Data access method and device, electronic equipment and storage medium

By obtaining target permission parameters and assigning identity credentials in the data analysis platform, the problem of excessive data access rights caused by users directly connecting to the Presto cluster is solved, and the security of data access is enhanced.

CN120470015APending Publication Date: 2025-08-12DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510383401.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the data analysis platform, after logging in, the user directly connects to the Presto cluster for data query, resulting in excessive data access permissions, which seriously threatens the security of business data.

Method used

After the user logs into the data analysis platform, he obtains the target permission parameters, determines whether to allow access to data based on the permission parameters, and assigns target identity credentials to the user. Through the data query engine, he uses the identity credentials to access the data cluster, and adds permission verification to limit the scope of data call.

Benefits of technology

Improves the security of the data access process, ensures that only specific users can access data in the target data cluster, and enhances the security of data resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120470015A_ABST
    Figure CN120470015A_ABST
Patent Text Reader

Abstract

The invention provides a data access method and device, electronic equipment and a storage medium, and relates to the technical field of data analys.The method comprises the steps that under the condition that a target object logs in a data analysis platform, code writing operation of the target object in a target webpage is received, and the code writing operation is used for calling target analysis data; under the condition that a target calling request for the target analysis data is triggered, target permission parameters corresponding to the target object are obtained, and the target permission parameters are used for representing the data calling range of the target object; under the condition that the target permission parameter indicates that the target object is allowed to access the target analysis data, distributing a target identity certificate to the target object based on the target permission parameter; and accessing the target data cluster through the data query engine carrying the target identity credential, wherein the target analysis data allowed to be accessed by the target object exists in the target data cluster. The method can improve the security of the process that the target webpage is connected with the target data cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data analysis technology, and in particular to a data access method, device, electronic device, and storage medium. Background Art

[0002] In the financial sector, methods such as data analysis and machine learning can help business personnel better understand user needs, optimize business processes, manage risks, and make decisions. Therefore, efficient data analysis methods are essential. Among related technologies, the combination of Jupyter and Presto is a commonly used and efficient data analysis tool. Jupyter is an open-source interactive computing tool suitable for fields such as data analysis and machine learning; Presto is a distributed SQL query engine based on big data. Its main purpose is to access and query data from different sources through SQL to improve the query speed of massive data. Summary of the Invention

[0003] This application provides a data access method, device, electronic device, and storage medium that can improve data security in data access scenarios. The technical solution is as follows:

[0004] According to one aspect of the present application, a data access method is provided, the method comprising:

[0005] When the target object logs in to the data analysis platform, receiving a code writing operation of the target object in a target webpage, wherein the code writing operation is used to call target analysis data;

[0006] In the case of triggering a target call request for the target analysis data, obtaining a target permission parameter corresponding to the target object, the target permission parameter being used to characterize a data call scope of the target object;

[0007] In a case where the target permission parameter indicates that the target object is allowed to access the target analysis data, allocating a target identity credential to the target object based on the target permission parameter;

[0008] The target data cluster is accessed by carrying the target identity credentials through a data query engine, and the target data cluster contains the target analysis data that the target object is allowed to access.

[0009] According to another aspect of the present application, a data access device is provided, the device comprising:

[0010] a receiving module, configured to receive a code writing operation performed by the target object in a target webpage when the target object logs into the data analysis platform, wherein the code writing operation is used to call target analysis data;

[0011] an acquisition module, configured to acquire a target permission parameter corresponding to the target object when a target call request for the target analysis data is triggered, wherein the target permission parameter is used to characterize a data call scope of the target object;

[0012] an allocating module, configured to allocate a target identity credential to the target object based on the target permission parameter if the target permission parameter indicates that the target object is allowed to access the target analysis data;

[0013] The access module is configured to access a target data cluster by carrying the target identity credentials through a data query engine, wherein the target data cluster contains the target analysis data that the target object is allowed to access.

[0014] According to one aspect of the present application, an electronic device is provided, including: a processor and a memory storing a program, wherein the program includes instructions, and when the instructions are executed by the processor, the processor executes the data access method described above.

[0015] According to another aspect of the present application, a non-transitory computer-readable storage medium storing computer instructions is provided, where the computer instructions are used to cause the computer to execute the data access method as described above.

[0016] According to another aspect of the present application, a computer program product is provided, the computer program product including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the above-mentioned data access method.

