A differentiated data authority management method based on user roles and territorial relations
By constructing a multi-dimensional data management model based on user roles and local relationships, the problem of low efficiency in power grid data management has been solved, enabling precise management and rapid filtering of power grid data, and adapting to the expansion of power grid business.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 广西电网能源科技有限责任公司
- Filing Date
- 2026-02-27
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies have low efficiency in power grid data management, making it impossible to manage massive and complex power grid data in an orderly manner, which limits the expansion of power grid business.
By adopting a differentiated data access management method based on user roles and geographical location, a multi-dimensional data management model is constructed to realize many-to-many mapping relationships, dynamically adjust data access permissions and tags, and form a multi-level data access management system to adapt to the dynamic growth of power grid data.
It enables the rapid filtering and display of exclusive data within a user's jurisdiction from power grid data, improving work efficiency, preventing unauthorized access, adapting to the needs of power grid business expansion, and providing orderly data support.
Smart Images

Figure CN122133166A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of power grid data management, and in particular to a differentiated data access control method based on user roles and geographical location. Background Technology
[0002] Currently, with the continuous expansion of the power grid and the continuous upgrading and optimization of the smart grid, especially after the distributed access of renewable resources to the power grid, the data of the power grid system is becoming more diversified and complex. Therefore, higher requirements are put forward for the management of massive and complex power grid data.
[0003] The amount of power grid data increases exponentially with the increase in power grid scale and access equipment data. In the process of managing massive and complex power grid data, different departments and municipal bureaus require different data. When screening or auditing data, managers often need to browse and filter a large amount of interference data to find the required power grid data. The manual operation of filtering the target data in massive amounts of data is labor-intensive, inefficient, and cannot manage massive amounts of power grid data in an orderly manner, which is not conducive to the expansion of power grid business. Summary of the Invention
[0004] To address the issue that the expansion of power grids and the growth of connected devices in existing technologies result in massive and complex power grid data, the current methods of manually filtering or managing this data are inefficient and cannot form an orderly management scheme for the massive and dynamically growing power grid data, thus hindering the expansion of power grid services, this application provides a differentiated data permission management method based on user roles and geographical location. This method can adapt to the dynamic growth and changes of power grid data through a differentiated data control scheme of "same platform or database, different data display views," which helps to provide orderly data support for the expansion of power grid services.
[0005] Firstly, the above-mentioned inventive objective of this application is achieved through the following technical solution: A differentiated data access control method based on user roles and geographic location, the method comprising: Obtain all user attributes of existing managed users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing managed users. The multidimensional power grid attributes of the power grid data are obtained and each power grid attribute is marked with a lookup tag to obtain the multidimensional lookup tags of the power grid data. The multidimensional data access permissions are matched with the multidimensional access tags, and a many-to-many mapping relationship between permissions and tags is constructed based on the matching results to generate a multidimensional data management model. The system obtains the data access request from the user, generates a dedicated data pool for the user through the multidimensional data management model, and searches for the target data in the dedicated data pool according to the data access request.
[0006] In a preferred embodiment, this application can be further configured as follows: after performing attribute matching between the multidimensional data access permissions and the multidimensional access tags, and constructing a many-to-many mapping relationship between permissions and tags based on the matching results to generate a multidimensional data management model, the application further includes: When the new power grid data has unknown attributes, manual query tags are configured for the unknown attributes, and the tag similarity between the manual query tags and the existing query tags in the multidimensional data management model is calculated. Map the existing query tag with the highest tag similarity to the multidimensional data query permission to the manual query tag, and construct a new mapping relationship between the manual query tag and the multidimensional data query permission.
[0007] In a preferred embodiment, this application can be further configured as follows: obtaining the data query request from the user, generating a dedicated data pool for the user through the multidimensional data management model, and searching for target data in the dedicated data pool according to the data query request, specifically includes: According to the user's multidimensional data access permissions, the multidimensional data management model calls the power grid data corresponding to the access tags that have a mapping relationship, and stores it in a temporarily built dedicated space to generate a dedicated data pool; The data query request is parsed using query keywords, and the target data is searched and displayed in a multi-dimensional manner in the dedicated data pool based on the parsed query keywords.
