Authority control method and electronic equipment

By decoupling permission control from functional operation portals and centrally managing permission configuration information, the problems of cumbersome permission control and poor security in the WEB storage management system are solved, achieving efficient permission management and security improvement.

CN120705898AActive Publication Date: 2025-09-26LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511205041.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-09-26
Estimated Expiration
2045-08-27

AI Technical Summary

Technical Problem

The permission control implementation of existing WEB storage management systems is cumbersome, prone to omissions or errors, and has poor security.

Method used

By decoupling permission control from functional operation entry, centrally managing permission configuration information, using local cache and server to perform permission verification, and distinguishing between encapsulated interfaces and custom interfaces for permission matching.

Benefits of technology

It reduces development workload, avoids omissions or errors in permission control, and improves system security and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705898A_ABST
    Figure CN120705898A_ABST
Patent Text Reader

Abstract

The invention discloses an authority control method and electronic equipment, and relates to the technical field of computer application, the method can monitor page operation, and obtain a function entry and a function request method related to a request page; and acquiring permission configuration information of an interface corresponding to the function entry from a local cache or a server. If the corresponding interface is a packaging interface, the authority configuration information is a plurality of packaged authority marks, and the plurality of authority marks correspond to a plurality of command lines needing to be called by the corresponding interface; and if the corresponding interface is a custom interface, matching the permission configuration information with a custom permission matching rule. And then, performing permission control on the target function entry based on the permission configuration information. According to the method, the authority configuration information corresponding to the interface is sorted, and the authority is managed in a centralized manner, so that the authority configuration information can be decoupled from a specific function entry, the development workload of the function entry and the interface is reduced, the authority control omission or error is avoided, and the safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer application technology, and in particular to an authority control method and electronic equipment. Background Art

[0002] Currently, permission control in WEB (World Wide Web) storage management systems is primarily implemented by defining a list of executable permissions for each function entry point during the development of the WEB system's functionality. This list is then configured within the HTML (Hypertext Markup Language) or JavaScript (a programming language that runs on web pages) code. During user operations, the JavaScript code performs a permission check based on the currently logged-in user's permissions. If the permissions do not match, the function entry point is disabled to prevent user errors.

[0003] The development work of this solution is tedious, the authority control is omitted or wrong, and the security is poor. Therefore, how to solve the authority control problem of the WEB storage management system is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention

[0004] The present invention provides an authority control method and electronic device, which decouples authority control from functional operation entry, thereby reducing development workload, avoiding omissions or errors in authority control, and improving security.

[0005] A permission control method, comprising: Monitor page operations and obtain the function entry and function request method involved in the requested page; Obtaining permission configuration information of the interface corresponding to the function entry from the local cache; If there is no permission configuration information of the corresponding interface in the local cache, a configuration information acquisition request is sent to the server based on the function request method to obtain the permission configuration information of the corresponding interface; Determine the target function entry corresponding to the current page operation, and use the obtained permission configuration information to perform permission control on the target function entry; wherein, if the corresponding interface is an encapsulated interface, the permission configuration information is a number of permission tags after encapsulation, and the several permission tags correspond to a number of command lines required to be called by the corresponding interface; if the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0006] A permission control method, comprising: Based on the calling requirements, the centralized authority management interface is divided into encapsulated interface and custom interface; Determine a number of command lines that need to be called by the encapsulation interface, obtain permission tags corresponding to the command lines, and encapsulate the permission tags to obtain permission configuration information of the encapsulation interface; Parsing the permission matching rules of the custom interface to obtain the permission configuration information of the custom interface; Saving the permission configuration information corresponding to the encapsulated interface and the custom interface respectively in the permission configuration information library; Receive a request for obtaining permission configuration from a client, and query permission configuration information of a corresponding interface from the permission configuration information library; The permission configuration information obtained from the query is fed back to the client, so that the client can perform permission control on the requested operation based on the permission configuration information.

