Role permission configuration method and device, storage medium and program product

CN122889302APending Publication Date: 2026-10-09BEIJING QINGSONG YIKANG INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611382049.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-09-08
Publication Date
2026-10-09

AI Technical Summary

Technical Problem

[0004]随着临床研究的发展,新增的项目日益增多,现有技术针对每个新增项目均需重复执行上述模板实例化后的权限项核对与适应性调整操作,工作量大幅增加,导致角色权限配置效率低下

Benefits of technology

[0016]第五方面,本公开实施例还提供了一种计算机程序产品,包括计算机程序/指令,该计算机程序/指令被处理器执行时实现以上任一项所述方法的步骤。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122889302A_ABST
    Figure CN122889302A_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose a role permission configuration method and device, a storage medium and a program product. The method comprises: judging whether there is a source project environment with configured role permission adapted to a target project environment; if there is, replacing the source project resource bound to the permission configuration of the specified role in the source project environment permission configuration list with a resource semantic tag; establishing a mapping relationship between the resource semantic tag and the resources in the resource list of the target project environment; converting the permission configuration into role permission rules recognizable by the target project environment based on the mapping relationship; and writing the role permission rules recognizable by the target project environment into the target project environment after conflict elimination when the target project environment has basic permission rules; if not, instantiating a role template matched with the target project environment and performing permission fine-tuning under the constraint condition to generate the role permission configuration of the target project environment. The method can reduce the workload of repeated configuration of administrators and improve the efficiency of role permission configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of clinical research information management technology, and in particular to a method, apparatus, storage medium, and program product for configuring role permissions. Background Technology

[0002] In clinical research information management, if a new research center or clinical trial project is added, a corresponding system operating environment needs to be set up, and permissions for various clinical research roles such as researchers, coordinators, monitors, and data administrators need to be configured for this environment to achieve hierarchical access and control of system resources for different roles.

[0003] Existing technology uses preset role templates for permission configuration. Role templates containing standard permission rule sets are predefined. When it is necessary to configure role permissions for a new environment, the administrator selects the corresponding role template from the template library, calls the template and instantiates it in the target environment, loads the permission rule set in the template and writes it into the permission storage system of the target environment, and generates a role configuration that can be used by the environment.

[0004] With the development of clinical research, the number of new projects is increasing. Existing technology requires repeated verification and adaptive adjustment of permission items after template instantiation for each new project, which greatly increases the workload and leads to low efficiency in role permission configuration. Summary of the Invention

[0005] In view of this, the present disclosure provides a role permission configuration method, apparatus, storage medium, and program product, which can realize the rapid reuse of role permissions across environments and the rapid generation of templated role permissions, reduce the workload of administrators in repetitive configuration, and improve the efficiency of role permission configuration.

[0006] In a first aspect, this disclosure provides a method for configuring role permissions, employing the following technical solution: Obtain the characteristic information of the target project environment, and based on the characteristic information, determine whether there is a source project environment with configured role permissions that is compatible with the target project environment; If it exists, obtain the permission configuration list of the source project environment, detect the source project resources that are bound to the permission configuration of the specified role in the permission configuration list, and obtain the source project resource identifier; Replace the source project resource identifier with a resource semantic tag that is common to project resources; Obtain a resource list of the target project environment, perform feature matching between the resource semantic tags and the target project resources in the resource list, and establish a mapping relationship between the resource semantic tags and the target project resources; Based on the mapping relationship, the permission configuration in the permission configuration list is converted into role permission rules that can be recognized by the target project environment; When the target project environment has basic permission rules, the conflict between the basic permission rules and the identifiable role permission rules is eliminated and then written into the target project environment to form a unique role permission configuration. If not found, a character template matching the target project environment will be selected from the preset character template library; The role template is instantiated and its permissions are fine-tuned under constraints to generate the role permission configuration for the target project environment.

[0007] Optionally, replacing the source project resource identifier with a resource semantic tag common to project resources includes: Construct a resource mapping table and match the source project resource identifiers in the permission configuration list with the source project resource identifiers in the resource mapping table; If a match is found, the corresponding resource semantic tag is extracted from the resource mapping table; If the matching fails, the resource type and business semantic tag of the source project resource are obtained, and the resource type and the business semantic tag are concatenated to form a resource semantic tag that is common to the project resources. Replace the source project resource identifier in the permission configuration list with the resource semantic tag.

[0008] Optionally, the step of performing feature matching between the resource semantic tags and target project resources in the resource list to establish a mapping relationship between the resource semantic tags and the target project resources includes: Based on the resource type in the resource semantic tags, target project resources of the same resource type are selected from the resource list; The business semantic tags in the resource semantic tags are matched with the target project resources of the same resource type to obtain similarity scores; Based on the similarity score, the target project resource that is closest to the resource semantic tag is identified and a mapping relationship is constructed.

