Electronic device for performing data caching based on user data permissions and operating method thereof
The electronic device addresses the challenges of user-level caching by generating a token for managing user data permissions and determining the appropriate cache type based on user permissions, ensuring secure and efficient data caching.
Patent Information
- Application Number
- PCT/KR2024/016339
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-10-24
- Publication Date
- 2025-06-19
AI Technical Summary
As the number of users increases, user-level caching in data processing systems can lead to various problems, including inefficient data retrieval and security concerns due to differing user authorities.
An electronic device generates a token for managing user data permissions and determines the available cache type by performing a dry run on the query, using the token, security information, specific function information, and type of token to decide between user, group, or shared caching.
This approach ensures secure and efficient data caching by accurately determining the appropriate cache type based on user permissions, thereby optimizing data retrieval and maintaining system security.
Smart Images

Figure KR2024016339_19062025_PF_FP_ABST
Abstract
Description
Electronic device performing data caching based on user data permissions and method of operation thereof
[0001] Various embodiments relate to an electronic device and a method of operating the same for performing data caching based on user data permissions.
[0002] Data caching technology is a technology that provides a quick response by storing the results of data processing requests in the form of keys and values and providing previously obtained results for the same data processing request.
[0003] Queries are typically used extensively for data processing requests. Systems that manage data based on permissions support user-level caching, as each user has different permissions. However, this user-level caching can lead to various issues as the number of users increases.
[0004] According to one embodiment, an electronic device may include one or more processors (120) and one or more memories (130) that store instructions executable by the one or more processors (120). When at least some of the instructions stored in the one or more memories (130) are executed by the one or more processors (120), at least some of the executed instructions may control the electronic device (101) (or the one or more processors (120)) to perform the following operations. The electronic device (101) may generate a token for managing data permissions of a user who has requested a query. The electronic device (101) may determine a cache type available to the user using the query and the token. The electronic device (101) may request cache data corresponding to the execution result of the query based on the determined cache type.
[0005] According to one embodiment, an operating method of an electronic device may include an operation in which the electronic device (101) generates a token for managing data permissions of a user who has requested a query. The operating method of the electronic device may include an operation in which the electronic device (101) determines a cache type available to the user using the query and the token. The operating method of the electronic device may include an operation in which the electronic device (101) requests cache data corresponding to an execution result of the query based on the determined cache type. The operation in which the cache type is determined may include an operation in which a dry run is performed on the query to obtain job information about the query. The operation in which the cache type is determined may include an operation in which the type of cache available to the user is determined as at least one of a user cache, a group cache, or a shared cache based on security information included in the job information, specific function information included in the query, and a type of token.
[0006] According to one embodiment, instructions recorded on a computer-readable recording medium, when executed by one or more processors, can cause the electronic device to perform operations of a method of operating the electronic device.
[0007] FIG. 1 is a block diagram of an electronic device within a network environment according to one embodiment.
[0008] FIG. 2 is a diagram illustrating the overall configuration of an electronic device that performs data caching according to a user's data permissions according to one embodiment.
[0009] FIG. 3 is a diagram illustrating a method for performing data caching according to a user's data permissions according to one embodiment.
[0010] FIG. 4 is a flowchart illustrating detailed operations of a cache type manager according to one embodiment.
[0011] FIG. 5 is a flowchart illustrating an operation method when a user's available cache is a shared cache according to one embodiment.
[0012] Hereinafter, embodiments will be described in detail with reference to the attached drawings. In the description with reference to the attached drawings, identical components are assigned the same reference numerals regardless of the drawing numbers, and redundant descriptions thereof will be omitted.
[0013] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with the electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of the electronic device (104) or the server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).
[0014] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or operations. According to one embodiment, as at least a part of the data processing or operations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). The processor (120) may also be implemented as a system on chip (SoC) or an integrated circuit (IC) that performs processing. The processor (510) may include one or more processors, and the operations of the electronic device (101) described in the present disclosure may be performed by a single processor or by a combination of multiple processors. When the operations of the electronic device (101) are performed by a combination of multiple processors, any one processor included in the combination of processors may perform some of the operations of the electronic device (101).