[0008] In a preferred embodiment, this application can be further configured such that the method also includes: Obtain user registration information to create a user attribute profile, assign corresponding data access permissions to each user attribute in the user attribute profile, and obtain new multi-dimensional data access permissions for registered users. When a data access request is received from a registered user, a dedicated data pool corresponding to the new multidimensional data access permission is built through the multidimensional data management model. The data query request is parsed using keywords. Based on the keyword parsing results, the target data is searched in the dedicated data pool and displayed in a multi-dimensional format according to the style set by the registered user.
[0009] In a preferred embodiment, this application can be further configured as follows: when a data access request from a registered user is received, a dedicated data pool corresponding to the new multidimensional data access permission is established through the multidimensional data management model, specifically including: The new multidimensional data access permissions are matched with the existing data access permissions in the multidimensional data management model to filter the target access permissions that successfully match. The system retrieves the power grid data corresponding to the query tag that has a mapping relationship with the target query permission, stores it in a temporarily built storage space, and generates a dedicated data pool corresponding to the new multidimensional data query permission.
[0010] In a preferred embodiment, this application can be further configured as follows: the step of obtaining user registration information to create a user attribute profile, assigning corresponding data access permissions to each user attribute in the user attribute profile, and obtaining new multidimensional data access permissions for the registered user, further includes: When a new user attribute exists in the user registration information, the superior registration approval authority configures the viewing permission for the new user attribute to obtain the configuration viewing permission. Calculate the permission similarity between the configured access permission and the existing access permission in the multidimensional data management model, and select the existing access permission with the highest similarity as the reference access permission; The mapping relationship between the reference viewing permission and the multidimensional viewing tag is mapped to the configuration viewing permission, thus constructing a new mapping relationship between the configuration viewing permission and the multidimensional viewing tag.
[0011] In a preferred embodiment, this application can be further configured as follows: after mapping the mapping relationship between the reference access permission and the multidimensional access tag to the configuration access permission, and constructing a new mapping relationship between the configuration access permission and the multidimensional access tag, the application further includes: The new mapping relationship is verified by the superior authority that approves the registration. If there is a mapping error in the new mapping relationship, it is manually modified, and a new mapping relationship is established based on the result of the manual modification.
[0012] Secondly, the above-mentioned inventive objective of this application is achieved through the following technical solutions: A differentiated data access control system based on user roles and geographic location, the system comprising: The permission setting module is used to obtain all user attributes of existing management users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing management users. The tag setting module is used to obtain the multi-dimensional power grid attributes of the power grid data and perform lookup tag marking processing on each power grid attribute to obtain the multi-dimensional lookup tags of the power grid data; The model building module is used to perform attribute matching between the multidimensional data access permissions and the multidimensional access tags, and to build a many-to-many mapping relationship between permissions and tags based on the matching results, thereby generating a multidimensional data management model. The data search module is used to obtain the data search request from the user, generate a dedicated data pool for the user through the multidimensional data management model, and search for the target data in the dedicated data pool according to the data search request.
[0013] Thirdly, the above-mentioned objectives of this application are achieved through the following technical solutions: A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the aforementioned differentiated data access control method based on user roles and geographic location.
[0014] Fourthly, the above-mentioned objectives of this application are achieved through the following technical solutions: A computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned differentiated data access control method based on user roles and geographic location.
[0015] In summary, this application includes at least one of the following beneficial technical effects: 1. Set multi-dimensional data access permissions based on user roles, responsible business attributes, geographical location, and department. When storing power grid data, assign corresponding access tags according to business attributes, geographical location, and user access permissions. Map each data access permission to access tags in a many-to-many manner to form a multi-level data access management model or system. After users in different departments or municipal bureaus log in or register in the system, the model or system automatically associates the user's access permissions with the corresponding access tags. Dynamically filter and display exclusive data (such as new energy power generation, electric vehicle ownership, etc.) within the user's jurisdiction from massive power grid data, and achieve precise data control of "same platform or database, different data display views". Prevent unauthorized users from accessing data from the source and meet the needs of differentiated data access management. 2. By constructing a multi-dimensional data management model through multi-dimensional data access permissions and multi-dimensional data access tags in a many-to-many mapping manner, it is possible to quickly screen data in a dedicated data pool based on keywords when users search for data, thereby improving work efficiency. Furthermore, through multi-level and multi-dimensional data access permission allocation, it prevents users from accessing data without authorization, and achieves hierarchical and orderly differentiated permission management. Compared with traditional manual screening or management methods, it improves work efficiency and adapts to the dynamic growth trend of power grid data development. It can effectively manage newly generated user attributes or data attributes, and provide orderly data support for the expansion of power grid business. Attached Figure Description
[0016] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.