[0009] Optionally, the step of converting the permission configurations in the permission configuration list into role permission rules recognizable by the target project environment based on the mapping relationship includes: Based on the mapping relationship between the resource semantic tags and the target project resources, the resource semantic tags bound to the permission configuration in the permission configuration list are replaced with the corresponding target project resource identifiers; The permission configuration and the corresponding target project resource identifier are converted into a triplet format permission containing role, resource operation permission and target project resource identifier. The triplet format permission is a role permission rule that can be recognized by the target project environment.

[0010] Optionally, the step of eliminating conflicts between the basic permission rules and the identifiable role permission rules and then writing them into the target project environment to form a unique role permission configuration includes: The identifiable role permission rules are subjected to conflict detection with the basic permission rules. The corresponding conflict resolution strategy is executed according to the detected conflict type and the severity of the conflict to obtain the permission rules after conflict resolution. Write the conflict-free permission rules into the target project environment and verify them to form a role and permission configuration specific to the target project environment.

[0011] Optionally, the step of instantiating the role template and fine-tuning permissions under constraints to generate the role permission configuration for the target project environment includes: The permission rules and constraints contained in the role template are parsed, and a role instance is generated based on the permission rules; Display the adjustable permission items in the role instance, monitor the administrator's modification operation on the adjustable permission items, and use the constraint propagation algorithm to determine whether the modification operation meets the constraint conditions; If the conditions are not met, corresponding feedback information is generated based on the type of constraint. If satisfied, the role instance is updated based on the modified adjustable permission items to form the role permission configuration for the target project environment.

[0012] Optionally, the step of using a constraint propagation algorithm to determine whether the modification operation satisfies the constraint conditions includes: A permission dependency graph is constructed based on the aforementioned constraints. The nodes of the permission dependency graph are permission items, and the edges between the nodes represent the constraint relationships between the permission items. Starting from the modified adjustable permission item, determine the associated permission item along the permission dependency graph, and obtain the state change impact value of the associated permission item; Based on the impact value of the state change and the current state of the associated permission item, determine whether the modification operation satisfies the constraint conditions.

[0013] Secondly, this disclosure also provides a role-based access control system, which adopts the following technical solution: The judgment module is used to obtain the feature information of the target project environment, and based on the feature information, to determine whether there is a source project environment with configured role permissions that is compatible with the target project environment; if it exists, the detection module is executed; if it does not exist, the selection module is executed. The detection module is used to obtain the permission configuration list of the source project environment, detect the source project resources that are bound to the permission configuration of the specified role in the permission configuration list, and obtain the source project resource identifier. The replacement module is used to replace the source project resource identifier with a resource semantic tag that is common to project resources; A module is established to obtain a resource list of the target project environment, perform feature matching between the resource semantic tags and the target project resources in the resource list, and establish a mapping relationship between the resource semantic tags and the target project resources; The conversion module is used to convert the permission configuration in the permission configuration list into role permission rules that can be recognized by the target project environment based on the mapping relationship. The writing module is used to eliminate the conflict between the basic permission rules and the identifiable role permission rules when the target project environment has basic permission rules, and then write them into the target project environment to form a unique role permission configuration. The selection module is used to select a character template that matches the target project environment from a preset character template library; The fine-tuning module is used to instantiate the role template and fine-tune permissions under constraints to generate the role permission configuration for the target project environment.

[0014] Thirdly, this disclosure also provides a computer device, which adopts the following technical solution: The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform any of the role permission configuration methods described above.

[0015] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute any of the role and permission configuration methods described above.

[0016] Fifthly, embodiments of this disclosure also provide a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the methods described above.

[0017] The role-permission configuration method provided in this disclosure achieves adaptive selection of the configuration path by obtaining the feature information of the target project environment and determining whether a suitable source project environment exists. When a suitable source environment exists, the method replaces the resource identifier bound in the permission configuration of the source project environment with a resource semantic tag to remove the personalized content of the source project environment. Then, it establishes a mapping relationship between the resource semantic tag and the feature matching of the target environment resources and converts it into permission rules that can be recognized by the target environment, thus solving the problem of permission configuration being strongly bound to the environment and thus preventing direct permission migration. By eliminating conflicts between the recognizable permission rules and the basic permission rules of the target environment before writing them, the method retains the existing configuration of the target environment while reusing the source environment configuration, avoiding permission conflicts. This method achieves rapid cross-environment reuse of permission configuration when a suitable source project environment exists, improving the efficiency of role-permission configuration. When no suitable source project environment exists, the method can still quickly complete the configuration by selecting a matching template from the template library and instantiating and fine-tuning it.

