Permission access control method and device
By obtaining the role tags of target users and determining the permission point tags using preset tag mapping relationships, the problem of large workload in permission configuration when enterprise employees access external systems is solved, and efficient permission management and data security are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- RICHFIT INFORMATION TECH
- Filing Date
- 2024-10-31
- Publication Date
- 2026-05-01
AI Technical Summary
When enterprise employees access external systems, configuring permissions is a labor-intensive task, consumes too much human resources, and is inefficient.
By obtaining the target user's role tags, determining the corresponding permission point tags using a preset tag mapping relationship, and performing access control based on the permission point tags, the permission configuration process is simplified.
It simplifies permission configuration, improves work efficiency, and ensures enterprise data security.
Smart Images

Figure CN121959531A_ABST
Abstract
Description
A method and apparatus for access control Technical Field
[0001] This invention relates to the field of access control technology, specifically to an access control method and apparatus. Background Technology
[0002] Enterprise employees frequently need to access external systems through their terminals. In order to ensure that enterprise employees can handle their work normally and to ensure the security of enterprise data, it is necessary to pre-open login accounts for each external system and configure corresponding permissions according to the identity and role of the enterprise employees. This makes the permission configuration workload too large, consumes too much human resources, and has low work efficiency. Summary of the Invention
[0003] To address the problems in the prior art, embodiments of the present invention provide a permission access control method and apparatus, which can at least partially solve the problems existing in the prior art.
[0004] On one hand, the present invention proposes a permission access control method, comprising:
[0005] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0006] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0007] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0008] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0009] The step of obtaining the target user's target role tag during the target user's access to the system includes:
[0010] During the process of a target user accessing the system, the target user's target role information is obtained, and a target role tag corresponding to the target role information is obtained according to a first preset correspondence relationship.
[0011] The first preset correspondence includes the mapping relationship between preset role information and preset role tags.
[0012] The step of obtaining the target user's target role information during the target user's access to the system includes:
[0013] During the process of a target user accessing the system, the target user's target ID is obtained, and the target role information corresponding to the target ID is obtained according to a preset role mapping relationship;
[0014] The preset role mapping relationship includes the mapping relationship between preset IDs and preset role information.
[0015] The step of controlling access to the system by the target user based on the target permission point corresponding to the target permission point label includes:
[0016] According to the second preset correspondence, obtain the target permission point corresponding to the target permission point label;
[0017] The second preset correspondence includes the mapping relationship between preset permission point information and preset permission point labels;
[0018] Access control is performed on the target user's access to the system based on the target permission point.
[0019] Establishing the preset label mapping relationship includes:
[0020] Retrieve the permission management objects corresponding to each external system;
[0021] Each permission management object is identified as a preset permission point, and a preset permission point label is generated for each preset permission point.
[0022] Establish a mapping relationship between each preset permission point label and the corresponding preset role label to obtain the preset label mapping relationship.
[0023] The permission management objects include menu operation items, data operation items, and interface API operation items corresponding to each external system.
[0024] The step of obtaining the permission management objects corresponding to each external system includes:
[0025] When importing permission management objects that need to be managed from various external systems to the local machine, the local machine obtains the permission management objects corresponding to each external system.
[0026] On one hand, the present invention proposes a permission access control device, comprising:
[0027] The acquisition unit is used to acquire the target role tag of the target user during the process of the target user accessing the system; the system is one of the external systems accessed by the target user;
[0028] The determining unit is used to determine the target permission point label corresponding to the target role label according to a preset label mapping relationship;
[0029] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0030] The control unit is used to perform access control on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0031] In another aspect, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a bus, wherein,
[0032] The processor and the memory communicate with each other via the bus;
[0033] The memory stores program instructions that can be executed by the processor, and the processor can execute the following methods by calling the program instructions:
[0034] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0035] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0036] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0037] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0038] This invention provides a non-transitory computer-readable storage medium, comprising:
[0039] The non-transitory computer-readable storage medium stores computer instructions that cause the computer to perform the following methods:
[0040] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0041] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0042] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0043] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0044] The access control method and apparatus provided in this invention obtain a target role tag of a target user during the process of a target user accessing a system; the system is one of the external systems accessed by the target user; a target permission point tag corresponding to the target role tag is determined according to a preset tag mapping relationship; wherein, the preset tag mapping relationship includes a mapping relationship between preset role tags and preset permission point tags; access control is performed on the target user's access to the system according to the target permission point corresponding to the target permission point tag, which can simplify permission configuration work, improve work efficiency, and ensure enterprise data security. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0046] Figure 1 is a flowchart illustrating an access control method according to an embodiment of the present invention.
