Post-based permission processing method and device

By using a role-based permission processing method, user identity information is obtained and role identifiers are determined, forming a dual permission verification mechanism. This solves the problems of high cost and low accuracy of permission management in enterprise SaaS systems, and achieves data security and accurate permission allocation.

CN120974468APending Publication Date: 2025-11-18BEIJING BAIJU YIXING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510954476.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In enterprise SaaS systems, existing technologies suffer from high cost and error-prone access control due to the complexity of role management, making it difficult to achieve accurate access control allocation.

Method used

By using a job-based access control method, user identity information is obtained, job identifiers are determined, and a dual access control mechanism is formed based on the preset job identifiers and access control relationships to ensure that each job can only access data that is consistent with its responsibilities, thus preventing unauthorized access.

Benefits of technology

It improves data security, reduces access control costs, ensures the accuracy and consistency of access control allocation, and reduces internal security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120974468A_ABST
    Figure CN120974468A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of permission processing, and discloses a post-based permission processing method and device. The method comprises the steps that when a data access request is received, identity information of a user is acquired; determining a post identifier of the user according to the identity information, and determining a first target permission corresponding to the data access request according to the data access request; determining a second target permission corresponding to the post identifier according to an association relationship between a preset post identifier and a preset permission and the post identifier; and when the first target permission is not higher than the second target permission, determining data corresponding to the data access request according to the data access request.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of permission processing, and particularly relates to a post-based permission processing method and device. BACKGROUND

[0002] With the acceleration of enterprise digital transformation, SaaS (Software as a Service) systems have become the core tools for enterprises to improve operational efficiency and achieve business collaboration. In SaaS systems, user permission management is a key link to ensure data security, standardize business operations, and meet compliance requirements. Different users (such as administrators, ordinary employees, external partners, etc.) need to be granted differentiated system access permissions (such as function module operation rights, data viewing / editing rights, etc.) according to their roles, responsibilities, and business needs.

[0003] In related technologies, permissions are set for each user individually, so that each user can use the corresponding permission data.

[0004] However, when the business of an enterprise is complex, a large number of roles need to be defined to cover the subdivided permission requirements, resulting in a sharp increase in role management costs and an increased likelihood of errors.

[0005] Therefore, how to reduce costs while improving the accuracy of permission processing has become a technical problem to be solved. SUMMARY

[0006] Therefore, the present application provides a post-based permission processing method and device.

[0007] In a first aspect, the present application provides a post-based permission processing method, which comprises: when a data access request is received, obtaining identity information of a user; determining a post identifier of the user according to the identity information, and determining a first target permission corresponding to the data access request according to the data access request; determining a second target permission corresponding to the post identifier according to the association relationship between the preset post identifier and the preset permission and the post identifier; when the first target permission is not higher than the second target permission, determining data corresponding to the data access request according to the data access request.

[0008] The post-based permission processing method provided in this embodiment forms a double permission checking mechanism by obtaining user identity information, determining a post identifier, and associating a preset permission. First, the first target permission is determined according to the data access request, and then the second target permission is determined according to the post identifier. Only when the first target permission is not higher than the second target permission, the data can be accessed, which effectively prevents users from accessing sensitive data beyond their authority, greatly improving data security.

[0009] Moreover, the preset post identifier and the associated relationship of the permissions are ensured to enable each post to access only the data corresponding to the responsibilities. Different posts have different data permissions due to different work contents and responsibilities. Through the association, the system can accurately assign appropriate permissions to each user to prevent over-assignment or under-assignment of permissions and ensure data security from the source.

[0010] In one possible implementation, the method further includes: when the first target permission is higher than the second target permission, sending a permission deficiency prompt information to the terminal of the user.

[0011] The post-based permission processing method provided in the embodiment can quickly determine the permission condition after the user initiates a data access request. If the permission is insufficient, prompt information is sent to the user terminal in time, so that the user can know the problem at the first time, avoid waiting for a long time without any feedback, and thus reduce the anxiety and doubt of the user.