[0018] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating the role and permission configuration method provided in this embodiment of the disclosure; Figure 2 A flowchart illustrating the source project resource identifier replacement method provided in this embodiment of the disclosure; Figure 3 A flowchart illustrating the method for establishing the mapping relationship between resource semantic tags and target project resources provided in this embodiment of the disclosure; Figure 4 A flowchart illustrating the method for obtaining role permission rules provided in this embodiment of the disclosure; Figure 5 A flowchart illustrating the conflict resolution and permission writing method provided in this embodiment of the disclosure; Figure 6 A flowchart illustrating the role template instantiation and permission fine-tuning method provided in this embodiment of the disclosure; Figure 7A flowchart illustrating a method for determining whether constraints are met, provided in an embodiment of this disclosure; Figure 8 This is a schematic diagram of the role and permission configuration system provided in the embodiments of this disclosure; Figure 9 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. Detailed Implementation

[0021] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0022] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0023] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0024] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0025] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0026] Reference Figure 1 This disclosure provides a method for configuring role permissions, including the following steps: S1: Obtain the characteristic information of the target project environment. Based on the characteristic information, determine whether there exists a source project environment with configured roles and permissions that is compatible with the target project environment. If it exists, proceed to S2; otherwise, proceed to S7. S2: Obtain the permission configuration list of the source project environment, detect the source project resources bound to the permission configuration of the specified role in the permission configuration list, and obtain the source project resource identifier; S3: Replace the source project resource identifier with a resource semantic tag that is common to all project resources; S4: Obtain the resource list of the target project environment, perform feature matching between the resource semantic tags and the target project resources in the resource list, and establish a mapping relationship between the resource semantic tags and the target project resources; S5: Based on the mapping relationship, convert the permission configuration in the permission configuration list into role permission rules that can be recognized by the target project environment; S6: When basic permission rules exist in the target project environment, the basic permission rules are written into the target project environment after conflict elimination with the identifiable role permission rules to form a unique role permission configuration. S7: Select a character template from the preset character template library that matches the target project environment; S8: Instantiate the role template and fine-tune permissions under constraints to generate the role permission configuration for the target project environment.

[0027] The role-based permission configuration method disclosed herein achieves adaptive selection of configuration paths by obtaining the characteristic information of the target project environment and determining whether a suitable source project environment exists. When a suitable source environment exists, the method replaces the resource identifiers bound in the permission configuration of the source project environment with resource semantic tags to remove the personalized content of the source project environment. Then, it establishes a mapping relationship between the resource semantic tags and the characteristics of the target environment resources and converts them into permission rules that can be recognized by the target environment, thus solving the problem of permission configuration being strongly bound to the environment and thus preventing direct permission migration. By eliminating conflicts between the recognizable permission rules and the basic permission rules of the target environment before writing them, the method retains the existing configuration of the target environment while reusing the source environment configuration, avoiding permission conflicts. This method achieves rapid cross-environment reuse of permission configuration when a suitable source project environment exists, improving the efficiency of role-based permission configuration. When a suitable source project environment does not exist, the method can still quickly complete the configuration by selecting a matching template from the template library and instantiating and fine-tuning it.

[0028] In S1, when a new research center or clinical trial project is added, the corresponding system operating environment is set up as the target project environment. The target project environment is connected through the environment adapter interface, and characteristic information such as project type, research stage, and regulatory requirements are automatically collected from the configuration information of the target project environment, project metadata, or administrator input.

[0029] The system pre-stores the feature information and role / permission configuration status of each existing project environment. A weighted feature matching algorithm is used to calculate the compatibility score between the target project environment's feature information and the feature information of each existing project environment. This compatibility score is calculated by weighted summation after comprehensively considering factors such as project type matching, research phase matching, and regulatory requirement matching. If the compatibility score of an existing project environment reaches a preset threshold, it is determined that the existing project environment is a source project environment compatible with the target project environment; if the compatibility scores of all existing project environments do not reach the preset threshold, it is determined that there is no compatible source project environment. Alternatively, the existing project environments can be sorted in descending order of compatibility score for the administrator to specify the source project environment from among them. Alternatively, if the administrator directly specifies the source project environment, it is not necessary to calculate the compatibility score again.

[0030] In S2, the administrator specifies roles of the same type or function in the source project environment according to the role setting requirements of the target project environment, obtains the role identifier list of the specified roles in the source project environment, and for each role identifier, it iterates through all the permission configuration records corresponding to it in the source project environment, reads the complete field value of each permission configuration record one by one, and summarizes all the read permission configuration entries into the original permission configuration set, i.e., the permission configuration list.

[0031] A resource mapping table is pre-built, which contains each resource type and its corresponding detection rules. The detection rules include two types: regular expression rules and field naming convention rules.

[0032] If regular expression rules are used, the resource mapping table records each resource type and its corresponding regular expression pattern. The field values ​​of each permission configuration entry in the permission configuration list are traversed, and the field values ​​are matched with the regular expression pattern. If the match is successful, the field is identified as the environment binding field that binds the source project resource of that type. The field value is obtained as the source project resource identifier, and its resource type is marked.