[0017] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least:

[0018] The embodiment of the present application provides a data access method: when a target call request for target analysis data is triggered in a target webpage of a data analysis platform, the target permission parameter corresponding to the target object is obtained, and based on the target permission parameter, it is determined whether the target object is allowed to call the target analysis data, and when the call is allowed, a target identity credential is assigned to the target object based on the target permission parameter, so that the data analysis engine can access the target data cluster based on the target identity credential. By adding verification of the target permission parameter in the process of connecting the target webpage to the target data cluster, the scope of the data call corresponding to the target object is increased, and it is determined that the data in the target data cluster can only be accessed by specific users, thereby improving the security of the process of connecting the target webpage to the target data cluster, and further improving the security of the data resources in the target cluster. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Further details, features and advantages of the present application are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:

[0020] Figure 1 A flow chart of a data access method according to an exemplary embodiment of the present application is shown;

[0021] Figure 2 A flow chart showing another data access method according to an exemplary embodiment of the present application is shown;

[0022] Figure 3 A flow chart showing another data access method according to an exemplary embodiment of the present application is shown;

[0023] Figure 4 This is a schematic diagram of the process of connecting Jupyter to a Presto cluster provided by an exemplary embodiment of the present application;

[0024] Figure 5 This is a structural diagram of a data access device provided in an embodiment of the present application;

[0025] Figure 6 A structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present application is shown. DETAILED DESCRIPTION

[0026] The following describes embodiments of the present application in more detail with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are for illustrative purposes only and are not intended to limit the scope of protection of the present application.

[0027] It should be understood that the various steps described in the method embodiments of the present application can be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this respect.

[0028] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; and the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first" and "second" mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units. It should be noted that the modifiers of "one" and "a plurality of" mentioned in this application are illustrative and not restrictive. Those skilled in the art should understand that unless the context clearly indicates otherwise, they should be understood as "one or more". The names of the messages or information exchanged between multiple devices in the embodiments of this application are for illustrative purposes only and are not used to limit the scope of these messages or information.

[0029] The following describes the solution of the present application with reference to the accompanying drawings, and illustrates the technical solution provided by the embodiments of the present application in detail through specific embodiments and their application scenarios.

[0030] In the financial sector, methods such as data analysis and machine learning can help business personnel better understand user needs, optimize business processes, manage risks, and make decisions. Therefore, efficient data analysis methods are essential. In related technologies, the combination of Jupyter and Presto is commonly used as an efficient data analysis tool. Jupyter is an open-source interactive computing tool suitable for fields such as data analysis and machine learning. Its core application is Jupyter Notebook, an interactive notebook-style programming environment that runs in a web browser and is an open-source web application. In Jupyter Notebook, users can write code, formulas, explanatory text, plots, and view code execution results in real time. It is a widely used interactive code execution tool. Presto is a distributed SQL query engine based on big data. Its main purpose is to access and query data from different sources through SQL to improve the query speed of massive data.

[0031] Currently, after integrating Jupyter and Presto into the data analysis platform, users can directly operate the Jupyter web page after logging into the data analysis platform. After triggering a data call request, they can directly connect to the Presto cluster and execute data queries. Due to the large number of users who can use the data analysis platform, the ability to directly connect to the Presto cluster and execute data queries after simple login verification results in any user having access to a very wide range of business data, seriously threatening the security of business data.

[0032] In order to improve the security of business data, this application embodiment improves the process of connecting Jupyter to the Presto cluster and adds permission control operations to avoid the problem of excessive scope of user data access rights. Figure 1 , which shows a flow chart of a data access method according to an exemplary embodiment of the present application. Figure 1 As shown, the method includes:

[0033] Step 101: When a target object logs into a data analysis platform, a code writing operation of the target object in a target webpage is received, where the code writing operation is used to call target analysis data.

[0034] The data analysis platform can be a platform built within the enterprise for submitting various data analysis requests. Users need to use a specific account and password to log in to the data analysis platform to ensure the security of data and information.

[0035] In one possible implementation, a user can open a target webpage in the data analysis platform and trigger the call of target analysis data by writing code on the target webpage to perform subsequent data analysis operations. The target webpage is a Jupyter Notebook web application page.

[0036] Step 102 : When a target call request for target analysis data is triggered, a target permission parameter corresponding to the target object is obtained. The target permission parameter is used to characterize the data call scope of the target object.

