Pass authority authorization method, electronic equipment and storage medium

By automatically binding the relationship between departments and access control devices in the access control system and utilizing multi-threaded concurrent authorization technology, the inefficiency problem in the existing access control system is solved, and efficient departmental-level access permission authorization is achieved.

CN120977039APending Publication Date: 2025-11-18SHENZHEN HONGMEN INTELLIGENT PARKING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511104284.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

The existing access control system is inefficient in authorizing department employees to grant access permissions, especially when there are multiple combinations of conditions, which require manual cross-authorization operations, resulting in reduced management efficiency.

Method used

By responding to the user's selection of a target department in the organizational chart, the system queries the database to retrieve the target employee list, automatically binds it to the target access control device, obtains permission configuration information, and achieves batch binding and authorization at the department level. It also utilizes multi-threaded concurrent authorization technology to improve efficiency.

Benefits of technology

It enables batch binding operations at the department level, avoiding the repetitive work of selecting each person individually, improving management efficiency, and automatically handling multi-dimensional permission configurations, reducing human error and improving the reliability and efficiency of authorization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120977039A_ABST
    Figure CN120977039A_ABST
Patent Text Reader

Abstract

The invention relates to the field of access control authority management, in particular to a pass authority authorization method, electronic equipment and a storage medium, the pass authority authorization method comprises the following steps: responding to an operation of a user to select a target department in an organization structure chart, querying a database according to the target department, and obtaining a target employee list, the organization structure chart comprises a plurality of departments, the target employee list comprises employee information of each employee under the target department, binding the target employee list with the target access control equipment to obtain a bound employee list, obtaining permission configuration information of the target access control equipment, and authorizing the passing permission of each employee in the bound employee list according to the permission configuration information. According to the embodiment of the invention, the employee group is automatically associated through the department level, and the authorization relationship between the department and the access control equipment is automatically bound, so that the employees of each department needing to be bound do not need to be manually selected one by one, the repeated labor of selecting one by one is avoided, and the batch binding operation of the department level is realized, thereby improving the management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control and management, specifically to a method for authorizing access permissions, an electronic device, and a storage medium. Background Technology

[0002] With the development of intelligent buildings and enterprise digital management, modern access control systems have evolved from traditional mechanical locks to intelligent access control systems based on electronic identity authentication. An access control system is a comprehensive system of devices and software used to control and manage access to specific areas. It aims to achieve access control of target areas by identifying, judging, and controlling the entry and exit of personnel. It is widely used in residential communities, office buildings, schools, hospitals, factories, and other places, providing strong support for security management.

[0003] When administrators authorize access permissions for department employees through the current access control system, they generally need to manually select each department employee who needs to be bound to the access control device, resulting in repetitive work of selecting each person individually. This reduces management efficiency, especially when encountering permission requirements with multiple combinations of conditions. Administrators need to manually perform multiple cross-authorization operations in the access control system, which will further reduce management efficiency. Summary of the Invention

[0004] One objective of this embodiment is to provide a method for authorizing access permissions, an electronic device, and a storage medium to solve the technical problem of low management efficiency in existing access control systems.

[0005] In a first aspect, embodiments of the present invention provide a method for authorizing access permissions, comprising:

[0006] In response to a user's selection of a target department in an organizational chart, the system queries the database based on the target department to obtain a list of target employees. The organizational chart includes multiple departments, and the list of target employees includes employee information for each employee under the target department.

[0007] The target employee list is bound to the target access control device to obtain the bound employee list;

[0008] Obtain the permission configuration information of the target access control device;

[0009] Authorize access permissions for each employee in the bound employee list based on the permission configuration information.

[0010] Optionally, authorizing access permissions for each employee in the bound employee list based on the permission configuration information includes:

[0011] Based on the permission configuration information, a task to be authorized is generated, wherein the task to be authorized includes permission authorization tasks for each employee in the bound employee list;

[0012] The task to be authorized is divided into multiple task units, wherein each task unit includes a permission authorization task for at least one employee in the bound employee list;

[0013] Identify a target thread group, wherein the target thread group includes multiple task processing threads;

[0014] The target thread group is controlled to concurrently grant access permissions to each employee in the bound employee list based on multiple task units.

[0015] Optionally, determining the target thread group includes:

[0016] Obtain the device status code;

[0017] The device response status is determined based on the device status code;

[0018] The target thread group is determined based on the device response status.

[0019] Optionally, controlling the target thread group to concurrently grant access permissions to each employee in the bound employee list based on multiple task units includes:

[0020] Each of the task units is assigned to each of the task processing threads;

[0021] Each task processing thread is controlled to authorize access permissions for employees corresponding to each authorization task in the assigned task unit.

[0022] Optionally, the method further includes:

[0023] Obtain the task processing result for each permission authorization task fed back by each of the task processing threads;

[0024] The results of the task processing are summarized to obtain summary information.

[0025] An audit report is generated based on the summarized information from the results.

[0026] Optionally, the task processing result includes authorization success result and authorization failure result, the result summary information includes the number of successes, and the result summary information obtained by summarizing the task processing results includes:

[0027] If the task processing result is an authorization success result, then record the employee information of the employee corresponding to the authorization task and update the number of successes;

[0028] If the task processing result is an authorization failure, the permission authorization task is added to the retry queue as a retry task, and a designated asynchronous thread is controlled to authorize the access permissions of the employee corresponding to the target retry task according to the target retry task in the retry queue.

[0029] Optionally, the step of controlling the designated asynchronous thread to authorize access permissions for the employee corresponding to the target retry task based on the target retry task in the retry queue includes:

[0030] Determine the exception type based on the authorization failure result;

[0031] The retry interval duration for each retry is determined based on the type of exception.

[0032] The specified asynchronous thread is controlled to grant access permissions to the employee corresponding to the retry task according to the retry interval.

[0033] Optionally, the result summary information may further include anomaly details, and the method may further include:

[0034] Obtain the retry result fed back by the specified asynchronous thread for the target retry task, wherein the retry result includes retry success result and retry failure result;

[0035] If the retry result is a successful retry, then record the employee information of the employee corresponding to the target retry task and update the number of successful retryes;

[0036] If the retry result is a retry failure result, then the exception type is determined based on the retry failure result, and the exception type and the employee information of the employee corresponding to the target retry task are added to the exception details.

[0037] Optionally, the method further includes:

[0038] The current task progress is determined based on the number of successful attempts.

[0039] If the network is interrupted, the authorization data of the processed permission authorization tasks and the current task progress will be stored in a preset storage area;

[0040] If the network returns to normal, control the target thread group to continue processing the unprocessed permission authorization tasks.