[0033] If the field naming convention is adopted, the resource mapping table records each resource type and its corresponding field name suffix and data type constraints. The system traverses the field names and field values ​​of each permission configuration entry in the permission configuration list. If the field name contains a suffix and the corresponding field value is a string type, the field is identified as an environment binding field that binds to the source project resource of that type. The field value of the field is obtained as the source project resource identifier and its resource type is marked.

[0034] In S3, refer to Figure 2 The flowchart illustrating the source project resource identifier replacement method shows that "replacing the source project resource identifier with a common resource semantic tag for project resources" includes the following steps: S31: Construct a resource mapping table and match the source project resource identifier in the permission configuration list with the source project resource identifier in the resource mapping table; if the match is successful, execute S32; if the match fails, execute S33. S32: Extract the corresponding resource semantic tags from the resource mapping table; S33: Obtain the resource type of the source project resource, generate the corresponding business semantic tag according to the business context, and concatenate the resource type and business semantic tag into a resource semantic tag that is common to project resources; S34: Replace the source project resource identifier in the permission configuration list with the resource semantic tag.

[0035] Each entry in the resource mapping table includes, in addition to the detection rules, the source project resource identifier, resource type, business semantic tag, and resource semantic tag. The system iterates through the source project resources bound to the permission configurations of the specified roles in the permission configuration list. For each source project resource found during the iteration, it checks if a matching resource semantic tag exists in the resource mapping table. If the current source project resource identifier exists in the resource mapping table, the corresponding resource semantic tag is extracted and used to replace the current source project resource identifier in the resource mapping table.

[0036] When the resource identifier for the current source project does not exist in the resource mapping table, based on the resource type pointed to by the resource identifier, for system-predefined resource types, a business semantic tag is automatically generated using a rule-based generation method according to the resource type and business context; for custom resource types, the administrator is prompted to enter a business semantic tag. The resource type and the business semantic tag are concatenated in the format "resource type:business semantic tag" to form a new resource semantic tag, which replaces the resource identifier for the current source project in the permission configuration list. The resource identifier for the current source project, the resource type, the business semantic tag, and the newly generated resource semantic tag are then stored as a new entry in the resource mapping table.

[0037] The replaced permission configuration list, resource mapping table, and snapshot metadata are encapsulated into a permission snapshot package. The snapshot metadata includes a unique snapshot identifier, a source project environment identifier, and the snapshot creation time. The SHA-256 hash value of the permission snapshot package content is calculated as a verification hash and filled into the permission snapshot package to ensure verifiable integrity during transmission and storage. This permission snapshot package does not contain any resource identifiers specific to the source project environment and can be parsed and restored in any target project environment, facilitating resource mapping and permission import during subsequent cross-environment permission copying.

[0038] In S4, the resources of the target project environment are scanned to obtain metadata information of various resources and form a resource list. This resource list includes the resource identifier, resource type, resource name, resource attributes and scan time of each resource in the target project environment.

[0039] Reference Figure 3 The flowchart illustrating the method for establishing the mapping relationship between resource semantic tags and target project resources shows that "matching the features of resource semantic tags with the target project resources in the resource list to establish the mapping relationship between resource semantic tags and target project resources" includes the following steps: S41: Based on the resource type in the resource semantic tag, filter out target project resources of the same resource type from the resource list; S42: Perform feature matching between the business semantic tags in the resource semantic tags and target project resources of the same resource type to obtain similarity scores; S43: Based on the similarity score, identify the target project resource that is closest to the resource semantic tag and construct a mapping relationship.

[0040] In steps S41-S42, resources with the same resource type are selected from the resource list as a candidate resource set based on the resource type in the resource semantic tags. For each candidate resource in the candidate resource set, the resource name is segmented and mapped to word vectors using a domain vocabulary, and the average value is taken to obtain the name feature. The resource type is converted into type features using One-Hot encoding. The key-value pairs of resource attributes are encoded and concatenated to obtain attribute features, where the attribute names in the key-value pairs are mapped using an attribute vocabulary, and the attribute values ​​are normalized. The name feature, type feature, and attribute feature are extracted and concatenated to form the feature vector of the candidate resource. The same processing is applied to the resource semantic tags to obtain the feature vector of the source project resource. The cosine similarity between the feature vector of the source project resource and the feature vectors of each candidate resource is calculated to obtain a similarity score.

[0041] In step S43, similarity scores are sorted from highest to lowest, and the candidate resource with the highest similarity score is selected as the closest target project resource. If the highest similarity score reaches the first threshold, the target project resource is directly identified as the mapping target, and a mapping relationship between the resource semantic tag and the target project resource is automatically established. If the highest similarity score does not reach the first threshold but reaches the second threshold, the candidate resources with similarity reaching the second threshold are provided for manual confirmation. If the highest similarity score does not reach the second threshold, it is marked as awaiting manual configuration. All mapping relationships are summarized into a permission mapping result table, recording the correspondence between resource semantic tags and target project resource identifiers.

