical relationship opposite to the second default logical relationship; when the second preset logical control word is not identified in the first constraint condition statement, determining that the logical relationship between variable fields under a condition type is the second default logical relationship;
[0247] When a third preset logical control word is identified in the first constraint condition statement, determining that the logical relationship between variable field values of variable fields is a logical relationship opposite to the third default logical relationship; when the third preset logical control word is not identified in the first constraint condition statement, determining that the logical relationship between variable field values of variable fields is the third default logical relationship.
[0248] Wherein, the first preset logical control word, the second preset logical control word, and the third preset logical control word are preset and different logical control words. The first default logical relationship is the default logical relationship between sub-calculation units, that is, the default logical relationship between condition types. The second default logical relationship is the default logical relationship between field calculation units, that is, the default logical relationship between variable fields. The third default logical relationship is the default logical relationship within the field calculation unit, that is, the default logical relationship between variable field values.
[0249] Specifically, the logical relationship between condition types is controlled by a first preset logical control word. When the first preset logical control word is recognized in the first constraint condition statement, it is determined that the logical relationship between condition types is a logical relationship that is logically opposite to the first default logical relationship; when the first preset logical control word is not recognized in the first constraint condition statement, it is determined that the logical relationship between condition types is the first default logical relationship. For example, if the first default logical relationship is and, when the first preset logical control word is recognized, it is determined that the logical relationship between condition types is or, and when the first preset logical control word is not recognized, it is determined that the logical relationship between condition types is and.
[0250] For example, the constraint condition statement is as follows:
[0251] {
[0252] " condition" : {
[0253] "string_euqal:operator_or" :{
[0254] "name" :
[0255] "a"
[0257] },
[0258] "numeric_less_than " : {
[0259] “manage_level”: 10
[0262] }
[0263] }
[0264] }
[0265] Among them, operator_or is the first preset logical control word, which is used to indicate that the logical relationship between string_euqal (string equality) and numeric_less_than (number less than) is or, rather than the default and. The meaning of the constraint condition statement is that the user name is a or the user management rank is less than 10.
[0266] The logical relationship between variable fields is controlled by a second preset logical control word. When the second preset logical control word is recognized in the first constraint condition statement, it is determined that the logical relationship between variable fields is a logical relationship that is logically opposite to the second default logical relationship; when the second preset logical control word is not recognized in the first constraint condition statement, it is determined that the logical relationship between variable fields is the second default logical relationship.
[0267] For example, the constraint condition statement is as follows:
[0268] {
[0269] "condition": {
[0270] "string_euqal: for_any_value": {
[0271] "name":
[0272] "a",
[0273] ,
[0274] "ip":
[0275] "111.111.1.1",
[0276] "111.111.1.2"
[0278] }
[0279] }
[0280] }
[0281] Among them, for_any_value is the second preset logical control word, which is used to indicate that the logical relationship between the variable field name and the variable field ip is and, rather than the default or. The meaning of the constraint condition statement is that the user name is a and the ip is 111.111.1.1 or 111.111.1.2.
[0282] The logical relationship between variable field values is controlled by the third preset logical control word. When the third preset logical control word is recognized in the first constraint condition statement, it is determined that the logical relationship between variable field values is the logical relationship opposite to the third default logical relationship; when the third preset logical control word is recognized in the first constraint condition statement, it is determined that the logical relationship between variable field values is the third default logical relationship.
[0283] For example, the constraint condition statement is as follows:
[0284] {
[0285] "condition": {
[0286] "string_euqal: for_all_value": {
[0287] "tag":
[0288] "Operating product & Product A",
[0289] "Person in Charge & Zhang San"
[0290] ,
[0291] "ip" :
[0292] "111.111.1.1",
[0294] }
[0295] }
[0296] }
[0297] Among them, for_all_value is the third preset logical control word, which is used to indicate that the logical relationship between the field values of the variable field tag is and, rather than the default or. The meaning of the constraint condition statement is that the operating product is A, the person in charge is Zhang San, and the ip is 111.111.1.1.
[0298] In the above embodiments, different preset logical control words are used to control logical relationships at different levels, which can avoid logical confusion. There is a default logical relationship in the constraint condition statement. By adding a preset logical control word in the constraint condition statement, the logical relationship can be modified from the default logical relationship to a logical relationship that is logically opposite to the default logical relationship. This can effectively reduce the code amount of the constraint condition statement and reduce the storage pressure.