[0012] In one possible implementation, the method further includes: obtaining post identifiers of the enterprise; wherein the post identifiers include a sales post identifier, a financial post identifier, and a technical post identifier; processing static data and matching the static data with the post identifiers to obtain a first matching result; wherein the static data includes customer data, financial data, and business processes; assigning static data processing permissions to the posts corresponding to the post identifiers according to the first matching result; processing system resource data and matching the system resource data with the post identifiers to obtain a second matching result; wherein the system resource data includes server resources, file storage resources, and interface resources; assigning coefficient resource data processing permissions to the posts corresponding to the post identifiers according to the second matching result; and obtaining an associated relationship of the preset post identifiers and the preset permissions according to the coefficient resource data processing permissions and the static data processing permissions.

[0013] The post-based permission processing method provided in the embodiment clearly obtains post identifiers of sales, finance, and technology, and carefully processes and matches static data (customer data, financial data, and business processes) and system resource data (server resources, file storage resources, and interface resources) according to different posts.

[0014] Moreover, the static data and the system resource data are processed and assigned permissions respectively, and finally the associated relationship of the preset post identifiers and the preset permissions is obtained. This hierarchical processing method makes the permission management more clear and orderly.

[0015] In a possible implementation, the method further includes: obtaining identity information of a new user; determining a post identifier of the new user according to the identity information of the new user; and determining a third target permission of the new user according to the post identifier of the new user and the association table, wherein the association table stores an association relationship between a preset post identifier and a preset permission.

[0016] The post-based permission processing method provided in the embodiment realizes the precision of permission allocation by determining the post identifier according to the identity information of the new user and determining the third target permission according to the association table. The permission range of each new user is clear, and the security threat that may be caused by excessive permissions of internal personnel is reduced. Even if a certain employee account is maliciously used, because the permission is limited, the information that the attacker can obtain and the operation that the attacker can perform are strictly limited, so that the loss caused by internal security events to the enterprise is minimized.

[0017] In a possible implementation, the method further includes: when the post identifier of the user is changed, determining the post identifier of the user from the association table; and changing the post identifier of the user to the post identifier of the user after the change.

[0018] The post-based permission processing method provided in the embodiment stores the association relationship between the preset post identifier and the preset permission in the association table. When the post identifier of the user is changed, the user can be quickly located from the association table, and the post identifier of the user is updated to the identifier after the change in a timely manner. Moreover, each post has specific permission requirements. By updating the post identifier in a timely manner, the system can obtain the corresponding permission from the association table according to the new post identifier, so that the user can only access the data and functions related to the new post.

[0019] In a second aspect, the present application provides a post-based permission processing device, which comprises: an obtaining module, configured to obtain identity information of a user when receiving a data access request; a first determining module, configured to determine a post identifier of the user according to the identity information, and determine a first target permission corresponding to the data access request according to the data access request; a second determining module, configured to determine a second target permission corresponding to the post identifier according to an association relationship between a preset post identifier and a preset permission and the post identifier; and a third determining module, configured to determine data corresponding to the data access request according to the data access request when the first target permission is not higher than the second target permission.

[0020] In a possible implementation, the device further comprises a sending module, configured to send a prompt information of insufficient permission to a terminal of the user when the first target permission is higher than the second target permission.

[0021] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the job-based access control method of the first aspect or any corresponding embodiment described above.

[0022] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the role-based access control method described in the first aspect or any corresponding embodiment thereof.

[0023] Fifthly, the present invention provides a computer program product, including computer instructions for causing a computer to execute the role-based access control method described in the first aspect or any corresponding embodiment thereof. Attached Figure Description

[0024] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of the permission processing based on job position according to an embodiment of the present invention;

[0026] Figure 2 This is a structural block diagram of a job-based access control device according to an embodiment of the present invention;

[0027] Figure 3 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] According to an embodiment of the present invention, a job-based permission processing method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0030] This embodiment provides a role-based access control method, which can be used on computer devices such as computers and servers. Figure 1 This is a flowchart illustrating a role-based access control method according to an embodiment of the present invention, as shown below. Figure 1 As shown, the process includes the following steps:

[0031] Step S101: When a data access request is received, obtain the user's identity information.