[0037] In the related art, if a user logs in to the data analysis platform and writes code on the target web page to trigger a target call request for the target analysis data, the data cluster (Presto cluster) where the target analysis data is located will be directly connected to call the analysis data for data analysis; this will cause security risks to the business data in the data cluster; in order to reduce the security risks caused by arbitrary calls to business data, in an embodiment of the present application, when a target call request for the target analysis data is triggered, the target permission parameter corresponding to the target object will first be obtained. The target permission parameter is used to characterize the data call scope of the target object, so that it can be subsequently determined based on the target permission parameter whether the target object is allowed to call the target analysis data.

[0038] Among them, the target object has a unique target permission parameter, which can be determined by the business department to which the target object belongs, that is, users in different business departments are allowed to access different analytical data, corresponding to different target permission parameters; or, the target permission parameter can also be determined by the job function of the target object; that is, in the same business department, users with different job functions are allowed to access different analytical data, corresponding to different target permission parameters.

[0039] For example, if target object A is responsible for online testing business, and target object B is responsible for offline testing business, in order to ensure the safe operation of online tasks, target object A and target object B have different target authority parameters to correspond to the data corresponding to the online testing business and the data corresponding to the offline testing business, respectively, thereby isolating online and offline data and ensuring the safe operation of online tasks.

[0040] Optionally, the target permission parameters associated with the target object can be obtained based on the account information of the target object logging into the data analysis platform.

[0041] Exemplarily, the target authority parameter may also be referred to as an RRC (Radio Resource Control) group parameter or an RRC parameter.

[0042] Step 103 : When the target permission parameter indicates that the target object is allowed to access the target analysis data, a target identity credential is allocated to the target object based on the target permission parameter.

[0043] After obtaining the target permission parameters, the data call scope of the target object is first verified based on the target permission parameters. If the target permission parameters indicate that the target object is allowed to access the target analysis data, the target identity credentials are assigned to the target object based on the target permission parameters so that the target data cluster can be accessed subsequently with the target identity credentials.

[0044] Exemplarily, the target identity credential is a temporary keytab identity credential allocated to the target object based on the target permission parameters.

[0045] Step 104 : Access the target data cluster by carrying the target identity credentials through the data query engine. The target data cluster contains target analysis data that the target object is allowed to access.

[0046] Furthermore, after obtaining the target identity credentials of the target object in the backend, the data query engine can be called to use the target identity credentials to access the target data cluster, which contains the target analytical data that the target object is allowed to access. Because the target analytical data in the target data cluster is the analytical data that the target object is allowed to access, the target data cluster can be prevented from being accessed and called by other objects that do not have access rights, thereby ensuring the security of the data in the target data cluster.

[0047] Exemplarily, the target data cluster is a presto cluster resource, that is, the data access method implemented in the embodiment of the present application is a process suitable for calling a presto cluster resource through jupyter.

[0048] Optionally, data clusters are divided in advance according to different target permission parameters, so that specific target permission parameters can be connected to specific target data clusters through different target identity credentials, further improving data security in the data clusters.

[0049] In summary, the embodiment of the present application provides a data access method: when a target call request for target analysis data is triggered in a target webpage of a data analysis platform, the target permission parameters corresponding to the target object are obtained, and based on the target permission parameters, it is determined whether the target object is allowed to call the target analysis data, and when the call is allowed, a target identity credential is allocated to the target object based on the target permission parameters, so that the data analysis engine can access the target data cluster based on the target identity credential. By adding verification of the target permission parameters in the process of connecting the target webpage to the target data cluster, the restriction on the call scope of the data corresponding to the target object is increased, and it is determined that the data in the target data cluster can only be accessed by specific users, thereby improving the security of the process of connecting the target webpage to the target data cluster, and further improving the security of the data resources in the target cluster.

[0050] Please refer to Figure 2 , which shows a flow chart of another data access method according to an exemplary embodiment of the present application. Figure 2 As shown, the method includes:

[0051] Step 201 : When a target object logs into a data analysis platform, a code writing operation of the target object in a target webpage is received, where the code writing operation is used to call target analysis data.

[0052] Step 202 : When a target call request for target analysis data is triggered, a target permission parameter corresponding to the target object is obtained. The target permission parameter is used to characterize the data call scope of the target object.

[0053] The implementation of step 201 and step 202 may refer to step 101 and step 102, and will not be described in detail in this embodiment.

[0054] Step 203: Obtain target business data associated with the target authority parameter.

[0055] In order to verify whether the target object is allowed to access the target analysis data, that is, to determine whether the target analysis data to be called belongs to the data call scope of the target object; after obtaining the target permission parameters that represent the data call scope of the target object, the target business data associated with the target object can be determined according to the target permission parameters. The target business data is the data that the target object has access rights to; and then determine whether the target business data includes the target analysis data to be called.

