User information authority management method and device, equipment and medium
By performing security detection and encryption processing on user permission requests, combined with multiple approval mechanisms, the problem of low data security in hierarchical management is solved, and permissions are opened while ensuring data security.
Patent Information
- Application Number
- CN202510557542.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-15
AI Technical Summary
In the prior art, hierarchical management of user rights leads to a reduction in data security, and users directly respond to permission requests to display data, which fails to effectively ensure information security.
By obtaining user permission request data, security detection is carried out based on user type, determining the proportion of requested reference data and private information corresponding to request permissions, encrypting and approval are carried out to ensure data security.
Improve data security, ensuring that permissions are only allowed to access data after security detection is passed, and multiple approvals are required, enhancing data protection.
Smart Images

Figure CN120493299A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to a user information rights management method, apparatus, device and medium. Background Art
[0002] With the development of information technology, the application scenarios of enterprise application servers have also increased accordingly. Management users with different functions need to use the same application server. To ensure the security of application server information, it is necessary to manage the management permissions of management users with different functions.
[0003] Currently, user permissions are typically managed hierarchically to avoid system insecurity issues caused by all administrative users being able to exercise full permissions. However, this hierarchical management approach directly responds to user permission requests and only displays the data they want to view, which reduces data security. Summary of the Invention
[0004] Embodiments of the present invention provide a user information rights management method, apparatus, device, and medium, which manage the rights requested by a first user after a security check is passed, thereby improving data security.
[0005] In a first aspect, an embodiment of the present invention provides a method for managing user information rights, including:
[0006] Obtaining the first user's permission request data;
[0007] performing a security check on the permission request data based on the user type of the first user, and obtaining a target detection result corresponding to the permission request data;
[0008] parsing the permission request data based on the target detection result to determine the requested access data corresponding to the requested access data requested by the first user and a proportion of private information corresponding to the requested access data;
[0009] Determining target display data corresponding to the requested data based on the private information ratio and the requested data;
[0010] Based on the approval information fed back by the second user regarding the permission request data, the requested permission is granted to the first user, so that the first user can view the target display data.
[0011] Optionally, the method also includes: if the user type of the first user is an external user, performing potential virus detection and anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data; if the user type of the first user is an internal user, performing anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data.
[0012] Optionally, the method further includes: performing potential virus detection on the permission request data based on a preset virus database to obtain a virus detection result corresponding to the permission request data; if the virus detection result is no virus risk, performing anti-tampering detection based on the metadata of the permission request data to obtain a target detection result corresponding to the permission request data.
[0013] Optionally, the method further includes: performing consistency detection based on the real-time metadata and historical metadata in the permission request data to obtain a target detection result corresponding to the permission request data.
[0014] Optionally, the method further includes: if the proportion of the private information is greater than or equal to a preset encryption threshold, encrypting the requested data to determine the target display data corresponding to the requested data; if the proportion of the private information is less than the preset encryption threshold, determining the requested data as the target display data.
[0015] Optionally, the method further includes: separating the requested access data based on a preset sequence length to obtain multiple subsequence data; performing encryption processing based on the multiple subsequence data and a preset encryption method to determine the target display data corresponding to the requested access data.
[0016] Optionally, the method further includes: performing multi-directional scrambling processing on each subsequence data to obtain multi-directional scrambled sub-data; and determining target display data corresponding to the requested data based on irregular arrangement and combination of the multi-directional scrambled sub-data.
[0017] In a second aspect, an embodiment of the present invention further provides a user information rights management device, the device comprising:
[0018] A permission request data acquisition module, configured to acquire permission request data of a first user;
[0019] a target detection result determination module, configured to perform a security check on the permission request data based on the user type of the first user, and obtain a target detection result corresponding to the permission request data;
[0020] a request access data determination module, configured to parse the permission request data based on the target detection result, and determine the request access data corresponding to the requested permission requested by the first user and a proportion of private information corresponding to the request access data;
[0021] a target display data determination module, configured to determine target display data corresponding to the requested access data based on the private information ratio and the requested access data;
[0022] The permission request opening module is used to open the requested permission to the first user based on the approval information fed back by the second user for the permission request data, so that the first user can view the target display data.
[0023] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising:
[0024] one or more processors;
[0025] a memory for storing one or more programs;
[0026] When the one or more programs are executed by the one or more processors, the one or more processors implement the user information rights management method provided by any embodiment of the present invention.
[0027] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the user information rights management method provided by any embodiment of the present invention.