[0032] A data access request is a request made by a user to the system to obtain, view, modify, or perform other operations on specific data. For example, in a ride-hailing platform, actions such as a driver viewing their historical order records and a passenger checking their trip details are both data access requests.

[0033] User identity information refers to information used to uniquely identify a user, such as username, password, ID card number, and mobile phone number. In the ride-hailing scenario, the mobile phone number and ID card number provided by passengers and drivers during registration constitute identity information.

[0034] When the system receives a data access request from a user, it obtains the user's identity information through a specific authentication mechanism.

[0035] As an example, when a user enters their username and password, the system searches the database for a matching record to obtain the user's identity information.

[0036] As an example, the system sends a verification code to the user's mobile phone, the user enters the verification code to complete the identity verification, and the system obtains the user's identity information based on the mobile phone number.

[0037] As an example, when a user initiates an access request to static data or resources in a SaaS system, the system first intercepts the request and obtains the user's identity information through a user authentication mechanism.

[0038] Step S102: Determine the user's job identifier based on the identity information, and determine the first target permission corresponding to the data access request based on the data access request.

[0039] Job title identifiers are used within the system to distinguish different user roles or responsibilities. These job title identifiers can indicate roles such as finance, sales, and technology. First target permissions indicate the operational permissions a user expects to obtain regarding a given data access request. For example, if a passenger requests to view their itinerary, their first target permission is the permission to view that itinerary.

[0040] As an example, the association between job IDs and permissions is stored in a hash table, allowing for quick lookup of the corresponding second target permission using the job ID as the key.

[0041] As an example, in a relational database, a query can be performed using the job title identifier field to retrieve the corresponding permission records.

[0042] As an example, a rules engine is used to handle the association between job titles and permissions, and to determine the permissions of the second target based on preset rules.

[0043] Step S103: Based on the association between the preset job identifier and the preset permissions, and the job identifier, determine the second target permission corresponding to the job identifier.

[0044] The second target permission can indicate the permissions that a user corresponding to a given job title should have, determined from a preset job title and permission association relationship. For example, a sales position may have read and write permissions for customer data to facilitate recording customer information and following up on business; a finance position may have comprehensive operation permissions for financial data, including modification and deletion, to ensure the accuracy and integrity of financial data.

[0045] Step S104: When the first target permission is not higher than the second target permission, determine the data corresponding to the data access request based on the data access request.

[0046] When the first target permission is not higher than the second target permission, which means that the user has permission to access the data, the data corresponding to the data access request is determined according to the data access request.

[0047] As an example, write a permission comparison function to compare the first target permission and the second target permission item by item, and determine whether the first target permission is not higher than the second target permission.

[0048] As an example, permissions can be represented as binary bits, allowing for quick comparison of permission levels through bitwise operations.

[0049] As an example, if the permission relationships are complex, a permission tree can be constructed, and the permission tree can be traversed to determine whether the first target permission is within the scope of the second target permission.

[0050] In one scenario, Xiao Zhang, a marketing specialist in the company, opens the company's internal project management system and clicks the "View Market Research Report" button. The system receives a data access request. Xiao Zhang enters his employee ID "M001" and password on the login screen. The system searches the employee information database to obtain Xiao Zhang's identity information. Based on Xiao Zhang's employee ID "M001," the system searches the employee information table and determines that Xiao Zhang's job title is "Marketing Specialist." Simultaneously, the system analyzes Xiao Zhang's data access request and finds that he requests to view market research reports, determining that the first target permission is the permission to view market research reports. The system searches the preset job title and permission association table for the permissions corresponding to the "Marketing Specialist" job title and determines that the second target permission includes viewing market research reports, publishing marketing activity information, and participating in market discussions. The system compares the first target permission (the permission to view market research reports) with the second target permission (the permission to view market research reports, publish marketing activity information, and participate in market discussions), finding that the first target permission is no higher than the second target permission. Based on the data access request, the system retrieves the market research report data from the database and displays it to Xiao Zhang.