[0299] In one embodiment, for any one condition type, a field calculation unit corresponding to the variable field is generated based on the field information of the variable field under the same condition type in the first constraint condition statement. The logical relationship between the field calculation units is determined based on the logical relationship between the variable fields. The field calculation units and the logical relationship between the field calculation units are combined to form a sub-calculation unit corresponding to the condition type, including:
[0300] For any one variable field under the same condition type, the field name, field value, logical relationship between the field values, operator in the condition type, and translator identifier of the syntax translator corresponding to the second engine in the first constraint condition statement are combined to form a field calculation unit corresponding to the variable field; the logical relationship between the field calculation units is determined based on the logical relationship between the variable fields; for the same condition type, the field calculation units, the logical relationship between the field calculation units, and the translator identifier are combined to form a sub-calculation unit corresponding to the condition type.
[0301] Among them, the translator identifier is an identifier used to uniquely identify the syntax translator. For example, the translator identifier can be the call address of the syntax translator.
[0302] Specifically, the field calculation unit corresponding to a variable field includes the field name of the variable field in the first constraint condition statement, each field value, the logical relationship between the field values, the operator corresponding to the calculation type to which the variable field belongs, and the translator identifier of the syntax translator corresponding to the second engine. For each variable field under the same condition, a field calculation unit corresponding to each variable field is generated, and each field calculation unit, the logical relationship between the field calculation units, and the translator identifier of the syntax translator corresponding to the second engine are combined to form a sub-calculation unit corresponding to the condition type.
[0303] In the above embodiment, the field calculation unit corresponding to the variable field includes not only the field information of the variable field, but also the translator identifier of the syntax translator corresponding to the second engine. When translation is required, the syntax translator corresponding to the second engine can be automatically called through the translator identifier in the field calculation unit, and the field calculation unit can be quickly translated into a field constraint statement. The sub-calculation unit includes not only the field calculation unit and the logical relationship between the field calculation units, but also the translator identifier of the syntax translator corresponding to the second engine. When translation is required, based on the logical relationship between the field calculation units, the field constraint condition statements corresponding to each field calculation unit can be quickly combined.
[0304] In one embodiment, combining each sub-calculation unit and the logical relationship between the sub-calculation units to form a total calculation unit corresponding to the first constraint condition statement includes:
[0305] Combining each sub-calculation unit, the logical relationship between the sub-calculation units, and the translator identifier to form a total calculation unit corresponding to the first constraint condition statement.
[0306] Specifically, the total calculation unit includes not only each sub-calculation unit and the logical relationship between the sub-calculation units, but also the translator identifier of the syntax translator corresponding to the second engine. When translation is required, the syntax translator corresponding to the second engine can be automatically called through the translator identifier in the total calculation unit, and based on the logical relationship between the sub-calculation units, each sub-constraint condition statement can be quickly combined to obtain the second constraint condition statement corresponding to the first constraint condition statement.
[0307] In one embodiment, as Figure 7As shown in the figure, the method of this application splits the constraint condition statement (i.e., the calculation module) into the smallest calculation unit (i.e., the field calculation unit) and the sub-calculation unit. The smallest calculation unit includes: field name (used to represent the variable used in the calculation, for example, the network is represented by "network", and the employee account is represented by "staffname"), field value (used to represent the value of the variable used in the calculation, for example, the value of the network can be "Tencent-WiFi", and the values of the enterprise WeChat accounts can be "a", "b", and there can be multiple field values), operator (used to represent the operation relationship between the field name and the field value, generally including =,!=, >=, <=, etc.), logical relationship (the logical relationship controlled by the logical control word, used to represent the logical relationship between the field name and the field value, for example, "and" means that the field name variable must be equal to all field values, and "or" means that as long as the field name variable is equal to one field value), and syntax translator identifier (used to identify the syntax translator, which is used to output other syntax according to the field name, field value, operator, and logical relationship, for example, staffname == "a" || staffname == "b").
[0308] In the smallest operation unit, there is only one field name, indicating that the smallest calculation unit only calculates this one field name, and other field names will be calculated in other smallest calculation units. There is a translator identifier of the syntax translator in the smallest calculation unit, and the syntax translator will integrate the elements in the smallest calculation unit and output the translation result of the smallest calculation unit.
[0309] The sub-calculation unit is composed of multiple different smallest calculation units. The operators and calculation types of the smallest calculation units within the sub-calculation unit are the same. For example, for the "equal calculation of strings", they will all be placed in a sub-calculation unit for calculation and processing. There is also a logical relationship within the sub-calculation unit to control the logical relationship between different smallest calculation units (and logical relationship, or logical relationship). There is also a translator identifier of the syntax translator in the sub-calculation unit, and the syntax translator will integrate the translation results of the smallest calculation units according to the logical relationship in the sub-calculation unit and output the translation result of the sub-calculation unit. For example, network==”Tencent-WiFi” && (staffname == “a” || staffname == “b”).