[0047] Figure 2 is a flowchart illustrating the access control method provided in another embodiment of the present invention.
[0048] Figure 3 is a schematic diagram of the access control device provided in an embodiment of the present invention.
[0049] Figure 4 is a schematic diagram of the physical structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments and descriptions of the present invention are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other.
[0051] Explanation of relevant terms:
[0052] Permission points: These are the specific operations or resources that a user can perform or access within a system. Permission point management systems typically divide permissions into menu permissions and function point permissions, further subdivided into read permissions (R) and write permissions (W).
[0053] Permission points can be further subdivided into different types, such as specific actions like signing, approving, adding, deleting, querying, and modifying. These permission points are not directly assigned to users, but are managed through roles. Users obtain corresponding permissions by being assigned to a specific role.
[0054] Figure 1 is a flowchart illustrating an access control method according to an embodiment of the present invention. As shown in Figure 1, the access control method provided in this embodiment includes:
[0055] Step S1: Obtain the target user's target role tag during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0056] Step S2: Determine the target permission point label corresponding to the target role label according to the preset label mapping relationship;
[0057] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags.
[0058] Step S3: Perform access control on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0059] In step S1 above, the device acquires the target user's target role tag during the target user's access to the system; the system is one of the external systems accessed by the target user. The device can be a computer device that executes the method, for example, it may include a terminal. It should be noted that the acquisition and analysis of data involved in this embodiment of the invention are authorized by the user.
[0060] The target user can be understood as an enterprise employee who wants to access the system through a terminal. The external system is related to the enterprise's industry, main business, and the employee's job title. Taking the enterprise's industry as petrochemical, its main business as oil refining, and the employee's job title as a dispatcher as an example, the external system can include a material movement system and a material balance system. Referring to the above example, the target user's target role label is dispatcher.
[0061] The step of obtaining the target user's target role tag during the target user's access to the system includes:
[0062] During the process of a target user accessing the system, the target user's target role information is obtained, and a target role tag corresponding to the target role information is obtained according to a first preset correspondence relationship.
[0063] The first preset mapping relationship includes the mapping relationship between preset role information and preset role tags. Referring to the example above, both the target role information and the target role tag can be a scheduler. The purpose of the target role information is to facilitate information processing by the processor, and the purpose of the target role tag is to identify the role of the enterprise employee user, facilitating operation by the permission configuration personnel. The permission configuration personnel need to pre-configure the first preset mapping relationship, that is, to establish the association between scheduler information and scheduler tags through configuring the first preset mapping relationship.
[0064] The process of obtaining the target user's target role information during the target user's access to the system includes:
[0065] During the process of a target user accessing the system, the target user's target ID is obtained, and the target role information corresponding to the target ID is obtained according to a preset role mapping relationship;
[0066] The preset role mapping relationship includes the mapping relationship between preset IDs and preset role information. The target ID can be understood as the user identity identifier corresponding to the target user in the login system. Permission configuration personnel need to pre-configure the preset role mapping relationship, that is, establish the association between user identity information and user role information through configuring the preset role mapping relationship. For example, if the user identity information is Zhang Moumou and the user role information is dispatcher, then the preset role mapping relationship can reflect that Zhang Moumou is a dispatcher of the enterprise.
[0067] In step S2 above, the device determines the target permission point label corresponding to the target role label according to the preset label mapping relationship;
[0068] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags. Permission configuration personnel need to pre-configure the preset tag mapping relationship, that is, establish the association between role tags and permission point tags through configuration. Since multiple enterprise employee users are dispatchers, permission configuration personnel do not need to create a separate preset tag mapping relationship for each enterprise employee user; they only need to create a preset tag mapping relationship for the dispatcher role, thus simplifying the permission configuration work.
[0069] Referring to the above description, the permission points corresponding to the material movement system include reading inbound and outbound data, writing inbound and outbound data, and approving inbound and outbound data; the permission points corresponding to the material balance system include reading inbound and outbound data, writing inbound and outbound data, and adjusting the balance of inbound and outbound material data.
