Data query method and device, electronic equipment and storage medium
By generating a target virtual view and determining the data query results based on user permissions, the problem of data leakage caused by permission bypass in conversational systems is solved, and secure and accurate data query is achieved.
Patent Information
- Application Number
- CN202511512296.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-22
- Publication Date
- 2026-01-23
AI Technical Summary
In existing technologies, the problem of data leakage caused by permission bypass when querying data through conversational systems has not been effectively solved, especially in complex nested structured query statements, where incorrect or missing permission conditions can lead to data leakage.
By obtaining the user's natural language query statement, a target virtual view is generated. The target virtual view includes the fields and records that the user has query permissions for. The data query results are determined based on this view, avoiding the dynamic injection of permission conditions after generating the structured query statement, and ensuring that the user only obtains the data within their permissions.
This effectively avoids data leaks caused by permission bypassing, improves the security of data queries, ensures that users only obtain data within their authorized scope, and enhances the security and accuracy of data queries.
Smart Images

Figure CN121387931A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to a data query method and device, electronic equipment and a storage medium. BACKGROUND
[0002] A dialog system usually converts a natural language query into a structured query statement based on a large language model. In the process of querying data, the permission control of data is crucial. At present, the permission control of data usually adopts a post-injection mode, that is, a permission condition is dynamically injected after the structured query statement is generated. However, dynamic injection of the permission condition needs to accurately parse an abstract syntax tree of the structured query statement to determine a correct position of injecting the permission condition. For a complex nested structured query statement, the injection of the permission condition may be wrong or missed, resulting in permission bypassing, data leakage, and return of an incorrect result. SUMMARY
[0003] The present application provides a data query method and device, electronic equipment and a storage medium to solve the problem of permission bypassing and data leakage when data is queried through a dialog system.
[0004] According to an aspect of the present application, a data query method is provided, which comprises:
[0005] obtaining a first query statement input by a user in a target system, the target system being capable of interacting with the user in a natural language manner to query data, the first query statement being a statement expressed in a natural language for querying a target database associated with the target system;
[0006] determining a data query result based on the first query statement and a target virtual view, the target virtual view being generated based on the target database, the target virtual view including fields and records for which the user has query permission, and the data query result being data corresponding to the first query statement in the target database and for which the user has query permission;
[0007] returning the data query result to the user through the target system.
[0008] According to another aspect of the present application, a data query device is provided, which comprises:
[0009] a first obtaining module configured to obtain a first query statement input by a user in a target system, the target system being capable of interacting with the user in a natural language manner to query data, the first query statement being a statement expressed in a natural language for querying a target database associated with the target system;
[0010] The first determining module is configured to determine a data query result based on the first query statement and a target virtual view, the target virtual view is generated based on a target database, the target virtual view includes fields and records that the user has query permissions, and the data query result is data corresponding to the first query statement in the target database and having query permissions of the user.
[0011] The first returning module is configured to return the data query result to the user through the target system.
[0012] According to another aspect of the present application, an electronic device is provided, which comprises:
[0013] at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the data query method of any of the embodiments of the present application.
[0014] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to implement the data query method of any of the embodiments of the present application when executed.
[0015] The technical solution of the embodiments of the present application acquires the first query statement input by the user in the target system, the target system can interact with the user in a natural language manner, the first query statement is a statement for querying the target database associated with the target system in a natural language, determines the data query result based on the first query statement and the target virtual view, the target virtual view is generated based on the target database, and the data query result is data corresponding to the first query statement in the target database and having query permissions of the user, returns the data query result to the user through the target system, and realizes that the user has query permissions for the fields and records included in the target virtual view, so that the data query result corresponding to the first query statement is determined through the target virtual view, the problem of data leakage caused by permission bypass can be effectively avoided after the structured query statement is generated, and the security of data query of the user in the target system is improved.
[0016] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to make the technical solutions in the embodiments of the present application clearer, the accompanying drawings needed in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description only represent some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.
[0018] Figure 1 A flow chart of a data query method provided by an embodiment of the present application is shown in FIG. 2.
[0019] Figure 2 A flow chart of another data query method provided by an embodiment of the present application is shown in FIG. 3.