[0007] The present invention also provides a permission control client, comprising: The page monitoring module is used to monitor page operations and obtain the function entry and function request method involved in the requested page; A cache search module, used to obtain the permission configuration information of the interface corresponding to the function entry from the local cache; A configuration request module is configured to send a configuration information acquisition request to the server based on the function request method to obtain the permission configuration information of the corresponding interface if there is no permission configuration information of the corresponding interface in the local cache; The permission control module is used to determine the target function entry corresponding to the current page operation, and use the obtained permission configuration information to perform permission control on the target function entry; wherein, if the corresponding interface is an encapsulated interface, the permission configuration information is a number of encapsulated permission tags, and the several permission tags correspond to a number of command lines required to be called by the corresponding interface; if the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0008] The present invention also provides a permission control server, comprising: The interface classification module is used to classify the interfaces of centralized authority management into encapsulated interfaces and custom interfaces according to the calling requirements; A permission encapsulation module is used to determine a number of command lines that need to be called by the encapsulation interface, obtain permission tags corresponding to a number of the command lines, and encapsulate the several permission tags to obtain permission configuration information of the encapsulation interface; A permission parsing module, used to parse the permission matching rules of the custom interface and obtain the permission configuration information of the custom interface; A permission storage module, used for storing the permission configuration information corresponding to the encapsulated interface and the custom interface in a permission configuration information library; The permission query module is used to receive the permission configuration request sent by the client and query the permission configuration information of the corresponding interface from the permission configuration information library; The permission feedback module is used to feed back the permission configuration information obtained from the query to the client, so that the client can perform permission control on the requested operation based on the permission configuration information.

[0009] The present invention also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any one of the above-mentioned permission control methods when executing the computer program.

[0010] The present invention also provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program implements the steps of any of the above-mentioned permission control methods when executed by a processor.

[0011] The present invention also provides a computer program product, comprising a computer program, which implements the steps of any of the above-mentioned permission control methods when executed by a processor.

[0012] The present invention monitors page operations to obtain the function entry and function request method associated with the requested page. The system then retrieves the permission configuration information for the interface corresponding to the function entry from the local cache. If the permission configuration information for the corresponding interface is not available in the local cache, a configuration information request is sent to the server based on the function request method to obtain the permission configuration information for the corresponding interface. In other words, the permission configuration information for the interface corresponding to the function entry is no longer configured in the relevant code of the function entry, but is instead centrally managed. Specifically, this centralized storage occurs in two locations: the local cache and the server. If the permission configuration information for the corresponding interface is not available in the local cache, it can be obtained from the server. Permission control can then be performed on the target function entry corresponding to the current page operation based on the obtained permission configuration information. It should be noted that the permission configuration information for different interfaces varies. For example, if the corresponding interface is a packaged interface, the permission configuration information consists of several encapsulated permission tags, which correspond to the command lines required to call the corresponding interface. If the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0013] It can be seen that the present invention can decouple the permission configuration information from the specific function entry by organizing the permission configuration information corresponding to different interfaces and centrally managing it, so that the permission configuration information of different function entries can be centrally managed and the permissions can be centrally verified, thereby reducing the development workload, avoiding omissions or errors in permission control, and improving security.

[0014] In response to the above control method, another control method, permission control client, permission control server, electronic device, readable storage medium and computer program product of the present invention also have corresponding technical effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0016] Figure 1 A flowchart of a permission control method provided by an embodiment of the present invention; Figure 2 A diagram illustrating an implementation framework of a storage management system provided by an embodiment of the present invention; Figure 3 A flowchart of another permission control method provided by an embodiment of the present invention; Figure 4 A schematic diagram of an implementation framework for implementing permission control in a storage management system provided by an embodiment of the present invention; Figure 5 A schematic diagram of a permission control client provided by an embodiment of the present invention; Figure 6 A schematic diagram of a permission control server provided by an embodiment of the present invention; Figure 7 A schematic structural diagram of an electronic device provided by an embodiment of the present invention; Figure 8 A schematic diagram of the specific structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0018] It should be noted that, in the description of the present invention, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. The terms "first," "second," etc., in the present invention are used to distinguish similar objects, and are not used to describe a particular order or precedence.

[0019] In order to enable those skilled in the art to better understand the solutions of the present invention, the present invention is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0020] The permission control method provided in this embodiment can be applied to web storage management systems to implement permission control over user operations, enabling categorized management and control of user operations. This ensures that users can only access data and functions within their responsibilities, preventing low-privilege users from accidentally operating critical functions, reducing human risks, and improving system security. Comprehensive permission management has become an indispensable foundational capability in system design.

[0021] like Figure 2 As shown, this web storage management system includes a browser and a storage system. The browser has a permission control client, and the storage system has a permission control server. Users can control the browser, and the permission control client and permission control server can control user operations. The permission control server is responsible for defining basic permission policies, automatically generating permission configurations for various APIs, and server-side permission control. The permission control client is responsible for obtaining and managing permission configurations for function entry points, and controlling permission for function entry points (for pages).

[0022] For details, please refer to Figure 1 , Figure 1 The method shown can be applied to Figure 2 The permission control client shown includes the following steps.

[0023] S101: Monitor page operations and obtain function entries and function request methods involved in the requested page.