[0310] In an authentication scenario, the syntax translator can be the syntax translator corresponding to the rules engine, and the syntax translator corresponding to the rules engine is used to output the executable syntax for computer programs. The calculation module of a permission policy statement (i.e., the constraint condition statement in the permission policy statement) can be split into multiple different sub-calculation units. Each calculation module contains logical relationships and the translator identifier of the syntax translator inside, and the translator identifier of the syntax translator is also in the sub-calculation unit. The syntax translator outputs the executable statements for computer programs according to the smallest calculation unit, integrates the executable statements of these smallest calculation units according to the logical relationships between the smallest calculation units to output the executable statements of the sub-calculation unit for computer programs, and integrates the executable statements of these sub-calculation units according to the logical relationships between the sub-calculation units to output the executable statements of the calculation module for computer programs. Finally, the executable statements of the calculation module are processed through the rules engine to obtain the final calculation result to determine the authentication result (authorization result).
[0311] In one embodiment, the scenarios applicable to the permission policy syntax are mainly access control scenarios, especially access control management in complex scenarios such as data authentication and cloud resource access control. For example, verifying whether a certain user has the permission to expand a certain cloud resource at a certain moment in a certain office network, verifying whether a certain user has the query / update permission for a certain field in a certain table in a certain database, etc. In these complex verification scenarios, it is necessary to rely on the permission policy syntax to create complex permission policies to achieve resource access control in various application scenarios to protect enterprise resource security, data security, user privacy security, etc.
[0312] Reference Figure 8, traditional permission policy syntax usually directly and forcibly defines the logical relationships in the constraint condition statements by default. In constraint condition statement 1 (i.e., Condition1), the logical relationship between different variables (i.e., between key1 and key2) is and, and the logical relationship between different variable values of the same variable (i.e., between value1a, value1b, and value1c) is or. The logical relationship between different constraint condition statements (i.e., between Condition1 and Condition2) is and. This forced definition of logical relationships obviously has the drawback of imperfect syntax logic. The support for the combination relationship between and and or is not perfect enough, which may lead to situations where some special logical scenarios cannot be satisfied. This forced definition of logical relationships obviously has the drawback of bloated syntax structure, which easily leads to a great deal of redundancy in the data of permission policy statements. In access control management with tens of millions of data volume, this redundant data will cause a huge waste of storage resources, and it is even possible that the configurable permission policies will be restricted due to the limited length of a permission policy statement. The data structure of traditional permission policy syntax generally uses json. Limited by the limitations of the json hash dictionary structure (there cannot be two identical keys in one level of the Json hash dictionary), it may lead to situations where some special logical scenarios cannot be satisfied. For example, it cannot satisfy the following scenario: The tags of cloud resources must simultaneously meet the two conditions of ("operation product & product A", "person in charge & sky"). The scalability of traditional permission policy syntax is weak. If new calculation logics (such as new calculation types) need to be added, a large amount of code needs to be modified, and the syntax usually embeds specific business logic fields, with poor generality.
[0313] The method of this application proposes a new permission policy syntax. In the constraint condition part of the permission policy syntax, logical control words are designed to control various logical relationships in the constraint conditions. Based on the idea of "mutually independent and completely exhaustive", the calculation module in the permission policy syntax is split into the smallest calculation units, and sub-calculation units are obtained by combining the smallest calculation units. The combined calculation of the sub-calculation units can be used to determine the permission verification result of the permission policy syntax, solving the problems of defective logic and bloated syntax structure in traditional permission policy syntax. Moreover, the generation of each smallest calculation unit in the method of this application is through a factory class method, and the factory class method is very convenient for the business to expand its own custom calculation types and operators, solving the problem of weak scalability of traditional permission policy syntax. Moreover, the role of the syntax translator can be to translate into a syntax executable by a computer program or to translate into the permission policy syntax of other platforms. The method of this application has strong generality.
[0314] In a specific embodiment, the method of this application can be applied to the authentication scenario. Refer toFigure 9 When a user initiates authentication, the permission policy engine (which can also be called the permission policy matching engine) will load the permission policy statements bound to the user and integrate them (the user may have hundreds or thousands of permission policy statements, and the system will deduplicate and integrate these permission policy statements internally to facilitate subsequent calculation modules for syntax translation and calculation). Subsequently, it will load the calculation modules in the integrated permission policy statements. The calculation module will, according to the integrated permission policy statements, respectively identify and load the calculation types, operators, and their logical relationships in the statements through factory class methods to generate a total calculation unit. Finally, the syntax translator will translate the total calculation unit into a rule statement that the rule engine can recognize, input the rule statement and the user's attribute information into the rule engine to obtain the authentication result. It can be understood that the translated rule statement can be stored for quick authentication the next time. If the permission policy statements bound to the user are updated later (deleted, added, or modified), the updated permission policy statements can be syntactically translated to obtain new rule statements, and the new rule statements can be used to replace the old rule statements and stored to ensure the accuracy of authentication.