[0028] In a fifth aspect, an embodiment of the present invention provides a computer program product, including a computer program, which, when executed by a processor, implements the user information rights management method provided by any embodiment of the present invention.
[0029] The technical solution of the embodiment of the present invention is to obtain the permission request data of the first user; perform a security check on the permission request data based on the user type of the first user to obtain a target detection result corresponding to the permission request data; thereby retaining the permission request data that passes the security check through the security check, and after the security check passes, parsing the retained permission request data to determine the request access data corresponding to the request permission requested by the first user and the proportion of private information corresponding to the request access data; perform different levels of privacy processing on the request access data based on the proportion of private information to determine the target display data corresponding to the request access data, thereby improving the security of the target display data, and the opening of the request permission requires the consent of the second user, and then based on the approval information fed back by the second user for the permission request data, the request permission is opened to the first user for the first user to view the target display data, thereby improving data security.
[0030] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0032] Figure 1 This is a flowchart of a user information rights management method provided by Example 1 of the present invention;
[0033] Figure 2 This is a flowchart of a user information rights management method provided by Example 2 of the present invention;
[0034] Figure 3 This is a schematic diagram of the structure of a user information rights management device provided by the third embodiment of the present invention;
[0035] Figure 4 It is a structural diagram of an electronic device for implementing the user information rights management method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0036] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0037] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0038] Example 1
[0039] Figure 1 A flowchart of a user information rights management method is provided for the first embodiment of the present invention. This embodiment is applicable to the case of securely authorizing the rights request data submitted by the user. The method can be executed by a user information rights management device. The user information rights management device can be implemented in the form of hardware and / or software. The user information rights management device can be configured in an electronic device. Figure 1 As shown, the method includes:
[0040] S110: Obtain permission request data of the first user.
[0041] The first user may refer to a user who applies for permission to view specific data. The permission request data may refer to the request data generated by the permission application. For example, the permission request data may include but is not limited to a user identifier (such as a user ID), a requested permission, and a requested access data. The requested access data may refer to the data that the user wants to view. The requested permission may refer to the permission that the user needs to activate to view the requested access data.
[0042] Specifically, a first user logs in to a server, and the server uses the first user's corresponding user ID to determine the first user's corresponding optional permissions from a pre-set permissions management package. The first user selects a request to access data on the server, and the server determines the requested permissions corresponding to the requested data. The server then obtains the first user's permission request data.
[0043] It should be noted that the pre-configuration process for the permissions management package includes: obtaining all permissions for all user IDs on the server; numerically labeling user IDs; labeling all permissions set on the server with a combination of English and numbers; determining the optional permissions corresponding to each user ID to obtain the permission set corresponding to each user ID; and merging the permission sets corresponding to all user IDs to form the permissions management package. The server monitors the optional permissions of new user IDs and the permission updates of old user IDs in real time, and updates the permissions management package in real time.
[0044] S120: Perform a security check on the permission request data based on the user type of the first user to obtain a target detection result corresponding to the permission request data.
[0045] User types may include, but are not limited to, external users and internal users. Internal users may be classified and ranked by importance based on their positions in the internet project. Security testing may be used to detect whether permission request data poses a security risk to the server. Target detection results may refer to the security testing results of permission request data, indicating whether the permission request data is accepted.
[0046] Specifically, for first users of different user types, security detection methods with different security factors can be used to perform security detection on the permission request data, thereby achieving targeted security detection and accurately obtaining the target detection results corresponding to the permission request data, thereby improving the security of the server.
[0047] In the technical aspects of the above technical solution, "performing a security check on the permission request data based on the user type of the first user to obtain a target detection result corresponding to the permission request data" may include: if the user type of the first user is an external user, performing a potential virus check and an anti-tampering check on the permission request data to obtain a target detection result corresponding to the permission request data; if the user type of the first user is an internal user, performing an anti-tampering check on the permission request data to obtain a target detection result corresponding to the permission request data.
[0048] The potential virus detection may refer to a security detection for whether the permission request data carries a virus, and the anti-tampering detection may refer to a security detection for whether the permission request data content has been tampered with.
[0049] Specifically, if the first user's user type is an external user, the permission request data is subjected to potential virus detection and anti-tampering detection, respectively, to obtain a target detection result corresponding to the permission request data. This target detection result must be determined to be a safe and acceptable result if the potential virus detection shows no virus and the anti-tampering detection shows no tampering. If the first user's user type is an internal user, only the permission request data can be subjected to anti-tampering detection to obtain a target detection result corresponding to the permission request data.