[0070] If a new external system is added, and the corresponding permission points for this system include reading inbound and outbound data, writing inbound and outbound data, and calculating material data budgets, since reading and writing inbound and outbound data are the same as the previous permission points, and the new permission point is only material data budget calculation, then the permission configuration personnel can update and maintain the above-mentioned preset label mapping relationship only for this one item. That is, add the preset permission point label "budget calculation" to the preset permission point labels and establish a mapping relationship between it and the preset role label "accountant". Therefore, it is not necessary to establish a preset label mapping relationship for all permission points in each new external system; it is only necessary to update and maintain the preset label mapping relationship for each incremental permission point in each new external system within the existing preset label mapping relationship.
[0071] In step S3 above, the device performs access control on the target user's access to the system based on the target permission point corresponding to the target permission point label. The step of performing access control on the target user's access to the system based on the target permission point corresponding to the target permission point label includes:
[0072] According to the second preset correspondence, obtain the target permission point corresponding to the target permission point label;
[0073] The second preset correspondence includes the mapping relationship between preset permission point information and preset permission point labels;
[0074] Access control is implemented for the target user's access to the system based on the target permission points. Referring to the example above, if the target user is a dispatcher who has logged into the material movement system, the target permission points are read, write, and approve of inbound and outbound data.
[0075] Similarly, both target permission points and target permission point tags can be for reading, writing, and approving incoming and outgoing data. The purpose of target permission points is to facilitate information processing by the processor, while target permission point tags are used to identify target permission points, making it easier for permission configuration personnel to operate. Permission configuration personnel need to pre-configure a second preset correspondence, that is, to establish the association between permission point information and permission point tags through configuring the second preset correspondence.
[0076] Establishing the preset tag mapping relationship includes:
[0077] Obtain the permission management objects corresponding to each external system; the permission management objects include menu operation items, data operation items, and interface API operation items corresponding to each external system. Taking the material movement system as an example, the menu operation items may specifically include material configuration and movement relationship configuration, the data operation items may specifically include gasoline and diesel, and the interface API operation items may specifically include the atmospheric and vacuum distillation unit's receipt and payment data API interface and the atmospheric and vacuum distillation unit's operation log API interface.
[0078] Each permission management object is defined as a preset permission point, and a preset permission point label is generated for each preset permission point. Taking two external systems as an example, the total number of permission management objects in external system 1 is m1, and the total number of permission management objects in external system 2 is m2. Then the total number of preset permission points is m1+m2. A preset permission point label is generated for each preset permission point, so the total number of preset permission point labels is also m1+m2.
[0079] Establish a mapping relationship between each preset permission point label and its corresponding preset role label to obtain the preset label mapping relationship. If a certain preset role label, such as a dispatcher, requires the permission points of reading inbound and outbound data, writing inbound and outbound data, and auditing inbound and outbound data, then select these three items from m1+m2 preset permission point labels as the permission point labels matching the dispatcher.
[0080] The step of obtaining the permission management objects corresponding to each external system includes:
[0081] When importing permission management objects that need to be managed from various external systems to the local machine, the local machine retrieves the corresponding permission management objects for each external system. The local machine can be specifically understood as the local storage space of the terminal used by the target user.
[0082] As shown in Figure 2, the core process is further explained as follows:
[0083] The core process includes permission settings and permission acquisition; among which:
[0084] Permission settings include:
[0085] First, import menus, data, APIs, and other content requiring access control from external systems into this system, creating corresponding resource types. Second, the system abstracts these into unified permission points, assigns permission points to roles through system configuration, and then tags these permission points. Third, permission points are tagged, and roles are then tagged accordingly, transforming these into a set of permission points possessed by each role. Fourth, roles are assigned to relevant users or devices, granting them legitimate access to the system.
[0086] Permissions acquisition includes:
[0087] After a user or device logs into the system, it obtains the set of roles it possesses through its ID, and then obtains the set of permission points that the role possesses.
[0088] The access control method provided in this embodiment of the invention has the following beneficial effects:
[0089] 1) Provide unified access control, centrally manage the permissions of all systems, and reduce the workload of other systems.
[0090] 2) Standardized access control mode provides a unified access control interface for system implementation, reducing the workload of implementation.
[0091] 3) It is compatible with the permission management requirements of different systems. As long as the content of the system's permission management can be organized according to the unified permission management standard, it can be imported and abstracted through a unified interface, thereby meeting the permission management requirements of different systems.
[0092] 4) The flexible permission tagging method greatly satisfies the problem that fixed permission management modes cannot meet system requirements, and the tag system can provide multiple hierarchical permission management.
