A permission association processing method, apparatus, device, and medium

By generating permission tags and automatically binding permissions using entity association networks, the problem of low permission configuration efficiency in existing technologies is solved, enabling rapid permission configuration in large-scale data scenarios and improving the level of automation in permission management.

CN122153934APending Publication Date: 2026-06-05BONREE DATA TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BONREE DATA TECH CO LTD
Filing Date
2026-02-26
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

In existing technologies, data permission configuration is inefficient, especially when dealing with massive amounts of data, making it difficult to manage permissions efficiently.

Method used

By generating permission tags for source entities and using a pre-built entity association network to determine target entities, permission tags are automatically bound, enabling the automatic transfer of permission tags between entities.

Benefits of technology

It improves the efficiency of permission configuration, enabling the system to quickly complete batch permission configuration in large-scale data scenarios, and enhances the automation level of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122153934A_ABST
    Figure CN122153934A_ABST
Patent Text Reader

Abstract

The application discloses a kind of right association processing method, device, equipment and medium.The method comprises: generating the right label corresponding to source entity;The data generated by the source entity is bound with the corresponding right label;For at least one target entity, according to the association relationship between each entity in the association network, the target entity associated with the source entity is inquired in the target entity;The data generated by the target entity is bound with the right label;The target account is assigned the right label;The target account assigned with the right label has the right to access the data generated by the source entity and the target entity bound with the right label.This embodiment of the application can improve the efficiency of right configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet technology, and in particular to a method, apparatus, device, and medium for processing permissions association. Background Technology

[0002] With the development of the big data era, data security will become a future trend. Setting data permissions is a common method to ensure data security. Data permissions define which users can query or operate on data they are authorized to access.

[0003] In existing technologies, data permission configuration is mainly achieved by establishing a mapping relationship between data and accounts with the same identifier. This method usually relies on manual labeling of data and associated accounts, which results in low efficiency in data permission configuration when dealing with massive amounts of data. Summary of the Invention

[0005] This invention provides a method, apparatus, device, and medium for permission association processing, which can improve the automation level of permission management and increase the efficiency of permission configuration.

[0006] According to one aspect of the present invention, an embodiment of the present invention provides a permission association processing method, the method comprising:

[0007] Generate the permission tags corresponding to the source entity;

[0008] Bind the data generated by the source entity with the corresponding permission tag;

[0009] For at least one target entity, based on the association relationships between entities in the association network, query the target entity associated with the source entity in the target entity;

[0010] Bind the data generated by the target entity to the permission tag;

[0011] Assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

[0012] According to another aspect of the present invention, embodiments of the present invention also provide a permission association processing apparatus, the apparatus comprising:

[0013] The permission tag generation module is used to generate permission tags corresponding to the source entity;

[0014] The first tag binding module is used to bind the data generated by the source entity to the corresponding permission tag;

[0015] The target entity determination module is used to query the target entity associated with the source entity in the target entity based on the association relationship between entities in the association network, for at least one target entity.

[0016] The second tag binding module is used to bind the data generated by the target entity to the permission tag;

[0017] The permission tag allocation module is used to assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

[0018] According to another aspect of the present invention, embodiments of the present invention also provide a permission association processing device, the permission association processing device comprising:

[0019] At least one processor; and

[0020] A memory that is communicatively connected to at least one processor; wherein,

[0021] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the permission association processing method of any embodiment of the present invention.

[0022] According to another aspect of the present invention, a computer-readable storage medium is provided, which stores computer instructions for causing a processor to execute and implement the permission association processing method of any embodiment of the present invention.

[0023] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the permission association processing method described in any embodiment of the present invention.

[0024] The technical solution of this invention generates permission tags by determining the source entity, binds the permission tags to the data generated by the source entity, and then uses a pre-built entity association network to determine the target entity associated with the source entity, binding the permission tags to the data generated by the target entity. Through the association relationship between entities, the automatic binding of permission tags is realized, enabling the transfer of permissions to other entities based on the association relationship between entities. This solves the problem of low permission configuration efficiency in the prior art, enabling the system to quickly complete the configuration of batch permissions in large-scale data scenarios, thus improving the efficiency of permission configuration.