[0017] Figure 1 This is a flowchart illustrating the implementation of the differentiated data permission management method based on user roles and geographic location in this embodiment.
[0018] Figure 2 This is a flowchart illustrating the implementation of step S40 of the differentiated data permission management method in this embodiment.
[0019] Figure 3 This is a flowchart illustrating the implementation of the differentiated data access control method in this embodiment for handling unknown attributes of power grid data.
[0020] Figure 4 This is a flowchart illustrating the implementation of the differentiated data permission management method for managing the permissions of newly registered users in this embodiment.
[0021] Figure 5 This is a flowchart illustrating the implementation of the differentiated data permission management method for handling new user attributes in this embodiment.
[0022] Figure 6 This is a flowchart illustrating the implementation of step S60 of the differentiated data permission management method in this embodiment.
[0023] Figure 7 This is a structural block diagram of the differentiated data permission management system based on user roles and geographical location in this embodiment.
[0024] Figure 8 This is a schematic diagram of the internal structure of a computer device used to implement differentiated data access control methods. Detailed Implementation
[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0027] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0028] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0029] In one embodiment, such as Figure 1 As shown, this application discloses a differentiated data access control method based on user roles and geographic location, which specifically includes the following steps: S10: Obtain all user attributes of existing managed users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing managed users.
[0030] Specifically, the user attributes of existing management users in the power grid management system are obtained, including user roles, responsible business attributes, geographical location, and affiliated departments. Corresponding viewing permissions are set for each user attribute of each management position. For example, the business attribute A can search for power grid data of the corresponding business, or the geographical location attribute can search for power grid data of the corresponding geographical location, and the affiliated department attribute can search for power grid data managed by the corresponding department. For example, when the user role attribute is leader, the user can search for power grid data within the scope of the authority of all subordinates under the leader, and so on. The data viewing permissions of all user attributes are summarized to obtain the multi-dimensional data viewing permissions of existing management users.
[0031] S20: Obtain the multidimensional power grid attributes of the power grid data and perform lookup tag marking on each power grid attribute to obtain the multidimensional lookup tags of the power grid data.
[0032] Specifically, when generating and storing power grid data, multi-dimensional power grid attributes, including business attributes, local relationships, power dispatch relationships, and power composition, covering the entire process of power resources from production, dispatch to consumption, are acquired. Corresponding query tags are set for each power grid attribute. For example, query tags are configured for business attributes that can only be searched by relevant business personnel, for local relationship attributes that can only be searched by relevant local management personnel, and for power dispatch relationship attributes that can only be searched by relevant dispatch management personnel. By summarizing the query tags of all power grid attributes, multi-dimensional query tags for storing power grid data are obtained.
[0033] S30: Match the multidimensional data access permissions with the multidimensional access tags, and construct a many-to-many mapping relationship between permissions and tags based on the matching results to generate a multidimensional data management model.
[0034] Specifically, all existing user attributes are matched with existing power grid attributes. For example, user business attributes are matched with power grid data business attributes, user location relationship attributes are matched with power grid data location relationship attributes, and the power dispatching or collaborative business that the user is responsible for is matched with the power dispatching relationship in the power grid data. Based on the matching results, a many-to-many mapping relationship between multi-dimensional data access permissions and multi-dimensional access tags is constructed. For example, business access permissions can access power grid data with relevant business access tags and power grid data with power grid dispatching relationship tags. Based on location relationship access permissions, power grid data with the same location relationship access tag, business-related power grid data for the current location, and power grid data with power dispatching relationship tags for the current location can be accessed. This forms a many-to-many mapping relationship between user roles, permissions, and tags, and a multi-dimensional data management model between power grid data.
[0035] S40: Obtain the data viewing request from the user, generate a dedicated data pool for the user through a multidimensional data management model, and search for the target data in the dedicated data pool according to the data viewing request.