[0041] Optionally, the permission configuration information includes the access period, and after obtaining the permission configuration information of the target access control device, it further includes:

[0042] If there are two or more target access control devices, determine whether there is a device mutual exclusion problem between each target access control device;

[0043] If a device mutual exclusion issue exists, a first prompt message will be generated;

[0044] If there is no device mutual exclusion problem, then determine whether there is a time conflict problem during the passage period;

[0045] If a time conflict exists, a second prompt message will be generated;

[0046] If there is no time conflict, proceed to the step of authorizing access permissions for each employee in the bound employee list based on the permission configuration information.

[0047] Optionally, after querying the database based on the target department to obtain the target employee list, the method further includes:

[0048] Obtain employee status information for each employee in the blacklist and / or target department;

[0049] The target employee list is filtered based on the blacklist and / or employee status information.

[0050] Optionally, the method further includes:

[0051] Obtain newly added employee information, which includes the employee information and department information of the newly added employee;

[0052] Determine the permission configuration information and target access control device that match the department information;

[0053] The newly added employee is granted access permissions based on the permission configuration information and the target access control device.

[0054] Optionally, the access permission authorization method further includes:

[0055] Obtain department merger information, which includes department information for each department to be merged;

[0056] The access permissions for each of the departments to be merged are determined based on the department information.

[0057] A permission selection page is displayed, which includes merge and reconfiguration options.

[0058] In response to the user selecting the merge option on the permission selection page, merge the access permissions of each of the departments to be merged;

[0059] In response to the user selecting the reconfiguration option on the permission selection page, a permission configuration page is displayed, allowing the user to reconfigure the access permissions for each of the departments to be merged.

[0060] Optionally, binding the target employee list to the target access control device to obtain the bound employee list includes:

[0061] The access control device map is displayed on the access control management interface, wherein the access control device map includes multiple access control devices distributed within the target area;

[0062] In response to the user's confirmation operation of selecting the target access control device on the access control device map, the target access control device is associated with each employee information in the target employee list to obtain a bound employee list.

[0063] In a second aspect, embodiments of the present invention provide an electronic device, including a memory and a processor, wherein the memory is connected to the processor, and the processor is configured to execute one or more computer programs stored in the memory, wherein when the processor executes the one or more computer programs, the electronic device implements the access permission authorization method as described in the first aspect.

[0064] In a third aspect, embodiments of the present invention provide a storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, cause the processor to perform the access authorization method as described in the first aspect.

[0065] Compared with existing technologies, this invention provides an access permission authorization method, an electronic device, and a storage medium. The access permission authorization method includes: responding to a user's selection of a target department in an organizational chart; querying a database based on the target department to obtain a target employee list; the organizational chart includes multiple departments, and the target employee list includes employee information for each employee under the target department; binding the target employee list to a target access control device to obtain a bound employee list; obtaining the permission configuration information of the target access control device; and authorizing access permissions for each employee in the bound employee list based on the permission configuration information. This embodiment automatically associates employee groups at the department level and automatically binds the authorization relationship between departments and access control devices, eliminating the need to manually select each employee in each department to be bound, avoiding repetitive work of selecting one person at a time, and realizing batch binding operations at the department level, thereby improving management efficiency. Furthermore, this embodiment can automatically bind employees from multiple departments to multiple access control devices with set access permissions, eliminating the need for manual cross-authorization operations, thereby further improving management efficiency. Attached Figure Description

[0066] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0067] Figure 1 This is a schematic diagram of the structure of an access permission authorization system provided in an embodiment of the present invention;

[0068] Figure 2 A flowchart illustrating a method for granting access permissions according to an embodiment of the present invention;

[0069] Figure 3 A schematic diagram of an organizational chart provided for an embodiment of the present invention;

[0070] Figure 4 This is a schematic diagram of an access control device map provided in an embodiment of the present invention;

[0071] Figure 5 This is a flowchart illustrating step S24 of a method for granting access permissions according to an embodiment of the present invention.

[0072] Figure 6 This is a schematic diagram of the structure of a passage authorization device provided in an embodiment of the present invention;

[0073] Figure 7 This is a schematic diagram of the structure of the authorization module in a access control authorization device provided in an embodiment of the present invention;

[0074] Figure 8 A schematic diagram of a passage authorization device provided in another embodiment of the present invention;

[0075] Figure 9 This is a schematic diagram of the structure of the aggregation module in a pass authorization device provided in an embodiment of the present invention;

[0076] Figure 10 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0077] To facilitate understanding of the present invention, a more detailed description is provided below with reference to the accompanying drawings and specific embodiments. It should be noted that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. The term "and / or" as used in this specification includes any and all combinations of one or more of the associated listed items.

[0078] Please see Figure 1 This invention provides a pass authorization system, such as... Figure 1 As shown, the access control authorization system 100 includes an electronic device 101, a server 102, and at least one access control device 103.

[0079] Electronic device 101 is the execution subject of the access permission authorization method provided in the embodiments of the present invention. Electronic device 101 includes, but is not limited to, user equipment (UE) such as smartphones, desktop computers, laptops, digital broadcast receivers, personal digital assistants (PDAs), and portable Android devices (PADs), handheld devices, in-vehicle devices, wearable devices, computing devices or other processing devices connected to wireless modems, mobile stations (MS), and mobile terminals.

[0080] In some embodiments, the electronic device 101 may run an application or plug-in. The application is a program with a graphical user interface (GUI). The application can be any visual program and can run in the foreground or background of the electronic device 101. For example, the application could be a permission management system application. A graphical user interface refers to a computer operating user interface displayed graphically. It is a human-computer communication interface format that allows users to manipulate icons or menu options on the display screen of the electronic device 101 in various ways to select commands, access files, launch programs, or perform other routine tasks. The plug-in can be a permission management system plug-in.

[0081] Server 102 is communicatively connected to electronic device 101 and is used to transmit various types of data related to access permission authorization to electronic device 101. In some embodiments, server 102 may be a physical server or a logical server virtualized from multiple physical servers. In some embodiments, server 102 may also be a server cluster composed of multiple interconnected servers, and each functional module may be distributed on each server in the server cluster.

[0082] Each access control device 103 is communicatively connected to the electronic device 101, and is used to transmit various types of data related to access permission authorization with the electronic device 101. Access control device 103 refers to a device that controls entry and exit through technical means, and is widely used in public places, enterprises, institutions, residential communities, and other places to achieve secure control over personnel entry and exit and ensure internal security. In some embodiments, access control device 103 includes an authentication device, an access controller, an execution device, and management software and platform.

[0083] Authentication devices are used to verify user identity information. Types of authentication devices include, but are not limited to, biometric devices, card readers, and keypads. Biometric devices are used to identify user biometric information and include, but are not limited to, fingerprint readers, facial recognition terminals, iris / retina scanners, palm print readers, and QR code / barcode scanners. Card readers are used to read information from physical cards (such as magnetic stripe cards, IC cards, ID cards, proximity cards / RFID cards) or mobile devices (NFC-enabled mobile phones). Keypads provide password verification functionality, allowing users to enter a preset password for verification.