[0315] For example, if the permission configuration information is "Among people with a management rank > 10, except for the two people 'a' and 'b', everyone else must be within the company's office network to view and edit all documents in Application A", based on the permission policy syntax of this application, the permission configuration information is converted into the following permission policy statement:
[0316] {
[0317] "Effect": "Allow",
[0318] "Actions":
[0319] "View",
[0320] "Edit"
[0321] ,
[0322] "Resources":
[0323] "All documents in Application A"
[0324] ,
[0325] "Condition":{
[0326] "string_equal:for_any_value":{
[0327] "name":
[0328] "a",
[0329] "b",
[0331] "Current network":
[0332] "Company-WIFI"
[0334] }
[0335] "Numeric greater than": {
[0336] "Manage level": 10
[0339] }
[0340] }
[0341] }
[0342] Load permission policy statements through the permission policy matching engine.
[0343] Through the factory class method, split the permission policy statements to generate corresponding total calculation units. The total calculation unit includes two sub-calculation units X and Y. Among them, the calculation type of sub-calculation unit X is string type, the operator is equal, and the calculation type of sub-calculation unit Y is numeric type, and the operator is greater than.
[0344] There are two minimum calculation units x1 and x2 in sub-calculation unit X. Among them, the field name of x1 is name, the field values are "a" and "b", the operator is =, the logical relationship is or, and the field name of x2 is network, the field value is "Company-WIFI", and the operator is =. Due to the relationship of the logical control word "for_any_value", the logical relationship between x1 and x2 changes from and to or.
[0345] There is one minimum calculation unit y in sub-calculation unit Y. The field name of y is manage level, the field value is 10, and the operator is >.
[0346] Perform syntax translation on the total computing unit through a syntax translator. Starting from x1, the translation of x1 outputs staffname == “a” || staffname == “b”, and the translation of x2 outputs network == “Company-WIFI”. Integrate the translation results of x1 and x2 according to the logical control word “for_any_value” (i.e., the logical relationship or), and output (staffname == “a” || staffname == “b”) || network == “Company-WIFI”.
[0347] Since the sub-computing unit Y has only one minimum computing unit y, the translation of y outputs manage_level > 10.
[0348] Integrate the translation results of sub-computing units X and Y according to the logical relationship between them, and finally output the rule: ((staffname == “a” || staffname == “b”) || network == “Tencent-WiFi”) && manage_level > 10.
[0349] Pass the translated rule to the rule engine, and the rule engine initializes according to this rule and waits for the relevant input data of the external authentication request.
[0350] If user a (management level is 11) requests to edit the A application document on the external network, input the relevant attribute information of user a (staffname is a, network is the external network, manage_level is 11) into the rule engine. The rule engine will run [((“a” == “a” || “a” == “b”) || “external network” == “Company-WIFI”) && 11 > 10], ((true || false) || false) && true) and the logical execution is successful, returning authentication success, thus allowing user a to edit the A application document.
[0351] If user c (management level is 11) requests to edit the A application document on the external network, input the relevant attribute information of user c (staffname is c, network is the external network, manage_level is 11) into the rule engine. The rule engine will run [((“c” == “a” || “c” == “b”) || “external network” == “Company-WIFI”) && 11 > 10], ((false || false) || false) && true) and the logical execution fails, returning authentication failure, thus prohibiting user c from editing the A application document.
[0352] The entire authentication process adopts the idea of divide and conquer, splitting the calculation logic and passing it layer by layer. The logic is "mutually independent and completely exhaustive". Through logical control words, a very complete permission policy syntax mechanism is established, solving the problems of defective logic, bloated syntax structure, and weak scalability in traditional permission policy syntax.
[0353] The method of this application can be applied to various authentication scenarios (such as application layer authentication, data layer authentication, cloud resource authentication, etc.) to achieve a reliable and efficient permission verification process.
[0354] In a specific embodiment, the method of this application can be applied to the permission synchronization scenario for cloud resources. Users can configure permission policy statements based on the permission policy syntax of this application. Refer to Figure 10 , when a user initiates permission synchronization (i.e., permission policy synchronization), the permission policy engine will load the permission policy statements to be synchronized, load the calculation modules in the permission policy statements, and the calculation modules will respectively identify and load the calculation types, operators, and their logical relationships in the statements through factory class methods to generate a total calculation unit. Finally, the total calculation unit will be translated into a permission policy statement that can be recognized by other cloud platforms through a syntax translator, and the translated permission policy statement will be stored in other cloud platforms.