[0025] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0026] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0027] Figure 1A This is a flowchart of a permission association processing method provided by an embodiment of the present invention;

[0028] Figure 1B This is a schematic diagram illustrating the relationships between entities according to embodiments of the present invention;

[0029] Figure 2 This is a flowchart of a permission association processing method provided by an embodiment of the present invention;

[0030] Figure 3 This is a structural diagram of a permission association processing device provided according to an embodiment of the present invention;

[0031] Figure 4 This is a schematic diagram of the structure of a permission association processing device provided in an embodiment of the present invention. Detailed Implementation

[0032] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0033] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0034] The acquisition, storage, and application of traffic information and other related information in the technical solutions of this invention comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0035] Figure 1A This is a flowchart illustrating a permission association processing method provided in an embodiment of the present invention. This embodiment is applicable to permission association processing scenarios, and the method can be executed by a permission association processing device, which can be implemented in hardware and / or software. This permission association processing device can be configured in a server.

[0036] See Figure 1A The permission association processing method shown includes:

[0037] S101. Generate the permission tag corresponding to the source entity.

[0038] Functionally, an entity can be a hardware device or software program capable of sending or receiving information. Entity types can include: network requests, services, service instances, hosts, and processes, etc.

[0039] In this context, a network request can be a structured data entity initiated by the requester to the service provider. A service can be a functional module entity with a specific function that can be invoked. A service instance can be an execution entity deployed on computer hardware or in a virtualized environment that can run. A process can be a basic resource entity that the operating system allocates system resources to run programs. A host can be a physical or virtual computing device entity with a unique identifier in the network.

[0040] The source entity can be the entity that serves as the source of the permission association. Permission tags are tags used to describe data access permissions.

[0041] Permission tags can be generated based on the attributes of the source entity. For example, certain characters in the source entity name can be used as the tag name for the permission tag.

[0042] In an optional embodiment, generating the permission tag corresponding to the source entity includes: obtaining permission configuration information, the permission configuration information including account filtering information and entity filtering information; determining the source entity based on the entity filtering information in the permission configuration information; and before assigning the permission tag to the target account, further including: determining the target account based on the account filtering information.

[0043] The permission configuration information can be user-preset permission settings. Account filtering information can filter accounts with access permissions. Account filtering information is used to determine the target account. The target account can be an account with access permissions. Entity filtering information can filter entities containing accessed content. Entity filtering information is used to determine the source entity.

[0044] In one specific embodiment, entity filtering information may include: entity type and entity filtering criteria. Source entities are determined based on the entity type and entity filtering criteria.

[0045] For example: If the entity filtering information is: {Entity type: service; Entity filtering condition: service name = "test"}, the service whose service name contains "test" will be filtered out: service 1, and service 1 will be used as the source entity.

[0046] In one specific embodiment, the account filtering information may include: account information and account filtering criteria. The target account is determined based on the account information and the account filtering criteria. For example, the account information includes: username, department, and job title; the filtering criteria are: testing department and senior engineer. All accounts whose department is testing and whose job title is senior engineer are filtered out and selected as the target account.

[0047] As can be seen, by obtaining permission configuration information, determining the target account through account filtering information, and determining the source entity through entity filtering information, the object and scope of permission control can be accurately matched, thereby achieving the standardization of permission management.

[0048] In an optional embodiment, obtaining permission configuration information includes: obtaining permission configuration information input by the user; or obtaining permission configuration information in the configuration rules selected by the user.

[0049] In some embodiments, users can directly input permission configuration information. For example, users can create permission label names.

[0050] In some embodiments, users can refine the configuration rules by entering permission configuration information. For example, users can select a rule for generating permission tag names on the page. The system then generates tags based on the permission tag name generation rule.

[0051] It is evident that by obtaining permission configuration information input by the user or permission configuration information in the configuration rules selected by the user, the generation of permission tags corresponding to the source entity becomes more flexible.

[0052] S102. Bind the data generated by the source entity to the corresponding permission tag.