[0050] In the technical aspects of the above technical solution, "performing potential virus detection and anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data" may include: performing potential virus detection on the permission request data based on a preset virus database to obtain a virus detection result corresponding to the permission request data; if the virus detection result is no virus risk, performing anti-tampering detection based on the metadata of the permission request data to obtain a target detection result corresponding to the permission request data.
[0051] The preset virus database may refer to a preconfigured database of user-generated virus detection data. The virus detection result may indicate a virus risk exists or does not exist. The target detection result may indicate safe and acceptable or unsafe and rejected. Metadata may include: creator information and data volume information. Creator information may refer to the user ID that created the permission request data. Data volume information may refer to the size of the permission request data.
[0052] Specifically, the server obtains the communication protocol of the preset virus database and establishes a communication connection with the preset virus database based on the communication protocol of the preset virus database. The permission request data is scanned and judged according to the virus data stored in the preset virus database. If part of the content in the permission request data coincides with the virus data stored in the preset virus database, the permission request data is rejected and a virus detection result indicating a virus risk is output. If all the content in the permission request data does not coincide with the virus data stored in the preset virus database, the virus detection result corresponding to the permission request data is determined to be free of virus risk, and anti-tampering detection is performed based on the metadata of the permission request data to obtain a target detection result corresponding to the permission request data, thereby improving the security of the server.
[0053] In the technical aspects of the above technical solution, "performing anti-tampering detection based on the metadata of the permission request data to obtain the target detection result corresponding to the permission request data" may include: performing consistency detection based on the real-time metadata and historical metadata in the permission request data to obtain the target detection result corresponding to the permission request data.
[0054] The permission request data is transmitted to the server and may be tampered with during transmission. Real-time metadata can refer to the metadata of the permission request data at the most recent transmission location. Historical metadata can refer to the metadata of the permission request data submitted by the first user. Historical metadata can also be understood as original metadata.
[0055] Specifically, a consistency check is performed based on the real-time metadata and historical metadata in the permission request data. If the creator information in the historical metadata is the same as the creator information in the real-time metadata, and the data volume information in the historical metadata is the same as the data volume information in the real-time metadata, a safe and acceptable target detection result is output, and the permission request data is accepted. If the creator information in the historical metadata is different from the creator information in the real-time metadata, or the data volume information in the historical metadata is different from the data volume information in the real-time metadata, a target detection result is output, indicating that it is unsafe and unacceptable, and the permission request data is rejected.
[0056] S130: Parse the permission request data based on the target detection result to determine the requested access data corresponding to the requested permission requested by the first user and the proportion of private information corresponding to the requested access data.
[0057] The requested data may include some highly private information. The private information ratio may refer to the proportion of private information in the requested data. Private information may include, but is not limited to, personal identity information and financial information.
[0058] Specifically, if the target detection result is an unsafe and unacceptable detection result, the permission request data will not be parsed, and the security risk will be reported to the first user and the administrator. If the target detection result is a safe and acceptable detection result, the permission request data will be parsed to determine the requested data corresponding to the requested permission requested by the first user and the proportion of private information corresponding to the requested data.
[0059] S140: Determine target display data corresponding to the requested data based on the proportion of private information and the requested data.
[0060] The target display data may refer to the viewable data received by the first user. The target display data may differ from the original data format of the requested view data. For example, to ensure the security of the requested view data during transmission, the requested view data may be encrypted before transmission.
[0061] Specifically, based on the proportion of private information, it is evaluated whether the requested data needs to be encrypted. If encryption is not required, the requested data is transmitted as the target display data.
[0062] S150: Based on the approval information fed back by the second user regarding the permission request data, the requested permission is granted to the first user, so that the first user can view the target display data.
[0063] The second user may be a user who decides whether to grant the first user the permission to request data viewing, for example, an administrator and a user of the highest importance.
[0064] Specifically, the second user can monitor the permission request data submitted by the first user in real time through the server and approve the first user's permission requests. If the server detects that the administrator has denied the first user's permission request, it denies the requested permission to the first user, preventing the first user from accessing the target display data. If the server detects that the administrator has approved the first user's permission request, it checks whether the most important user has approved the first user's permission request. If the server detects that the most important user has denied the first user's permission request, it denies the requested permission to the first user, preventing the first user from accessing the target display data. If the server detects that the most important user has approved the first user's permission request, it checks whether the target display data is encrypted. If the server detects that the target display data is not encrypted, it directly grants the requested permission to the first user, allowing the first user to access the target display data. If the server detects that the target display data is encrypted, it submits the request to the most important user for a second review to attempt to obtain a decryption method. If the server detects that the most important user has failed the second review, it denies the requested permission to the first user, preventing the first user from accessing the target display data. If the server detects that the user with the highest importance has passed the second approval, it obtains the decryption method and grants the request permission to the first user, so that the first user can view the target display data through the decryption method.