[0084] The access control controller is the core processing unit of the access control device 103. It is used to receive user credential information from authentication devices such as card readers, determine whether the user has the right to enter at the current time according to the preset permission rules (stored in the access control controller or server database), and send the "open door" or "keep locked" command to the execution device according to the judgment result.

[0085] The actuator is electrically connected to the access control controller and is used to physically lock or release the door passage according to the instructions of the access control controller. In some embodiments, the actuator includes an electronic lock.

[0086] The management software and platform provide a human-machine interface for configuring, managing, and monitoring the entire access control system. In some embodiments, the functions of the management software and platform include, but are not limited to, user management, access control, device management, monitoring, record query, and access configuration. Specifically, user management involves adding, deleting, and modifying user information (name, department, etc.); access control involves assigning / revoking access permissions for users (specifying which users can enter which doors and during what time periods); device management involves managing the parameters and status of devices (authentication devices, access controllers, actuators, etc.); monitoring involves real-time monitoring of door opening / closing status and alarms; record query involves querying and exporting detailed entry / exit records and alarm logs; and access configuration involves setting complex access rules such as holidays and time periods.

[0087] Please see Figure 2 This invention provides a method for granting access permissions, such as... Figure 2 As shown, the access permission authorization method includes:

[0088] S21. Respond to the user's operation of selecting a target department in the organizational chart, query the database based on the target department, and obtain the target employee list. The organizational chart includes multiple departments, and the target employee list includes employee information for each employee under the target department.

[0089] In this step, the organizational chart is a visual image or table presented in the access control interface, used to display information such as the hierarchical relationships and departmental divisions within the organization. The organizational chart can be pre-configured and stored in a database, and can be loaded at any time when a user needs to use it.

[0090] For example, please see Figure 3 This organizational chart illustrates a corporate organizational structure tree, which includes a management level and departmental levels. The management level includes the general manager, while the departmental level comprises multiple departments: R&D, Production, Sales, Marketing, Finance, Legal, and Human Resources. The management level is the highest decision-making body, responsible for formulating the company's development strategy and goals, coordinating the work between departments, and monitoring the overall operation of the company. The departmental level is responsible for translating management decisions into concrete action plans, with each department executing specific tasks. Different departments perform different tasks.

[0091] Each department includes at least one employee. For example, as mentioned above, the R&D department may include employees E1001, E1002, E1005, E1006, E1008, E1009, E10011, and E10012; the production department may include employees E1003, E1014, E1015, E1017, E1020, and E1022; the sales department may include employees E1013, E1019, and E1025; the marketing department may include employees E1018, E1024, and E1027; the finance department may include employee E1003; the legal department may include employees E1021, E1028, and E1030; and the human resources department may include employees E1007 and E1026.

[0092] The access control management interface is the display interface used to configure and manage the access control system's access control settings. The access control management interface allows administrators to perform operations such as employee management, access control binding, access permission configuration, and access permission authorization. In some embodiments, users can open the access control management system by operating an electronic device. The access control management system is configured with a department authorization mode, which is a mode for authorizing access permissions for employees within a department. When the access control management system is open, the electronic device's display interface includes a mode selection area where users can freely select a mode, such as the department authorization mode. When a user completes the selection of the department authorization mode in the mode selection area, the electronic device can respond to the user's operation by entering the department authorization mode and displaying the access control management interface. The access control management interface includes a department authorization tab. When a user clicks on the department authorization tab, the electronic device can respond to the user's operation by loading an organizational chart.

[0093] The database stores a mapping table, which maps the correspondence between departments and employee lists. The employee list includes employee information for each employee in the corresponding department.

[0094] For example, the mapping relationship table is shown in Table 1 below:

[0095] Table 1

[0096]

[0097] The electronic device can look up the list of target employees corresponding to the target department in the mapping table. The target department can be one or more departments, and correspondingly, the list of target employees can be one or more employee lists. For example, as mentioned earlier, when the user selects the R&D department as the target department in the organizational chart, the electronic device can look up the list of target employees corresponding to the R&D department (List_1) in the mapping table. When the user selects the Production department and Sales department as the target departments in the organizational chart, the electronic device can look up the list of target employees corresponding to the Production department (List_2) and the list of target employees corresponding to the Sales department (List_3) in the mapping table.

[0098] In some embodiments, after S21, the access permission authorization method further includes: obtaining the employee status information of each employee under the blacklist and / or the target department, and filtering the target employee list according to the blacklist and / or the employee status information.

[0099] In this embodiment, the blacklist includes employee information of employees with conflicting permissions, and employee status information includes employed status and resigned status. The electronic device can remove employees listed on the blacklist or employees in a resigned status from the target employee list, thereby filtering the target employee list.

[0100] Therefore, this embodiment can automatically filter employees with conflicting permissions and employees who have left the company, realize automatic member synchronization, reduce human error, and improve the reliability of subsequent access permission authorization.

[0101] S22. Bind the target employee list to the target access control device to obtain the bound employee list.

[0102] In this step, the employee binding list is the list of employees bound to the target access control device, and the employee binding list includes the employee information of each employee who has been bound. The target access control device is the access control device that needs to be bound to each employee in the target employee list. The target access control device can be one or more access control devices.

[0103] In some embodiments, the access control system is configured with an access control device map, which includes multiple access control devices distributed within a target area.

[0104] For example, please see Figure 4The target area includes Building 1, Building 2, Building 3, and Building 4. Building 1 has a Door_1100 access control device at its main entrance; Building 2 has a Door_2202 access control device in Room 202 on the 2nd floor; Building 2 has a Door_2405 access control device in Room 405 on the 4th floor; Building 3 has a Door_3307 access control device in the laboratory (Room 307) on the 3rd floor; Building 3 has a Door_3509 access control device in the R&D hall (Room 509) on the 5th floor; and Building 4 has a Door_4100 access control device at its main entrance.

[0105] In some embodiments, the electronic device can display a map of access control devices on the access control device management interface. Users can select access control devices on the map according to their actual needs. After the selection is completed, the user can click the confirmation button on the access control management interface to indicate that the selected access control devices are confirmed to be correct. At this time, the electronic device can respond to the user's confirmation operation of selecting the target access control device on the access control device map, associate the target access control device with the information of each employee in the target employee list, and obtain the bound employee list.

[0106] For example, as mentioned earlier, the target employee list is List_1. After the user selects access control devices Door_1100, Door_3307, and Door_3509 on the access control device map and confirms, the electronic device can respond to this operation and associate the target employee list List_1 with the access control devices Door_1100, Door_3307, and Door_3509 respectively, resulting in the bound employee list shown in Table 2 below.