[0015] According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) (e.g., a graphics processing unit (GPU), a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together with the main processor (121). For example, when the electronic device (101) includes the main processor (121) and the auxiliary processor (123), the auxiliary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a given function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as a part thereof.
[0016] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0017] The memory (130) can store various data used by at least one component (e.g., the processor (120) or the sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., the program (140)) and input data or output data for commands related thereto. The memory (130) can include a volatile memory (132) or a non-volatile memory (134). The memory (130) can store at least one instruction executable by the processor (120). The memory (130) can include one or more memories, and instructions for controlling the processor (120) to perform operations of the electronic device (101) described in the present disclosure can be stored in one memory or can be divided and stored in multiple memories.
[0018] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).
[0019] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0020] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.
[0021] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0022] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).
[0023] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0024] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0025] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0026] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
[0027] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.
[0028] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).
[0029] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0030] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).
[0031] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.
[0032] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197). In an embodiment, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent to a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.
[0033] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0034] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
[0035] Electronic devices according to the embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments disclosed in this document are not limited to the aforementioned devices.
[0036] The embodiments of this document and the terminology used herein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0037] The term "module" used in the embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0038] Embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0039] According to one embodiment, the method according to the embodiments disclosed in the present document may be provided as a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smart phones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0040] According to embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to embodiments, operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
[0041]
[0042] FIG. 2 is a diagram illustrating the overall configuration of an electronic device that performs data caching according to a user's data permissions according to one embodiment.
[0043] Referring to FIG. 2, one or more processors (e.g., processor (120) of FIG. 1) included in an electronic device (e.g., electronic device (101) of FIG. 1) can control the operation of a service (210), a query engine (220), a cache type manager (230), a cache store (240), and an identity and access management (IAM) system (250) to perform data caching according to a user's data authority.
[0044] The service (210) may refer to a client or server that uses the query engine (220). When a query is requested from a user, the service (210) may transmit a token for managing the user's data authority along with the query to the cache type manager (230) to determine what type of cache the user can use. Once the cache type that the user can use is identified, the service (210) may request a result for the query from the cache store (240) based on the identified cache type. If the result for the query does not exist in the cache store (240), the service (210) may request the query from the query engine (220).
[0045] The query engine (220) may utilize a permission management system (250) to determine a user's data permissions. The query engine (220) may determine whether to perform a query requested by a user based on the user's data permissions determined by the permission management system (250). The query engine (220) may support row-level security, column-level security, or dry-run. For example, the query engine (220) may exist in GCP (BigQuery) or Azure (Synapse Analytics), but the types of such query engines (220) are merely examples and are not limited to the above examples.
[0046] The cache type manager (230) can determine the type of cache available to the user as at least one of a user cache, a group cache, and a shared cache. To this end, the cache type manager (230) can include at least one checker among a dry-run checker, a security checker, a function-query checker, and a user-group checker.
[0047] The dry run checker can acquire permissions and information about a query by executing a dry run or query plan with the query engine (220) to check the data permissions of the user for the query requested by the user. If the permissions of the user for the query are valid and the query is valid, the dry run checker can acquire information about the successfully executed dry run or query plan from the query engine (220). At this time, the unit in which the query is executed by the query engine (220) can be displayed as a job, and information about the job can be displayed as job information. Such job information can include security information about the data (e.g., a table) referenced by the query.
[0048] The security checker can perform a function of determining the operation information received from the query engine (220) when a dry run or query plan executed by the query engine (220) is successfully executed. More specifically, the security checker can determine whether row-level security is applied to a table referenced by the query based on the security information included in the operation information. Row-level security has the characteristic of having specific user-specific permissions per row, resulting in different query execution results for each user. Therefore, if row-level security is applied to a table referenced by the query, the security checker can determine the available cache for the user as the user cache.