[0056] Step 204: Based on the relationship between the target business data and the target analysis data, perform permission verification on the target call request to obtain a permission verification result.

[0057] Specifically, if the target analysis data belongs to the target business data, that is, the target analysis data is part of the data to which the target object has access rights, then it can be determined that the permission check of the target call request has passed, that is, the permission check result of the target call request is permission check passed; conversely, if there is some data in the target analysis data that does not belong to the target business data, that is, there is some data in the target analysis data to which the target object does not have access rights, then it can be determined that the permission check of the target call request has failed, that is, the permission check result of the target call request is permission check failed.

[0058] Step 205 : If the permission verification result indicates that the permission verification is passed, it is determined that the target object is allowed to access the target analysis data, and a target identity credential is allocated to the target object based on the target permission parameter.

[0059] If the permission check result of the target call request indicates that the permission check is passed, it is determined that the target object is allowed to access the target analysis data, and then a target identity credential can be assigned to the target object based on the target permission parameter; optionally, the target identity credential can be randomly generated based on the target permission parameter, for example, the target permission parameter is encrypted with a key to obtain the target identity credential; or, different target permission parameters correspond to different target identity credentials.

[0060] Step 206: Generate a cluster access request based on the target identity credentials and target permission parameters.

[0061] Since the target identity credential is used to indicate that the target object can access the target analysis data, and which cluster data can be accessed specifically needs to be determined based on the target permission parameters; before connecting to the server where the cluster resources are located, a cluster access request is first generated based on the target identity credential and the target permission parameters; that is, the cluster access request carries two parameter information: the target identity credential and the target permission parameters.

[0062] Step 207: Send a cluster access request to the target server through the data query engine. When the target server determines that the target identity credential indicates that access is allowed, it determines the target data cluster based on the target permission parameter and accesses the target analysis data in the target data cluster.

[0063] Furthermore, a cluster access request is sent to the target server through the data query engine. After the target server receives the cluster access request, it first obtains the target identity credentials and target permission parameters from it to verify whether access is allowed through the target identity credentials. If the verification is passed, the target data cluster to be accessed is further determined based on the target permission parameters so that it can access the target analysis data in the target data cluster.

[0064] In this embodiment, by comparing the relationship between the target business data associated with the target permission parameters and the target analysis data to be called, it is determined whether the target object is allowed to access the target analysis data. This can prevent objects that do not have data call permissions from accessing the data, thereby improving data access security. In addition, when accessing the cluster, by carrying the target permission parameters, the target data cluster can also be determined according to the data call range indicated by the target permission parameters, so that it can accurately access the target analysis data in a specific data cluster, further improving data access security.

[0065] In addition to improving data call security by adding target permission parameters to limit the scope of data calls in the above embodiment, the embodiment of the present application also adds a double-layer verification mechanism to avoid the problem of data security risks caused by the target object's account information being illegally borrowed and then using the target permission parameters to implement data calls.

[0066] Please refer to Figure 3 , which shows a flow chart of another data access method according to an exemplary embodiment of the present application. Figure 3 As shown, the method includes:

[0067] Step 301 : When a target object logs into a data analysis platform and receives an opening operation for a target webpage, a verification page is displayed. The verification page is used to verify the target object's page usage authority for the target webpage.

[0068] Unlike related technologies, in which the target object can directly use the target web page and call cluster resources after logging into the data analysis platform using its account and password information, the embodiment of the present application adds a layer of verification operation when opening the target web page to further verify the target object's page usage permission for the target web page. In a corresponding possible implementation, after the target object logs into the data analysis platform, if the web link corresponding to the target web page or the open control of the target web page is triggered, the target web page will not be directly redirected to the target web page. Instead, a verification page will be displayed first. The verification page contains an input control for entering verification information, so that the target object's page usage permission for the target web page can be verified by entering verification information in the input control.

[0069] Step 302: If the page usage permission verification on the verification page passes, the target webpage is displayed, and a code writing operation of the target object in the target webpage is received.

[0070] If the page usage permission check on the verification page passes, it means that the target object has the permission to use the target web page to connect to the cluster resources to access the analysis data. The target web page will be displayed accordingly, and the target object's code writing operations in the target web page will be received to execute the subsequent data call process.