[0036] Specifically, such as Figure 2 As shown, step S40 includes: S401: Based on the multidimensional data access permissions of the user, the system calls the power grid data corresponding to the access tags with mapping relationships through the multidimensional data management model, and stores it in a temporarily built dedicated space to generate a dedicated data pool.
[0037] Specifically, based on the multidimensional data access permissions of the users, the multidimensional data management model is used to find the power grid data corresponding to the access tags that have a mapping relationship with the multidimensional data access permissions, and stores it in a temporarily built dedicated space to generate a dedicated data pool. In this embodiment, the temporarily built dedicated space can be an object pool or a cache pool, which is set according to the data search needs. The dedicated data pool can be a new energy power generation data pool, an electric vehicle ownership data pool, etc.
[0038] S402: Parse the query keywords for the data query request, and search for the target data and display it in multiple dimensions in the dedicated data pool based on the parsed query keywords.
[0039] Specifically, the system analyzes the keywords in the data query requests. These keywords include new energy power generation, new energy network configuration, and vehicle ownership. Based on the analyzed keywords, the system performs keyword matching in a dedicated data pool and selects the data with the highest matching degree as the target data. The target data is then displayed in a multi-dimensional manner according to a preset or user-defined data display format.
[0040] In this embodiment, as Figure 3 As shown, after performing attribute matching between multidimensional data access permissions and multidimensional access tags, and constructing a many-to-many mapping relationship between permissions and tags based on the matching results to generate a multidimensional data management model, the process also includes: S301: When new power grid data has unknown attributes, manually check the tags for the unknown attributes and calculate the tag similarity between the manually checked tags and the existing check tags in the multidimensional data management model.
[0041] Specifically, when there are unknown attributes in the new power grid data, such as new businesses, new locations, and new power sources, the data source management personnel (usually power plants or business initiators) manually check and set tags for the unknown attributes. This includes setting the scope of business, power source, or location relationship. Data is filtered by calculating the tag similarity between the manually checked tags and the existing tags in the multi-dimensional data management model. The similarity calculation method can be Euclidean distance or cosine similarity.
[0042] S302: Map the existing query tag with the highest tag similarity to the multidimensional data query permission to the manual query tag, and construct a new mapping relationship between the manual query tag and the multidimensional data query permission.
[0043] Specifically, the existing search tags with the highest tag similarity are selected, and the mapping relationship between the existing search tags and multidimensional data search permissions is mapped to the manual search tags, thus constructing a new mapping relationship between the manual search tags and multidimensional data search permissions.
[0044] In one embodiment, such as Figure 4 As shown, the method also includes: S50: Obtain user registration information to create user attribute profiles, assign corresponding data viewing permissions to each user attribute in the user attribute profile, and obtain new multi-dimensional data viewing permissions for registered users.
[0045] Specifically, when a new user registers with the power grid system, the system retrieves the registration information entered during registration and creates a user attribute profile based on this information. This profile includes the user's role (ordinary employee, management, etc.), the business attributes they are responsible for, their geographical location, and their department. Corresponding data access permissions are then set for each attribute. For example, user role attributes are assigned data access permissions within their respective jurisdictions; ordinary employees are limited to their own business scope; management personnel have access to all data under their jurisdiction; business attributes are limited to the scope of their specific business; and geographical location is limited to the scope of data within their respective region. The data access permissions related to the user attributes of all registered users are then aggregated to obtain a new multidimensional data access permission system.
[0046] In this embodiment, as Figure 5 As shown, step S50 further includes: S501: When a new user attribute exists in the user registration information, the superior authority of the registration approval can configure the viewing permission for the new user attribute to obtain the configuration viewing permission.
[0047] Specifically, when new user attributes exist in the user registration information, such as new business, new geographical location, or new user role, the approval authority of the registered user can manually configure the access permissions for viewing the new user attributes, thus forming the configuration access permissions for the registered user.
[0048] S502: Calculate the permission similarity between the configured access permission and the existing access permission in the multidimensional data management model, and select the existing access permission with the highest similarity as the reference access permission.
[0049] Specifically, the configured access permissions are compared with existing access permissions in the multi-dimensional data management model using Euclidean distance or cosine similarity calculations. The existing access permission with the highest similarity is selected as the reference access permission for the configured access permissions. If there are multi-dimensional unknown attributes, manual access tags are set and similar access tags are selected one by one.