[0093] 5) This system can meet the access control needs of various access segments, including personnel, equipment terminals, backend services, and application systems. It can manage access control for single systems and multiple systems.
[0094] 6) The system of this invention can serve as a general permission management platform for PaaS, SaaS and other platforms, providing a unified permission management mode and services for other systems and applications.
[0095] The access control method provided in this invention obtains the target user's target role tag during the target user's access to the system; the system is one of the external systems accessed by the target user; a target permission point tag corresponding to the target role tag is determined according to a preset tag mapping relationship; wherein, the preset tag mapping relationship includes a mapping relationship between preset role tags and preset permission point tags; access control is performed on the target user's access to the system according to the target permission point corresponding to the target permission point tag, which can simplify permission configuration work, improve work efficiency, and ensure enterprise data security.
[0096] Furthermore, obtaining the target user's target role tag during the target user's access to the system includes:
[0097] During the process of a target user accessing the system, the target user's target role information is obtained, and the target role tag corresponding to the target role information is obtained according to the first preset correspondence relationship; this can be referred to the above embodiment for explanation, and will not be repeated here.
[0098] The first preset correspondence includes the mapping relationship between preset role information and preset role tags. This can be referred to the above embodiments for explanation, and will not be repeated here.
[0099] Furthermore, obtaining the target user's target role information during the target user's access to the system includes:
[0100] During the process of a target user accessing the system, the target user's target ID is obtained, and the target role information corresponding to the target ID is obtained according to the preset role mapping relationship; this can be referred to the above embodiment for explanation, and will not be repeated here.
[0101] The preset role mapping relationship includes the mapping relationship between preset IDs and preset role information. This can be referred to the above embodiments for explanation, and will not be repeated here.
[0102] Further, the step of controlling access to the system by the target user based on the target permission point corresponding to the target permission point label includes:
[0103] The target permission point corresponding to the target permission point label is obtained according to the second preset correspondence; the above embodiments can be referred to for explanation, and will not be repeated here.
[0104] The second preset correspondence includes the mapping relationship between preset permission point information and preset permission point labels; this can be referred to the above embodiments for explanation, and will not be repeated here.
[0105] Access control is performed on the target user's access to the system based on the target permission point. This can be referred to the above embodiments for explanation, and will not be repeated here.
[0106] Further, establishing the preset label mapping relationship includes:
[0107] Obtain the permission management objects corresponding to each external system; refer to the above embodiments for details, which will not be repeated here.
[0108] Each permission management object is identified as a preset permission point, and a preset permission point label is generated for each preset permission point; the above embodiments can be referred to for explanation, and will not be repeated here.
[0109] A mapping relationship is established between each preset permission point label and its corresponding preset role label to obtain the preset label mapping relationship. This can be referred to the above embodiment for explanation, and will not be repeated here.
[0110] Furthermore, the permission management object includes menu operation items, data operation items, and interface API operation items corresponding to each external system.
[0111] Furthermore, obtaining the permission management objects corresponding to each external system includes:
[0112] When importing permission management objects that need to be managed from various external systems to the local machine, the local machine obtains the permission management objects corresponding to each external system. This can be referred to the above embodiment for explanation, and will not be repeated here.
[0113] Figure 3 is a schematic diagram of the access control device provided in an embodiment of the present invention. As shown in Figure 3, the access control device provided in this embodiment of the present invention includes an acquisition unit 301, a determination unit 302, and a control unit 303, wherein:
[0114] The acquisition unit 301 is used to acquire the target role tag of the target user during the process of the target user accessing the system; the system is one of the external systems accessed by the target user; the determination unit 302 is used to determine the target permission point tag corresponding to the target role tag according to the preset tag mapping relationship; wherein, the preset tag mapping relationship includes the mapping relationship between the preset role tag and the preset permission point tag; the control unit 303 is used to perform permission access control on the target user's access to the system according to the target permission point corresponding to the target permission point tag.
[0115] Specifically, the acquisition unit 301 in the device is used to acquire the target role tag of the target user during the process of the target user accessing the system; the system is one of the external systems accessed by the target user; the determination unit 302 is used to determine the target permission point tag corresponding to the target role tag according to the preset tag mapping relationship; wherein, the preset tag mapping relationship includes the mapping relationship between the preset role tag and the preset permission point tag; the control unit 303 is used to perform permission access control on the target user's access to the system according to the target permission point corresponding to the target permission point tag.