[0071] Optionally, the verification page displays the type of verification information that the user needs to fill in. After the verification page is displayed, the user can enter the target verification information in the verification page. The corresponding electronic device receives the input operation of the target verification information in the verification page and verifies the obtained target verification information. If the target verification information is verified, it can be determined that the page usage permission verification on the verification page is passed, so that the target web page can be displayed.

[0072] In order to avoid the problem that a simple account and password verification can be easily borrowed, an embodiment of the present application provides a dual verification mechanism of account and password + token. Specifically, the target verification information may include a first verification information and a second verification information, and the second verification information is verified after the first verification information is verified. In other words, the first verification information is verified first, and after the first verification information is verified, the second verification information is verified; until both the first verification information and the second verification information are verified, the target web page will be displayed. Exemplarily, the first verification information may be information in the form of an account and password, and the second verification information may be information in the form of a token.

[0073] Correspondingly, in an exemplary example, the verification process of the page usage permission may include the following steps (ie, step 302 may include steps 302A to 302D).

[0074] Step 302A: receiving an input operation for first verification information in the verification page.

[0075] Among them, the first verification information is verification information composed of the account and password. It should be noted that the first verification information is verification information different from the account and password for logging into the data analysis platform. The corresponding target object first needs to enter the first verification information in the verification page, and the corresponding receiving operation of the input of the first verification information in the verification page is received, the first verification information is obtained, and the first verification information is compared with the verification information associated with the target object. If the comparison is consistent, it can be determined that the first verification information verification has passed; if the comparison is inconsistent, it is determined that the first verification information verification has failed.

[0076] Step 302B: If the first verification information is verified successfully, a token generation request is sent to the associated device indicated by the first verification information, and the associated device is used to generate a target token based on the token generation request.

[0077] If the first verification information is verified and passed, token verification is still required. The corresponding electronic device sends a token generation request to the associated device indicated by the first verification information. The corresponding associated device can generate a target token based on the token generation request; at the same time, the electronic device end will also generate the same target token for subsequent token verification.

[0078] Exemplarily, the target token may be a 6-digit random number; or, the target token may be a 6-digit letter; or, a random number or letter of other digits; this embodiment does not limit the form of the target token.

[0079] Optionally, when the first verification information fails to be verified, there is no need to perform subsequent token verification, and verification failure information is directly fed back.

[0080] Optionally, when the first verification information is an account and password, the associated device may be a device such as a smart phone, tablet computer, or desktop computer held by the administrator corresponding to the account and password.

[0081] Step 302C: receiving an input operation for the second verification information in the verification page, and verifying the second verification information based on the target token.

[0082] The target object can view the target token generated on the associated device and input the target token into the verification page displayed by the current electronic device; the corresponding electronic device receives the input operation of the second verification information in the verification page, and verifies the second verification information based on the target token generated by the electronic device at the same time; if the two are consistent, it is determined that the second verification information verification has passed; otherwise, if the two are inconsistent, it is determined that the second verification information verification has failed.

[0083] Step 302D: If the second verification information is verified successfully, determine that the page usage authority verification on the verification page is successful, and display the target web page.

[0084] When the second verification information is also verified to be successful, it indicates that the target object has the page usage authority of the target webpage. Then, it is determined that the page usage authority verification on the verification page is successful, and the target webpage can be displayed.

[0085] On the contrary, if the second verification information fails to be verified, the target web page will not be displayed.

[0086] If the page usage permission check on the verification page fails, it means that the target object does not have the permission to use the target web page to connect to cluster resources to access analytical data. Accordingly, the target web page will not be displayed. This can avoid the problem of illegal access to data due to illegal borrowing of the target object's account information, further improving data security.

[0087] Optionally, to ensure the security of the target token, the target token may also have a time limit. Specifically, if the first verification information is verified successfully, a token generation request for the target token is sent to the associated device indicated by the first verification information. A target timer is also set. The duration of the target timer is the expiration date of the target token. For example, the timer duration may be 1 minute.

[0088] When the target timer reaches the timing length, if the verification page still has not received the second verification information, or the second verification information has not been verified, the electronic device sends a token update request to the associated device indicated by the first verification information, so that the associated device generates an updated target token based on the token update request; at the same time, the electronic device also generates an updated target token.

[0089] Optionally, when the target timer reaches the timing duration, since the target token is updated at this time, the electronic device needs to verify the second verification information based on the updated target token.

[0090] It should be noted that both the electronic device and the associated device are deployed with a token generator, and the target tokens generated by the two at the same time are the same.

