Movatterモバイル変換


[0]ホーム

URL:


CN109657436A - A kind of method and system in the long-range number library of access - Google Patents

A kind of method and system in the long-range number library of access
Download PDF

Info

Publication number
CN109657436A
CN109657436ACN201811615673.2ACN201811615673ACN109657436ACN 109657436 ACN109657436 ACN 109657436ACN 201811615673 ACN201811615673 ACN 201811615673ACN 109657436 ACN109657436 ACN 109657436A
Authority
CN
China
Prior art keywords
data base
remote data
role
user
functional module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811615673.2A
Other languages
Chinese (zh)
Other versions
CN109657436B (en
Inventor
王海
冯勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SHANGHAI BESTONE INFORMATION TECHNOLOGY Co Ltd
Original Assignee
SHANGHAI BESTONE INFORMATION TECHNOLOGY Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by SHANGHAI BESTONE INFORMATION TECHNOLOGY Co LtdfiledCriticalSHANGHAI BESTONE INFORMATION TECHNOLOGY Co Ltd
Priority to CN201811615673.2ApriorityCriticalpatent/CN109657436B/en
Publication of CN109657436ApublicationCriticalpatent/CN109657436A/en
Application grantedgrantedCritical
Publication of CN109657436BpublicationCriticalpatent/CN109657436B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Classifications

Landscapes

Abstract

This application provides a kind of method and systems for accessing remote data base, and when user logs in, user terminal verifies the character data permission of login user;If it is determined that the character data permission cannot access any producing line tree of remote data base, then user terminal terminates the login of the user;If it is determined that the character data permission is able to access that the producing line tree of remote data base, then user terminal verification is allocated to the functional module of role's operating right of the user, it sends and instructs to remote data base, call the functional module for being allocated to role's operating right in remote data base on producing line tree.The method and system of access remote data base provided by the present invention, multiple functional modules are configured for remote data base, role's operating right of user and data permission difference, the functional module with its permission match can only then be transferred, do not have the user of permission can not access or operate related function module, so that it is guaranteed that Information Security.