[0050] S503: Map the mapping relationship between reference access permissions and multidimensional access tags to configuration access permissions, and build a new mapping relationship between configuration access permissions and multidimensional access tags.
[0051] Specifically, the mapping relationship between reference access permissions and multidimensional access tags is mapped to configuration access permissions, thus constructing a new mapping relationship between configuration access permissions and multidimensional access tags.
[0052] In this embodiment, after step S503, the method further includes: verifying the new mapping relationship through the registration approval superior; manually modifying the new mapping relationship when there is a mapping error; and establishing a new mapping relationship based on the result of the manual modification.
[0053] Specifically, the new mapping relationship is verified by the superior registration and approval authority. If the mapping relationship is correct, it is verified as correct. If the new mapping relationship has a mapping error, it is manually modified by the superior registration and approval authority, and a new modified mapping relationship is established based on the manual modification result.
[0054] S60: When a data access request is received from a registered user, a dedicated data pool corresponding to the new multidimensional data access permission is built through the multidimensional data management model.
[0055] Specifically, such as Figure 6 As shown, step S60 includes: S601: Match the new multidimensional data access permissions with the existing data access permissions in the multidimensional data management model, and filter the target access permissions that successfully match.
[0056] Specifically, upon receiving a registered user's access request, the system uses a multidimensional data management model to search for and match existing multidimensional data access permissions of the same type as the new multidimensional data access permissions, based on the registered user's new multidimensional data access permissions, and then filters out the successfully matched target access permissions.
[0057] S602: Retrieve the power grid data corresponding to the query tag that has a mapping relationship with the target query permission, and store it in the temporarily built storage space to generate a dedicated data pool corresponding to the new multidimensional data query permission.
[0058] Specifically, based on the mapping relationship between target access permissions and access tags, access tags are synchronously mapped to new multidimensional data access permissions. This establishes a many-to-many mapping relationship between new multidimensional data access permissions and similar access tags. According to this newly constructed many-to-many mapping relationship, the corresponding power grid data is stored in a temporarily constructed dedicated space, forming a dedicated data pool within the registered user's jurisdiction or data access scope. In this embodiment, the dedicated temporary storage space can be built using an object pool or a cache pool.
[0059] S70: Perform keyword parsing on data query requests, search for the target data in the dedicated data pool according to the keyword parsing results, and display the multi-dimensional data according to the style set by the registered user.
[0060] Specifically, keywords are extracted from user-input query requests, including "Business A," "Region B," and "Power Dispatch from XX to XXX." Based on these keywords, the corresponding target data is searched in a dedicated data pool. This includes power grid data related to Business A, power grid data belonging to Region B, and power grid data belonging to XX and XXX respectively, with the business being power dispatch. The search results are then displayed in multiple dimensions, forming a multi-level, multi-dimensional hierarchical management and display solution for power grid data. This achieves precise data control across "the same platform or database, but different data display views," preventing unauthorized users from accessing data at the source and meeting the needs of hierarchical management.
[0061] In this embodiment, the new mapping relationships corresponding to new user attributes and unknown attributes are updated in the multidimensional data management model to update and iterate the model.
[0062] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0063] In one embodiment, a differentiated data access control system based on user roles and geographic location is provided. This differentiated data access control system corresponds one-to-one with the differentiated data access control method based on user roles and geographic location described in the above embodiments. For example... Figure 7 As shown, this differentiated data access control system based on user roles and geographic location includes an access control module, a tag setting module, a model building module, and a data search module. Detailed descriptions of each functional module are as follows: The permission settings module is used to obtain all user attributes of existing management users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing management users.
[0064] The tag setting module is used to obtain the multi-dimensional power grid attributes of the power grid data and perform lookup tag marking processing on each power grid attribute to obtain the multi-dimensional lookup tags of the power grid data.
[0065] The model building module is used to match the attributes of multidimensional data access permissions with multidimensional access tags, and build a many-to-many mapping relationship between permissions and tags based on the matching results, thereby generating a multidimensional data management model.
[0066] The data search module is used to obtain the data search request from the user, generate a dedicated data pool for the user through a multidimensional data management model, and search for the target data in the dedicated data pool according to the data search request.
[0067] Preferably, after the model building module, it also includes: The tag configuration submodule is used to manually configure tags for unknown attributes when there are unknown attributes in the new power grid data, and to calculate the tag similarity between the manually viewed tags and the existing viewed tags in the multidimensional data management model.