[0091] Optionally, in order to avoid the token generation request corresponding to the request signal being transmitted to the associated device for too long, exceeding the timing duration of the target timer, thereby causing the verification to fail multiple times due to signal transmission problems. In one possible implementation, the timing start timing of the target timer can be dynamically adjusted. Specifically, after the electronic device sends a token generation request to the associated device, the associated device can feedback a response signal to the electronic device after receiving the token generation request and generating the target token. After receiving the response signal, the corresponding electronic device starts the target timer to time the generation time limit of the target token; until the target timer reaches the timing duration, if the verification page still does not receive the second verification information, or the second verification information is not verified, the electronic device sends a token update request to the associated device.

[0092] Step 303: When a target call request for target analysis data is triggered, a target permission parameter corresponding to the target object is obtained. The target permission parameter is used to characterize the data call scope of the target object.

[0093] Step 304 : When the target permission parameter indicates that the target object is allowed to access the target analysis data, a target identity credential is allocated to the target object based on the target permission parameter.

[0094] Step 305: Access the target data cluster by carrying the target identity credentials through the data query engine. The target data cluster contains target analysis data that the target object is allowed to access.

[0095] The implementation of steps 303 to 305 can refer to the above embodiment, and will not be described in detail in this embodiment.

[0096] In this embodiment, after logging into the data analysis platform, a double-layer verification mechanism of account password + token is added to the opening of the target web page, thereby avoiding the problem of data security risks caused by the target object's account information being illegally borrowed and data calls being implemented through target permission parameters, and further improving the security of the target web page connecting to cluster resources.

[0097] Figure 4 This is a schematic diagram of the process of connecting Jupyter to a Presto cluster provided by an exemplary embodiment of the present application. The process includes the following five stages:

[0098] 1. Use desktop cloud monitoring system.

[0099] Desktop cloud system: Used for behavior monitoring, it's essentially a virtual machine system equipped with a user behavior monitoring system, capable of monitoring user behavior. After a user logs into the desktop cloud, all data uploads and downloads are monitored, and any user actions within the system are recorded. This desktop cloud system is implemented using purchased third-party products.

[0100] It should be noted that the desktop cloud monitoring system needs to monitor any operation in the device or system based on user authorization.

[0101] 2. Model Platform (i.e., the data analysis platform in the above embodiment)

[0102] The company's self-built model platform serves as the entry point for users to conduct various data analysis operations. All user data analysis needs must be submitted and executed through this platform. Users must obtain authorization before logging into the platform to ensure the security of resources and information.

[0103] 3. Jupyter two-factor authentication

[0104] JupyterHub's source code has been modified to implement security controls: logging into JupyterHub now uses a two-factor authentication system: "password + token" instead of a single password. Tokens are obtained upon successful application through the company's platform. The token value is a 6-digit random number that changes every minute.

[0105] 4. Security Control of Connecting Clusters

[0106] Calling Python's PrestoDB (i.e., the target data cluster in the above embodiment): Modify the code of the open source version of PrestoDB to implement the permission management function: Add user identity RCC group permission verification, and implement user RCC identity verification in the code background; The background grants the user a temporary keytab identity credential after the verification, so that the user can connect to the Presto cluster via a key.

[0107] 5. Access the presto client (corresponding to the target server in the above embodiment)

[0108] The presto client was modified to implement resource isolation. Development and test machine isolation, production and research cluster isolation, and task classification logic were implemented based on RCC groups.

[0109] Please refer to Figure 5 , which is a structural diagram of a data access device provided by an embodiment of the present application. For example, Figure 5 As shown, the apparatus 500 includes:

[0110] A receiving module 501 is configured to receive a code writing operation performed by a target object in a target webpage when the target object logs into the data analysis platform, wherein the code writing operation is used to call target analysis data;

[0111] An acquisition module 502 is configured to acquire a target permission parameter corresponding to the target object when a target call request for the target analysis data is triggered, wherein the target permission parameter is used to represent a data call scope of the target object;

[0112] An allocating module 503 is configured to allocate a target identity credential to the target object based on the target permission parameter if the target permission parameter indicates that the target object is allowed to access the target analysis data;

[0113] The access module 504 is configured to access a target data cluster by carrying the target identity credentials through a data query engine, where the target data cluster contains the target analysis data that the target object is allowed to access.