[0051] The job-based access control method provided in this embodiment obtains user identity information, determines job identifiers, and associates them with preset permissions to form a dual access control mechanism. First, a first target permission is determined based on the data access request; then, a second target permission is determined based on the job identifier. Data access is only permitted when the first target permission is no higher than the second target permission, effectively preventing users from unauthorized access to sensitive data and greatly improving data security. Furthermore, the preset association between job identifiers and permissions ensures that each job can only access data consistent with its responsibilities. Different jobs require different data permissions due to different job content and responsibilities. Through this association, the system can accurately assign appropriate permissions to each user, preventing over- or under-assignment of permissions and ensuring data security from the source.

[0052] In one possible implementation, the above method further includes: sending a permission insufficient prompt message to the user's terminal when the first target permission is higher than the second target permission.

[0053] An insufficient permissions message is a notification sent by the system to the user terminal, informing the user that the data operation requested exceeds the scope of their assigned permissions and cannot be performed. The message typically includes clear text and may also include guidance, such as suggesting the user contact the administrator.

[0054] When the system compares the first and second target permissions and finds that the first target permission is higher than the second target permission, the system will trigger a process of generating and sending a prompt message. Specifically, the system will generate a personalized permission deficiency prompt message based on a preset prompt message template, combined with the current user's identity information and request content, and then send the prompt message to the user's terminal device through the communication interface with the user's terminal.

[0055] As an example, various permission-insufficient prompt templates for different scenarios are predefined in the system. For example, "[Username], the permission you requested for [Operation Name] exceeds the permission scope of your current position [Position Identifier]. Please contact the administrator to obtain more permissions." When a prompt message needs to be sent, the system replaces the placeholders in the template with the actual values ​​based on the user information and the request content, generating the final prompt message.

[0056] The role-based access control method provided in this embodiment can quickly determine the access status after a user initiates a data access request. If the access is insufficient, a prompt message is promptly sent to the user's terminal, allowing the user to know the problem immediately and avoiding prolonged waiting without any feedback, thereby reducing user anxiety and confusion.

[0057] In one possible implementation, the above method also includes:

[0058] Step S201: Obtain the job identifiers of the enterprise; wherein, the job identifiers include sales job identifiers, finance job identifiers, and technical job identifiers.

[0059] Job identifiers can be used to uniquely identify different positions within an enterprise, such as sales job identifiers, finance job identifiers, and technical job identifiers, making it easier for the system to distinguish and manage different positions.

[0060] Obtain job identifiers from sources such as the company's organizational structure and human resource management system to identify different job types within the company, such as sales, finance, and technical positions.

[0061] As an example, the job information table is queried from the company's human resources database to obtain the job identifier.

[0062] As an example, the company's job information is imported into the system in file formats such as Excel and CSV, and the system reads the file to obtain the job identifier.

[0063] As an example, if a company's organizational structure information is stored in another system, job identifiers can be obtained by calling that system's interface.

[0064] Step S202 involves processing the static data and matching the static data with job identifiers to obtain the first matching result; wherein, the static data includes: customer data, financial data, and business processes.

[0065] Static data refers to data that is relatively stable and does not change frequently during the operation of an enterprise, such as customer data (basic customer information, purchase records, etc.), financial data (financial statements, accounting information, etc.), and business processes (the standardized procedures for various business operations within the enterprise).

[0066] Static data is organized, classified, and cleaned to meet the system's processing requirements. Then, based on the responsibilities and work needs of different positions, the static data is matched with position identifiers to determine the range of static data that each position can access and process, thus obtaining the first matching result.

[0067] As an example, rule matching involves defining matching rules between static data and job titles. For instance, sales positions can access basic customer information and purchase records in customer data, while finance positions can access financial data. Matching is then performed according to these rules.

[0068] As an example, managers in a company manually associate and label static data with job titles based on job responsibilities.

[0069] As an example, machine learning algorithms are used to automatically learn the correlation between static data and job identifiers based on historical data and job operation records, and then perform matching.

[0070] Step S203: Based on the first matching result, assign static data processing permissions to the job corresponding to the job identifier.

[0071] The first matching result indicates the result obtained after matching static data with job identifiers. It clarifies the correspondence between different job identifiers and static data, that is, which jobs can access and process which static data.