[0355] For example, a company has machine resources on cloud platform A and also has machine resources on cloud platform B. When configuring permission policies through the method of this application, there is no need to configure permission policies on cloud platform A and cloud platform B separately. The permission policies can be synchronized to multiple cloud platforms with one click.
[0356] The method of this application provides a highly general and extensible permission policy syntax. Based on this syntax, a permission policy engine is implemented, which can easily support special calculation types and operators of the business. The permission policy matching engine is decoupled from the business logic.
[0357] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0358] Based on the same inventive concept, an embodiment of the present application further provides a permission data processing apparatus for implementing the above-mentioned permission data processing method. The solution provided by this apparatus for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the permission data processing apparatus provided below can refer to the limitations on the permission data processing method in the foregoing, and will not be elaborated here.
[0359] In one embodiment, as Figure 11 shown, a permission data processing apparatus is provided, including: an acquisition module 1102, a splitting module 1104, and a translation module 1106, where:
[0360] The acquisition module 1102 is configured to acquire a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of the target permission in the first engine.
[0361] The splitting module 1104 is configured to split the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units corresponding to each condition type in the first constraint condition statement, and the logical relationship between the sub-calculation units. The condition type includes a calculation type and an operator corresponding to the calculation type; the sub-calculation unit includes field calculation units corresponding to each variable field under the same condition type in the first constraint condition statement, and the logical relationship between the field calculation units. The field calculation unit includes the field information of the variable field in the first constraint condition statement. The logical relationship in the total calculation unit is determined based on the logical control word in the first constraint condition statement;
[0362] The translation module 1106 is configured to, for any one sub-calculation unit, translate each field calculation unit included in the sub-calculation unit into a field constraint condition statement through the syntax translator corresponding to the second engine, and combine the field constraint condition statements corresponding to each field calculation unit based on the logical relationship between the field calculation units to obtain a sub-constraint condition statement corresponding to the sub-calculation unit;
[0363] The translation module 1106 is further configured to, through the syntax translator, combine each sub-constraint condition statement based on the logical relationship between the sub-calculation units to obtain a second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
[0364] In one embodiment, the first constraint condition statement is a constraint condition statement in the permission policy statement corresponding to the first engine for the target permission. The permission data processing apparatus is further configured to:
[0365] Receive a permission configuration request for the first engine; the permission configuration request carries the permission configuration information of the target permission;
[0366] Identify the permission effect configuration information from the permission configuration information, and convert the permission effect configuration information into a permission effect statement based on the permission policy syntax corresponding to the first engine; the permission effect statement is used to indicate the effect of the target permission.
[0367] Identify the constraint condition configuration information from the permission configuration information, and convert the constraint condition configuration information into a constraint condition statement based on the permission policy syntax corresponding to the first engine; the constraint condition statement is used to indicate the effective condition of the target permission, and the permission policy syntax corresponding to the first engine controls the logical relationship between statements in the constraint condition statement through a preset set of logical control words.
[0368] Combine the permission effect statement and the constraint condition statement into the permission policy statement corresponding to the target permission in the first engine.
[0369] In one embodiment, the first engine is a permission policy engine and the second engine is a rules engine. The obtaining module 1102 is further configured to:
[0370] Receive an authentication request carrying an authentication object identifier.
[0371] In the first engine, obtain the permission policy statement corresponding to the authentication object identifier, and use the constraint condition statement in the permission policy statement as the first constraint condition statement.
[0372] The method further includes:
[0373] Obtain the variable field from the first constraint condition statement, and obtain the variable field value of the authentication object identifier on the variable field as the authentication field value of the variable field.
[0374] Input the authentication field value of the variable field and the second constraint condition statement into the rules engine for calculation, obtain the calculation result, and determine the authentication result corresponding to the authentication object identifier according to the calculation result.
[0375] In one embodiment, the obtaining module 1102 is further configured to:
[0376] Obtain multiple permission policy statements bound to the authentication object identifier.
[0377] Deduplicate and integrate the multiple permission policy statements to obtain the comprehensive permission policy statement corresponding to the authentication object identifier.
[0378] Use the constraint condition statement in the comprehensive permission policy statement as the first constraint condition statement.
[0379] In one embodiment, the first engine is the permission policy engine of the first platform, and the second engine is the permission policy engine of the second platform. The obtaining module 1102 is further configured to:
[0380] Receive a permission policy synchronization request for the first platform and the second platform;
[0381] Obtain a first permission policy statement from the permission policy engine of the first platform, and use the constraint condition statement in the first permission policy statement as the first constraint condition statement;
[0382] The method further includes:
[0383] Generate a second permission policy statement based on the second constraint condition statement, and store the second permission policy statement in the permission policy engine of the second platform.