[0042] In S5, refer to Figure 4 The flowchart illustrating the method for obtaining role permission rules demonstrates that "converting the permission configuration in the permission configuration list into role permission rules that can be recognized by the target project environment based on the mapping relationship" includes the following steps: S51: Based on the mapping relationship between resource semantic tags and target project resources, replace the resource semantic tags bound to the permission configuration in the permission configuration list with the corresponding target project resource identifier; S52: Convert the permission configuration and the corresponding target project resource identifier into a triplet format permission containing role, resource operation permission and target project resource identifier. The triplet format permission is a role permission rule that can be recognized by the target project environment.

[0043] In S51, permission configuration entries and their bound resource semantic tags are extracted from the permission snapshot package. Based on the mapping relationship recorded in the permission mapping result table, each permission configuration is traversed, and the resource semantic tags in it are replaced with the corresponding target project resource identifier.

[0044] In S52, permission configuration includes roles and operations. Roles are the objects to which permissions are granted, operations are the actions performed on resources, and the target project resource identifier is the specific resource object controlled by the permissions. Based on the permission configuration and the corresponding target project resource identifier, permission rules are generated, expressed as triples of role, operation, and target project resource identifier. After the replacement, all resource semantic tags in the permission snapshot package are replaced with the target project resource identifier, becoming permission rules expressed using the target project resource identifier—that is, role-based permission rules recognizable by the target project environment.

[0045] In S6, when the target project environment is a newly created environment and no role permissions have been configured, the recognizable role permission rules are directly written into the target project environment and then verified, without the need for conflict detection.

[0046] When the target project environment has already been manually configured with some role permissions (i.e., the source project permission adaptation import method is only used after the administrator has configured to a certain extent), or when the administrator has specifically pre-configured unique permissions for the target project environment, these basic permission rules are obtained.

[0047] Reference Figure 5 The flowchart illustrating the conflict resolution and permission writing method includes the following steps: "After resolving conflicts between the basic permission rules and the identifiable role permission rules, the configuration is written to the target project environment to form a unique role permission configuration": S61: Perform conflict detection between the identifiable role permission rules and the basic permission rules, and execute the corresponding conflict resolution strategy according to the detected conflict type and severity to obtain the permission rules after conflict resolution; S62: Write the conflict-free permission rules into the target project environment and verify them to form a role and permission configuration specific to the target project environment.

[0048] In S61, during the source project permission adaptation import process, the identifiable role permission rules are the permission rules to be imported, and conflict detection is performed between them and the basic permission rules of the target project environment. For each permission rule to be imported, its triples are matched against the triples of each rule in the basic permission rules; if an existing rule with a completely matching triple is found and the permission values ​​(i.e., allowed or prohibited status) of the two rules are different, it is determined to be an overriding conflict; if the permission combination of two permission rules violates the predefined mutual exclusion rule table (e.g., "data deletion" and "read-only" are mutually exclusive), it is determined to be a mutual exclusion conflict; if the resource corresponding to the resource identifier in the permission rule to be imported does not exist in the target project environment, it is determined to be a dependency conflict.

[0049] For each detected conflict, the permission importance configuration table is queried based on the type of permission item involved to obtain the permission importance weight. If the weight is greater than or equal to the first threshold, the severity is high; if the weight is between the first and second thresholds, the severity is medium; and if the weight is less than or equal to the second threshold, the severity is low. The preset conflict type-policy mapping table is then queried based on the conflict type and severity to obtain the corresponding conflict resolution policy: for overriding conflicts with low severity, the imported permission overwrites the existing permission; for mutually exclusive conflicts, administrator confirmation is requested; for dependency conflicts, existing permissions are retained and the differences are recorded; for overriding conflicts with high severity and requiring manual confirmation, a conflict details report is generated and sent to the administrator for approval. The administrator can then choose to accept the overriding, retain the existing permission, manually merge the conflict, or cancel the import, resulting in the permission rules after conflict resolution.

[0050] In S62, the conflict-resolved permission rules are written to the target project environment. After writing, the imported permission configuration undergoes integrity, consistency, and reachability verification. Integrity verification checks if all permission rules to be imported have been successfully written; consistency verification checks for logical contradictions between permission rules; and reachability verification checks if the resources referenced by the permission rules are accessible in the target project environment. Upon successful verification, an audit log is generated, recording the operator, operation time, source project environment, target project environment, number of copied permission rules, mapping statistics, and conflict resolution results, forming a role-permission configuration specific to the target project environment.