[0049] Alternatively, the security checker can determine whether the table referenced by the query has been masked based on the security information contained in the operation information. If the table referenced by the query has been masked, the security checker can determine the user's available cache as the user cache.
[0050] Additionally, the security checker can determine the available cache for a user by judging special cases where data permissions for the user are distinguished after a dry run according to the query engine (220).
[0051] The function-query checker can determine whether a Structured Query Language (SQL) statement corresponding to a query received from the service (210) contains specific function information. If the SQL statement contains specific function information, the function-query checker can determine the available cache for the user as the user cache.
[0052] At this time, specific function information may include a time-related function that changes for each operation. In addition, specific function information may include a universally unique identifier (UUID) generation function, a random value generation function, or a current user identification function. Such specific function information may vary depending on the characteristics supported by each query engine (220).
[0053] For example, specific function information may include the following functions, which are commonly used nondeterministic functions:
[0054] (i)CURRENT_DATE: A function that returns the current time in Date format.
[0055] (ii)CURRENT_DATETIME: A function that returns the current time in DateTime format.
[0056] (iii)CURRENT_TIME: A function that returns the current time in Time format.
[0057] (iv)CURRENT_TIMESTAMP: A function that returns the current time in timestamp format.
[0058] (v)GENERATE_UUID: A function that randomly generates a UUID.
[0059] (vi)RAND: A function that generates random values
[0060] (vii)SESSION_USER: Function to get the current user
[0061] (viii)ST_GEOGPOINT: A function that creates a point used in geography.
[0062] However, the functions included in the specific function information as above are only an example and are not limited to the above example.
[0063] The user-group checker can determine whether the token received from the service (210) is a token of a specific group. If the user-group checker determines that the token is a token of a specific group, the user-group checker can determine the available cache for the user as a group cache. The decision logic of such a group cache can determine whether to use it or not according to a group usage policy. In general, the user-group checker can receive group information from the authority management system (250) and process the decision logic of the group cache, and can also process the decision logic of the group cache using a group-related mapping table stored internally in the service (210).
[0064] The cache store (240) stores the execution result of a query derived through the query engine (220) as cache data, and when cache data is requested from the service (210), the cache store (240) can provide the requested cache data to the service (210). For example, the cache store (240) may be Redis (Remote Dictionary Storage) or Memcached, but the type of the cache store (240) is only one example and is not limited to the above example.
[0065] More specifically, the cache store (240) may determine and store cache data as at least one of a shared cache, a user cache, and a group cache. The shared cache may include cache data that can be commonly used by all users. At this time, the shared cache may use a query statement as a key value, and the query execution result may be stored as a value value. The user cache may include cache data that can be exclusively used by individual users. At this time, the user cache may use a query statement and user identification information as key values, and the query execution result may be stored as a value value. The group cache may include cache data that can be commonly used by users of a specific group. At this time, the group cache may use a query statement and group identification information as key values, and the query execution result may be stored as a value value.
[0066] The authorization management system (250) can identify, based on the token received from the service (210), whether the token represents data authorization for a specific user or a token represents data authorization for a specific group.
[0067] According to one embodiment, the electronic device (101) may include one or more processors (120) and one or more memories (130) that store instructions executable by the one or more processors (120). When at least some of the instructions stored in the one or more memories (130) are executed by the one or more processors (120), at least some of the executed instructions may control the electronic device (101) (or the one or more processors (120)) to perform the following operations.
[0068] According to one embodiment, the electronic device (101) can generate a token to manage the data permissions of a user who has requested a query. The electronic device (101) can use the query and the token to determine the cache type available to the user. Based on the determined cache type, the electronic device (101) can request cache data corresponding to the query execution result.