[0107] Table 2

[0108]

[0109] Therefore, this embodiment automatically associates employee groups at the department level and automatically binds the authorization relationship between departments and access control devices. It eliminates the need to manually select each employee in each department to be bound, avoiding repetitive work of selecting one person at a time. This enables batch binding operations at the department level, thereby improving management efficiency.

[0110] S23. Obtain the permission configuration information of the target access control device;

[0111] In this step, the permission configuration information is the information configured to grant access permissions to each employee in the target employee list that is bound to the target access control device.

[0112] In some embodiments, the permission configuration information includes the effective time, the period of access, and the permission type.

[0113] For example, as mentioned earlier, the permission configuration information of the target access control device Door_1100 is as follows:

[0114] Effective period: January 1, 2023 to January 1, 2024

[0115] Traffic hours: Weekdays 08:00-20:00

[0116] Permission type: Normal access (non-emergency permission)

[0117] The permission configuration information shows that employees of the department bound to the target access control device Door_1100 are allowed to pass through the access control device Door_1100 normally during the working days from 08:00 to 20:00 from January 1, 2023 to January 1, 2024. They are not allowed to pass through the access control device Door_1100 outside of the period from January 1, 2023 to January 1, 2024, or on rest days, holidays, or outside the working days from 08:00 to 20:00.

[0118] In some embodiments, the electronic device may display an effective time configuration box, an access time configuration box, and a permission type configuration box on the permission management interface. Users can configure the effective time in the effective time configuration box, the access time configuration box, and the permission type configuration box. After completing the permission configuration, users can click the confirmation button on the permission management interface to indicate that the configured permission information is correct. At this time, the electronic device can respond to this operation and obtain the permission configuration information of the target access control device.

[0119] It is understandable that when there are two or more target access control devices, users can configure the effective time, access period and permission type for each target access control device in the permission management interface. It is also understandable that the permission configuration information of different target access control devices can be the same or different.

[0120] Therefore, this embodiment only requires configuring access permissions for the target access control device to batch configure access permissions for employees of multiple departments bound to the target access control device. It also realizes the creation of department and permission configurations and multi-dimensional composite permission configurations for access control devices, eliminating the need for users to configure permissions for each dimension individually. This significantly improves the flexibility and efficiency of multi-dimensional permission coupling and avoids human configuration errors, thereby significantly reducing the configuration error rate.

[0121] In some embodiments, after S23, the access permission configuration method further includes: if there are two or more target access control devices, then determine whether there is a device mutual exclusion problem between each target access control device; if there is a device mutual exclusion problem, then generate a first prompt message; if there is no device mutual exclusion problem, then determine whether there is a time conflict problem during the access period; if there is a time conflict problem, then generate a second prompt message; if there is no time conflict problem, then proceed to the step of authorizing access permissions for each employee in the employee list according to the permission configuration information.

[0122] In this embodiment, the first prompt message is used to inform the user of a device conflict between multiple target access control devices, and the second prompt message is used to inform the user of a time conflict between passage periods.

[0123] For example, please continue reading Figure 4 Room 307 on the 3rd floor of Building 3 is a laboratory, and Room 405 on the 4th floor of Building 2 is a confidential area. Employees are not allowed to pass through both the laboratory and the confidential area at the same time. Therefore, there is a device mutual exclusion problem between the access control device Door_3307 in the laboratory and the access control device Door_2405 in the confidential area. If the target access control device includes both Door_3307 and Door_2405, the electronic device can generate the first prompt message that there is a device mutual exclusion problem between Door_3307 and Door_2405.

[0124] In some embodiments, the database includes a device mutual exclusion table, which stores each access control device combination that has a device mutual exclusion problem. If there are two or more target access control devices, the electronic device can arbitrarily select two target access control devices as an access control device combination and match the access control device combination with each access control device combination in the device mutual exclusion table. If there is a matching access control device combination in the device mutual exclusion table, the electronic device can determine that the access control device combination has a device mutual exclusion problem.

[0125] In some embodiments, if there are two or more target access control devices, the electronic device can obtain the permission configuration information of different target access control devices, extract the passage time period from the permission configuration information of each target access control device, and determine whether there is a time conflict problem based on whether there is an overlap in the passage time period.

[0126] Understandably, upon receiving the first notification, users can reselect the target access control device in the access control interface to eliminate the device mutual exclusion problem; upon receiving the second notification, users can reconfigure permissions in the access control interface to eliminate the time conflict problem.

[0127] Therefore, this embodiment can automatically perform permission rule verification before authorizing the communication permissions of department employees, avoiding time conflicts or device mutual exclusion issues, reducing manual review costs, and avoiding human operation errors or manual review errors. This helps to further reduce the configuration error rate, thereby improving the reliability of subsequent access permission authorization.

[0128] S24. Authorize access permissions for each employee in the employee list based on the permission configuration information.

[0129] In this step, as mentioned earlier, it is assumed that the access permissions for employees E1001, E1002, E1006, E1008, E1009, E10011, and E10012 under the target department are successfully authorized. Employee E1005 only fails to obtain access permission authorization on the target access control device Door_3307. The access permissions for each target access control device are shown in Table 3 below:

[0130] Table 3

[0131]

[0132] On the one hand, this embodiment automatically associates employee groups at the department level and automatically binds the authorization relationship between departments and access control devices. It eliminates the need to manually select each employee in each department to be bound, avoiding repetitive work of selecting one person at a time, and realizes batch binding operations at the department level, thereby improving management efficiency. On the other hand, this embodiment can automatically bind employees from multiple departments to multiple access control devices with set access permissions, eliminating the need for manual cross-authorization operations, thereby further improving management efficiency.

[0133] In some embodiments, the electronic device can obtain new employee information, which includes the employee information and department information of the new employee, determine the permission configuration information and target access control device that match the department information, and authorize the new employee's access permissions according to the permission configuration information and target access control device.

[0134] For example, suppose the newly added employee E1031 is an employee of the R&D department. The new employee information includes the employee information E1031 and the department information of the R&D department, as shown in Table 3 above. The electronic device can determine the permission configuration information matching the department information of the R&D department (effective time: 2023-01-01 to 2024-01-01; access time: weekdays 08:00-20:00; permission type: normal access) and the target access control devices Door_1100, Door_3307 and Door_3509. After the electronic device authorizes the access permission of the newly added employee E1031 according to the permission configuration information and the target access control devices, Table 3 above can be updated to Table 4 below:

[0135] Table 4

[0136]

[0137] Therefore, this embodiment can automatically inherit the access permissions of the department to which the new employee belongs, without the need for cumbersome permission configuration operations for the new employee, which helps to improve the efficiency of permission authorization for the new employee.

[0138] In some embodiments, the electronic device can obtain department merging information, which includes department information for each department to be merged. Based on the department information, it determines the access permissions for each department to be merged, presents a permission selection page, which includes merge and reconfiguration options. In response to the user's selection of the merge option on the permission selection page, it merges the access permissions for each department to be merged. In response to the user's selection of the reconfiguration option on the permission selection page, it presents a permission configuration page so that the user can reconfigure the access permissions for each department to be merged on the permission configuration page.