[0020] Figure 3 A structure diagram of a target system provided by an embodiment of the present application is shown in FIG. 4.
[0021] Figure 4 A structure diagram of a data query device provided by an embodiment of the present application is shown in FIG. 5.
[0022] Figure 5 A structure diagram of an electronic device for implementing a data query method provided by an embodiment of the present application is shown in FIG. 6. DETAILED DESCRIPTION
[0023] In order to make the technical solutions in the embodiments of the present application clearer, the accompanying drawings needed in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description only represent some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.
[0024] It should be noted that the terms "first", "second", and the like in the description and claims of the present application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to the process, method, product or device.
[0025] It can be understood that before using the technical solutions disclosed in the embodiments of the present application, the type of personal information involved in the present application, the use range, the use scenario, etc. should be informed to the user and the authorization of the user should be obtained according to relevant laws and regulations through appropriate means.
[0026] For example, in response to receiving the user's active request, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can voluntarily choose whether to provide personal information to the electronic device, application program, server or storage medium, etc. software or hardware that performs the operation of the technical solutions of the present application according to the prompt information.
[0027] Figure 1 A flowchart of a data query method provided by an embodiment of the present application. The embodiment of the present application can be applicable to the case of querying data through a conversational system. The method can be executed by a data query device, which can be realized in the form of hardware and / or software and can be configured in an electronic device that implements the data query method. As shown in Figure 1 the data query method includes:
[0028] S101, obtaining a first query statement input by a user in a target system, the target system being capable of interacting with the user in a natural language manner for data, and the first query statement being a statement in a natural language for querying a target database associated with the target system.
[0029] The target system can be a system that can simulate a conversation by interacting with the user in a natural language, understand the user's intention and generate a corresponding response. For example, the target system can be a conversational system. The target system can be constructed based on a large language model (LLM). The first query statement can be used to reflect the user's data query requirement. Specifically, the first query statement input by the user can be obtained through a visual interface associated with the target system.
[0030] S102, determining a data query result based on the first query statement and a target virtual view, the target virtual view being generated based on the target database, the target virtual view including fields and records that the user has query authority for, and the data query result being data corresponding to the first query statement in the target database and having query authority for the user.
[0031] The target virtual view can refer to a virtual table generated by a structured query statement based on the target database, all fields and all records in the target database that the user has query permissions for. The target virtual view does not store actual data, and only saves the structured query statement used to generate the target virtual view. Specifically, the user has query permissions for the fields and records included in the target virtual view, so that determining the data query result corresponding to the first query statement through the target virtual view can effectively avoid the problem of data leakage caused by permission bypass.
[0032] As an optional implementation of the embodiment of the present application, the determination process of the target virtual view includes: obtaining the data query permissions of the user for the target database from the preset permission library; and generating the target virtual view in the target system based on the data query permissions and the target database.
[0033] The preset permission library can refer to a set of data query permissions of different users for the target database established in advance. The data query permissions can include Row-Level Security (RLS) permissions and Column-Level Security (CLS) permissions. The CLS permissions correspond to all fields in the target database that the user has query permissions for. The RLS permissions correspond to all records in the target database that the user has query permissions for.
[0034] Specifically, the target virtual view corresponding to each user can be generated based on the target database and the data query permissions of each user for the target database included in the preset permission library. For example, the target virtual view can be generated based on “SELECT [allowed_columns] FROM table WHERE [row_permission_conditions]”, wherein allowed_columns is determined based on the CLS permissions, and row_permission_conditions is determined based on the RLS permissions.
[0035] S103, returning the data query result to the user through the target system.
[0036] Specifically, the target system can display the data query result to the user in a natural language manner through an associated visual interface to improve user experience.
[0037] As an optional implementation of the embodiment of the present application, the data query method further includes steps A1-A2:
[0038] Step A1, obtaining all query logs in the target system, the query logs recording first query statements, users corresponding to the first query statements and data query results.
[0039] Step A2, performing permission management and anomaly detection based on all query logs, the permission management being used for updating data query permissions of users on the target database, and the anomaly detection being used for identifying whether the users have abnormal query behaviors.