[0065] It should be noted that in the embodiment of the present invention, the opening of the first user's request permission requires the consent of both the administrator and the most important user before it can be opened to the first user, and the embodiment of the present invention can automatically determine, further ensuring data security.
[0066] The technical solution of the embodiment of the present invention obtains the permission request data of the first user; performs a security check on the permission request data based on the user type of the first user, and obtains a target detection result corresponding to the permission request data; thereby retaining the permission request data that passes the security check through the security check, and after the security check passes, parsing the retained permission request data to determine the requested access data corresponding to the requested permission requested by the first user and the proportion of private information corresponding to the requested access data; performs different levels of privacy processing on the requested access data based on the proportion of private information, and determines the target display data corresponding to the requested access data, thereby improving the security of the target display data, and the opening of the requested permission requires the consent of the second user, and then based on the approval information fed back by the second user for the permission request data, the requested permission is opened to the first user for the first user to view the target display data, thereby improving data security.
[0067] Example 2
[0068] Figure 2 This is a flowchart of a user information rights management method provided by the second embodiment of the present invention. Based on the above embodiment, this embodiment describes in detail the process of determining the target display data corresponding to the requested access data. The explanations of the terms that are the same or corresponding to the above embodiments are not repeated here. Figure 2 As shown, the method includes:
[0069] S210: Obtain permission request data of the first user.
[0070] S220: Perform a security check on the permission request data based on the user type of the first user to obtain a target detection result corresponding to the permission request data.
[0071] S230: Parse the permission request data based on the target detection result to determine the requested access data corresponding to the requested permission requested by the first user and the proportion of private information corresponding to the requested access data.
[0072] S240: If the proportion of private information is greater than or equal to the preset encryption threshold, encrypt the requested data and determine the target display data corresponding to the requested data.
[0073] The preset encryption threshold may refer to a preset minimum percentage of information that needs to be encrypted. The preset encryption threshold may be used to represent the importance of information.
[0074] Specifically, the private information ratio is determined based on the ratio between the amount of private information and the amount of data requested for review. If the private information ratio is greater than or equal to a preset encryption threshold, the requested data is encrypted using a preset encryption method, and the target display data corresponding to the requested data is determined.
[0075] On the basis of the above technical solution, "encrypting the requested data and determining the target display data corresponding to the requested data" may include: separating the requested data based on a preset sequence length to obtain multiple subsequence data; encrypting the multiple subsequence data and a preset encryption method to determine the target display data corresponding to the requested data.
[0076] The preset sequence length may refer to a preset length for dividing long sequence data into multiple short sequence data. The preset sequence length may be one or more lengths. In embodiments of the present invention, the preset sequence length may include a first preset length and a second preset length. Subsequence data may refer to data obtained by separating multiple preset sequence lengths.
[0077] Specifically, the requested data is segmented based on a preset sequence length to obtain a plurality of subsequence data of a first preset length and a plurality of subsequence data of a second preset length. The first preset length is less than the second preset length. Encryption processing is performed based on the subsequence data of the first preset length, the subsequence data of the second preset length, and a preset encryption method to determine target display data corresponding to the requested data.
[0078] On the basis of the above technical solution, "encrypting based on multiple subsequence data and a preset encryption method to determine the target display data corresponding to the requested data" may include: performing multi-directional scrambling processing on each subsequence data to obtain multi-directional scrambled sub-data; and determining the target display data corresponding to the requested data based on the irregular arrangement and combination of the multi-directional scrambled sub-data.
[0079] Specifically, a multi-directional scrambling operation is performed on each of the plurality of sub-sequence data of the first preset length and the plurality of sub-sequence data of the second preset length to generate a plurality of multi-directional scrambled sub-data. The plurality of multi-directional scrambled sub-data generated from the plurality of sub-sequence data of the first preset length and the plurality of multi-directional scrambled sub-data generated from the plurality of sub-sequence data of the second preset length are irregularly arranged and combined to determine target display data corresponding to the requested data.
[0080] S250: If the proportion of private information is less than the preset encryption threshold, the requested data is determined as target display data.