[0139] For example, as mentioned earlier, assuming the sales department and the marketing department are merged, both the sales department and the marketing department are departments to be merged. The electronic device obtains the department merger information, which includes the department information of the sales department and the marketing department. Assume that the access permissions of the sales department and the marketing department are as shown in Tables 5 and 6 below:

[0140] Table 5

[0141]

[0142] Table 6

[0143]

[0144] If the user selects the merge option on the permission selection page, the electronic device can respond to the user's selection of the merge option on the permission selection page and merge the access permissions of the sales department and the marketing department. When merging access permissions, the electronic device can take the union of the effective time and the access period. The merged access permissions are shown in Table 7 below:

[0145] Table 7

[0146]

[0147] If the user selects the reconfiguration option on the permission selection page, the electronic device will display the permission configuration page. Assume the user reconfigures the access permissions for target access control devices Door_2202, Door_2405, and Door_4100 on the permission configuration page as follows:

[0148] Effective period: January 1, 2024 to January 1, 2027

[0149] Traffic hours: Weekdays 08:00-20:00

[0150] Permission type: Normal access (non-emergency permission)

[0151] The electronic device can then obtain the access permissions shown in Table 8 below based on this permission configuration information:

[0152] Table 8

[0153]

[0154] Therefore, when departments are merged, electronic devices can automatically update the access permissions of each department to be merged according to user needs, without requiring users to manually adjust authorized employees. When access permissions need to be merged and are inconsistent, users do not need to manually modify the access permissions of each employee in each department to be merged. When access permissions need to be reconfigured, only one permission configuration operation needs to be performed for each relevant access control device, which helps to improve the synchronization efficiency of access permissions for each department to be merged.

[0155] In some embodiments, please refer to Figure 5 S24 includes:

[0156] S241. Generate tasks to be authorized based on permission configuration information, wherein the tasks to be authorized include permission authorization tasks for each employee in the employee list.

[0157] S242. The task to be authorized is split into multiple task units, wherein each task unit includes a permission authorization task for at least one employee in the employee list.

[0158] S243. Determine the target thread group, where the target thread group includes multiple task processing threads.

[0159] S244. Control the target thread group to concurrently authorize the access permissions of each employee in the employee list based on multiple task units.

[0160] In S241, the tasks to be authorized are those that authorize access permissions for each employee in the bound employee list. As mentioned earlier, the tasks to be authorized include those that authorize access permissions for R&D department employees E1001, E1002, E1005, E1006, E1008, E1009, E10011, and E10012 at target access control devices Door_1100, Door_3307, and Door_3509, respectively. Since there are 8 employees in the R&D department and 3 target access control devices, as shown in Table 9 below, the number of permission authorization tasks in the tasks to be authorized is 8 * 3 = 24.

[0161] Table 9

[0162] Unauthorized tasks Task content Unauthorized tasks Task content Duty_1 E1001, Door_1100 Duty_13 E1008, Door_1100 Duty_2 E1001, Door_3307 Duty_14 E1008, Door_3307 Duty_3 E1001, Door_3509 Duty_15 E1008, Door_3509 Duty_4 E1002, Door_1100 Duty_16 E1009, Door_1100 Duty_5 E1002, Door_3307 Duty_17 E1009, Door_3307 Duty_6 E1002, Door_3509 Duty_18 E1009, Door_3509 Duty_7 E1005, Door_1100 Duty_19 E10011, Door_1100 Duty_8 E1005, Door_3307 Duty_20 E10011, Door_3307 Duty_9 E1005, Door_3509 Duty_21 E10011, Door_3509 Duty_10 E1006, Door_1100 Duty_22 E10012, Door_1100 Duty_11 E1006, Door_3307 Duty_23 E10012, Door_3307 Duty_12 E1006, Door_3509 Duty_24 E10012, Door_3509

[0163] In Table 9 above, the task content includes the employee information of each employee in the employee list and the target access control device that needs to be authorized for each employee. This means that the task needs to be executed to obtain authorization for each employee in the employee list at the corresponding target access control device. As shown in Table 9 above, the task to be authorized, Duty_1, includes employee information E1001 and target access control device Door_1100. Therefore, the task to be authorized, Duty_1, is the task of obtaining authorization for employee E1001 at the target access control device Door_1100.

[0164] In S242, the electronic device can split the task to be authorized into multiple task units in any task splitting method. For example, the electronic device can split the task to be authorized into multiple task units with the same or different number of authorized tasks according to the number of authorized tasks. Alternatively, the electronic device can split the task to be authorized into task units corresponding to each employee in the bound employee list, in which case the number of task units is the same as the number of employees.

[0165] For example, as mentioned above, an electronic device can break down 24 authorization tasks into 12 task units, each task unit may include 2 authorization tasks, or an electronic device can break down 24 authorization tasks into 6 task units, each task unit may include 4 authorization tasks.

[0166] In S243, the electronic device can determine the target thread group based on the number of task units. For example, when the number of task units is 12, the electronic device can determine a target thread group consisting of 12 task processing threads, with each task processing thread processing one task processing unit. Alternatively, the electronic device can determine a target thread group consisting of 6 task processing threads, with each task processing thread processing one task processing unit.

[0167] In some embodiments, the electronic device may obtain a device status code, determine the device response status based on the device status code, and determine the target thread group based on the device response status.

[0168] In this embodiment, the device status code is a numeric or text value used to describe the device response status. The device response status refers to the reaction status of the electronic device to external events or inputs during operation.

[0169] If the device response status indicates that the device load is light, the electronic device can determine a target thread group consisting of as many task processing threads as possible; if the device response status indicates that the device load is heavy, the electronic device can determine a target thread group consisting of relatively few task processing threads.

[0170] Therefore, this embodiment can flexibly adjust the number of task processing threads used to process task units according to the device response status, thereby avoiding device overload and significantly improving the processing speed of large-scale authorization.

[0171] In S244, the electronic device can assign each task unit to each task processing thread and control each task processing thread to authorize the access rights of the employee corresponding to each authorization task according to each authorization task in the assigned task unit.

[0172] For example, as shown above, when the electronic device breaks down the task to be authorized into task units corresponding to each employee in the bound employee list, the number of task units is 8. A target thread group consisting of 8 task processing threads is determined. The electronic device can assign the task unit corresponding to employee EOOO1 to the first task processing thread and control the processing permissions of this task processing thread to authorize tasks Duty_1, Duty_2, and Duty_3, thereby authorizing access permissions for employee EOOO1. Similarly, it can assign the task unit corresponding to employee EOOO2 to the second task processing thread and control the processing permissions of this task processing thread to authorize tasks Duty_4, Duty_5, and Duty_6, thereby authorizing access permissions for employee E1OO2…

[0173] Therefore, this embodiment significantly improves task processing efficiency by splitting batch tasks into multiple task units and using multi-threaded concurrent processing of multiple task units, thereby improving permission authorization efficiency and optimizing system resource usage, thus avoiding system lag or system crashes in high-concurrency scenarios.