[0069] In one embodiment, the operation of determining the cache type may include performing a dry run on a query to receive job information for the query. The operation of determining the cache type may determine the user's available cache type as at least one of a user cache, a group cache, or a shared cache based on security information included in the job information, specific function information included in the query, and the type of token.
[0070] In one embodiment, the operation of determining the cache type may identify whether the table referenced by the query is a table with row-level security based on security information included in the operation information. If the table referenced by the query is identified as a table with row-level security, the operation of determining the cache type may determine the user's available cache as a user cache.
[0071] In one embodiment, the operation of determining the cache type may identify whether masking has been applied to the table referenced by the query based on security information included in the operation information. If masking has been applied to the table referenced by the query, the operation of determining the cache type may determine the user's available cache as a user cache.
[0072] In one embodiment, the operation of determining the cache type may identify whether the token used to manage the user's data permissions is a token belonging to a specific group. If the token is identified as belonging to a specific group, the operation of determining the cache type may determine the user's available cache as a group cache.
[0073] In one embodiment, the operation of determining the cache type may identify whether a Structured Query Language (SQL) statement corresponding to the query includes specific function information. If the SQL statement is identified as including specific function information, the operation of determining the cache type may determine the user's available cache as a user cache.
[0074] According to one embodiment, the specific function information may include at least one of a time-related function using the current time, a universally unique identifier (UUID) generation function, a random value generation function, or a current user identification function.
[0075] According to one embodiment, the operation of determining the cache type may determine the user's available cache as a shared cache if the cache type determined based on security information included in the task information, specific function information included in the query, and the type of token is not a user cache or a group cache.
[0076]
[0077] FIG. 3 is a diagram illustrating a method for performing data caching based on a user's data permissions according to one embodiment. In one embodiment, at least one of the operations illustrated in FIG. 3 may be performed concurrently or in parallel with other operations, and the order of the operations may be changed. Furthermore, at least one of the operations may be omitted, and other operations may be additionally performed. The operations illustrated in FIG. 3 may be performed by at least one component of an electronic device (e.g., the electronic device (101) of FIG. 1 ).
[0078] In operation (310), the electronic device (101) may generate a token for managing the data permissions of the user who requested the query. In operation (320), the electronic device (101) may determine the types of caches available to the user using the query and the token. In operation (330), the electronic device (101) may request cache data corresponding to the execution result of the query based on the determined cache type.
[0079] In one embodiment, the operation of determining the cache type may include performing a dry run on a query to obtain job information for the query. The operation of determining the cache type may determine the user's available cache type as at least one of a user cache, a group cache, or a shared cache based on security information included in the job information, specific function information included in the query, and the type of token.
[0080] In one embodiment, the operation of determining the cache type may identify whether the table referenced by the query is a table with row-level security based on security information included in the operation information. If the table referenced by the query is identified as a table with row-level security, the operation of determining the cache type may determine the user's available cache as a user cache.
[0081] In one embodiment, the operation of determining the cache type may identify whether masking has been applied to the table referenced by the query based on security information included in the operation information. If masking has been applied to the table referenced by the query, the operation of determining the cache type may determine the user's available cache as a user cache.
[0082] In one embodiment, the operation of determining the cache type may identify whether the token used to manage the user's data permissions is a token belonging to a specific group. If the token is identified as belonging to a specific group, the operation of determining the cache type may determine the user's available cache as a group cache.
[0083] In one embodiment, the operation of determining the cache type may identify whether a Structured Query Language (SQL) statement corresponding to the query includes specific function information. If the SQL statement is identified as including specific function information, the operation of determining the cache type may determine the user's available cache as a user cache.
[0084] According to one embodiment, the specific function information may include at least one of a time-related function using the current time, a universally unique identifier (UUID) generation function, a random value generation function, or a current user identification function.
[0085] According to one embodiment, the operation of determining the cache type may determine the user's available cache as a shared cache if the cache type determined based on security information included in the task information, specific function information included in the query, and the type of token is not a user cache or a group cache.