[0068] The new mapping relationship construction submodule is used to map the existing query tag with the highest tag similarity to the multidimensional data query permission to the manual query tag, and to build a new mapping relationship between the manual query tag and the multidimensional data query permission.
[0069] Preferably, the data search module specifically includes: The data pool construction submodule is used to call the power grid data corresponding to the query tags with mapping relationships according to the multidimensional data query permissions of the querying user, and store it in a temporarily built dedicated space to generate a dedicated data pool.
[0070] The target data search submodule is used to parse search keywords for data search requests, and then search for and display target data in a dedicated data pool based on the parsed search keywords.
[0071] Preferably, the system also includes: The new registration permission allocation module is used to obtain user registration information to create user attribute profiles, and to assign corresponding data viewing permissions to each user attribute in the user attribute profile, thereby obtaining the new multi-dimensional data viewing permissions for registered users.
[0072] The new registration data pool construction module is used to build a dedicated data pool corresponding to the new multidimensional data viewing permissions through a multidimensional data management model when a data viewing request is received from a registered user.
[0073] The target data search module is used to parse keywords in data search requests, search for the target data in a dedicated data pool according to the keyword parsing results, and display the data in a multi-dimensional format according to the style set by the registered user.
[0074] Preferably, the newly registered data pool construction module specifically includes: The permission matching submodule is used to match the new multidimensional data viewing permissions with the existing data viewing permissions in the multidimensional data management model, and filter the target viewing permissions that successfully match.
[0075] The dedicated data pool construction submodule is used to call the power grid data corresponding to the query tags that have a mapping relationship with the target query permissions, and store it in the temporarily built storage space to generate a dedicated data pool corresponding to the new multidimensional data query permissions.
[0076] Preferably, the new registration permission allocation module also includes: The new user attribute permission configuration submodule is used to configure the viewing permission of new user attributes through the registration approval superior when new user attributes exist in the user registration information, so as to obtain the configuration viewing permission.
[0077] The reference permission selection submodule is used to calculate the permission similarity between the configured access permission and the existing access permission in the multidimensional data management model, and select the existing access permission with the highest similarity as the reference access permission.
[0078] The new mapping relationship construction submodule is used to map the mapping relationship between reference access permissions and multidimensional access tags to configuration access permissions, and to build a new mapping relationship between configuration access permissions and multidimensional access tags.
[0079] Preferably, after the new mapping relationship construction submodule, it also includes: The manual verification submodule is used to verify new mapping relationships through the registration approval process. When a new mapping relationship has mapping errors, it is manually modified, and a new mapping relationship is established based on the manual modification results.
[0080] Specific limitations regarding the differentiated data access control system based on user roles and geographic location can be found in the above section on the limitations of the differentiated data access control method based on user roles and geographic location, and will not be repeated here. Each module in the aforementioned differentiated data access control system based on user roles and geographic location can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0081] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and the database. The internal memory provides the environment for the operation of the operating system and computer programs in the non-volatile storage media. The database stores data related to differentiated data access control. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements a differentiated data access control method based on user roles and geographic location.
[0082] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements a differentiated data access control method based on user roles and geographic relationships.
[0083] Those skilled in the art will recognize that the units of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application of the technical solution and the constraints involved. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.
[0084] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical functional division. In actual implementation, there may be other division methods, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored.
[0085] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0086] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0087] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.
Claims
1. A differentiated data access control method based on user roles and geographic location, characterized in that, The method includes: Obtain all user attributes of existing managed users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing managed users. The multidimensional power grid attributes of the power grid data are obtained and each power grid attribute is marked with a lookup tag to obtain the multidimensional lookup tags of the power grid data. The multidimensional data access permissions are matched with the multidimensional access tags, and a many-to-many mapping relationship between permissions and tags is constructed based on the matching results to generate a multidimensional data management model. The system obtains the data access request from the user, generates a dedicated data pool for the user through the multidimensional data management model, and searches for the target data in the dedicated data pool according to the data access request.