[0051] In S7, a role template library is pre-defined, containing several standard role templates. Each role template has a predefined set of standard permission rules and is labeled with the applicable environment type. When no source project environment with configured role permissions that matches the target project environment does not exist, a matching set of candidate role templates is retrieved from the role template library based on the characteristic information of the target project environment. For each candidate template in the set, its compatibility score with the target project environment is calculated based on a multi-dimensional matching algorithm. This multi-dimensional matching algorithm comprehensively considers factors such as project type matching weight, permission coverage, and historical usage frequency, and calculates the compatibility score by weighting and summing the scores of each dimension. The templates are then sorted from high to low according to their compatibility scores, and the role template with the highest compatibility score is selected as the role template that matches the target project environment.

[0052] In S8, refer to Figure 6 The flowchart illustrating the role template instantiation and permission fine-tuning method shows that "instantiating the role template and fine-tuning permissions under constraints to generate the role permission configuration for the target project environment" includes the following steps: S81: Parse the permission rules and constraints contained in the role template, and generate role instances based on the permission rules; S82: Display the adjustable permission items in the role instance, monitor the administrator's modification operations on the adjustable permission items, and use the constraint propagation algorithm to determine whether the modification operation meets the constraint conditions; if not, execute S83; if it meets the constraint conditions, execute S84. S83: Generate and display a revised solution for adjustable permission items; S84: Update role instances based on the modified adjustable permission items to form the role permission configuration for the target project environment.

[0053] In S81, the permission rule set defines the standard permission items contained in the template, and the constraint set defines the dependency, mutual exclusion and implication relationships between permission items. An initial role instance is generated based on the permission rule set, which contains all the permission items defined in the template and their default states.

[0054] In S82, the role template also includes an adjustable parameter set, which is used to identify the permission items that can be adjusted when the template is instantiated. It identifies the permission items marked as adjustable in the role instance, generates a fine-tuning configuration interface, and displays the adjustable permission items and their current status to the administrator, so that the administrator can modify them according to the actual needs of the target project environment.

[0055] Reference Figure 7 The flowchart illustrating the method for determining whether constraints are met includes the following steps: "Using the constraint propagation algorithm to determine whether a modification operation meets constraints": S821: Construct a permission dependency graph based on constraints. The nodes of the permission dependency graph are permission items, and the edges between the nodes are the constraint relationships between the permission items. S822: Starting from the modified adjustable permission item, determine the associated permission items along the permission dependency graph and obtain the impact value of the state change of the associated permission items; S823: Based on the impact value of the state change and the current state of the associated permission item, determine whether the modification operation meets the constraints.

[0056] In S821, for a permission dependency graph, each edge contains three attributes: constraint type, constraint strength, and propagation direction. The constraint type includes dependency constraints, mutual exclusion constraints, and implied constraints. The constraint strength is used to distinguish between mandatory constraints and advisory constraints. The propagation direction is used to indicate whether the influence is transmitted unidirectionally or bidirectionally.

[0057] In S822, when a user modifies the state of an adjustable permission item, a breadth-first traversal is performed along the edge direction of the permission dependency graph, starting with the modified permission item. The associated permission items are determined layer by layer, and the impact value of the state change of each associated permission item is calculated.

[0058] First, calculate the state change of the modified permission item, which is the state value after modification minus the state value before modification. The value of the state change ranges from -1 (closed), 0 (unchanged), and 1 (open). The calculation method for the impact value is determined based on the constraint type between the current permission item and related permission items. If it is a dependency constraint, it means that if the current permission item is closed, the related permission item must be closed, and the impact value propagates in the same direction as the modification direction, i.e., the state change of the current permission item multiplied by the constraint strength. If it is a mutual exclusion constraint, it means that the two permission items cannot be opened simultaneously, and the impact value propagates in the opposite direction as the modification direction, i.e., a negative state change of the current permission item multiplied by the constraint strength. If it is an implicit constraint, it means that if the current permission item is opened, the related permission item automatically follows suit, and the impact value propagates in the same direction as the modification direction, i.e., the state change of the current permission item multiplied by the constraint strength. The constraint strength ranges from zero to one, with one indicating a mandatory constraint and below a preset threshold indicating a suggested constraint.

[0059] If an associated permission item has multiple incoming edges, meaning multiple permission items impose constraints on it, then the influence values ​​of each edge are weighted and summed according to the constraint strength, and the result is truncated to between -1 and +1. Associated permission items with non-zero influence values ​​are added to the influence set, and these associated permission items serve as new starting points to continue propagating outward along the permission dependency graph until the influence set no longer expands, meaning no new associated permission items are added.

[0060] In S823, each associated permission item in the influence set is traversed. If the influence value of the associated permission item is positive, it means that the constraint requires the permission item to be enabled, but the current state of the permission item is disabled. In this case, it is determined that the associated permission item has a constraint violation, and the violation amount is equal to the influence value. If the influence value is negative, it means that the constraint requires the permission item to be disabled, but the current state of the permission item is enabled. In this case, it is determined that the associated permission item has a constraint violation, and the violation amount is equal to the absolute value of the influence value.