[0072] Based on the first matching result, static data processing permissions are assigned to the positions corresponding to the job identifiers, and the specific operation permissions of each position for static data are specified, such as viewing, modifying, and deleting.

[0073] As an example, the system provides a permission configuration interface, through which administrators can assign static data processing permissions to each position based on the first matching result.

[0074] As an example, a permission configuration script can be written to automatically assign permissions to roles based on the first matching result, thereby improving configuration efficiency.

[0075] Step S204: Process the system resource data and match the system resource data with the job identifier to obtain a second matching result; wherein, the system resource data includes: server resources, file storage resources and interface resources.

[0076] System resource data can indicate the resource data on which an enterprise information system depends for operation, including server resources (server configuration, performance, usage, etc.), file storage resources (file storage location, capacity, access permissions, etc.), and interface resources (interface information and calling rules provided by the system to the outside world).

[0077] The system resource data is collected, organized, and analyzed to understand the distribution and usage of system resources. Next, the system resource data is matched with job identifiers to determine the scope of system resources available to each job, resulting in a second matching result.

[0078] As an example, system resource data can be categorized, such as server resources being divided into development servers, test servers, production servers, etc., and then different types of system resources can be matched with job identifiers based on job responsibilities and work requirements.

[0079] As an example, ACLs are used to define the matching relationship between system resource data and job identifiers, clarifying the access permissions of each job to system resources.

[0080] For example, a detailed inventory of all resources within the system should be conducted, including server resources, file storage resources, and API interface resources. Based on job requirements, appropriate resource access permissions should be assigned to each position, such as full control, partial use, or read-only access. For instance, technical positions may have higher access permissions to server resources and API interface resources for system maintenance and development, while general business positions may only have read-only and limited write permissions to file storage resources.

[0081] Step S205: Based on the second matching result, assign coefficient resource data processing permissions to the job corresponding to the job identifier.

[0082] Based on the second matching result, system resource data processing permissions are assigned to the positions corresponding to the position identifiers, specifying the operation permissions of each position for system resource data, such as starting and stopping the server, uploading and downloading files, and calling interfaces.

[0083] Step S206: Based on the coefficient resource data processing permissions and static data processing permissions, obtain the association relationship between the preset job identifier and the preset permissions.

[0084] By integrating static data processing permissions and system resource data processing permissions, a relationship between preset job identifiers and preset permissions is formed, providing a unified basis for enterprise permission management.

[0085] As an example, static data processing permissions and system resource data processing permissions are stored in the database to form a table relating preset job identifiers and preset permissions.

[0086] As an example, the association between preset job identifiers and preset permissions can be cached in memory, such as using Redis caching.

[0087] In one scenario, a company's human resources department maintains job information in its HR management system. The system queries the database to obtain job identifiers, including "SALES" for sales positions, "FINANCE" for finance positions, and "TECH" for technical positions. The company processes the static data, categorizing customer data into basic customer information, purchase records, and customer feedback; financial data into financial statements, account details, and tax information; and business processes into sales processes, procurement processes, and expense reimbursement processes. Then, based on job responsibilities, the system matches basic customer information and purchase records with the "SALES" job identifier, matches financial statements and account details with the "FINANCE" job identifier, and matches business processes with the corresponding job positions, obtaining the first matching result.

[0088] In the system's permission configuration interface, based on the first matching result, administrators can assign permissions to the "SALES" job category to view basic customer information and purchase records, and to modify customer purchase records (such as updating order status); and to the "FINANCE" job category to view and modify financial statements and account details, etc.

[0089] The enterprise processes system resource data, categorizing server resources into development servers, test servers, and production servers; file storage resources into project document storage and customer data storage; and interface resources into sales interfaces, financial interfaces, and technical interfaces. Then, based on job responsibilities, the development server and project document storage are matched with the technical job identifier "TECH," and the production server and customer data storage are matched with sales and financial job identifiers, resulting in a second matching result. Based on this second matching result, the technical job identifier "TECH" is assigned start / stop permissions for the development server, upload / download permissions for the project document storage, and access permissions for the sales and financial interfaces; while the sales and financial job identifiers are assigned access permissions for the production server and view / modify permissions for the customer data storage.