[0053] The data generated by the source entity can be runtime data generated during the operation of the source entity, or processing results generated by the source entity during processing.

[0054] Establish an association mapping between the source entity's runtime data and permission tags to achieve the binding and association between data and permission tags.

[0055] S103. For at least one target entity, based on the association relationships between entities in the association network, query the target entity associated with the source entity in the target entity.

[0056] The target entity can be the entity that is passed as an authorization tag. The association network can be a network describing the relationships between entities. The association relationship can be the static structural relationship and / or dynamic interaction relationship between entities in the system. Association relationships include: inclusion, invocation, and execution affiliation.

[0057] For example, if service A contains service instance 1 and service instance 2, then service A is associated with service instance 1 and service A is associated with service instance 2.

[0058] Determine the type of the target entity, and query the target entities associated with the source entity from the target entities of that type. For example, if the source entity is service A, and service A contains service instance 1 and service instance 2, then for the service instances, you can query service instance 1 and service instance 2 associated with the source entity service A. Use service instance 1 and service instance 2 as the target entities.

[0059] S104. Bind the data generated by the target entity to the permission tag.

[0060] Specifically, an association mapping is established between the data generated by the target entity during operation and the permission tags, thereby achieving the binding and association between the data generated by the target entity and the permission tags.

[0061] In a specific embodiment, such as Figure 1B As shown, the relationships between entities of different types are as follows: network requests can invoke services; a service can contain multiple service instances; service instances need to run on processes; and processes need to run on hosts. Specifically, the relationships between entities can be: Query 1 invokes service 2 to perform the query function. Service 2 contains service instance 1 and service instance 2. Service instance 1 runs in process 1, service instance 2 runs in process 2, and both process 1 and service instance 2 run on host 1. When setting permission configuration information, users can filter query requests whose query addresses contain "http: / / url1". The system will take query request 1 from the network requests as the source entity and generate a permission tag corresponding to the source entity—tag 1. Tag 1 and the data generated by query request 1 are bound together. Then, based on the relationships between entities, service 2 is taken as the target entity, and the data generated by tag 1 and service 2 are bound together. Similarly, service instance 1, service instance 2, service instance 1, service instance 2, and host 1 are taken as target entities, and tag 1 is bound to the data it generates, completing the binding of permission tags to the data generated by the entities.

[0062] S105. Assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

[0063] This involves assigning permission tags to target accounts. Target accounts can then view data generated by entities with the same permission tags.

[0064] For example, account A's permission tags include: test1. Account B's permission tags do not include: test1.

[0065] The data bound to the permission tag test1 includes: data of service 1, data of service instance 1, data of service instance 2, data of process A, and data of process 2.

[0066] Account A has access to the data described above, while account B does not.

[0067] In an optional embodiment, the method further includes: when it is detected that the entity filtering information corresponding to the permission tag has been modified, unbinding the permission tag from the bound data and deleting the permission tag; determining a new entity and a new tag based on the modified entity filtering information; binding the data generated by the new entity to the new tag; and assigning the new tag to the target account.

[0068] When it is necessary to modify the data content corresponding to a permission tag, the user can modify the permission configuration information through the permission configuration page. When the system detects that the entity filtering information corresponding to the permission tag has been modified, it first unbinds the permission tag from the bound data and deletes the original permission tag. Then, based on the modified entity filtering information, it determines the new source entity and reassigns the tag to the target account according to S101 to S105.

[0069] As can be seen, by dynamically responding to changes in entity filtering information, automatically unbinding old permission tags, cleaning up invalid configurations, and rebinding data and new tags based on new filtering conditions, and assigning updated permission tags to the corresponding accounts, permission control can adapt to changes in system structure or business strategies in a timely manner, thereby improving the efficiency of permission management.

[0070] The technical solution of this invention generates permission tags by determining the source entity, binds the permission tags to the data generated by the source entity, and then uses a pre-built entity association network to determine the target entity associated with the source entity, binding the permission tags to the data generated by the target entity. Through the association relationship between entities, the automatic binding of permission tags is realized, enabling the transfer of permissions to other entities based on the association relationship between entities. This solves the problem of low permission configuration efficiency in the prior art, enabling the system to quickly complete the configuration of batch permissions in large-scale data scenarios, thus improving the efficiency of permission configuration.