[0081] S260: Based on the approval information fed back by the second user regarding the permission request data, the requested permission is granted to the first user, so that the first user can view the target display data.
[0082] The technical solution of the embodiment of the present invention encrypts the requested data if the proportion of private information is greater than or equal to a preset encryption threshold, determining the target display data corresponding to the requested data; if the proportion of private information is less than the preset encryption threshold, the requested data is determined as the target display data. This encrypts the highly private requested data to obtain the target display data, preventing the target display data from being intercepted or tampered with during transmission, ensuring that the first user can access accurate and secure data, and further improving data security and user experience.
[0083] The following is an embodiment of a user information rights management device provided by an embodiment of the present invention. The device and the user information rights management methods of the above-mentioned embodiments belong to the same inventive concept. For details not fully described in the embodiment of the user information rights management device, please refer to the embodiment of the above-mentioned user information rights management method.
[0084] Example 3
[0085] Figure 3 This is a schematic diagram of the structure of a user information rights management device provided by the third embodiment of the present invention. Figure 3 As shown, the device includes: a permission request data acquisition module 310, a target detection result determination module 320, a request access data determination module 330, a target display data determination module 340 and a permission activation request module 350.
[0086] Among them, the permission request data acquisition module 310 is used to obtain the permission request data of the first user; the target detection result determination module 320 is used to perform a security detection on the permission request data based on the user type of the first user, and obtain the target detection result corresponding to the permission request data; the request review data determination module 330 is used to parse the permission request data based on the target detection result, and determine the request review data corresponding to the request permission requested by the first user and the proportion of private information corresponding to the request review data; the target display data determination module 340 is used to determine the target display data corresponding to the request review data based on the proportion of private information and the request review data; the request permission activation module 350 is used to activate the request permission to the first user based on the approval information fed back by the second user for the permission request data, so that the first user can view the target display data.
[0087] The technical solution of the embodiment of the present invention obtains the permission request data of the first user; performs a security check on the permission request data based on the user type of the first user, and obtains a target detection result corresponding to the permission request data; thereby retaining the permission request data that passes the security check through the security check, and after the security check passes, parsing the retained permission request data to determine the requested access data corresponding to the requested permission requested by the first user and the proportion of private information corresponding to the requested access data; performs different levels of privacy processing on the requested access data based on the proportion of private information, and determines the target display data corresponding to the requested access data, thereby improving the security of the target display data, and the opening of the requested permission requires the consent of the second user, and then based on the approval information fed back by the second user for the permission request data, the requested permission is opened to the first user for the first user to view the target display data, thereby improving data security.
[0088] Based on the above technical solution, the target detection result determination module 320 may include:
[0089] a first target detection result determination submodule, configured to, if the user type of the first user is an outside user, perform potential virus detection and anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data;
[0090] The second target detection result determination submodule is configured to perform anti-tampering detection on the permission request data if the user type of the first user is an internal user, and obtain a target detection result corresponding to the permission request data.
[0091] Based on the above technical solution, the first target detection result determination submodule may include:
[0092] a virus detection result determination unit, configured to perform potential virus detection on the permission request data based on a preset virus database, and obtain a virus detection result corresponding to the permission request data;
[0093] The target detection result determining unit is used to perform anti-tampering detection based on the metadata of the permission request data if the virus detection result is no virus risk, and obtain the target detection result corresponding to the permission request data.
[0094] On the basis of the above technical solution, the target detection result determination unit is specifically used to: perform consistency detection based on the real-time metadata and historical metadata in the permission request data to obtain the target detection result corresponding to the permission request data.
[0095] Based on the above technical solution, the target display data determination module 340 may include:
[0096] A first target display data determination submodule is configured to encrypt the requested data and determine target display data corresponding to the requested data if the proportion of private information is greater than or equal to a preset encryption threshold;
[0097] The second target display data determination submodule is configured to determine the requested data as target display data if the proportion of private information is less than a preset encryption threshold.
[0098] Based on the above technical solution, the first target display data determination submodule may include:
[0099] a subsequence data determining unit, configured to separate the requested data based on a preset sequence length to obtain a plurality of subsequence data;
[0100] The target display data determining unit is configured to perform encryption processing based on the plurality of subsequence data and a preset encryption method to determine the target display data corresponding to the requested data.
[0101] Based on the above technical solution, the target display data determination unit is specifically used to: perform multi-directional garbled processing on each subsequence data to obtain multi-directional garbled sub-data; and determine the target display data corresponding to the requested data based on the irregular arrangement and combination of the multi-directional garbled sub-data.