[0061] The violation amount of each violated associated permission item is weighted and summed with its corresponding constraint strength to obtain a comprehensive violation score. If the comprehensive violation score is greater than zero and the strength of the corresponding constraint edge reaches or exceeds the preset mandatory constraint threshold, the current modification operation is determined to violate the mandatory constraint, triggering the subsequent correction process; if the strength of the corresponding constraint edge is lower than the mandatory constraint threshold, it is determined to violate the suggested constraint, only generating a warning prompt without blocking the operation.

[0062] When a violation of a mandatory constraint is determined, based on the set of impacts and the details of the violation, and with the minimum number of state changes as the optimization objective, the minimum combination of permission state adjustments required to bring the overall violation score to zero is calculated for all related permission items that violate the constraint. This forms a list of correction schemes, each of which includes the permission items to be adjusted, the adjusted state, and an explanation of the scope of impact, for users to choose from. The corrected permission dependency subgraph is also displayed to help users understand the logical relationships between permissions.

[0063] In S83, when an administrator's modification operation is detected to violate mandatory constraints, the minimum number of state changes is used as the optimization objective. The minimum combination of permission state adjustments required to bring the overall violation score to zero is calculated for all related permission items that violate the constraints. This forms a list of at least one correction scheme. Each correction scheme includes the permission items to be adjusted, the adjusted state, and a description of the scope of impact. The correction scheme is displayed on the interface for the administrator to choose from. When an administrator's modification operation is detected to violate suggested constraints, only an alert is generated, without blocking the administrator's modification operation.

[0064] In S84, after the administrator completes the modification of all adjustable permission items and all modifications pass the constraint validation, the status of the corresponding permission items in the role instance is updated according to the administrator's modification operation. The updated role instance is written to the target project environment, and audit information such as template source, fine-tuning content and operator is recorded to form the role permission configuration of the target project environment.

[0065] The embodiments of this disclosure use a constraint propagation algorithm to verify permission modification operations in real time, automatically detect and block logical conflicts caused by permission modifications, and ensure that the fine-tuned permission configuration always meets the preset constraint conditions, thus satisfying the personalized needs of the target project environment while ensuring the compliance of permission configuration.

[0066] Reference Figure 8 This disclosure provides a role-based access control (RBAC) system, including: The judgment module 101 is used to obtain the feature information of the target project environment, and based on the feature information, to determine whether there is a source project environment with configured role permissions that is compatible with the target project environment; if it exists, the detection module 102 is executed; if it does not exist, the selection module 107 is executed. The detection module 102 is used to obtain the permission configuration list of the source project environment, detect the source project resources that are bound to the permission configuration of the specified role in the permission configuration list, and obtain the source project resource identifier. Replacement module 103 is used to replace the source project resource identifier with a resource semantic tag that is common to project resources; Module 104 is established to obtain the resource list of the target project environment, perform feature matching between the resource semantic tags and the target project resources in the resource list, and establish a mapping relationship between the resource semantic tags and the target project resources. The conversion module 105 is used to convert the permission configuration in the permission configuration list into role permission rules that can be recognized by the target project environment based on the mapping relationship. The writing module 106 is used to write the basic permission rules and the identifiable role permission rules into the target project environment to form a unique role permission configuration when the target project environment has basic permission rules. Select module 107, used to select a character template that matches the target project environment from the preset character template library; The fine-tuning module 108 is used to instantiate the role template and fine-tune permissions under constraints to generate the role permission configuration for the target project environment.

[0067] The various variations and specific examples of the role permission configuration method provided above are also applicable to the role permission configuration system provided in this disclosure. Through the foregoing detailed description of the role permission configuration method, those skilled in the art can clearly understand the implementation method of the role permission configuration system. For the sake of brevity, they will not be described in detail here.

[0068] A computer device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc.

[0069] The processor may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of this disclosure, the processor is used to execute computer-readable instructions stored in the memory, causing the computer device to perform all or part of the steps of the role and permission configuration methods described in the foregoing embodiments of this disclosure.

[0070] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.

[0071] like Figure 9 This is a schematic diagram of a computer device provided for an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the computer device in the embodiments of the present disclosure. Figure 9 The computer device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0072] like Figure 9 As shown, a computer device may include a processor (such as a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from storage devices into random access memory (RAM). The RAM also stores various programs and data required for the operation of the computer device. The processor, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0073] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 9 A computer apparatus with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or included alternatively.

[0074] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the role and permission configuration method of embodiments of this disclosure are performed.

[0075] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0076] A computer-readable storage medium according to embodiments of the present disclosure stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the role and permission configuration methods described in the foregoing embodiments of the present disclosure are performed.