[0071] Figure 2 This is a flowchart illustrating a permission association processing method provided by an embodiment of the present invention. Based on the above embodiments, this embodiment binds the data generated by the source entity with the corresponding permission tag, specifically by: obtaining the data file associated with the source entity during processing; and binding the data file associated with the source entity with the corresponding permission tag.

[0072] It should be noted that for parts not described in detail in the embodiments of the present invention, please refer to the descriptions in other embodiments.

[0073] See Figure 2 The permission association processing method shown includes:

[0074] S201. Generate the permission tag corresponding to the source entity.

[0075] S202. Obtain the data file associated with the source entity during processing.

[0076] The data file associated with the source entity during processing can refer to a file related to the dynamic operation of the entity.

[0077] In an optional embodiment, obtaining the data file associated with the source entity during processing includes: when the source entity includes a network request, obtaining the data file generated by the network request as the data file associated with the source entity during processing; when the source entity includes a service, obtaining the data file generated by the service operation as the data file associated with the source entity during processing; when the source entity includes a service instance, obtaining the data file generated by the service instance operation as the data file associated with the source entity during processing; when the source entity includes a process, obtaining the data file generated by the process operation as the data file associated with the source entity during processing; and when the source entity includes a host, obtaining the data file generated by the host operation as the data file associated with the source entity during processing.

[0078] The data file generated by a network request can be a request log file. The request log file records data such as request parameters, request URL, and request time.

[0079] Data files generated during service operation can be records of service operation status, business interaction processes, and execution results. These data files include, but are not limited to: service log files, service business data files, service status snapshot files, and service performance statistics files.

[0080] Data files generated by a running service instance can refer to records of the service instance's running status and processing. These data files include, but are not limited to: service instance log files, service instance status snapshot files, and service instance monitoring metric files.

[0081] Data files generated by a running process can be various types of files created, written, or modified by a single operating system process during its lifecycle. These data files include, but are not limited to: process execution log files, process task processing detail files, process error stack log files, process resource usage statistics files, and process status record files.

[0082] The data files generated by the host operation can be global log files recording the overall operating status of the host, system resource usage, and network interaction processes. These data files include, but are not limited to: host system log files, host resource monitoring and statistics files, host kernel operation log files, host network packet archive files, and host hardware status detection log files.

[0083] It is evident that by collecting data files generated by network requests, services, service instances, processes, and host entities, refined and traceable management of computer system operation data can be achieved. This enables precise identification of the root causes of faults at each level, from network requests to the host, shortening the troubleshooting cycle. It also allows for targeted analysis of performance bottlenecks of each entity and layered optimization, improving the overall system operating efficiency and facilitating the operation and maintenance management of computer systems.

[0084] S203. Bind the data file associated with the source entity to the corresponding permission tag.

[0085] This method involves binding data files to permission tags. Accounts with the specified permission tag can access the corresponding data file, while accounts without the tag cannot. This file-based approach enables access control over data.

[0086] S204. For at least one target entity, based on the association relationships between entities in the association network, query the target entity associated with the source entity in the target entity.

[0087] S205. Bind the data generated by the target entity to the permission tag.

[0088] S206. Assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

[0089] The technical solution of this invention binds the data file associated with the source entity processing with the corresponding permission tag, which can realize the precise association and integrated management of data file and source entity permissions. Using files as carriers, it simplifies the permission management logic and improves the efficiency of permission configuration and verification.

[0090] Figure 3 This is a schematic diagram of a permission association processing device provided in an embodiment of the present invention. The embodiments of the present invention are applicable to permission association processing situations. This device can execute a permission association processing method and can be implemented in hardware and / or software.

[0091] See Figure 3 The permission association processing device shown includes:

[0092] The permission tag generation module 301 is used to generate permission tags corresponding to the source entity.