[0090] The system integrates static data processing permissions and system resource data processing permissions, storing them in a permission table in the database to form a relationship between preset job identifiers and preset permissions. For example, the permissions corresponding to the sales job identifier "SALES" include viewing and modifying basic customer information and purchase records, accessing the production server, viewing and modifying customer data storage, and calling sales interfaces.

[0091] The role-based permission processing method provided in this embodiment clearly obtains the job identifiers of sales, finance, and technology, and performs detailed processing and matching of static data (customer data, financial data, business processes) and system resource data (server resources, file storage resources, interface resources) for different roles.

[0092] Furthermore, static data and system resource data are processed and permissions are assigned separately, and finally integrated to obtain the association between preset job identifiers and preset permissions. This hierarchical processing method makes permission management clearer and more organized.

[0093] In one possible implementation, the above method also includes:

[0094] Step S301: Obtain the identity information of the new user.

[0095] A new user's identity information can refer to data used to uniquely identify the new user, such as an employee's name, ID number, employee ID, login account, etc. In enterprise scenarios, the information registered when an employee joins the company can often serve as a source of identity information.

[0096] Collecting new users' identity information through specific methods. In enterprise systems, this may involve scenarios such as new user registration processes and information entry by the human resources department.

[0097] As an example, on the registration page of an enterprise's internal system, new users fill in identity information such as name, ID number, contact information, and employee number, and the system collects and stores this information.

[0098] As an example, a company's Human Resources Management System (HRMS) is integrated with an access control system. When a new employee joins the company, the HRMS automatically pushes the new employee's identity information to the access control system.

[0099] As an example, the human resources department organizes new employees' identity information into files in formats such as Excel and CSV, and the access control system reads this information through the file import function.

[0100] Step S302: Determine the new user's job identifier based on the new user's identity information.

[0101] Using the acquired new user identity information, a query is performed in the company's personnel information database or related systems to determine the new user's job position.

[0102] Step S303: Determine the third target permissions of the new user based on the new user's job identifier and association table; wherein, the association table stores the association relationship between preset job identifiers and preset permissions.

[0103] The third target permission can indicate the set of permissions that a new user should have, obtained by querying the associated table based on the new user's job identifier. It represents the data access and operation permissions that the new user is allowed to perform in the system.

[0104] As an example, loading the related table into memory and using data structures such as hash tables for fast queries improves query performance.

[0105] As an example, we can use object-relational mapping (ORM) frameworks such as Hibernate (Java) and Django ORM (Python) to query permission information in related tables in an object-oriented manner.

[0106] In one scenario, a new employee, Xiao Wang, joins an e-commerce company. He fills in his personal information on the company's internal registration page, including his name "Xiao Wang," ID number "[specific ID number]," employee ID "E001," and department "Sales Department." The system collects and stores this information. The access control system, based on Xiao Wang's employee ID "E001," queries the personnel information database and determines that Xiao Wang's job title is "Sales Specialist." Using the "Sales Specialist" job title as an index, the access control system searches the job permission association table and finds that the third-party permissions corresponding to "Sales Specialist" include viewing basic customer information, creating sales orders, and tracking order status.

[0107] The role-based access control method provided in this embodiment determines the role identifier through the new user's identity information and then determines the third target permission based on the association table, achieving precise permission allocation. It clearly defines the permission scope for each new user, reducing the security threats that internal personnel may pose due to excessive permissions. Even if an employee account is maliciously exploited, the attacker's access to information and the operations they can perform will be strictly limited due to restricted permissions, thereby minimizing the losses caused to the enterprise by internal security incidents.

[0108] In one possible implementation, the above method also includes:

[0109] Step S401: When a user's job identifier changes, determine the user's job identifier from the association table.

[0110] Step S402: Change the user's job identifier to the changed user's job identifier.

[0111] When a user's job title changes, the user's job title is determined from the associated table. For example, when a user changes from a sales position to a finance position, the user's job title in the associated table is changed, thus changing the job title from sales to finance, and the preset permissions for the finance position are also associated.