[0174] In some embodiments, when the data of the permission authorization task of a task unit is too large, the electronic device compresses the data of the permission authorization task of each task unit and distributes it to each task processing thread. This helps to reduce the amount of data transmission, thereby reducing the data transmission pressure, and thus improving the response speed and reducing the latency.

[0175] In some embodiments, the electronic device can obtain the task processing results for each authorized task fed back by each task processing thread, summarize the task processing results, obtain result summary information, and generate an audit report based on the result summary information.

[0176] In this embodiment, the audit report is a report used to describe operation records and statistical records.

[0177] Therefore, this embodiment enables intuitive and convenient traceability, thereby reducing management costs.

[0178] In some embodiments, the task processing result includes an authorization success result, which is the result of the authorization task being successfully authorized. Correspondingly, the result summary information includes the number of successes, which is the number of authorization tasks that were successfully authorized.

[0179] In some embodiments, if a permission authorization task fails to grant permissions, the task processing result may also include an authorization failure result, which is the result of permission authorization failure.

[0180] In some embodiments, if the task processing result is authorization success, the electronic device can record the employee information of the employee corresponding to the authorization task and update the number of successes. If the task processing result is authorization failure, the electronic device can add the authorization task as a retry task to the retry queue and control a designated asynchronous thread to authorize the access permission of the employee corresponding to the target retry task according to the target retry task in the retry queue.

[0181] In this embodiment, the retry queue is used to handle permission authorization tasks that fail to execute by the task processing thread. The asynchronous thread is designated as the thread that executes the retry task alone, while other task processing threads (or other calling threads) do not need to wait for the retry task to complete and can continue to execute other permission authorization tasks.

[0182] On the one hand, since many authorization task failures are transient (e.g., network jitter or service overload) rather than permanent errors, electronic devices can delay retries after a failure through retry strategies, taking advantage of the system's brief recovery window to prevent authorization tasks from being abandoned due to minor issues. After a authorization task is successfully executed, data operations (such as database updates) are applied, causing all replicas to eventually reach a consistent state.

[0183] On the other hand, by combining monitoring and retry strategies (such as retry queues or circuit breaker modes), authorization tasks are reliably processed without relying on manual intervention. This aligns with the principle of eventual consistency, enabling the system to "self-heal" after a failure rather than achieving immediate strong consistency, which helps ensure system reliability.

[0184] Therefore, when a permission authorization task fails, this embodiment can automatically retry the failed permission authorization task through this retry strategy to overcome temporary failures such as network interruption and temporary service unavailability, and ensure that the task is eventually executed successfully, thereby supporting the eventual consistency of the distributed system.

[0185] In some embodiments, the electronic device can determine the exception type based on the authorization failure result, determine the retry interval for each retry based on the exception type, and control the designated asynchronous thread to authorize the access permissions of the employee corresponding to the retry task according to the retry interval.

[0186] In this embodiment, the exception types include, but are not limited to, communication timeout, non-existent employee ID, incorrect data format, and device offline. The number of retries can be determined based on the exception type or set according to actual needs; for example, the number of retries can be uniformly set to 3. It is understood that the retry interval will differ depending on the exception type. In some embodiments, the retry interval increases with the number of retries. For example, if the exception type is communication timeout, the retry interval between the first and second retries is 60 seconds, and the retry interval between the second and third retries is 300 seconds; if the exception type is device offline, the retry interval between the first and second retries is 30 seconds, and the retry interval between the second and third retries is 100 seconds.

[0187] Therefore, on the one hand, the intelligent retry strategy provided in this embodiment can adaptively adjust the retry interval of each retry according to the type of exception, avoiding system avalanche caused by blind retries, thereby improving system reliability. On the other hand, it also avoids invalid retries, thereby improving retry efficiency.

[0188] On the other hand, in a distributed system, the failure of a permission task may result in some nodes not updating their data (for example, updating one database copy but another fails). This embodiment can continuously retry through a retry strategy, and set the retry interval to increase with the number of retries until the task succeeds (or the maximum number of retries is reached), ensuring that the operation is completed on all relevant nodes, reducing data forks, speeding up consistency, thereby avoiding data inconsistency, and thus ensuring eventual consistency of the task.

[0189] In some embodiments, the result summary information may also include anomaly details, which are detailed records of various abnormal situations that occur during task execution.

[0190] In some embodiments, the exception details include the exception type of the retry task and the employee information of the employee corresponding to the retry task. For example, as shown in Table 9 above, if the retry task is Duty_8, and the specified asynchronous thread repeatedly attempts to retrace Duty_8 but encounters a communication timeout with the target access control device Door_3307, causing Duty_8 to fail to complete successfully, then the electronic device can generate the following exception details:

[0191] Employee Information: E1005 (Exception Type: Communication timeout with target access control device Door_3307)

[0192] In some embodiments, the electronic device can obtain the retry results fed back by a specified asynchronous thread for the target retry task. The retry results include retry success results and retry failure results. If the retry result is a retry success result, the employee information of the employee corresponding to the target retry task is recorded and the number of successes is updated. If the retry result is a retry failure result, the exception type is determined according to the retry failure result and the exception type and the employee information of the employee corresponding to the target retry task are added to the exception details.

[0193] In this embodiment, a successful retry result means the retry task succeeded, and a failed retry result means the retry task failed. If the retry result is successful, it means that the specified asynchronous thread did not encounter any abnormalities during the retry process and successfully authorized the access permission. If the retry result is failed, it means that the specified asynchronous thread encountered some kind of abnormality during multiple retries, which prevented it from successfully authorizing the access permission. In this case, the specified abnormal thread ends the retry and determines that the retry failed.

[0194] In some embodiments, the electronic device can determine the task processing progress based on the number of successful attempts and the number of failed retries, and present the task processing progress on the permission management interface.

[0195] For example, as mentioned earlier, if the number of authorization tasks is 24, the number of successful authorization tasks is 15, and the number of retry tasks that failed is 2, then the task processing progress is (15+2) / 24 = 71%.

[0196] In some embodiments, the task processing progress can be presented in the form of a progress bar on the permission management interface.

[0197] Therefore, this embodiment can present the task progress to the user intuitively, thereby improving the user experience.

[0198] In some embodiments, the electronic device can determine the current task progress based on the number of successful transactions. If the network is interrupted, the authorization data of the processed authorization tasks and the current task progress are stored in a preset storage area. If the network is restored, the target thread group is controlled to continue processing the unprocessed authorization tasks.