[0384] In one embodiment, the splitting module 1104 is further configured to:
[0385] Identify a calculation type, an operator corresponding to the calculation type, and a logical control word from the first constraint condition statement; the operator is used to indicate the operation relationship between the field name and the field value of the variable field under the calculation type;
[0386] Form a condition type by combining the identified calculation type and the operator corresponding to the calculation type, and determine the logical relationship between condition types, the logical relationship between variable fields under the condition type, and the logical relationship between variable field values of the variable fields based on the identified logical control word;
[0387] For any one condition type, generate a field calculation unit corresponding to the variable field based on the field information of the variable fields under the same condition type in the first constraint condition statement, determine the logical relationship between the field calculation units based on the logical relationship between the variable fields, and form a sub-calculation unit corresponding to the condition type by combining each field calculation unit and the logical relationship between the field calculation units; the field calculation unit corresponding to the variable field includes the logical relationship between the variable field values of the variable fields;
[0388] Determine the logical relationship between the sub-calculation units based on the logical relationship between the condition types, and form a total calculation unit corresponding to the first constraint condition statement by combining each sub-calculation unit and the logical relationship between the sub-calculation units.
[0389] In one embodiment, the splitting module 1104 is further configured to:
[0390] Identify calculation types from the first constraint condition statement through each calculation type subclass under the calculation type base class, and obtain each calculation type in the first constraint condition statement;
[0391] Identify operators from the first constraint condition statement through each operator subclass under the operator base class, and obtain each operator in the first constraint condition statement;
[0392] Determine the operators corresponding to each calculation type based on the positions of the calculation type and the operator in the first constraint condition statement.
[0393] Identify the logical control words from the first constraint condition statement through each logical control word subclass under the logical control word base class, and obtain each logical control word in the first constraint condition statement.
[0394] In one embodiment, the permission data processing device is further configured to:
[0395] Inherit the calculation type base class to obtain the first subclass to be configured corresponding to the custom calculation type;
[0396] Add the recognition logic corresponding to the custom calculation type to the first subclass to be configured to obtain the calculation type subclass corresponding to the custom calculation type;
[0397] Inherit the operator base class to obtain the second subclass to be configured corresponding to the custom operator;
[0398] Add the recognition logic corresponding to the custom operator to the second subclass to be configured to obtain the operator subclass corresponding to the custom operator.
[0399] In one embodiment, the splitting module 1104 is further configured to:
[0400] When the first preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between the condition types is a logical relationship that is logically opposite to the first default logical relationship; when the first preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between the condition types is the first default logical relationship;
[0401] When the second preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between the variable fields under the condition type is a logical relationship that is logically opposite to the second default logical relationship; when the second preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between the variable fields under the condition type is the second default logical relationship;
[0402] When the third preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between the variable field values of the variable field is a logical relationship that is logically opposite to the third default logical relationship; when the third preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between the variable field values of the variable field is the third default logical relationship.
[0403] In one embodiment, the splitting module 1104 is further configured to:
[0404] For any variable field under the same condition type, a field calculation unit corresponding to the variable field is formed by the field name, field value, logical relationship between field values in the first constraint condition statement, operator in the condition type, and translator identifier of the syntax translator corresponding to the second engine.
[0405] Determine the logical relationship between field calculation units based on the logical relationship between variable fields.
[0406] For the same condition type, each field calculation unit, the logical relationship between field calculation units, and the translator identifier are combined to form a sub-calculation unit corresponding to the condition type.
[0407] In one embodiment, the splitting module 1104 is further configured to:
[0408] Combine each sub-calculation unit, the logical relationship between sub-calculation units, and the translator identifier to form a total calculation unit corresponding to the first constraint condition statement.
[0409] When the above permission data processing device translates the constraint condition statement indicating the effective condition of the target permission from the syntax applicable to the first engine to the syntax applicable to the second engine, it first splits the first constraint condition statement to generate a total calculation unit corresponding to the constraint condition statement, splits the calculation logic in the constraint condition statement, and passes it layer by layer to generate field calculation units. The sub-calculation units are obtained by combining the field calculation units, and the total calculation unit is obtained by combining the sub-calculation units. Using the idea of divide and conquer, the total calculation unit not only has the key elements in the first constraint condition statement but also has the coherence between the elements. Furthermore, through the syntax translator applicable to the second engine, the total calculation unit can be quickly translated into a second constraint condition statement applicable to the second engine, improving the conversion efficiency of permission information between different syntaxes.
[0410] Each module in the above permission data processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0411] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 12As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as a syntax translator and permission policy statements. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for processing permission data.
[0412] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 13 shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a method for processing permission data. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the computer device housing, or an external keyboard, touchpad, or mouse, etc.