[0112] The job-based permission processing method provided in this embodiment stores the association relationship between preset job identifiers and preset permissions in an association table. When a user's job identifier changes, the system can quickly locate the user from the association table and promptly update their job identifier to the new identifier. Furthermore, each job has specific permission requirements. By updating the job identifier in a timely manner, the system can retrieve the corresponding permissions from the association table based on the new job identifier, ensuring that users can only access data and functions related to their new job.

[0113] In one specific implementation, a "Job Information Table" is created in the database of the SaaS system to record information such as job title, job description, and job ID. For example, records such as ("Sales Position", "Responsible for product sales and customer development", "position_001") and ("Finance Position", "Responsible for financial management and report preparation", "position_002") are inserted.

[0114] Create a "Static Data Resource Table" to record information such as data name, business module, and data storage path. Examples include ("Customer Information Data", "Sales Business Module", "database / sales / customers") and ("Financial Statement Data", "Financial Business Module", "database / finance / reports").

[0115] At the same time, a "Data Permission Table" is created to record the job ID, data resource ID, and data operation permissions. For example, ("position_001", "data_001", "read,write") indicates that the sales position has read and write permissions for customer information data.

[0116] Create a "System Resource Table" to record information such as resource name, resource type, and resource address. Examples include ("File Storage Server", "Storage Resource", "http: / / storage.example.com") and ("API Interface", "Interface Resource", "https: / / api.example.com"). Also create a "Resource Permission Table" to record the position ID, system resource ID, and resource access permissions. For example, ("position_002", "resource_001", "full_control") indicates that the finance position has full control over the file storage server.

[0117] By integrating the key information in the above table, the system establishes a link between job positions and data and resource permissions. For example, the table records job IDs, data resource IDs, data operation permissions, system resource IDs, and resource access permissions, facilitating quick querying and management of job permissions.

[0118] When a new employee joins the company, the system administrator assigns appropriate permissions to them in the "Position-Permission Mapping Table" based on their job information within the SaaS system's permission management interface. The system automatically associates the employee ID with the job ID, ensuring that the employee receives the set of permissions matching their job. For example, for a newly hired sales employee, the system administrator assigns permissions corresponding to the job "position_001" in the "Position-Permission Mapping Table," including read and write permissions for customer information data, as well as access to sales-related resources.

[0119] When an employee's position changes, the system administrator updates the employee's position ID in the permissions management interface. The system will automatically adjust the employee's permissions based on the new position's permission configuration. For example, if an employee is transferred from a sales position to a finance position, the system administrator updates the employee's position ID from "position_001" to "position_002". The system will automatically assign the employee full access to financial data and access to finance-related resources based on the finance position's permission configuration.

[0120] When a user initiates an access request for static data or resources in a SaaS system, the system frontend sends the request to the backend.

[0121] The access verification module obtains the user's identity information through a user authentication mechanism and queries the "Job Information Table" to determine the user's job ID.

[0122] Based on the user's job ID, the system queries the "Job-Permission Mapping Table" to find the corresponding static data permissions and resource permissions for that job. For example, if a user initiates a request to modify customer information data, and the system finds that the job has "read, write" permissions for that job, then it determines that the user has permission to perform the modification operation.

[0123] The system matches the user's requested permissions with the retrieved permissions. If a match is found, the system allows the user to access the corresponding data or resources and perform the appropriate operation; otherwise, the system denies access and returns a clear permission deficiency message to the user, such as "You do not have permission to perform this operation. Please contact the administrator."

[0124] The role-based permission management method provided in this embodiment achieves centralized and unified permission management by aggregating data permissions and resource permissions onto roles. Administrators only need to configure and maintain role-based permissions, eliminating the need to set permissions for each user individually, greatly simplifying the permission management process and improving management efficiency.

[0125] Furthermore, when a company's business architecture is adjusted or job functions change, it can quickly adapt to business changes simply by changing the relationship between job roles and permissions, ensuring that permission configurations match business needs in real time.