[0024] The permission control client is located in the browser and can monitor the user's page operations to obtain the function entry and function request method involved in the user's current requested page.

[0025] Among them, the function entry refers to the starting point for triggering a certain function or entering a certain operation process, such as a button on a web page (such as a send button, which starts sending related content when clicked), a menu / icon (such as a file save menu), a link / card (such as a view details link), etc.

[0026] The function request method is the same as the function request method defined in the JS code.

[0027] S102: Acquire the permission configuration information of the interface corresponding to the function entry from the local cache.

[0028] After determining all function entries and function request methods of the page requested by the page operation, the permission configuration information of the interface corresponding to the function entry can be obtained from the local cache.

[0029] That is, the permission configuration information corresponding to all interfaces involved in the function entry.

[0030] In this embodiment, the permission configuration information of the interface can be stored in the local cache to speed up the permission control efficiency. Therefore, when the permission configuration information needs to be obtained, the permission configuration information of the corresponding interface can be searched locally first.

[0031] In this embodiment, a mapping relationship between a function entry and the interface involved may be stored. After the function entry is determined, the corresponding interface involved may be determined.

[0032] There are two results when obtaining the permission configuration information of the corresponding interface in the local cache: one is that it can be found, and the other is that it cannot be found.

[0033] S103: If there is no permission configuration information of the corresponding interface in the local cache, a configuration information acquisition request is sent to the server based on a function request method to obtain the permission configuration information of the corresponding interface.

[0034] When the permission configuration information for the corresponding interface is not found in the local cache, a request to obtain the configuration information can be sent to the server based on the function request method. After receiving the request, the server can obtain the permission configuration information for the corresponding interface by searching the permission configuration information library and provide feedback.

[0035] In this way, the permission control client can obtain the permission configuration information of the corresponding interface.

[0036] In a specific embodiment of the present invention, after sending a request for obtaining configuration information to the server based on the function request method to obtain the permission configuration information of the corresponding interface, it also includes: storing the newly obtained permission configuration information in the local cache. That is to say, after obtaining the permission configuration information of the corresponding interface from the permission control server, in order to facilitate the subsequent permission control of the same function entry, the currently obtained permission configuration information can be cached locally. For example, after the server returns the permission configuration, the front-end div (division, partition, a basic container element) element ID of the function entry and the permission configuration can be put into the cache as a mapping relationship. The ID and the function entry have a one-to-one correspondence.

[0037] S104: Determine the target function entry corresponding to the current page operation, and perform permission control on the target function entry using the obtained permission configuration information.

[0038] Among them, if the corresponding interface is an encapsulated interface, the permission configuration information is a number of encapsulated permission tags, and the number of permission tags corresponds to a number of command lines required to be called by the corresponding interface; if the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0039] It should be noted that in the present invention, in order to achieve unified management of the permission configuration information of the interface and avoid missing relevant permission configuration, the interfaces are divided into types in this embodiment, and the corresponding permission configuration information is sorted out for different types of interfaces.

[0040] Specifically, interfaces can be divided into encapsulated interfaces and custom interfaces. The corresponding encapsulated interface means that the interface will call the command line to implement the corresponding function.

[0041] Therefore, in this embodiment, for the encapsulated interface, the permission configuration information corresponds to several encapsulated permission tags, and these permission tags correspond to the command lines that the interface needs to call. Specifically, all command lines can be divided according to storage objects and read / write operation types, and the permissions required to execute the command lines are generated. For example, the four commands mkstoragepool (create a storage pool), lsstoragepool (query a storage pool), chstoragepool (modify a storage pool), and rmstoragepool (delete a storage pool) all belong to the storagepool storage object. The mkstoragepool, chstoragepool, and rmstoragepool commands are commands related to configuring the storage pool and require storage pool write permissions; the lsstoragepool command is used to query storage pool information and requires storage pool read permissions. Based on the classification, each command line generates a permission tag, for example: mkstoragepool:storagepool_write / / Storage pool creation CLI: requires storage pool write permissions; lsstoragepool:storagepool_read / / Storage pool query CLI: requires storage pool read permissions.