[0413] Those skilled in the art can understand that Figure 12 、 13The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0414] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0415] In one embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0416] In one embodiment, a computer program product is provided, and the computer program product includes a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0417] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0418] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0419] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0420] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for processing permission data, characterized in that, The method includes: Obtaining a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of the target permission in the first engine; Splitting the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units corresponding to respective condition types in the first constraint condition statement, and the logical relationship between the sub-calculation units, where the condition types include calculation types and operators corresponding to the calculation types; the sub-calculation unit includes field calculation units corresponding to respective variable fields under the same condition type in the first constraint condition statement, and the logical relationship between the field calculation units, the field calculation unit includes the field information of the variable field in the first constraint condition statement, and the logical relationship in the total calculation unit is determined based on the logical control words in the first constraint condition statement; For any one sub-calculation unit, through the syntax translator corresponding to the second engine, translating each field calculation unit included in the sub-calculation unit into a field constraint condition statement respectively, and combining the field constraint condition statements corresponding to each field calculation unit based on the logical relationship between the field calculation units to obtain a sub-constraint condition statement corresponding to the sub-calculation unit; Through the syntax translator, combining each sub-constraint condition statement based on the logical relationship between the sub-calculation units to obtain a second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target permission in the second engine.
2. The method according to claim 1, characterized in that The first constraint condition statement is the constraint condition statement in the permission policy statement corresponding to the first engine for the target permission; The method further includes: Receiving a permission configuration request for the first engine; the permission configuration request carries the permission configuration information of the target permission; Identifying permission role configuration information from the permission configuration information, and converting the permission role configuration information into a permission role statement based on the permission policy syntax corresponding to the first engine; the permission role statement is used to indicate the role of the target permission; Identifying constraint condition configuration information from the permission configuration information, and converting the constraint condition configuration information into a constraint condition statement based on the permission policy syntax corresponding to the first engine; the constraint condition statement is used to indicate the effective condition of the target permission, and the permission policy syntax corresponding to the first engine controls the logical relationship between statements in the constraint condition statement through a preset set of logical control words; Combining the permission role statement and the constraint condition statement to form the permission policy statement corresponding to the first engine for the target permission.
3. The method according to claim 1, characterized in that The first engine is a permission policy engine, and the second engine is a rule engine. The obtaining of the first constraint condition statement includes: Receiving an authentication request carrying an authentication object identifier; In the first engine, obtaining the permission policy statement corresponding to the authentication object identifier, and using the constraint condition statement in the permission policy statement as the first constraint condition statement; The method further includes: Obtain a variable field from the first constraint condition statement, and obtain the variable field value of the authentication object identifier on the variable field as the authentication field value of the variable field; Input the authentication field value of the variable field and the second constraint condition statement into the rule engine for calculation to obtain a calculation result, and determine the authentication result corresponding to the authentication object identifier according to the calculation result.
4. The method according to claim 3, characterized in that, The obtaining the permission policy statement corresponding to the authentication object identifier includes: Obtain multiple permission policy statements bound to the authentication object identifier; Deduplicate and integrate the multiple permission policy statements to obtain the comprehensive permission policy statement corresponding to the authentication object identifier; Use the constraint condition statement in the comprehensive permission policy statement as the first constraint condition statement.
5. The method according to claim 1, characterized in that, The first engine is the permission policy engine of the first platform, and the second engine is the permission policy engine of the second platform. The obtaining the first constraint condition statement includes: Receive a permission policy synchronization request for the first platform and the second platform; Obtain a first permission policy statement from the permission policy engine of the first platform, and use the constraint condition statement in the first permission policy statement as the first constraint condition statement; The method further includes: Generate a second permission policy statement based on the second constraint condition statement, and store the second permission policy statement in the permission policy engine of the second platform.
6. The method according to claim 1, wherein The splitting the first constraint condition statement to generate the total calculation unit corresponding to the first constraint condition statement includes: Identify the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement; the operator is used to indicate the operation relationship between the field name and the field value of the variable field under the calculation type; Form a condition type by combining the identified calculation type and the operator corresponding to the calculation type, and determine the logical relationship between condition types, the logical relationship between variable fields under the condition type, and the logical relationship between variable field values of the variable fields based on the identified logical control word; For any one condition type, generate a field calculation unit corresponding to the variable field based on the field information of the variable fields under the same condition type in the first constraint condition statement, determine the logical relationship between the field calculation units based on the logical relationship between the variable fields, and form a sub-calculation unit corresponding to the condition type by combining each field calculation unit and the logical relationship between the field calculation units; the field calculation unit corresponding to the variable field includes the logical relationship between the variable field values of the variable fields; Determine the logical relationship between the sub-calculation units based on the logical relationship between the condition types, and form the total calculation unit corresponding to the first constraint condition statement by combining each sub-calculation unit and the logical relationship between the sub-calculation units.