[0126] In addition, the strict permission verification process and the role-based permission aggregation mechanism effectively prevent users from accessing the system without authorization, reduce the risk of data leakage and resource abuse, and enhance the security and stability of the system (such as SaaS system).

[0127] This embodiment also provides a role-based access control device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0128] This embodiment provides a role-based access control device, such as... Figure 2 As shown, it includes: an acquisition module 201, used to acquire the user's identity information when a data access request is received; a first determination module 202, used to determine the user's job identifier based on the identity information, and to determine the first target permission corresponding to the data access request based on the data access request; a second determination module 203, used to determine the second target permission corresponding to the job identifier based on the association between the preset job identifier and the preset permission, and the job identifier; and a third determination module 204, used to determine the data corresponding to the data access request based on the data access request when the first target permission is not higher than the second target permission.

[0129] In one possible implementation, the above-mentioned device further includes: a sending module, used to send a permission insufficient prompt message to the user's terminal when the first target permission is higher than the second target permission.

[0130] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0131] In this embodiment, the job-based access control device is presented in the form of a functional unit. Here, a functional unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0132] This invention also provides a computer device having the above-described features. Figure 2 The shown is a role-based access control device.

[0133] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 3 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 3 Take a processor 10 as an example.

[0134] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0135] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.

[0136] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0137] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0138] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.

[0139] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0140] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0141] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A job-based access control method, characterized in that, The method includes: When a data access request is received, the user's identity information is obtained; Based on the identity information, determine the user's job identifier, and based on the data access request, determine the first target permission corresponding to the data access request; Based on the association between preset job identifiers and preset permissions, and the job identifier, determine the second target permission corresponding to the job identifier; When the first target permission is not higher than the second target permission, the data corresponding to the data access request is determined according to the data access request.

2. The job-based permission processing method according to claim 1, characterized in that, The method further includes: When the permissions of the first target are higher than those of the second target, a permission insufficient prompt message is sent to the user's terminal.

3. The job-based permission processing method according to claim 1, characterized in that, The method further includes: Obtain the job identifiers of the enterprise; wherein, the job identifiers include sales job identifiers, finance job identifiers, and technical job identifiers; The static data is processed and matched with job identifiers to obtain a first matching result; wherein, the static data includes: customer data, financial data, and business processes; Based on the first matching result, static data processing permissions are assigned to the job corresponding to the job identifier; The system resource data is processed, and the system resource data is matched with the job identifier to obtain a second matching result; the system resource data includes: server resources, file storage resources, and interface resources; Based on the second matching result, assign coefficient resource data processing permissions to the job corresponding to the job identifier; Based on the coefficient resource data processing permissions and the static data processing permissions, the association between the preset job identifier and the preset permissions is obtained.

4. The job-based access control method according to claim 3, characterized in that, The method further includes: Obtain the identity information of new users; Based on the new user's identity information, determine the new user's job identifier; Based on the new user's job identifier and association table, the third target permissions of the new user are determined; wherein, the association table stores the association relationship between preset job identifiers and preset permissions.

5. The job-based permission processing method according to claim 4, characterized in that, The method further includes: When a user's job title changes, the user's job title is determined from the association table; Change the user's job title identifier to the new user's job title identifier.

6. A job-based access control device, characterized in that, The device includes: The acquisition module is used to acquire the user's identity information when a data access request is received; The first determining module is used to determine the user's job identifier based on the identity information, and to determine the first target permission corresponding to the data access request based on the data access request. The second determining module is used to determine the second target permission corresponding to the job identifier based on the association between the preset job identifier and the preset permission, and the job identifier. The third determining module is used to determine the data corresponding to the data access request based on the data access request when the first target permission is not higher than the second target permission.

7. The job-based access control device according to claim 6, characterized in that, The device further includes: The sending module is used to send a permission insufficient prompt message to the user's terminal when the permission of the first target is higher than that of the second target.

8. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the job-based access control method according to any one of claims 1 to 5 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the role-based access control method according to any one of claims 1 to 5.

10. A computer program product, characterized in that, Includes computer instructions for causing a computer to perform the role-based access control method as described in any one of claims 1 to 5.