[0114] Optionally, the allocation module 503 is further configured to:

[0115] Obtain target business data associated with the target authority parameter;

[0116] Based on the relationship between the target business data and the target analysis data, performing permission verification on the target call request to obtain a permission verification result;

[0117] If the permission check result indicates that the permission check is passed, it is determined that the target object is allowed to access the target analysis data, and the target identity credential is allocated to the target object based on the target permission parameter.

[0118] Optionally, the allocation module 503 is further configured to:

[0119] If the target analysis data belongs to the target business data, determining that the permission check of the target call request passes;

[0120] If some data that does not belong to the target business data exists in the target analysis data, it is determined that the permission check of the target call request has failed.

[0121] Optionally, the access module is further configured to:

[0122] Generate a cluster access request based on the target identity credential and the target permission parameter;

[0123] The cluster access request is sent to the target server through the data query engine. When the target server determines that the target identity credential indicates that access is allowed, it determines the target data cluster based on the target permission parameter and accesses the target analysis data in the target data cluster.

[0124] Optionally, the receiving module 501 is further configured to:

[0125] When the target object logs in to the data analysis platform and receives an opening operation for the target webpage, a verification page is displayed, wherein the verification page is used to verify the target object's page usage permission for the target webpage;

[0126] In the case that the page usage authority verification on the verification page passes, the target webpage is displayed, and the code writing operation of the target object in the target webpage is received.

[0127] Optionally, the receiving module 501 is further configured to:

[0128] Receiving an input operation on target verification information in the verification page;

[0129] In the case that the target verification information is verified, it is determined that the page usage authority verification on the verification page is passed, and the target web page is displayed.

[0130] Optionally, the target verification information includes first verification information and second verification information, and the second verification information is verified after the first verification information is verified and passed.

[0131] Optionally, the receiving module 501 is further configured to:

[0132] receiving an input operation for first verification information in the verification page;

[0133] If the first verification information is verified to be successful, sending a token generation request to the associated device indicated by the first verification information, and the associated device is configured to generate a target token based on the token generation request;

[0134] receiving an input operation of second verification information in the verification page, and verifying the second verification information based on the target token;

[0135] In the case where the second verification information is verified to be successful, it is determined that the page usage authority verification on the verification page is successful, and the target web page is displayed.

[0136] Optionally, the receiving module 501 is further configured to:

[0137] If the first verification information is verified to be successful, sending the token generation request target token to the associated device indicated by the first verification information, and setting a target timer;

[0138] The device further comprises:

[0139] a sending module, configured to send a token update request to the associated device indicated by the first verification information when the target timer reaches a timing duration, and the associated device generates an updated target token based on the token update request;

[0140] The receiving module 501 is further configured to:

[0141] When the target timer reaches the timing duration, the second verification information is verified based on the updated target token.

[0142] The embodiment of the present application provides a data access method: when a target call request for target analysis data is triggered in a target webpage of a data analysis platform, the target permission parameter corresponding to the target object is obtained, and based on the target permission parameter, it is determined whether the target object is allowed to call the target analysis data, and when the call is allowed, a target identity credential is assigned to the target object based on the target permission parameter, so that the data analysis engine can access the target data cluster based on the target identity credential. By adding verification of the target permission parameter in the process of connecting the target webpage to the target data cluster, the scope of the data call corresponding to the target object is increased, and it is determined that the data in the target data cluster can only be accessed by specific users, thereby improving the security of the process of connecting the target webpage to the target data cluster, and further improving the security of the data resources in the target cluster.

[0143] The exemplary embodiments of the present application further provide an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, wherein the computer program, when executed by the at least one processor, causes the electronic device to perform a method according to an embodiment of the present application.

[0144] An exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to perform a method according to an embodiment of the present application.

[0145] An exemplary embodiment of the present application further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to perform the method according to the embodiment of the present application.

[0146] refer to Figure 6, a block diagram of an electronic device 600 that can serve as a server or client of the present application will now be described, which is an example of a hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer equipment, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.

[0147] like Figure 6 As shown, electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. Various programs and data required for the operation of device 600 can also be stored in RAM 603. Computing unit 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.