[0042] For custom interfaces, the permission configuration information corresponds to the customized permission matching rules. For example, you can define matching rules for marking permissions. On the server side that processes interface requests, the same interface processing class can complete configuration tasks or query tasks based on different request parameters or parameter values. Therefore, it is necessary to combine multiple pieces of information to determine the permissions required for the request. Taking file downloading as an example, the corresponding permission matching rules are as follows: {"api":"DownloadFileHandler", / / API name: "DownloadFileHandler" "rules":[ / / Permission rules { "method":"get", / / "Request method": "Get" / / can also be POST (create), PUT (modify), DELETE (delete) “parameters”:[“filename=file1”,…], / / “request parameters”: [“parameter name=parameter value” "auth":"storagepool_r" / / "Required permissions": "storage pool read permission" }, { "method":"get", / / "Request method": "Get" “parameters”:[“filename=file2”,…], / / “request parameters”:[“parameter name=parameter value”,…], "auth": "volume_r" / / "Required permissions": "volume read permissions" },…].

[0043] After obtaining the permission configuration information, you can control the permission of the target function entrance.

[0044] In a specific embodiment of the present invention, the obtained permission configuration information is used to perform permission control on the target function entrance, including: obtaining the user permission information of the current operation; determining whether the user permission information matches the permission configuration information; if so, allowing entry to the target function entrance; if not, prohibiting entry to the target function entrance.

[0045] In actual applications, a permission list for each user role can be pre-defined: it is used to indicate which CLIs and custom interfaces each user role can execute. User permission information can specifically be a permission list for the corresponding role of the current user. Of course, user permission information can also be a permission configuration that is pre-customized for the user. After obtaining the permission configuration information and user permission information, it can be determined whether the user permission information matches the permission configuration information. For example, if the user's permission information only has volume read permission, and the permission configuration information includes volume creation, it means that the two do not match, and access to the target function entrance can be prohibited. If the user permission information includes all the permission configuration information, it means that the user's permission meets the permission corresponding to the target function entrance, and access to the target function entrance can be allowed. In other words, the user can be prohibited from using the relevant functions or pages, or allowed to use the relevant functions or pages.

[0046] Using the method provided by the embodiments of the present invention, page operations can be monitored to obtain the function entry and function request method involved in the requested page. The permission configuration information for the interface corresponding to the function entry can then be retrieved from the local cache. If the permission configuration information for the corresponding interface is not available in the local cache, a configuration information request is sent to the server based on the function request method to obtain the permission configuration information for the corresponding interface. In other words, the permission configuration information for the interface corresponding to the function entry is no longer configured in the relevant code of the function entry, but is instead centrally managed. Specifically, this centralized storage occurs in two locations: the local cache and the server. If the permission configuration information for the corresponding interface is not available in the local cache, it can be obtained from the server. Permission control can then be performed on the target function entry corresponding to the current page operation based on the obtained permission configuration information. It should be noted that the permission configuration information for different interfaces varies. For example, if the corresponding interface is a packaged interface, the permission configuration information consists of several encapsulated permission tags, which correspond to the command lines required to call the corresponding interface. If the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0047] It can be seen that the present invention can decouple the permission configuration information from the specific function entry by organizing the permission configuration information corresponding to different interfaces and centrally managing it, so that the permission configuration information of different function entries can be centrally managed and the permissions can be centrally verified, thereby reducing the development workload, avoiding omissions or errors in permission control, and improving security.

[0048] Based on the above method embodiments, the present invention also proposes several improvement schemes, and the similarities between the corresponding improvement schemes and the above processes are not repeated here.

[0049] In a specific embodiment of the present invention, it also includes: when the local cache reaches a preset capacity threshold, determining the comprehensive numerical values ​​corresponding to the cached permission configuration information; using the comprehensive numerical values ​​to delete the permission configuration information of the corresponding interface to release cache space. That is to say, considering that in actual applications, the number of interfaces is relatively large, and thus as time goes by, the cached permission configuration information will become more and more, and the storage space of the local cache is limited, in order to avoid cache overflow, the permission configuration information corresponding to different interfaces can also be comprehensively numerically calculated, so that the cached permission configuration information can be deleted based on the comprehensive numerical value, thereby releasing cache space. Accordingly, the permission configuration information with a lower comprehensive numerical value in the permission configuration information can be deleted. A comprehensive numerical value can be calculated separately for the permission configuration information corresponding to each interface. In this way, only the permission configuration information corresponding to some interfaces that are used more frequently and recently can be retained in the local cache.

[0050] In a specific embodiment of the present invention, determining the comprehensive values ​​corresponding to the cached permission configuration information includes: obtaining the last use time and the number of uses corresponding to each cached interface permission configuration; and calculating the time decay value matching the last use time using a time decay value formula; wherein the time decay value formula is: , where RS is the time decay value, is the difference between the current time and the last usage time; the usage frequency numerical formula is used to calculate the usage frequency value that matches the number of usage times; wherein, the usage frequency numerical formula is: , FS is the frequency of use, is the number of times used, is a preset constant; the time decay value and the usage frequency value are weighted and summed according to the preset weight coefficient to obtain a comprehensive value. The number of uses can be regularly revised based on the preset decay factor.