[0040] Specifically, in the process that the user performs data query through the target system, the query logs of the target system can be obtained by collecting the first query statements input by the user and the corresponding data query results. Further, based on the query logs, clustering analysis is performed, the data query results of the user on the target database are adjusted, and the preset permission library is updated, so that the permission management is realized. For example, when more than a preset number of users access the same data item outside the permission boundary of the user, the query permission for the data item needs to be relaxed. Based on the query logs, the anomaly detection is performed, and the abnormal query behaviors of a single user can be identified and marked. The abnormal query behaviors of the user can refer to query operations deviating from the normal operation habits of the user, not conforming to the query logic or having security risks. For example, the abnormal query behaviors can at least include exploratory questioning.
[0041] Based on the query logs, the permission management and the anomaly detection can make the target system have data-driven automatic permission optimization and active security early warning, and upgrade data governance from static configuration to dynamic intelligent operation and maintenance. Optionally, after the permission management and the anomaly detection based on all query logs are performed, a permission optimization suggestion report and a security risk early warning report are generated.
[0042] As an optional implementation manner of the embodiment of the present application, the data query method further includes: after the anomaly detection identifies that the user has abnormal query behaviors, generating abnormal behavior prompt information corresponding to the abnormal query behaviors of the user in the target system, and displaying the abnormal behavior prompt information.
[0043] The abnormal behavior prompt information can refer to information for prompting the abnormal query behaviors of the user. The abnormal behavior prompt information can be at least one form of prompt information in text, graphics and audio. Displaying the abnormal behavior prompt information can refer to displaying the abnormal behavior prompt information on a visual interface associated with the target system, or sending the abnormal behavior prompt information to a target prompt device. The target prompt device can refer to a digital computer or a mobile device of a relevant person. Specifically, in the case that the user has abnormal query behaviors, the abnormal behavior prompt information is generated and displayed, so as to realize security early warning and improve the security of data query in the target system.
[0044] The technical scheme of the embodiment of the present application acquires a first query statement input by a user in a target system, the target system can interact with the user in a natural language manner, the first query statement is a statement for querying data of a target database associated with the target system in a natural language manner; determines a data query result based on the first query statement and a target virtual view, the target virtual view is generated based on the target database, and the data query result is data corresponding to the first query statement in the target database and having a query permission of the user; and returns the data query result to the user through the target system, so that the user has a query permission for fields and records contained in the target virtual view, and the data query result corresponding to the first query statement can be determined through the target virtual view, the problem of data leakage caused by permission bypassing after generating a structured query statement can be avoided, and the security of data query of the user in the target system is improved.
[0045] Figure 2 The flowchart of another data query method provided by the embodiment of the present application is shown in FIG. 2. The technical scheme of the embodiment is further optimized for the process of determining a data query result based on a first query statement and a target virtual view in the foregoing embodiment on the basis of the technical scheme of the foregoing embodiment. The schemes not described in detail in the embodiment can be seen in the foregoing embodiment, and the embodiment can be combined with each optional scheme in one or more of the foregoing embodiments. As shown in FIG. 2, the data query method comprises the following steps. Figure 2
[0046] S201, acquiring a first query statement input by a user in a target system, the target system can interact with the user in a natural language manner, the first query statement is a statement for querying data of a target database associated with the target system in a natural language manner.
[0047] S202, determining a target field based on the first query statement and the target virtual view, the target field is a field in the target virtual view having a semantic similarity greater than a first preset similarity with the first query statement.
[0048] The semantic similarity between the first query statement and the field can refer to the semantic similarity between the key query information in the first query statement and the field. The key query information in the first query statement is used to indicate the query target, the query range and the query condition of the first query statement. The semantic similarity can be used to quantify the similarity degree of texts in the meaning level. Specifically, the target field can be obtained by determining the semantic similarity between the first query statement and each field in the target virtual view and based on the first preset similarity.
[0049] As an optional implementation of the embodiment of the present application, the target field is determined based on the first query statement and the target virtual view, comprising: determining a reference field based on the first query statement, the reference field being used to indicate the query intention of the first query statement; and determining the target field based on the reference field and the target virtual view.