[0116] The access control device provided in this embodiment of the invention obtains the target role tag of the target user during the process of the target user accessing the system; the system is one of the external systems accessed by the target user; a target permission point tag corresponding to the target role tag is determined according to a preset tag mapping relationship; wherein, the preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags; access control is performed on the target user's access to the system according to the target permission point corresponding to the target permission point tag, which can simplify permission configuration work, improve work efficiency, and ensure enterprise data security.
[0117] The embodiments of the present invention provide an access control device that can be used to execute the processing flow of the above method embodiments. Its functions will not be repeated here, but can be referred to the detailed description of the above method embodiments.
[0118] Figure 4 is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention. As shown in Figure 4, the electronic device includes: a processor 401, a memory 402, and a bus 403.
[0119] The processor 401 and the memory 402 communicate with each other via the bus 403.
[0120] The processor 401 is used to call program instructions in the memory 402 to execute the methods provided in the above-described method embodiments, including, for example:
[0121] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0122] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0123] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0124] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0125] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can perform the methods provided in the above-described method embodiments, such as:
[0126] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0127] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0128] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0129] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0130] This embodiment provides a computer-readable storage medium storing a computer program that causes the computer to execute the methods provided in the above-described method embodiments, including, for example:
[0131] The target user's target role tag is obtained during the target user's access to the system; the system is one of the external systems accessed by the target user.
[0132] Determine the target permission point label corresponding to the target role label based on the preset label mapping relationship;
[0133] The preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags;
[0134] Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
[0135] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0136] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0137] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0138] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0139] In the description of this specification, the references to terms such as "an embodiment," "a specific embodiment," "some embodiments," "for example," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0140] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for access control, characterized in that, include: During the process of a target user accessing the system, obtain the target user's target role tag; The system is one of the external systems accessed by the target user; The target permission point tag corresponding to the target role tag is determined according to the preset tag mapping relationship; wherein, the preset tag mapping relationship includes the mapping relationship between the preset role tag and the preset permission point tag; Access control is performed on the target user's access to the system based on the target permission point corresponding to the target permission point label.
2. The access control method according to claim 1, characterized in that, The step of obtaining the target user's target role tag during the target user's access to the system includes: obtaining the target user's target role information during the target user's access to the system, and obtaining the target role tag corresponding to the target role information according to a first preset correspondence relationship; wherein, the first preset correspondence relationship includes a mapping relationship between preset role information and preset role tags.
3. The access control method according to claim 2, characterized in that, The step of obtaining the target user's target role information during the target user's access to the system includes: obtaining the target user's target ID during the target user's access to the system, and obtaining the target role information corresponding to the target ID according to a preset role mapping relationship; wherein, the preset role mapping relationship includes the mapping relationship between preset ID and preset role information.
4. The access control method according to claim 1, characterized in that, The step of controlling access to the system by the target user based on the target permission point corresponding to the target permission point label includes: obtaining the target permission point corresponding to the target permission point label according to a second preset correspondence; wherein, the second preset correspondence includes a mapping relationship between preset permission point information and preset permission point labels; and controlling access to the system by the target user based on the target permission point.
5. The access control method according to any one of claims 1 to 4, characterized in that, Establishing the preset tag mapping relationship includes: obtaining the permission management objects corresponding to each external system; determining each permission management object as a preset permission point, and generating a preset permission point tag for each preset permission point; establishing a mapping relationship between each preset permission point tag and the corresponding preset role tag to obtain the preset tag mapping relationship.
6. The access control method according to claim 5, characterized in that, The permission management objects include menu operation items, data operation items, and interface API operation items corresponding to each external system.
7. The access control method according to claim 5, characterized in that, The step of obtaining the permission management objects corresponding to each external system includes: when importing the permission management objects to be managed from each external system to the local machine, obtaining the permission management objects corresponding to each external system on the local machine.
8. An access control device, characterized in that, include: The acquisition unit is used to acquire the target role tag of the target user during the process of the target user accessing the system; The system is one of the external systems accessed by the target user; The determining unit is configured to determine the target permission point tag corresponding to the target role tag according to a preset tag mapping relationship; wherein, the preset tag mapping relationship includes the mapping relationship between preset role tags and preset permission point tags; The control unit is used to perform access control on the target user's access to the system based on the target permission point corresponding to the target permission point label.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.