[0102] The user information rights management device provided by the embodiment of the present invention can execute the user information rights management method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the user information rights management method.
[0103] It is worth noting that in the above-mentioned embodiment of user information rights management, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0104] Example 4
[0105] Figure 4A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0106] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0107] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0108] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the user information rights management method.
[0109] In some embodiments, the user information rights management method can be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the user information rights management method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the user information rights management method in any other appropriate manner (e.g., by means of firmware).
[0110] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0111] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0112] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0113] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0114] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0115] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0116] An embodiment of the present invention further provides a computer program product, including a computer program, which, when executed by a processor, implements the user information rights management method provided in any embodiment of the present application.
[0117] In the process of implementation, the computer program product can be written in one or more programming languages or a combination thereof to write computer program codes for performing the operations of the present invention, and the programming languages include object-oriented programming languages, such as Java, Smalltalk, C++, and also conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet). The program product and the user information rights management method disclosed in each embodiment of the present application belong to the same inventive concept, so they are not described here.
[0118] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0119] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A user information rights management method, characterized in that: include: Obtaining the first user's permission request data; performing a security check on the permission request data based on the user type of the first user, and obtaining a target detection result corresponding to the permission request data; parsing the permission request data based on the target detection result to determine the requested access data corresponding to the requested access data requested by the first user and a proportion of private information corresponding to the requested access data; Determining target display data corresponding to the requested data based on the private information ratio and the requested data; Based on the approval information fed back by the second user regarding the permission request data, the requested permission is granted to the first user, so that the first user can view the target display data.
2. The method according to claim 1, characterized in that The performing a security check on the permission request data based on the user type of the first user to obtain a target detection result corresponding to the permission request data includes: If the user type of the first user is an external user, performing potential virus detection and anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data; If the user type of the first user is an internal user, an anti-tampering detection is performed on the permission request data to obtain a target detection result corresponding to the permission request data.
3. The method according to claim 2, characterized in that The performing of potential virus detection and anti-tampering detection on the permission request data to obtain a target detection result corresponding to the permission request data includes: Performing potential virus detection on the permission request data based on a preset virus database to obtain a virus detection result corresponding to the permission request data; If the virus detection result is no virus risk, anti-tampering detection is performed based on the metadata of the permission request data to obtain a target detection result corresponding to the permission request data.
4. The method according to claim 3, characterized in that The performing anti-tampering detection based on the metadata of the permission request data to obtain a target detection result corresponding to the permission request data includes: A consistency check is performed based on the real-time metadata and the historical metadata in the permission request data to obtain a target detection result corresponding to the permission request data.
5. The method according to claim 1, wherein The determining, based on the private information ratio and the requested access data, target display data corresponding to the requested access data includes: If the proportion of the private information is greater than or equal to a preset encryption threshold, encrypting the requested data and determining target display data corresponding to the requested data; If the proportion of the private information is less than the preset encryption threshold, the requested data is determined as the target display data.
6. The method according to claim 5, characterized in that The encrypting the requested access data and determining target display data corresponding to the requested access data includes: Separating the requested access data based on a preset sequence length to obtain a plurality of subsequence data; Encryption processing is performed based on the multiple subsequence data and a preset encryption method to determine target display data corresponding to the requested access data.
7. The method according to claim 6, characterized in that The performing encryption processing based on the plurality of subsequence data and a preset encryption method to determine target display data corresponding to the requested access data includes: Perform multi-directional garbled processing on each subsequence data to obtain multi-directional garbled sub-data; Based on the irregular arrangement and combination of the multi-directional garbled sub-data, target display data corresponding to the requested access data is determined.
8. A user information rights management device, characterized in that: The device comprises: A permission request data acquisition module, configured to acquire permission request data of a first user; a target detection result determination module, configured to perform a security check on the permission request data based on the user type of the first user, and obtain a target detection result corresponding to the permission request data; a request access data determination module, configured to parse the permission request data based on the target detection result, and determine the request access data corresponding to the requested permission requested by the first user and a proportion of private information corresponding to the request access data; a target display data determination module, configured to determine target display data corresponding to the requested access data based on the private information ratio and the requested access data; The permission request opening module is used to open the requested permission to the first user based on the approval information fed back by the second user for the permission request data, so that the first user can view the target display data.
9. An electronic device, characterized in that: The electronic device comprises: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the user information rights management method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the user information rights management method as described in any one of claims 1 to 7 is implemented.