7. The method according to claim 6, wherein The identifying the calculation type, the operator corresponding to the calculation type, and the logical control word from the first constraint condition statement includes: Identify the calculation type from the first constraint condition statement through each calculation type subclass under the calculation type base class to obtain each calculation type in the first constraint condition statement; Identify operators from the first constraint condition statement through each operator subclass under the operator base class to obtain each operator in the first constraint condition statement; Determine the operators corresponding to the respective calculation types based on the calculation type and the positions of the operators in the first constraint condition statement; Identify logical control words from the first constraint condition statement through each logical control word subclass under the logical control word base class to obtain each logical control word in the first constraint condition statement.
8. The method according to claim 7, wherein The method further includes: Inherit the calculation type base class to obtain a first subclass to be configured corresponding to the custom calculation type; Add the recognition logic corresponding to the custom calculation type to the first subclass to be configured to obtain a calculation type subclass corresponding to the custom calculation type; Inherit the operator base class to obtain a second subclass to be configured corresponding to the custom operator; Add the recognition logic corresponding to the custom operator to the second subclass to be configured to obtain an operator subclass corresponding to the custom operator.
9. The method according to claim 6, characterized in that, The determining the logical relationship between condition types, the logical relationship between variable fields under a condition type, and the logical relationship between variable field values of a variable field based on the recognized logical control words includes: When a first preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between condition types is a logical relationship opposite to the first default logical relationship; when the first preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between condition types is the first default logical relationship; When a second preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between variable fields under a condition type is a logical relationship opposite to the second default logical relationship; when the second preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between variable fields under a condition type is the second default logical relationship; When a third preset logical control word is recognized in the first constraint condition statement, determine that the logical relationship between variable field values of a variable field is a logical relationship opposite to the third default logical relationship; when the third preset logical control word is not recognized in the first constraint condition statement, determine that the logical relationship between variable field values of a variable field is the third default logical relationship.
10. The method according to claim 6, wherein For any one condition type, generating a field calculation unit corresponding to the variable field based on the field information of the variable fields under the same condition type in the first constraint condition statement, determining the logical relationship between the field calculation units based on the logical relationship between the variable fields, and forming a sub-calculation unit corresponding to the condition type by each field calculation unit and the logical relationship between the field calculation units, includes: For any one variable field under the same condition type, form a field calculation unit corresponding to the variable field by the field name, field value, logical relationship between the field values, operator in the condition type, and translator identifier of the syntax translator corresponding to the second engine in the first constraint condition statement; Determine the logical relationship between field calculation units based on the logical relationship between variable fields; For the same condition type, form a sub-calculation unit corresponding to the condition type by combining each field calculation unit, the logical relationship between the field calculation units, and the translator identifier.
11. The method according to claim 6, wherein The step of forming the total calculation unit corresponding to the first constraint condition statement by combining each sub-calculation unit and the logical relationship between the sub-calculation units includes: Form the total calculation unit corresponding to the first constraint condition statement by combining each sub-calculation unit, the logical relationship between the sub-calculation units, and the translator identifier.
12. A permission data processing device, characterized in that, The device includes: An acquisition module, configured to acquire a first constraint condition statement; the first constraint condition statement is used to indicate the effective condition of the target privilege in the first engine; A splitting module, configured to split the first constraint condition statement to generate a total calculation unit corresponding to the first constraint condition statement; the total calculation unit includes sub-calculation units respectively corresponding to each condition type in the first constraint condition statement, and the logical relationship between the sub-calculation units, the condition type includes a calculation type and an operator corresponding to the calculation type; the sub-calculation unit includes field calculation units respectively corresponding to each variable field under the same condition type in the first constraint condition statement, and the logical relationship between the field calculation units, the field calculation unit includes the field information of the variable field in the first constraint condition statement, and the logical relationship in the total calculation unit is determined based on the logical control word in the first constraint condition statement; A translation module, configured to, for any one sub-calculation unit, translate each field calculation unit included in the sub-calculation unit into a field constraint condition statement through a syntax translator corresponding to the second engine, and combine the field constraint condition statements corresponding to each field calculation unit based on the logical relationship between the field calculation units to obtain a sub-constraint condition statement corresponding to the sub-calculation unit; The translation module is further configured to, through the syntax translator, combine each sub-constraint condition statement based on the logical relationship between the sub-calculation units to obtain a second constraint condition statement corresponding to the first constraint condition statement; the second constraint condition statement is used to indicate the effective condition of the target privilege in the second engine.
13. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 11 are implemented.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 11 are implemented.