[0050] Specifically, the query intention of the first query statement can be the data expected to be acquired by the first query statement. The reference field can be determined based on the query intention of the first query statement, and the target field can be determined based on the semantic similarity between the reference field and each field in the target virtual view. The semantic similarity between the first query statement and the reference field is greater than a first preset similarity.
[0051] As an optional implementation of the embodiment of the present application, the target field is determined based on the reference field and the target virtual view, comprising steps B1-B2:
[0052] Step B1, if the reference field exists in the target virtual view, the reference field is taken as the target field.
[0053] Step B2, if the reference field does not exist in the target virtual view, a candidate field in the target virtual view is determined, and the candidate field is fed back to the user in a natural language form by the target system for confirmation. After the user confirms, the candidate field is taken as the target field. The semantic similarity between the candidate field and the reference field is greater than a second preset similarity.
[0054] Specifically, in the case that the reference field exists in the target virtual view, the query intention of the first query statement input by the user conforms to the data query authority of the user to the target database, and the reference field can be directly taken as the target field.
[0055] In the case that the reference field does not exist in the target virtual view, the query intention of the first query statement input by the user does not conform to the data query authority of the user to the target database. Then, the candidate field in the target virtual view is determined based on the reference field and the second preset similarity, and the candidate field is interactively confirmed with the user in a natural language form. After the user confirms, the candidate field can be taken as the target field, so as to avoid that the target system returns no access or meaningless query results when the data expected to be acquired by the user does not have the query authority in the target database, and the data interaction between the target system and the user is interrupted.
[0056] Optionally, when the data expected to be acquired by the user does not have the query authority in the target database, the specific data expected to be acquired by the user is replaced by corresponding summary data, or the data query range of the user is reduced to the data range with the authority.
[0057] S203, generating a second query statement based on the target field and the target virtual view, the second query statement being a structured query statement.
[0058] Specifically, the target virtual view can be taken as a data source, and a structured query statement corresponding to the first query statement can be generated through the target field and the filtering condition corresponding to the target field, so that the second query statement is obtained.
[0059] S204, determining a data query result based on the second query statement.
[0060] Specifically, the data query result can be obtained by executing the second query statement based on the target database associated with the target system.
[0061] S205, returning the data query result to the user through the target system.
[0062] Exemplarily, Figure 3 A structural diagram of a target system is provided for an embodiment of the present application. As shown in the figure, Figure 3 The target system includes a permission-aware dynamic virtual view generator, a query rewriting and intent protection engine, and a permission risk self-awareness engine.
[0063] The permission-aware dynamic virtual view generator is configured to generate a target virtual view corresponding to each user in advance in the target system based on a target database and data query permissions of each user in the target database included in a preset permission library.
[0064] The query rewriting and intent protection engine is configured to determine a candidate field in the target virtual view based on a query intent of a first query statement input by a user and a preset strategy knowledge base when the query intent of the first query statement cannot be fully satisfied in the target virtual view corresponding to the user, and feed back the candidate field to the user in a natural language form for confirmation, and take the candidate field as a target field after the user confirms.
[0065] The permission risk self-awareness engine is configured to collect all query logs in the target system, and perform permission management and anomaly detection based on the all query logs, generate a permission optimization suggestion report and a security risk early warning report, and generate and display abnormal behavior prompt information in the case that the user has abnormal query behavior. The permission risk self-awareness engine is a background daemon process of the target system.
[0066] The technical scheme of the embodiment of the present application acquires a first query statement input by a user in a target system, the target system can interact with the user in a natural language manner, the first query statement is a statement for querying data of a target database associated with the target system in a natural language, determines a target field based on the first query statement and a target virtual view, the target field is a field in the target virtual view with a semantic similarity greater than a first preset similarity to the first query statement, generates a second query statement based on the target field and the target virtual view, the second query statement is a structured query statement, and determines a data query result based on the second query statement. The semantic similarity between the first query statement and each field in the target virtual view is used to determine the target field, so that the target field and the target virtual view are used to generate the structured query statement, thereby further improving the accuracy of the data query result. The target system returns the data query result to the user, the user has query authority on the fields and records contained in the target virtual view, the data query result corresponding to the first query statement is determined through the target virtual view, the problem of data leakage caused by authority bypassing is effectively avoided, and the security of data query in the target system is improved.