[0093] The first tag binding module 302 is used to bind the data generated by the source entity with the corresponding permission tag;

[0094] The target entity determination module 303 is used to query the target entity associated with the source entity in the target entity based on the association relationship between entities in the association network for at least one target entity.

[0095] The second tag binding module 304 is used to bind the data generated by the target entity to the permission tag;

[0096] The permission tag allocation module 305 is used to allocate the permission tag to the target account; the target account with the allocated permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

[0097] The technical solution of this invention generates permission tags by determining the source entity, binds the permission tags to the data generated by the source entity, and then uses a pre-built entity association network to determine the target entity associated with the source entity, binding the permission tags to the data generated by the target entity. Through the association relationship between entities, the automatic binding of permission tags is achieved, which solves the problem of low permission configuration efficiency in the prior art. This enables the system to quickly complete permission configuration in large-scale data scenarios, improves the automation level of permission management, and increases the efficiency of permission configuration.

[0098] In an optional embodiment, the first tag binding module 302 includes:

[0099] A data file acquisition unit is used to acquire the data file associated with the source entity during processing;

[0100] The first tag binding unit is used to bind the data file associated with the source entity to the corresponding permission tag.

[0101] In an optional embodiment, the data file acquisition unit includes:

[0102] The network request data file acquisition subunit is used to acquire the data file formed by the network request when the source entity includes a network request, and use it as the data file associated with the source entity during processing;

[0103] The service data file acquisition subunit is used to acquire the data file generated by the service when the source entity includes a service, and use it as the data file associated with the source entity during processing;

[0104] The service instance data file acquisition subunit is used to acquire the data file generated by the service instance when the source entity includes a service instance, and use it as the data file associated with the source entity during processing;

[0105] The process data file acquisition subunit is used to acquire the data file generated by the process when the source entity includes a process, and use it as the data file associated with the source entity during processing;

[0106] The host data file acquisition subunit is used to acquire the data file generated by the host when the source entity includes a host, and use it as the data file associated with the source entity during processing.

[0107] In an optional embodiment, the permission label generation module 301 includes:

[0108] A permission configuration information acquisition unit is used to acquire permission configuration information, which includes account filtering information and entity filtering information.

[0109] The source entity determination unit is used to determine the source entity based on the entity filtering information in the permission configuration information;

[0110] In an optional embodiment, before assigning the permission tag to the target account, the method further includes:

[0111] The target account determination unit is used to determine the target account based on the account filtering information.

[0112] In an optional embodiment, the permission configuration information acquisition unit includes:

[0113] Obtain permission configuration information input by the user; or

[0114] Retrieve permission configuration information from the configuration rules selected by the user.

[0115] In an optional embodiment, the source entity determination unit includes:

[0116] The identification information filtering subunit is used to filter the identification information included in the entity filtering information in the permission configuration information.

[0117] The source entity determination subunit is used to filter out source entities that contain the identification information.

[0118] In an optional embodiment, it further includes:

[0119] The permission modification unit is used to unbind the permission tag from the bound data and delete the permission tag when it is detected that the entity filtering information corresponding to the permission tag has been modified.

[0120] The target determination unit is used to determine new entities and new labels based on the modified entity filtering information;

[0121] A data binding unit is used to bind the data generated by the new entity to the new label;

[0122] An account binding unit is used to assign the new tag to the target account.

[0123] The permission association processing device provided in the embodiments of the present invention can execute the permission association processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the permission association processing method.

[0124] Figure 4 A schematic diagram of the structure of a permission association processing device 400 that can be used to implement embodiments of the present invention is shown.

[0125] like Figure 4As shown, the access control processing device 400 includes at least one processor 401 and a memory, such as a read-only memory 402 or a random access memory 403, communicatively connected to the at least one processor 401. The memory stores computer programs executable by the at least one processor. The processor 401 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 402 or loaded from storage unit 408 into the random access memory 403. The random access memory 403 may also store various programs and data required for the operation of the access control processing device 400. The processor 401, read-only memory 402, and random access memory 403 are interconnected via a bus 404. An input / output interface 405 is also connected to the bus 404.