[0199] Therefore, this embodiment improves the ability to resume interrupted transmissions by automatically saving the task progress when the network is interrupted and continuing to process unfinished tasks after the network is restored, thereby improving the system reliability.

[0200] In some embodiments, electronic devices may use timestamp hash chain technology to generate immutable authorization records, supporting the rapid generation of audit reports by department, access control device, and time period.

[0201] For example, an authorization record may include: timestamp + data payload + preceding hash (the final hash value of the previous record in the chain) + digital signature (the server's private key signing the hash).

[0202] Therefore, this embodiment reduces management costs by constructing a digital signature and traceability system for operation logs.

[0203] In some embodiments, the audit report includes, but is not limited to, department information of the target department, device information of the target access control device, number of successes, and anomaly details.

[0204] For example, as mentioned above, the audit report is as follows:

[0205] Target Department: R&D Department

[0206] Target access control devices: Door_1100, Door_3307, and Door_3509

[0207] Number of successes: 23 (96%)

[0208] Exception details:

[0209] Employee Information: E1005 (Exception Type: Communication timeout with target access control device Door_3307)

[0210] It should be noted that in the above embodiments, there is no necessarily a certain order between the steps. Those skilled in the art can understand from the description of the embodiments of the present invention that the above steps may have different execution orders in different embodiments, that is, they may be executed in parallel or in turn, etc.

[0211] As another aspect of this invention, this embodiment provides a access permission authorization device. The access permission authorization device can be a software module, which includes several instructions stored in a memory. A processor can access the memory and execute the instructions to complete the access permission authorization methods described in the various embodiments above.

[0212] In some embodiments, the access control authorization device can be constructed from hardware devices. For example, the access control authorization device can be constructed from one or more chips, which can work together to complete the access control authorization method described in the various embodiments above. As another example, the access control authorization device can also be constructed from components such as general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), microcontrollers, ARM (Acorn RISC Machines), programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination of these components.

[0213] In some embodiments, please refer to Figure 6 The access permission authorization device 600 provided in this embodiment of the invention includes a query module 601, a binding module 602, a first acquisition module 603, and an authorization module 604.

[0214] The query module 601 is used to respond to the user's operation of selecting a target department in the organizational chart, query the database based on the target department, and obtain a list of target employees. The organizational chart includes multiple departments, and the list of target employees includes employee information for each employee under the target department. The binding module 602 is used to bind the list of target employees to the target access control device to obtain a list of bound employees. The first acquisition module 603 is used to acquire the permission configuration information of the target access control device. The authorization module 604 is used to authorize access permissions for each employee in the list of bound employees based on the permission configuration information.

[0215] In some embodiments, please refer to Figure 7 The authorization module 604 includes a generation unit 6041, a splitting unit 6042, a determination unit 6043, and a first control unit 6044.

[0216] The generation unit 6041 is used to generate a task to be authorized based on the permission configuration information, wherein the task to be authorized includes a permission authorization task for each employee in the employee list. The splitting unit 6042 is used to split the task to be authorized into multiple task units, wherein each task unit includes a permission authorization task for at least one employee in the employee list. The determining unit 6043 is used to determine the target thread group, wherein the target thread group includes multiple task processing threads. The first control unit 6044 is used to control the target thread group to concurrently authorize the access permissions of each employee in the employee list based on the multiple task units.

[0217] In some embodiments, the determining unit 6043 is specifically used to: obtain a device status code, determine a device response status based on the device status code, and determine a target thread group based on the device response status.

[0218] In some embodiments, the first control unit 6044 is specifically configured to: assign each task unit to each task processing thread, and control each task processing thread to authorize the access permissions of the employee corresponding to each authorization task according to each authorization task in the assigned task unit.

[0219] In some embodiments, please refer to Figure 8 The access authorization device 600 also includes a second acquisition module 605, a summarization module 606, and a generation module 607.

[0220] The second acquisition module 605 is used to acquire the task processing results for each authorized task fed back by each task processing thread. The summary module 606 is used to summarize the task processing results and obtain the result summary information. The generation module 607 is used to generate an audit report based on the result summary information.

[0221] In some embodiments, please refer to Figure 9 The task processing results include authorization success results and authorization failure results. The result summary information includes the number of successes. The summary module 606 includes a recording unit 6061, an update unit 6062, an addition unit 6063, and a second control unit 6064.

[0222] The recording unit 6061 records the employee information of the employee corresponding to the authorization task when the task processing result is authorization success. The updating unit 6062 updates the success count when the task processing result is authorization success. The adding unit 6063 adds the authorization task as a retry task to the retry queue when the task processing result is authorization failure. The second control unit 6064 controls a designated asynchronous thread to authorize the access permission of the employee corresponding to the target retry task according to the target retry task in the retry queue when the task processing result is authorization failure.

[0223] In some embodiments, the second control unit 6064 is specifically configured to: determine the exception type based on the authorization failure result, determine the retry interval duration for each retry based on the exception type, and control a specified asynchronous thread to authorize the access permissions of the employee corresponding to the retry task according to the retry interval duration.

[0224] It should be noted that the aforementioned access control authorization device can execute the access control authorization method provided in the embodiments of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in the embodiments of the access control authorization device can be found in the access control authorization method provided in the embodiments of the present invention.

[0225] Please see Figure 10 , Figure 10 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. For example... Figure 10 As shown, the electronic device 101 includes one or more processors 1011 and a memory 1012. Figure 10 Take the 1011 processor as an example.

[0226] Processor 1011 is configured to support the computer device in performing the corresponding functions in the methods described in the above method embodiments. Processor 1011 may be a Central Processing Unit (CPU), a Network Processor (NP), a hardware chip, or any combination thereof. The aforementioned hardware chip may be an Application Specific Integrated Circuit (ASIC), a Programmable Logic Device (PLD), or a combination thereof. The aforementioned PLD may be a Complex Programmable Logic Device (CPLD), a Field-Programmable Gate Array (FPGA), a Generic Array Logic (GAL), or any combination thereof.

[0227] Memory 1012 is used to store program code. Memory 1012 may include volatile memory (VM), such as random access memory (RAM); memory may also include non-volatile memory (NVM), such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); memory 1012 may also include combinations of the above types of memory.

[0228] The memory 1012 can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules, such as the program instructions / modules corresponding to the access permission authorization method in the embodiments of the present invention. The processor 1011 executes various functional applications and data processing of the access permission authorization method and access permission authorization device by running the non-volatile software programs, instructions, and modules stored in the memory 1012, that is, it realizes the functions of each module or unit of the access permission authorization method and access permission authorization device provided in the above method embodiments.