[0067] Figure 4 A structural diagram of a data query device is provided for the embodiment of the present application. The embodiment of the present application can be applied to the case of data query through a conversational system. The device can be realized in the form of hardware and / or software, and can be configured in an electronic device for implementing the data query method. As shown in the figure, the data query device includes: Figure 4
[0068] The first acquisition module 301 is configured to acquire a first query statement input by a user in a target system, the target system can interact with the user in a natural language manner, and the first query statement is a statement for querying data of a target database associated with the target system in a natural language.
[0069] The first determination module 302 is configured to determine a data query result based on the first query statement and a target virtual view, the target virtual view is generated based on the target database, the target virtual view includes fields and records with query authority of the user, and the data query result is data corresponding to the first query statement and with query authority of the user in the target database.
[0070] The first return module 303 is configured to return the data query result to the user through the target system.
[0071] Based on any of the optional technical solutions above, optionally, the first determining module 302 comprises a second determining unit, a first generating unit and a third determining unit. The second determining unit is configured to determine a target field based on the first query statement and the target virtual view, the target field being a field in the target virtual view that has a semantic similarity greater than a first preset similarity to the first query statement; the first generating unit is configured to generate a second query statement based on the target field and the target virtual view, the second query statement being a structured query statement; and the third determining unit is configured to determine the data query result based on the second query statement.
[0072] Based on any of the optional technical solutions above, optionally, the second determining unit comprises a fourth determining sub-unit and a fifth determining sub-unit. The fourth determining sub-unit is configured to determine a reference field based on the first query statement, the reference field being used to indicate a query intention of the first query statement; and the fifth determining sub-unit is configured to determine the target field based on the reference field and the target virtual view.
[0073] Based on any of the optional technical solutions above, optionally, the fifth determining sub-unit is specifically configured to, if the reference field exists in the target virtual view, take the reference field as the target field; if the reference field does not exist in the target virtual view, determine a candidate field in the target virtual view, and feed back the candidate field to the user in a natural language form through the target system for confirmation, and after the user confirms, take the candidate field as the target field, the candidate field having a semantic similarity greater than a second preset similarity to the reference field.
[0074] Based on any of the optional technical solutions above, optionally, the determination process of the target virtual view comprises: obtaining, from a preset permission library, a data query permission of the user for the target database; and generating the target virtual view in the target system based on the data query permission and the target database.
[0075] Based on any of the optional technical solutions above, optionally, the data query apparatus further comprises a second obtaining module and a first processing module. The second obtaining module is configured to obtain all query logs in the target system, the query logs recording the first query statement, a user corresponding to the first query statement and the data query result; and the first processing module is configured to perform permission management and anomaly detection based on all the query logs, the permission management being used to update the data query permission of the user for the target database, and the anomaly detection being used to identify whether the user has an abnormal query behavior.
[0076] Based on any of the optional technical solutions above, optionally, the data query apparatus further comprises a first prompting module. The first prompting module is configured to, after the anomaly detection identifies that the user has an abnormal query behavior, generate an abnormal behavior prompt information corresponding to the abnormal query behavior of the user in the target system, and display the abnormal behavior prompt information.
[0077] The technical scheme of the embodiment of the present application, through the first acquisition module 301, a first query statement input by a user in a target system is acquired, the target system can interact with the user in a natural language manner, and the first query statement is a statement for querying a target database associated with the target system in a natural language manner; through the first determination module 302, a data query result is determined based on the first query statement and a target virtual view, the target virtual view is generated based on the target database, and the data query result is data corresponding to the first query statement and having a query permission of the user in the target database; and the first return module 303 returns the data query result to the user through the target system, so that the user has a query permission for the fields and records contained in the target virtual view, the data query result corresponding to the first query statement is determined through the target virtual view, the problem of data leakage caused by permission bypass after generating a structured query statement can be avoided, and the security of data query of the user in the target system is improved.
[0078] The data query device provided in the embodiment of the present application can execute the data query method provided in any embodiment of the present application, and has the corresponding function modules and beneficial effects of the execution method.