[0126] Multiple components in the access control processing device 400 are connected to the input / output interface 405, including: an input unit 406, such as a keyboard or mouse; an output unit 407, such as various types of displays or speakers; a storage unit 408, such as a hard disk or optical disk; and a communication unit 409, such as a network interface card (NIC), a modem, or a wireless transceiver. The communication unit 409 allows the access control processing device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0127] Processor 401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 401 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 401 performs the various methods and processes described above, such as permission association processing methods.

[0128] In some embodiments, the permission association processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed onto the permission association processing device 400 via read-only memory 402 and / or communication unit 409. When the computer program is loaded into random access memory 403 and executed by processor 401, one or more steps of the permission association processing method described above may be performed. Alternatively, in other embodiments, processor 401 may be configured to execute the permission association processing method by any other suitable means (e.g., by means of firmware).

[0129] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), systems-on-a-chip (SoCs), complex programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0130] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0131] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, flash memory, optical fiber, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0132] To provide interaction with the user, the systems and techniques described herein can be implemented on an operation detection device. This access control processing device includes: a display device (e.g., a cathode ray tube or liquid crystal display monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the access control processing device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including voice input, speech input, or tactile input).

[0133] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0134] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product within the cloud computing service system. This addresses the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0135] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0136] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for processing permission association, characterized in that, The method includes: Generate the permission tags corresponding to the source entity; Bind the data generated by the source entity with the corresponding permission tag; For at least one target entity, based on the association relationships between entities in the association network, query the target entity associated with the source entity in the target entity; Bind the data generated by the target entity to the permission tag; Assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

2. The method according to claim 1, characterized in that, The step of binding the data generated by the source entity with the corresponding permission tag includes: Obtain the data file associated with the source entity during processing; Bind the data file associated with the source entity to the corresponding permission tag.

3. The method according to claim 2, characterized in that, The step of obtaining the data file associated with the source entity during processing includes: When the source entity includes a network request, the data file formed by the network request is obtained and used as the data file associated with the source entity during processing; When the source entity includes a service, the data file generated by the service is obtained and used as the data file associated with the source entity during processing; When the source entity includes a service instance, the data file generated by the service instance during operation is obtained and used as the data file associated with the source entity during processing; When the source entity includes a process, the data file generated by the process is obtained and used as the data file associated with the source entity during processing; When the source entity includes a host, the data file generated by the host is obtained and used as the data file associated with the source entity during processing.

4. The method according to claim 1, characterized in that, The permission tags corresponding to the generated source entity include: Obtain permission configuration information, which includes account filtering information and entity filtering information; The source entity is determined based on the entity filtering information in the permission configuration information; Before assigning the permission tag to the target account, the following is also included: Based on the account filtering information, the target account is determined.

5. The method according to claim 4, characterized in that, The permission configuration information to be obtained includes: Obtain permission configuration information input by the user; or Retrieve permission configuration information from the configuration rules selected by the user.

6. The method according to claim 4, characterized in that, The step of determining the source entity based on the entity filtering information in the permission configuration information includes: The entity filtering information in the permission configuration information includes the identification information; Filter out the source entities that contain the identification information.

7. The method according to claim 4, characterized in that, Also includes: When it is detected that the entity filtering information corresponding to the permission tag has been modified, the permission tag is unbound from the bound data and the permission tag is deleted. Based on the revised entity filtering information, determine the new entities and new tags; Bind the data generated by the new entity to the new label; Assign the new label to the target account.

8. A permission association processing device, characterized in that, The device includes: The permission tag generation module is used to generate permission tags corresponding to the source entity; The first tag binding module is used to bind the data generated by the source entity to the corresponding permission tag; The target entity determination module is used to query the target entity associated with the source entity in the target entity based on the association relationship between entities in the association network, for at least one target entity. The second tag binding module is used to bind the data generated by the target entity to the permission tag; The permission tag allocation module is used to assign the permission tag to the target account; the target account with the assigned permission tag has the permission to access the data generated by the source entity and the target entity bound to the permission tag.

9. A permission association processing device, characterized in that, The permission association processing device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the permission association processing method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the permission association processing method according to any one of claims 1-7.