[0086]
[0087] FIG. 4 is a flowchart illustrating detailed operations of a cache type manager according to one embodiment. In one embodiment, at least one of the operations illustrated in FIG. 4 may be performed concurrently or in parallel with other operations, and the order of the operations may be changed. Furthermore, at least one of the operations may be omitted, and other operations may be additionally performed. The operations illustrated in FIG. 4 may be performed by at least one component of an electronic device (e.g., the electronic device (101) of FIG. 1 ).
[0088] Referring to FIG. 4, when a query requested by a user is received, the service (401) can transmit (422) a request for a cache type to the cache type manager (403). At this time, the service (401) can transmit a token for managing the data authority of the user to the cache type manager (403) together with the received user's query. For example, if the user requesting the query is an individual user, the service (401) can transmit a user token to the cache type manager (403). Conversely, if the user requesting the query is a user included in a specific group, the service (401) can transmit a group token to the cache type manager (403).
[0089] The cache type manager (403) can send (424) a request for a dry run to the dry run checker (405). When a request for a dry run is received, the dry run checker (405) can perform (426) a dry run on the query to the query engine (413). At this time, if the dry run is successful, the query engine (413) can respond (428) with job information to the dry run checker (405). Alternatively, if the query is invalid or the user's data authority for the table referenced by the query is invalid, the query engine (413) can return (428) an error message corresponding to the failure to the dry run checker (405). The dry run checker (405) can transmit (430) the result of performing such a dry run to the cache type manager (403). At this time, if the cache type manager (403) identifies that the dry run has failed based on the execution result, it can transmit the execution result of the dry run related to the failure to the service (401).
[0090] In contrast, when the dry run is successful and the work information is received from the query engine (413), the cache type manager (403) can request the user-group checker (411) to determine (432) whether the token received from the service (401) is a token of a specific group. The user-group checker (411) can determine (434) whether the token received from the service (401) is a token of a specific group based on the token received from the service (401) and transmit (436) the determination result to the cache type manager (403). At this time, when the cache type manager (403) identifies that the token received from the service (401) is a token of a specific group based on the determination result, the cache type manager (403) can determine the available cache of the user as a group cache and then transmit the determined cache type to the service (401).
[0091] In contrast, if it is determined that the token received from the service (401) is not a token of a specific group, the cache type manager (403) may request (438) a judgment on security information from the security checker (407). The security checker (407) may determine (440) whether the table referenced by the query is a table to which row-level security is applied based on the security information included in the work information, and may transmit (442) the judgment result to the cache type manager (403). At this time, if the cache type manager (403) identifies that the table referenced by the query is a table to which row-level security is applied based on the judgment result, the cache type manager (403) may determine the available cache of the corresponding user as a user cache and then transmit the determined cache type to the service (401).
[0092] Alternatively, the security checker (407) may determine (440) whether masking has been applied to the table referenced by the query based on the security information included in the work information, and may transmit (442) the determination result to the cache type manager (403). At this time, if the cache type manager (403) identifies that masking has been applied to the table referenced by the query based on the determination result, the cache type manager (403) may determine the available cache of the user as a user cache and then transmit the determined cache type to the service (401).
[0093] In contrast, if the judgment result on the security information determines that the available cache of the corresponding user is not a user cache, the cache type manager (403) may request the function-query checker (409) to determine (444) whether specific function information is included in the SQL (Structured Query Language) statement corresponding to the query received from the service (401). The function-query checker (409) may determine (446) whether specific function information is included in the SQL statement and transmit (448) the judgment result to the cache type manager (403). At this time, if the cache type manager (403) identifies that the SQL statement includes specific function information based on the judgment result, the cache type manager (403) may determine the available cache of the corresponding user as a user cache and then transmit the determined cache type to the service (401).
[0094] In contrast, if the cache type determined based on the security information included in the work information, the specific function information included in the query, and the type of token is not a user cache or a group cache, the cache type manager (403) may determine the available cache of the user as a shared cache and then transmit (450) the determined cache type to the service (401).