[0229] The memory 1012 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and applications required for at least one function. The data storage area may store data created based on the use of the access control device. In some embodiments, the memory 1012 may optionally include memory remotely configured relative to the processor, which can be connected to the access control device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0230] The one or more modules are stored in the memory 1012. When executed by the one or more processors 1011, they execute the access permission authorization method in any of the above method embodiments. For example, they execute the method steps described in the above method embodiments to realize the functions of the modules described in the above device embodiments.

[0231] This invention also provides a storage medium storing a computer program, the computer program including program instructions, which, when executed by a computer, cause the computer to perform the method described in the foregoing embodiments.

[0232] It will be understood by those skilled in the art that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0233] Finally, it should be noted that the present invention can be implemented in many different forms and is not limited to the embodiments described in this specification. These embodiments are not intended to impose additional limitations on the content of the present invention; their purpose is to provide a more thorough and comprehensive understanding of the disclosure of the present invention. Furthermore, within the framework of the present invention, the above-mentioned technical features can be combined with each other, and many other variations of different aspects of the present invention as described above exist, all of which are considered to be within the scope of the present invention specification. Moreover, those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.

Claims

1. A method for authorizing access permissions, characterized in that, include: In response to a user's selection of a target department in an organizational chart, the system queries the database based on the target department to obtain a list of target employees. The organizational chart includes multiple departments, and the list of target employees includes employee information for each employee under the target department. The target employee list is bound to the target access control device to obtain the bound employee list; Obtain the permission configuration information of the target access control device; Authorize access permissions for each employee in the bound employee list based on the permission configuration information.

2. The access permission authorization method according to claim 1, characterized in that, The step of granting access permissions to each employee in the bound employee list based on the permission configuration information includes: Based on the permission configuration information, a task to be authorized is generated, wherein the task to be authorized includes permission authorization tasks for each employee in the bound employee list; The task to be authorized is divided into multiple task units, wherein each task unit includes a permission authorization task for at least one employee in the bound employee list; Identify a target thread group, wherein the target thread group includes multiple task processing threads; The target thread group is controlled to concurrently grant access permissions to each employee in the bound employee list based on multiple task units.

3. The access permission authorization method according to claim 2, characterized in that, The determination of the target thread group includes: Obtain the device status code; The device response status is determined based on the device status code; The target thread group is determined based on the device response status.

4. The access permission authorization method according to claim 2, characterized in that, The control of the target thread group to concurrently grant access permissions to each employee in the bound employee list based on multiple task units includes: Each of the task units is assigned to each of the task processing threads; Each task processing thread is controlled to authorize access permissions for employees corresponding to each authorization task in the assigned task unit.

5. The access permission authorization method according to claim 4, characterized in that, Also includes: Obtain the task processing result for each permission authorization task fed back by each of the task processing threads; The results of the task processing are summarized to obtain summary information. An audit report is generated based on the summarized information from the results.

6. The access permission authorization method according to claim 5, characterized in that, The task processing results include authorization success results and authorization failure results. The result summary information includes the number of successes. The result summary information obtained by summarizing the task processing results includes: If the task processing result is an authorization success result, then record the employee information of the employee corresponding to the authorization task and update the number of successes; If the task processing result is an authorization failure, the permission authorization task is added to the retry queue as a retry task, and a designated asynchronous thread is controlled to authorize the access permissions of the employee corresponding to the target retry task according to the target retry task in the retry queue.

7. The access permission authorization method according to claim 6, characterized in that, The control of the designated asynchronous thread to authorize access permissions for the employee corresponding to the target retry task based on the target retry task in the retry queue includes: Determine the exception type based on the authorization failure result; The retry interval duration for each retry is determined based on the type of exception. The specified asynchronous thread is controlled to grant access permissions to the employee corresponding to the retry task according to the retry interval.

8. The access permission authorization method according to claim 6, characterized in that, The summary results also include anomaly details, and the access permission authorization method further includes: Obtain the retry result fed back by the specified asynchronous thread for the target retry task, wherein the retry result includes retry success result and retry failure result; If the retry result is a successful retry, then record the employee information of the employee corresponding to the target retry task and update the number of successful retryes; If the retry result is a retry failure result, then the exception type is determined based on the retry failure result, and the exception type and the employee information of the employee corresponding to the target retry task are added to the exception details.

9. The access permission authorization method according to claim 6, characterized in that, Also includes: The current task progress is determined based on the number of successful attempts. If the network is interrupted, the authorization data of the processed permission authorization tasks and the current task progress will be stored in a preset storage area; If the network returns to normal, control the target thread group to continue processing the unprocessed permission authorization tasks.

10. The access permission authorization method according to claim 1, characterized in that, The permission configuration information includes the access period, and after obtaining the permission configuration information of the target access control device, it also includes: If there are two or more target access control devices, determine whether there is a device mutual exclusion problem between each target access control device; If a device mutual exclusion issue exists, a first prompt message will be generated; If there is no device mutual exclusion problem, then determine whether there is a time conflict problem during the passage period; If a time conflict exists, a second prompt message will be generated; If there is no time conflict, proceed to the step of authorizing access permissions for each employee in the bound employee list based on the permission configuration information.

11. The access permission authorization method according to claim 1, characterized in that, After querying the database based on the target department to obtain the target employee list, the process further includes: Obtain the blacklist and / or the employee status information of each employee under the target department; The target employee list is filtered based on the blacklist and / or employee status information.

12. The access permission authorization method according to claim 1, characterized in that, Also includes: Obtain newly added employee information, which includes the employee information and department information of the newly added employee; Determine the permission configuration information and target access control device that match the department information; The newly added employee is granted access permissions based on the permission configuration information and the target access control device.

13. The access permission authorization method according to claim 1, characterized in that, Also includes: Obtain department merger information, which includes department information for each department to be merged; The access permissions for each of the departments to be merged are determined based on the department information. A permission selection page is displayed, which includes merge and reconfiguration options. In response to the user selecting the merge option on the permission selection page, merge the access permissions of each of the departments to be merged; In response to the user selecting the reconfiguration option on the permission selection page, a permission configuration page is displayed, allowing the user to reconfigure the access permissions for each of the departments to be merged.

14. The access permission authorization method according to any one of claims 1 to 13, characterized in that, The step of binding the target employee list with the target access control device to obtain the bound employee list includes: A map of access control devices is presented, wherein the map includes multiple access control devices distributed within the target area; In response to the user's confirmation operation of selecting the target access control device on the access control device map, the target access control device is associated with each employee information in the target employee list to obtain the bound employee list.

15. An electronic device, characterized in that, The device includes a memory and a processor, the memory being connected to the processor, the processor being configured to execute one or more computer programs stored in the memory, the processor causing the electronic device to implement the access authorization method as described in any one of claims 1 to 14 when executing the one or more computer programs.

16. A storage medium, characterized in that, The storage medium stores a computer program, which includes program instructions that, when executed by a processor, cause the processor to perform the access authorization method as described in any one of claims 1 to 14.