[0148] Multiple components within electronic device 600 are connected to I / O interface 605, including an input unit 606, an output unit 607, a storage unit 608, and a communication unit 609. Input unit 606 can be any type of device capable of inputting information into electronic device 600. Input unit 606 can receive input numeric or character information and generate key signal inputs related to user settings and / or function control of the electronic device. Output unit 607 can be any type of device capable of presenting information and may include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. Storage unit 608 may include, but is not limited to, a magnetic disk or an optical disk. Communication unit 609 allows electronic device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks and may include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver and / or a chipset, such as a Bluetooth device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0149] The computing unit 601 may be a variety of general and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above. For example, in some embodiments, Figure 1 、 Figure 2 、 Figure 3 The illustrated method may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 600 via the ROM 602 and / or the communication unit 609. In some embodiments, the computing unit 601 may be configured to execute the computer program in any other suitable manner (e.g., by means of firmware). Figure 1 、 Figure 2 、 Figure 3 The method shown.

[0150] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. Such program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the program code is executed by the processor or controller, the functions / operations specified in the flow charts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0151] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0152] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a magnetic disk, an optical disk, a memory, a programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0153] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0154] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0155] Computer systems may include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The client and server relationship arises through computer programs running on the respective computers and having a client-server relationship to each other.

Claims

1. A data access method, characterized in that: The method comprises: When the target object logs in to the data analysis platform, receiving a code writing operation of the target object in a target webpage, wherein the code writing operation is used to call target analysis data; In the case of triggering a target call request for the target analysis data, obtaining a target permission parameter corresponding to the target object, the target permission parameter being used to characterize a data call scope of the target object; In a case where the target permission parameter indicates that the target object is allowed to access the target analysis data, allocating a target identity credential to the target object based on the target permission parameter; The target data cluster is accessed by carrying the target identity credentials through a data query engine, and the target data cluster contains the target analysis data that the target object is allowed to access.

2. The method according to claim 1, characterized in that When the target permission parameter indicates that the target object is allowed to access the target analysis data, allocating a target identity credential to the target object based on the target permission parameter includes: Obtain target business data associated with the target authority parameter; Based on the relationship between the target business data and the target analysis data, performing permission verification on the target call request to obtain a permission verification result; If the permission check result indicates that the permission check is passed, it is determined that the target object is allowed to access the target analysis data, and the target identity credential is allocated to the target object based on the target permission parameter.

3. The method according to claim 2, characterized in that The performing permission verification on the target call request based on the relationship between the target business data and the target analysis data to obtain a permission verification result includes: If the target analysis data belongs to the target business data, determining that the permission check of the target call request passes; If some data that does not belong to the target business data exists in the target analysis data, it is determined that the permission check of the target call request has failed.

4. The method according to any one of claims 1 to 3, characterized in that: The accessing the target data cluster by carrying the target identity credentials through the data query engine includes: Generate a cluster access request based on the target identity credential and the target permission parameter; The cluster access request is sent to the target server through the data query engine. When the target server determines that the target identity credential indicates that access is allowed, it determines the target data cluster based on the target permission parameter and accesses the target analysis data in the target data cluster.

5. The method according to any one of claims 1 to 3, characterized in that: When the target object logs in to the data analysis platform, receiving the code writing operation of the target object in the target webpage includes: When the target object logs in to the data analysis platform and receives an opening operation for the target webpage, a verification page is displayed, wherein the verification page is used to verify the target object's page usage permission for the target webpage; In the case that the page usage authority verification on the verification page passes, the target webpage is displayed, and the code writing operation of the target object in the target webpage is received.

6. The method according to claim 5, characterized in that If the page usage authority verification on the verification page passes, displaying the target web page includes: Receiving an input operation on target verification information in the verification page; In the case that the target verification information is verified, it is determined that the page usage authority verification on the verification page is passed, and the target web page is displayed.

7. The method according to claim 6, characterized in that The target verification information includes first verification information and second verification information, and the second verification information is verified after the first verification information is verified.

8. A data access device, characterized in that: The device comprises: a receiving module, configured to receive a code writing operation performed by the target object in a target webpage when the target object logs into the data analysis platform, wherein the code writing operation is used to call target analysis data; an acquisition module, configured to acquire a target permission parameter corresponding to the target object when a target call request for the target analysis data is triggered, wherein the target permission parameter is used to characterize a data call scope of the target object; an allocating module, configured to allocate a target identity credential to the target object based on the target permission parameter if the target permission parameter indicates that the target object is allowed to access the target analysis data; The access module is configured to access a target data cluster by carrying the target identity credentials through a data query engine, wherein the target data cluster contains the target analysis data that the target object is allowed to access.

9. An electronic device comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data access control method, electronic equipment and storage medium

    CN117556396A

  • Calling method and device between federated clusters, block chain system and storage medium

    CN118283122A

  • Authority control method and device, computer equipment and computer readable storage medium

    CN119167339A