[0095]
[0096] FIG. 5 is a flowchart illustrating an operation method when a user's available cache is a shared cache according to one embodiment.
[0097] In one embodiment, at least one of the operations illustrated in FIG. 5 may be performed concurrently or in parallel with other operations, and the order of the operations may be changed. Furthermore, at least one of the operations may be omitted, and other operations may be additionally performed. The operations illustrated in FIG. 5 may be performed by at least one component of an electronic device (e.g., the electronic device (101) illustrated in FIG. 1 ).
[0098] When a first user (e.g., User A in FIG. 5) requests a query (502) to a service, the service can request a cache type (504) from a cache type manager. The cache type manager can perform a dry run (506) on the query with a query engine. The query engine can check (508) data permissions for the tables referenced by the query through an authorization management system (IAM).
[0099] The cache type manager can return (510) the shared cache, which is the user's available cache determined according to the cache type determination logic, to the service, and the service can request (512) cache data corresponding to the query execution result from the cache store using the query statement as the key value. However, in the given example, an error message corresponding to a failure may be received by the service because the key value does not exist. Since the service does not have cache data corresponding to the query in the cache store, the service can request (514) a query from the query engine. The query engine can check (516) the data permissions for the table referenced by the query through the authorization management system (IAM) and execute the query if the permissions are determined to be valid (518). The query engine can transmit (520) the query execution result to the service, and the service can store (522) the query execution result received from the query engine in the cache store. At this time, since the user's available cache is the shared cache, the cache store can use the query statement as the key value and store the query execution result as the value value.
[0100] Meanwhile, if a new second user (e.g., User B in FIG. 5) requests the same query as the first user (524), the service can request the cache type from the cache type manager (526). The cache type manager can perform a dry run on the query with the query engine (528). The query engine can check (530) the permissions on the table referenced by the query through the authorization management system (IAM).
[0101] The cache type manager can return (532) a shared cache, which is a user's available cache determined based on the cache type determination logic, to the service, and the service can request (534) cache data corresponding to the query execution result from the cache store using the query statement as a key value. In this case, the cache store can respond with a value (query execution result) corresponding to the key value requested from the service based on the expiration time of the cache data if the previously stored cache data is before the expiration time.
[0102]
[0103] The embodiments of the present invention disclosed in this specification and drawings are merely specific examples presented to easily explain the technical contents according to the embodiments of the present invention and to help understand the embodiments of the present invention, and are not intended to limit the scope of the embodiments of the present invention. Therefore, the scope of the embodiments of the present invention should be interpreted as including all changes or modified forms derived based on the technical idea of the embodiments of the present invention in addition to the embodiments disclosed herein.
Claims
1. In an electronic device (101), one or more processors (120); and comprising one or more memories (130) storing instructions executable by the one or more processors (120); When at least some of the instructions stored in the one or more memories (130) are executed by the one or more processors (120), at least some of the instructions being executed cause the electronic device (101) to: An action to generate a token to manage the data permissions of the user who requested the query; An operation of determining a cache type available to the user using the above query and the above token; and An action of requesting cache data corresponding to the execution result of the query based on the cache type determined above. Control to perform, The action to determine the above cache type is: An action to obtain job information for the above query by executing a dry run for the above query; and An operation of determining the type of cache available to the user as at least one of a user cache, a group cache, or a shared cache based on the security information included in the above work information, specific function information included in the above query, and the type of the token. An electronic device (101) comprising:
2. In paragraph 1, The action to determine the above cache type is: An operation for identifying whether the table referenced by the query is a table to which row-level security is applied based on the security information included in the above work information; and If the table referenced by the above query is identified as a table with row-level security applied, the action of determining the available cache for the user as the user cache. An electronic device (101) comprising:
3. In any one of paragraphs 1 and 2, The action to determine the above cache type is: An operation for identifying whether masking has been applied to a table referenced by the query based on security information included in the above work information; and If masking is applied to the table referenced by the above query, the action of determining the available cache for the user as the user cache. An electronic device (101) comprising:
4. In any one of paragraphs 1 to 3, The action to determine the above cache type is: An action to identify whether the token for managing the data rights of the above user is a token of a specific group; and If the above token is identified as a token of a specific group, an action is taken to determine the user's available cache as the group cache. An electronic device (101) comprising:
5. In any one of paragraphs 1 to 4, The action to determine the above cache type is: An action to identify whether a Structured Query Language (SQL) statement corresponding to the above query contains specific function information; and If the above SQL statement is identified as containing specific function information, an action is taken to determine the user's available cache as the user cache. An electronic device (101) comprising:
6. In any one of paragraphs 1 to 5, The above specific function information is, An electronic device (101) comprising at least one of a time-related function using the current time, a universally unique identifier (UUID) generation function, a random value generation function, or a current user identification function.