[0051] In other words, to implement cache data clearing, we can first define the cache space capacity threshold T and the time decay factor γ; define the time decay value (Recency Score), denoted as RS, and calculate it using the following formula: ,in, Represents the current time minus the last used time ( ), logarithmic smoothing is used to avoid the influence of extreme values.

[0052] Define the frequency score (FS), calculated as: ,in, Represents a very small constant (such as 1e-5), preventing Use logarithmic smoothing to suppress weight differences in high-frequency operations (for scenarios with large value spans).

[0053] Definable number of uses Regular revision method to reduce the impact of historical data. Calculation formula: ,in, Represents the attenuation factor, with a value range of [0,1].

[0054] A comprehensive value (Eviction Score) can be defined, recorded as ES. Calculation formula: The weighting coefficients for the corresponding values ​​of α and β are adjusted based on business characteristics (for example, if configuration operations prioritize timeliness, increase the weight of time). A cache data deletion policy can be defined: deletion is triggered when the cache reaches capacity threshold T. The ES value of all cached items is calculated, and they are sorted by ES value, with items with lower values ​​being deleted first to free up cache space.

[0055] In a specific embodiment of the present invention, the obtained permission configuration information is used to perform permission control on the target function entry, including: using the obtained permission configuration information to perform permission control on the target function entry; recording the usage time corresponding to the permission configuration information, and using the usage time to update the last usage time of the permission configuration information; adding one to the number of uses corresponding to the permission configuration information. That is, each time the permission configuration information corresponding to an interface is used, the last usage time of the permission configuration information can be updated and the number of uses can be added by one. For example, the permission of each function entry in the cache is obtained once, and its reading time is recorded, which is recorded as , is read count (denoted as ) plus 1.

[0056] Please refer to Figure 3 The present invention also provides a permission control method applied to a permission control server, which includes the following steps.

[0057] S201. According to calling requirements, the interface of centralized authority management is divided into encapsulated interface and custom interface.

[0058] In this embodiment, the centralized authority management interface can be divided into a packaged interface and a custom interface according to whether the interface calls a command line (CLI).

[0059] S202: Determine several command lines that need to be called by the encapsulated interface, obtain permission tags corresponding to the several command lines, and encapsulate the several permission tags to obtain permission configuration information of the encapsulated interface.

[0060] In this embodiment, corresponding permission tags can be pre-defined for different command lines. When determining the permission configuration information for the encapsulated interface, the permission tags corresponding to all command lines that need to be called can be encapsulated to obtain the permission configuration information for the encapsulated interface. That is, the permission configuration information includes the permission tags of all command lines that need to be called by the interface.

[0061] S203: Parse the permission matching rules of the custom interface to obtain permission configuration information of the custom interface.

[0062] For a customized interface, there is no need to call a command line. The customized interface can pre-define its corresponding permission matching rules. By parsing the permission matching rules, the permission configuration information can be obtained.

[0063] S204: Save the permission configuration information corresponding to the encapsulated interface and the custom interface in the permission configuration information library.

[0064] After obtaining the permission configuration information of the interface, it can be saved in the permission configuration information library in a manner in which one interface corresponds to one piece of permission configuration information.

[0065] S205: Receive the permission configuration acquisition request sent by the client, and query the permission configuration information of the corresponding interface from the permission configuration information library.

[0066] After receiving the permission configuration request sent by the client, the permission configuration information of the corresponding interface can be queried from the permission configuration information data. For how to query the database, you can refer to the relevant database implementation solution, which will not be repeated here.

[0067] The client can execute Figure 1 After the relevant method steps shown, a request for obtaining permission configuration is sent.

[0068] S206: Feedback the permission configuration information obtained from the query to the client, so that the client can perform permission control on the requested operation based on the permission configuration information.

[0069] After querying and obtaining the permission configuration information, it can be fed back to the client. After the client receives the permission configuration information, it can execute the following Figure 1 The permission control operations in the method steps shown.

[0070] In a specific implementation of the present invention, it also includes: receiving an interface access request; querying the permission configuration information of the corresponding interface from the permission configuration information library; using the permission configuration information to perform permission verification on the interface access request; if the verification passes, access to the corresponding interface is allowed; if the verification fails, access to the corresponding interface is prohibited.