[0077] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0078] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0079] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0080] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.

[0081] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.

[0082] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0083] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0084] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0085] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A method for configuring role permissions, characterized in that, include: Obtain the characteristic information of the target project environment, and based on the characteristic information, determine whether there is a source project environment with configured role permissions that is compatible with the target project environment; If it exists, obtain the permission configuration list of the source project environment, detect the source project resources that are bound to the permission configuration of the specified role in the permission configuration list, and obtain the source project resource identifier; Replace the source project resource identifier with a resource semantic tag that is common to project resources; Obtain a resource list of the target project environment, perform feature matching between the resource semantic tags and the target project resources in the resource list, and establish a mapping relationship between the resource semantic tags and the target project resources; Based on the mapping relationship, the permission configuration in the permission configuration list is converted into role permission rules that can be recognized by the target project environment; When the target project environment has basic permission rules, the conflict between the basic permission rules and the identifiable role permission rules is eliminated and then written into the target project environment to form a unique role permission configuration. If not found, a character template matching the target project environment will be selected from the preset character template library; The role template is instantiated and its permissions are fine-tuned under constraints to generate the role permission configuration for the target project environment.

2. The role permission configuration method according to claim 1, characterized in that, The step of replacing the source project resource identifier with a resource semantic tag common to project resources includes: Construct a resource mapping table and match the source project resource identifiers in the permission configuration list with the source project resource identifiers in the resource mapping table; If a match is found, the corresponding resource semantic tag is extracted from the resource mapping table; If the matching fails, the resource type and business semantic tag of the source project resource are obtained, and the resource type and the business semantic tag are concatenated to form a resource semantic tag that is common to the project resources. Replace the source project resource identifier in the permission configuration list with the resource semantic tag.

3. The role permission configuration method according to claim 2, characterized in that, The step of performing feature matching between the resource semantic tags and target project resources in the resource list to establish a mapping relationship between the resource semantic tags and the target project resources includes: Based on the resource type in the resource semantic tags, target project resources of the same resource type are selected from the resource list; The business semantic tags in the resource semantic tags are matched with the target project resources of the same resource type to obtain similarity scores; Based on the similarity score, the target project resource that is closest to the resource semantic tag is identified and a mapping relationship is constructed.

4. The role permission configuration method according to claim 1, characterized in that, The process of converting the permission configurations in the permission configuration list into role permission rules recognizable by the target project environment based on the mapping relationship includes: Based on the mapping relationship between the resource semantic tags and the target project resources, the resource semantic tags bound to the permission configuration in the permission configuration list are replaced with the corresponding target project resource identifiers; The permission configuration and the corresponding target project resource identifier are converted into a triplet format permission containing role, resource operation permission and target project resource identifier. The triplet format permission is a role permission rule that can be recognized by the target project environment.

5. The role permission configuration method according to claim 1, characterized in that, The step of eliminating conflicts between the basic permission rules and the identifiable role permission rules and then writing them into the target project environment to form a unique role permission configuration includes: The identifiable role permission rules are subjected to conflict detection with the basic permission rules. The corresponding conflict resolution strategy is executed according to the detected conflict type and the severity of the conflict to obtain the permission rules after conflict resolution. Write the conflict-free permission rules into the target project environment and verify them to form a role and permission configuration specific to the target project environment.

6. The role permission configuration method according to claim 1, characterized in that, The step of instantiating the role template and fine-tuning permissions under constraints to generate the role permission configuration for the target project environment includes: The permission rules and constraints contained in the role template are parsed, and a role instance is generated based on the permission rules; Display the adjustable permission items in the role instance, monitor the administrator's modification operation on the adjustable permission items, and use the constraint propagation algorithm to determine whether the modification operation meets the constraint conditions; If the conditions are not met, corresponding feedback information is generated based on the type of constraint. If satisfied, the role instance is updated based on the modified adjustable permission items to form the role permission configuration for the target project environment.

7. The role permission configuration method according to claim 6, characterized in that, The step of using a constraint propagation algorithm to determine whether the modification operation satisfies the constraint conditions includes: A permission dependency graph is constructed based on the aforementioned constraints. The nodes of the permission dependency graph are permission items, and the edges between the nodes represent the constraint relationships between the permission items. Starting from the modified adjustable permission item, determine the associated permission item along the permission dependency graph, and obtain the state change impact value of the associated permission item; Based on the impact value of the state change and the current state of the associated permission item, determine whether the modification operation satisfies the constraint conditions.

8. A computer device, characterized in that, The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the role permission configuration method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the role and permission configuration method as described in any one of claims 1-7.

10. A computer program product comprising computer instructions, characterized in that, When executed by a processor, the computer instructions implement the steps of the role and permission configuration method according to any one of claims 1-7.