7. In any one of paragraphs 1 to 6, The action to determine the above cache type is: An operation of determining the user's available cache as a shared cache if the cache type determined based on the security information included in the above task information, the specific function information included in the above query, and the type of the token is not a user cache or a group cache. An electronic device (101) comprising:
8. In the method of operating an electronic device, An action to generate a token to manage the data permissions of the user who requested the query; An operation of determining a cache type available to the user using the above query and the above token; and An action of requesting cache data corresponding to the execution result of the query based on the cache type determined above. Including, The action to determine the above cache type is: An action to obtain job information for the above query by executing a dry run for the above query; and An operation of determining the type of cache available to the user as at least one of a user cache, a group cache, or a shared cache based on the security information included in the above work information, specific function information included in the above query, and the type of the token. A method of operation comprising:
9. In paragraph 8, The action that determines the above cache type is: An operation for identifying whether the table referenced by the query is a table to which row-level security is applied based on the security information included in the above work information; and If the table referenced by the above query is identified as a table with row-level security applied, the action of determining the available cache for the user as the user cache. A method of operation comprising:
10. In any one of paragraphs 8 to 9, The action that determines the above cache type is: An operation for identifying whether masking has been applied to a table referenced by the query based on security information included in the above work information; and If masking is applied to the table referenced by the above query, the action of determining the available cache for the user as the user cache. A method of operation comprising:
11. In any one of paragraphs 8 to 10, The action that determines the above cache type is: An action to identify whether the token for managing the data rights of the above user is a token of a specific group; and If the above token is identified as a token of a specific group, an action is taken to determine the user's available cache as the group cache. A method of operation comprising:
12. In any one of paragraphs 8 to 11, The action that determines the above cache type is: An action to identify whether a Structured Query Language (SQL) statement corresponding to the above query contains specific function information; and If the above SQL statement is identified as containing specific function information, an action is taken to determine the user's available cache as the user cache. A method of operation comprising:
13. In any one of paragraphs 8 to 12, The above specific function information is, A method of operation comprising at least one of a time-related function using the current time, a universally unique identifier (UUID) generation function, a random value generation function, or a current user identification function.
14. In any one of paragraphs 8 to 13, The action that determines the above cache type is: If the cache type determined based on the security information included in the above work information, the specific function information included in the above query, and the type of the token is not a user cache or a group cache, an operation of determining the user's available cache as a shared cache. A method of operation comprising:
15. A computer-readable recording medium having recorded thereon instructions that, when executed by one or more processors, cause the one or more processors to perform the method of any one of claims 8 to 14. .
Citation Information
Patent Citations
Method, system and computer program for balancing the access to shared resources with credit-based tokens
KR1020100053654A
System and method for supporting patching in a multitenant application server environment
KR1020170058955A
Authorization processing method and device
KR1020180022999A
Polishing tool for robot with adjustable compression force
KR1020230053254A
Rowgroup consolidation with global delta accumulation and versioning in distributed systems
US20220318223A1