2. The differentiated data access control method based on user roles and geographic location as described in claim 1, characterized in that, After performing attribute matching between the multidimensional data access permissions and the multidimensional access tags, and constructing a many-to-many mapping relationship between permissions and tags based on the matching results to generate a multidimensional data management model, the method further includes: When the new power grid data has unknown attributes, manual query tags are configured for the unknown attributes, and the tag similarity between the manual query tags and the existing query tags in the multidimensional data management model is calculated. Map the existing query tag with the highest tag similarity to the multidimensional data query permission to the manual query tag, and construct a new mapping relationship between the manual query tag and the multidimensional data query permission.
3. The differentiated data access control method based on user roles and geographic location as described in claim 1, characterized in that, The process of obtaining the data query request from the user, generating a dedicated data pool for the user through the multidimensional data management model, and searching for the target data in the dedicated data pool according to the data query request specifically includes: According to the user's multidimensional data access permissions, the multidimensional data management model calls the power grid data corresponding to the access tags that have a mapping relationship, and stores it in a temporarily built dedicated space to generate a dedicated data pool; The data query request is parsed using query keywords, and the target data is searched and displayed in a multi-dimensional manner in the dedicated data pool based on the parsed query keywords.
4. The differentiated data access control method based on user roles and geographic location as described in claim 1, characterized in that, The method further includes: Obtain user registration information to create a user attribute profile, assign corresponding data access permissions to each user attribute in the user attribute profile, and obtain new multi-dimensional data access permissions for registered users. When a data access request is received from a registered user, a dedicated data pool corresponding to the new multidimensional data access permission is built through the multidimensional data management model. The data query request is parsed using keywords. Based on the keyword parsing results, the target data is searched in the dedicated data pool and displayed in a multi-dimensional format according to the style set by the registered user.
5. The differentiated data access control method based on user roles and geographic location as described in claim 4, characterized in that, When a data access request from a registered user is received, the process of establishing a dedicated data pool corresponding to the new multidimensional data access permission through the multidimensional data management model specifically includes: The new multidimensional data access permissions are matched with the existing data access permissions in the multidimensional data management model to filter the target access permissions that successfully match. The system retrieves the power grid data corresponding to the query tag that has a mapping relationship with the target query permission, stores it in a temporarily built storage space, and generates a dedicated data pool corresponding to the new multidimensional data query permission.
6. The differentiated data access control method based on user roles and geographic location as described in claim 4, characterized in that, The step of obtaining user registration information to create a user attribute profile, assigning corresponding data access permissions to each user attribute in the user attribute profile, and obtaining new multi-dimensional data access permissions for registered users, also includes: When a new user attribute exists in the user registration information, the superior registration approval authority configures the viewing permission for the new user attribute to obtain the configuration viewing permission. Calculate the permission similarity between the configured access permission and the existing access permission in the multidimensional data management model, and select the existing access permission with the highest similarity as the reference access permission; The mapping relationship between the reference viewing permission and the multidimensional viewing tag is mapped to the configuration viewing permission, thus constructing a new mapping relationship between the configuration viewing permission and the multidimensional viewing tag.
7. The differentiated data access control method based on user roles and geographic location as described in claim 6, characterized in that, After mapping the mapping relationship between the reference access permission and the multidimensional access tag to the configuration access permission, and constructing a new mapping relationship between the configuration access permission and the multidimensional access tag, the method further includes: The new mapping relationship is verified by the superior authority that approves the registration. If there is a mapping error in the new mapping relationship, it is manually modified, and a new mapping relationship is established based on the result of the manual modification.
8. A differentiated data access control system based on user roles and geographic location, characterized in that, The system includes: The permission setting module is used to obtain all user attributes of existing management users, assign data access permissions to each existing user attribute, and obtain multi-dimensional data access permissions for existing management users. The tag setting module is used to obtain the multi-dimensional power grid attributes of the power grid data and perform lookup tag marking processing on each power grid attribute to obtain the multi-dimensional lookup tags of the power grid data; The model building module is used to perform attribute matching between the multidimensional data access permissions and the multidimensional access tags, and to build a many-to-many mapping relationship between permissions and tags based on the matching results, thereby generating a multidimensional data management model. The data search module is used to obtain the data search request from the user, generate a dedicated data pool for the user through the multidimensional data management model, and search for the target data in the dedicated data pool according to the data search request.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the differentiated data permission management method based on user role and location relationship as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the differentiated data permission management method based on user roles and location relationships as described in any one of claims 1 to 7.