[0071] In other words, if a third party hijacks a request and simulates front-end page operations, directly initiating a request to the web system's server in an attempt to disrupt the system, the front-end page's permission restrictions are bypassed, resulting in poor security. To address this issue, the server in the storage system of the present invention can verify interface access requests and only allow access to the corresponding interface if verification is successful. This prevents security attacks and improves security.

[0072] In a specific embodiment of the present invention, when the permission configuration of a certain function entry or data interface changes, the corresponding permission configuration information in the permission configuration information library on the server can be updated; when a new function entry or data entry is added, the corresponding permission configuration information is added to the permission configuration information library. In other words, because the permission configuration information is centrally managed, when there is a permission change, only the permission configuration information in the permission configuration library needs to be adjusted to implement permission control based on the new permission configuration, without having to modify the code of the function entry or data interface itself. This can reduce development workload and avoid missing relevant permission controls.

[0073] Please refer to Figure 4 ,Will Figure 1 and Figure 3 The methods shown are mainly applied to Figure 2 In the system shown, the collaborative process of the two is as follows.

[0074] Command Line Permission Definition: System CLIs are categorized by storage resource object and CLI operation type, and basic permission configuration information for each CLI is defined based on the type. This information is used to generate permission configuration for the server-side encapsulated API that calls the CLI.

[0075] Custom interface permission definition: Define permission configuration for APIs that do not call the CLI on the server.

[0076] Permission generation: When the server is started, the permission configuration of each encapsulated API is generated according to the basic permission configuration information of the system CLI; when the client has a permission acquisition request, the permission configuration of the request is returned according to the request content; and the corresponding permission configuration corresponding to the requested API is provided to the permission verification module.

[0077] Permission Verification (Server): Responsible for verifying the permissions of requests made directly to the server API. Based on the request information, it obtains the required permissions from the permission generation module and verifies whether the request meets the permission requirements to improve system security.

[0078] Permission Request: Responsible for obtaining the permission configuration information for API requests based on the API request information transmitted by the Operation Monitoring Module. It prioritizes obtaining the corresponding permission configuration from the client-side permission cache module. If the corresponding permission configuration is not available in the cache, it then requests it from the permission control server. It prioritizes obtaining the permission configuration from the cache; after obtaining the request, it saves it to the permission cache module.

[0079] Operation monitoring: Monitor user operations on WEB pages, obtain API request information of the function entry involved in the corresponding page, and pass it to the permission request module, especially returning the permission configuration of the function entry involved in the page.

[0080] Permission Cache: This module is responsible for storing and retrieving permission configurations, improving the response speed of permission configuration retrieval requests and ensuring timely permission control by the permission verification (client) module. It is also responsible for clearing permission configurations that have not been used for a long time. When the cache reaches a certain capacity, the relevant permission configuration information can also be cleared based on information usage to free up cache space.

[0081] Permission Verification (Client): Obtain the permission configuration information of the current function entrance and verify whether the current user has permission to operate this function based on this information. If not, disable the current operation location.

[0082] As can be seen, the permission control method provided by the present invention eliminates the need to pre-define permission configurations for each front-end function entry, avoiding tedious design and development work and improving development efficiency. When a new function needs to be developed and delivered, only the CLI permissions or custom interface permissions required for the function need to be configured, without additional design and development work, and has excellent flexibility and scalability. At the same time, this method can simultaneously support permission verification for both client operations and server-side APIs, minimizing the possibility of unauthorized operation of the system and enhancing system security.

[0083] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0084] The embodiment of the present invention also provides a permission control client, which can be used with Figure 1 The permission control methods shown refer to each other.

[0085] Please refer to Figure 5 , the client includes: The present invention also provides a permission control client, comprising: The page monitoring module 101 is used to monitor page operations and obtain the function entry and function request method involved in the requested page; The cache search module 102 is used to obtain the permission configuration information of the interface corresponding to the function entry from the local cache; The configuration request module 103 is configured to send a configuration information acquisition request to the server based on a function request method to obtain the permission configuration information of the corresponding interface if there is no permission configuration information of the corresponding interface in the local cache; The permission control module 104 is used to determine the target function entry corresponding to the current page operation, and use the obtained permission configuration information to perform permission control on the target function entry; wherein, if the corresponding interface is an encapsulated interface, the permission configuration information is a number of permission tags after encapsulation, and the number of permission tags corresponds to a number of command lines required to be called by the corresponding interface; if the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

[0086] In a specific implementation of the present invention, the permission control module is specifically used to obtain user permission information of the current operation; determine whether the user permission information matches the permission configuration information; if so, allow access to the target function entrance; if not, prohibit access to the target function entrance.