[0079] Figure 5 A structural schematic diagram of an electronic device for implementing the data query method is provided in the embodiment of the present application. The electronic device is intended to represent various forms of digital computers, such as a laptop computer, a desktop computer, a workstation, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as a personal digital processing, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, and the like), and other similar computing devices. The components shown in the present document, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the present application described and / or claimed herein.
[0080] As Figure 5As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., connected to the at least one processor 11 in communication. The memory stores computer programs executable by the at least one processor 11, and the processor 11 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0081] Various components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0082] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the data query method.
[0083] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present application. For example, embodiments of the present application include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication unit 19, or installed from the storage unit 18, or installed from the ROM 12. When the computer program is executed by the processor 11, the above-mentioned functions defined in the methods of embodiments of the present application are performed.
[0084] In some embodiments, the data query method can be implemented as a computer program tangibly embodied in a computer readable storage medium, e.g., storage unit 18. In some embodiments, parts or all of the computer program can be loaded and / or installed onto electronic device 10 via, e.g., ROM 12 and / or communication unit 19. When the computer program is loaded onto RAM 13 and executed by processor 11, one or more steps of the data query method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the data query method by way of other means, e.g., by way of firmware.
[0085] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, specially designed application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0086] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor of the machine, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0087] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0088] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0089] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0090] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0091] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, each step described in the present application can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which is not limited herein.
[0092] The above detailed description does not constitute a limitation on the scope of protection of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A data query method, characterized by, The method comprises: obtaining a first query statement input by a user in a target system, the target system being capable of interacting with the user in a natural language manner, the first query statement being a statement in a natural language for querying a target database associated with the target system; determining a data query result based on the first query statement and a target virtual view, the target virtual view being generated based on the target database, the target virtual view comprising fields and records that the user has query permissions for, the data query result being data corresponding to the first query statement in the target database and having query permissions for the user; returning the data query result to the user through the target system.
2. The method of claim 1, wherein, The method further comprises: determining a target field based on the first query statement and the target virtual view, the target field being a field in the target virtual view having a semantic similarity greater than a first preset similarity to the first query statement; generating a second query statement based on the target field and the target virtual view, the second query statement being a structured query statement; determining the data query result based on the second query statement.
3. The method of claim 2, wherein, The method further comprises: determining a reference field based on the first query statement, the reference field being used to indicate a query intention of the first query statement; determining the target field based on the reference field and the target virtual view.
4. The method of claim 3, wherein, The method further comprises: if the reference field exists in the target virtual view, taking the reference field as the target field; if the reference field does not exist in the target virtual view, determining a candidate field in the target virtual view, and feeding back the candidate field to the user in a natural language form through the target system for confirmation, and taking the candidate field as the target field after the user confirms, the candidate field having a semantic similarity greater than a second preset similarity to the reference field.
5. The method of claim 1, wherein, The method further comprises: obtaining data query permissions of the user for the target database from a preset permission library; generating the target virtual view in the target system based on the data query permissions and the target database.
6. The method of claim 1, wherein, The method further comprises: obtaining all query logs in the target system, the query logs recording first query statements, users corresponding to the first query statements, and data query results; performing permission management and anomaly detection based on all the query logs, the permission management being used to update data query permissions of the user for the target database, and the anomaly detection being used to identify whether the user has abnormal query behavior.
7. The method of claim 6, wherein, The method further comprises: after the anomaly detection identifies that the user has abnormal query behavior, generating abnormal behavior prompt information corresponding to the abnormal query behavior of the user in the target system, and displaying the abnormal behavior prompt information.
8. A data query apparatus, characterized by comprising: The device comprises: The first obtaining module is configured to obtain a first query statement input by a user in a target system, the target system being capable of interacting with the user in a natural language manner, and the first query statement being a statement in a natural language for querying a target database associated with the target system; The first determining module is configured to determine a data query result based on the first query statement and a target virtual view, the target virtual view being generated based on the target database, the target virtual view including fields and records that the user has query permissions for, and the data query result being data corresponding to the first query statement in the target database and having query permissions of the user; The first returning module is configured to return the data query result to the user through the target system.
9. An electronic device, comprising: The electronic device comprises: at least one processor; and a memory connected with the at least one processor in communication, wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the data query method in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to enable the processor to implement the data query method in any one of claims 1-7 when executed.