[0087] In a specific implementation of the present invention, it also includes: a cache management module, which is used to determine the comprehensive numerical values ​​corresponding to the cached permission configuration information when the local cache reaches a preset capacity threshold; and use the comprehensive numerical values ​​to delete the permission configuration information of the corresponding interface to release cache space.

[0088] In a specific implementation of the present invention, the cache management module is specifically configured to obtain the last usage time and usage count corresponding to each cached interface permission configuration; and calculate a time decay value that matches the last usage time using a time decay numerical formula; wherein the time decay numerical formula is: , where RS is the time decay value, is the difference between the current time and the last usage time; the usage frequency numerical formula is used to calculate the usage frequency value that matches the number of usage times; wherein, the usage frequency numerical formula is: , FS is the frequency of use, is the number of times used, is a preset constant; according to the preset weight coefficient, the time attenuation value and the usage frequency value are weighted and summed to obtain a comprehensive value.

[0089] In a specific implementation of the present invention, the cache management module is further configured to periodically correct the number of uses based on a preset decay factor.

[0090] In a specific implementation of the present invention, the permission control module is specifically used to use the obtained permission configuration information to perform permission control on the target function entrance; record the usage time corresponding to the permission configuration information, and use the usage time to update the last usage time of the permission configuration information; and add one to the number of uses corresponding to the permission configuration information.

[0091] In a specific implementation of the present invention, it also includes: a cache update module, which is used to store the newly obtained permission configuration information in the local cache after sending a configuration information acquisition request to the server based on the function request method to obtain the permission configuration information of the corresponding interface.

[0092] The embodiment of the present invention also provides a permission control server, which can be used with Figure 3 The permission control methods shown refer to each other.

[0093] Please refer to Figure 6 , the server includes: The interface classification module 201 is used to classify the interfaces of the centralized authority management into encapsulated interfaces and custom interfaces according to the calling requirements; The permission encapsulation module 202 is used to determine a number of command lines that need to be called by the encapsulated interface, obtain permission tags corresponding to the command lines, and encapsulate the permission tags to obtain permission configuration information of the encapsulated interface; The permission parsing module 203 is used to parse the permission matching rules of the custom interface and obtain the permission configuration information of the custom interface; The permission storage module 204 is used to store the permission configuration information corresponding to the encapsulated interface and the custom interface in the permission configuration information library; The permission query module 205 is used to receive the permission configuration request sent by the client and query the permission configuration information of the corresponding interface from the permission configuration information library; The permission feedback module 206 is used to feed back the permission configuration information obtained from the query to the client, so that the client can perform permission control on the requested operation based on the permission configuration information.

[0094] In a specific embodiment of the present invention, it also includes: an access control module, which is used to receive interface access requests; query the permission configuration information of the corresponding interface from the permission configuration information library; use the permission configuration information to verify the permission of the interface access request; if the verification passes, access to the corresponding interface is allowed; if the verification fails, access to the corresponding interface is prohibited.

[0095] Corresponding to the above method embodiment, an embodiment of the present invention further provides an electronic device. The electronic device described below and the permission control method described above can refer to each other.

[0096] See also Figure 7 As shown, the electronic device includes: Memory 332, for storing computer programs; The processor 322 is configured to implement the steps of the permission control method of the above method embodiment when executing a computer program.

[0097] For details, please refer to Figure 8 , Figure 8 This is a schematic diagram of the specific structure of an electronic device provided in this embodiment. This electronic device may vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) (for example, one or more processors) and memory 332. The memory 332 stores one or more computer programs 342 or data 344. The memory 332 may be temporary storage or permanent storage. The program stored in the memory 332 may include one or more modules (not shown), each of which may include a series of instruction operations in the data processing device. Furthermore, the processor 322 may be configured to communicate with the memory 332 to execute the series of instruction operations in the memory 332 on the electronic device 301.

[0098] The electronic device 301 may further include one or more power supplies 326 , one or more wired or wireless network interfaces 350 , one or more input / output interfaces 358 , and / or one or more operating systems 341 .

[0099] The steps in the permission control method described above can be implemented by the structure of an electronic device, which can be a computer carrying a permission control client or a server carrying a permission control server.

[0100] Corresponding to the above method embodiments, embodiments of the present invention further provide a readable storage medium. The readable storage medium described below and the permission control method described above can be referenced in correspondence with each other. Embodiments of the present invention further provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps of any of the above permission control method embodiments when executed.

[0101] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0102] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of any one of the above-mentioned permission control method embodiments are implemented.

[0103] An embodiment of the present invention further provides another computer program product, comprising a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any of the above-mentioned permission control method embodiments are implemented.

[0104] Those skilled in the art may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0105] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The description of the above examples is only intended to help understand the method and core concept of the present invention. It should be noted that those skilled in the art may make various improvements and modifications to the present invention without departing from the principles of the present invention, and such improvements and modifications also fall within the scope of protection of the present invention.

Claims

1. A permission control method, characterized in that: include: Monitor page operations and obtain the function entry and function request method involved in the requested page; Obtaining permission configuration information of the interface corresponding to the function entry from the local cache; If there is no permission configuration information of the corresponding interface in the local cache, a configuration information acquisition request is sent to the server based on the function request method to obtain the permission configuration information of the corresponding interface; Determine the target function entry corresponding to the current page operation, and use the obtained permission configuration information to perform permission control on the target function entry; wherein, if the corresponding interface is an encapsulated interface, the permission configuration information is a number of permission tags after encapsulation, and the several permission tags correspond to a number of command lines required to be called by the corresponding interface; if the corresponding interface is a custom interface, the permission configuration information matches the custom permission matching rules.

2. The method according to claim 1, characterized in that Also includes: When the local cache reaches a preset capacity threshold, determining the comprehensive values ​​corresponding to the cached permission configuration information; The comprehensive value is used to delete the permission configuration information of the corresponding interface to release cache space.

3. The method according to claim 2, characterized in that Determine the comprehensive values ​​corresponding to the cached permission configuration information, including: Get the last usage time and usage count corresponding to each cached interface permission configuration; A time decay value matching the last usage time is calculated using a time decay numerical formula; wherein the time decay numerical formula is: , where RS is the time decay value, The difference between the current time and the last used time; The frequency of use numerical formula is used to calculate a determined frequency of use numerical value that matches the number of times of use; wherein the frequency of use numerical formula is: , FS is the frequency of use, is the number of times used, is a preset constant; The time decay value and the usage frequency value are weighted and summed according to a preset weight coefficient to obtain the comprehensive value.

4. The method according to claim 3, characterized in that Also includes: The number of uses is periodically revised based on a preset decay factor.

5. The method according to claim 3, characterized in that Using the obtained permission configuration information to perform permission control on the target function entrance, including: Using the obtained permission configuration information to perform permission control on the target function entrance; Record the usage time corresponding to the permission configuration information, and use the usage time to update the last usage time of the permission configuration information; The number of times the permission configuration information is used is increased by one.

6. The method according to claim 1, characterized in that After sending a configuration information acquisition request to the server based on the function request method to obtain the permission configuration information of the corresponding interface, the method further includes: Store the newly acquired permission configuration information in the local cache.

7. The method according to any one of claims 1 to 6, characterized in that Using the obtained permission configuration information to perform permission control on the target function entrance, including: Get the user permission information of the current operation; Determining whether the user authority information matches the authority configuration information; If yes, then allowing access to the target function entrance; If not, entry into the target function entry is prohibited.

8. A permission control method, characterized in that: include: Based on the calling requirements, the centralized authority management interface is divided into encapsulated interface and custom interface; Determine a number of command lines that need to be called by the encapsulation interface, obtain permission tags corresponding to the command lines, and encapsulate the permission tags to obtain permission configuration information of the encapsulation interface; Parsing the permission matching rules of the custom interface to obtain the permission configuration information of the custom interface; Saving the permission configuration information corresponding to the encapsulated interface and the custom interface respectively in the permission configuration information library; Receive a request for obtaining permission configuration from a client, and query permission configuration information of a corresponding interface from the permission configuration information library; The permission configuration information obtained from the query is fed back to the client, so that the client can perform permission control on the requested operation based on the permission configuration information.

9. The method according to claim 8, characterized in that Also includes: Receive interface access request; Query the permission configuration information of the corresponding interface from the permission configuration information library; Performing permission verification on the interface access request using the permission configuration information; If the verification is successful, access to the corresponding interface is allowed; If the verification fails, access to the corresponding interface is prohibited.

10. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the permission control method according to any one of claims 1 to 9 when executing the computer program.

Citation Information

Patent Citations

  • Authorization configuration method, device, device and storage medium for security component

    CN109067809A

  • Interface permission control method and device, storage medium and electronic equipment

    CN118171297A

  • Page permission configuration method and device, computer equipment and storage medium

    CN119397504A

  • Dynamic authority management method and device of Web front end, medium and equipment

    CN119718267A

  • Network access authority dynamic management and control method and system based on behavior analysis

    CN119996084A