Description

A kind of method and system in the long-range number library of access
Technical field
The present invention relates to a kind of management methods of remote data base, more particularly to one kind, and there is higher-security remotely to count librariesAccess method and system.
Background technique
With the development of internet industry, remote data base, especially cloud database have become common data storageMode.Remote data base is the installation database in remote server, and user terminal accesses to database by internet.CloudDatabase is a kind of special remote data base, is deployed in a virtual computation environmental, and, deployment low with use cost is heldEasily, the features such as automated back-up, can carry out it is simple, facilitate drive data management.
But network security has become the focus that entire internet industry is paid close attention to, for remote data base,Ensure that system data receives protection, do not wreck due to accidental or malice the reason of, change, reveal, is very crucial.
Summary of the invention
For the safety problem of remote data base, this application provides a kind of method and systems for accessing remote data base.
First aspect of the present invention provides a kind of method for accessing remote data base, comprising:
For teledata lab setting functional module, functional module is formed into one or more producing line trees;For user terminal configurationIt may have access to the character data permission of remote data base producing line tree, configure one or more role's operating rights for user terminal, and beEvery kind of role's operating right setting may have access to or the functional module of editor;
When user logs in, user terminal verifies the character data permission of login user;If it is determined that the character data permission is notAny producing line tree of remote data base can be accessed, then user terminal terminates the login of the user;If it is determined that the character data permissionBeing able to access that the producing line tree of remote data base, then user terminal verification is allocated to the functional module of role's operating right of the user,It sends and instructs to remote data base, call the function mould for being allocated to role's operating right in remote data base on producing line treeBlock.
The second aspect of the present invention provides a kind of system for accessing remote data base, comprising: user terminal, character data permissionConfiguration module, role's operating right configuration module, functional module configuration module, character data authorization check module, role's operationAuthorization check module, communication module, wherein
Functional module configuration module is teledata lab setting functional module, and functional module is formed one or more producing linesTree;Character data permission configuration module user terminal configures the character data permission that may have access to remote data base producing line tree;Role behaviourMaking permission configuration module is that user terminal configures one or more role's operating rights, and can visit for every kind of role's operating right settingThe functional module asked or edited;
Character data authorization check module verifies the character data permission of login user when user logs in;
The verification of role's operating right correction verification module is allocated to the functional module of role's operating right of the user;
Communication module sends to remote data base and instructs, and calls in remote data base and is allocated to role behaviour on producing line treeMake the functional module of permission.
In an advantageous embodiment, user terminal judges that role's operating right of the user is a kind of or a variety of, ifIt is a kind of role's operating right, then sends and instruct to remote data base, calls in remote data base and be allocated to this on producing line treeThe functional module of role's operating right, if it is various rolls operating right, then user terminal will be allocated to various rolls operationThe functional module of module takes maximum intersection, sends and instructs to remote data base, calls the configuration in remote data base on producing line treeTo the intersection of the functional module of the various rolls operating right.
In an advantageous embodiment, user terminal judge the character data permission of login user be it is a kind of or a variety of, such asFruit is judged as a variety of, then successively verifies each character data permission of login user, and finds out the maximum character data power of permissionLimit, and judge that the maximum character data permission of the permission is any products-tree for accessing enough wide remote databases, if it can,Then verify role's operating right of the user.
In an advantageous embodiment, user terminal judge the character data permission of login user be it is a kind of or a variety of, such asFruit is judged as a variety of, then successively verifies each character data permission of login user, and finds out and be able to access that in remote data baseAll character data permissions of one or more producing line trees, and then judge role's operating right of all data permissions.
In an advantageous embodiment, whether remote data base checks producing line tree after the instruction for receiving user terminal transmissionThe functional module in need transferred is preset, if presetting the functional module in need transferred, is called for user terminal.
It is highly preferred that if the producing line tree Non-precondition functional module in need transferred, verifying role's operating right isIt is no to be able to access that or edit the functional module, if it is then user terminal transfers the functional module from remote data base, forFamily accesses or is edited on producing line tree.
In an advantageous embodiment, the system of the access remote data base further includes producing line tree building module, userAfter transferring functional module in remote data base, user constructs module by producing line tree and the functional module is edited into producing line tree at endOn.
In an advantageous embodiment, remote data base checks login user after the instruction for receiving user terminal transmissionCharacter data permission, if it is determined that the character data permission cannot access the producing line tree of remote data base, then remote data base toThe instruction that the transmission of user forbids user to log in;If it is determined that the character data permission is able to access that the producing line of remote data baseTree, then allow user terminal calling functional modules.
In an advantageous embodiment, remote data base is after the instruction for receiving user terminal transmission, or is judging the angleAfter color data permission is able to access that the producing line tree of remote data base, role's operating right of the user is checked, if it is a kind of angleColor permission then allows to be allocated to the functional module of role's operating right described in user terminal calling, operates if it is various rollsPermission, then the functional module for being allocated to the various rolls operation module is taken maximum intersection by database, and user terminal is allowed to callThe intersection of the functional module for being allocated to the various rolls operating right.
In an advantageous embodiment, the system of the access remote data base further includes for being arranged in remote data baseSecond role data permission correction verification module, remote data base receive user terminal transmission instruction after, second role data powerLimit the character data permission that correction verification module checks login user.
In an advantageous embodiment, the system of the access remote data base further includes for being arranged in remote data baseSecond role operating right correction verification module, journey database or judging the role after the instruction for receiving user terminal transmissionAfter data permission is able to access that the producing line tree of remote data base, second role operating right correction verification module checks the role of the userOperating right
The method and system of access remote data base provided by the present invention, configures multiple function moulds for remote data baseBlock, role's operating right and the data permission difference of user, then can only transfer the functional module with its permission match, not have powerThe user's of limit can not access or operate related function module, so that it is guaranteed that Information Security.
Detailed description of the invention
Fig. 1 is that remote data base method flow schematic diagram is accessed in an embodiment of the present invention;
Fig. 2 is to access remote data base method flow schematic diagram in another embodiment of the present invention;
Fig. 3 is to access remote data base method flow schematic diagram in the third embodiment of the invention.
Specific embodiment
Embodiment 1
Present embodiments provide a kind of system for accessing remote data base, comprising: user terminal, character data authority configuration mouldBlock, role's operating right configuration module, functional module configuration module, character data authorization check module, role's operating right schoolTest module, communication module.
Referring to Fig.1, the method for the present embodiment access remote data base is as follows:
For teledata lab setting functional module, functional module is formed into one or more producing line trees;For user terminal configurationIt may have access to the character data permission of remote data base producing line tree, configure one or more role's operating rights for user terminal, and beEvery kind of role's operating right setting may have access to or the functional module of editor;
When user logs in, user terminal verifies the character data permission of login user;If it is determined that the character data permission is notAny producing line tree of remote data base can be accessed, then user terminal terminates the login of the user;If it is determined that the character data permissionBeing able to access that the producing line tree of remote data base, then user terminal verification is allocated to the functional module of role's operating right of the user,It sends and instructs to remote data base, call the function mould for being allocated to role's operating right in remote data base on producing line treeBlock.
Wherein, user terminal judge the character data permission of login user be it is a kind of or a variety of, if it is determined that a variety of, thenEach character data permission of login user is successively verified, and finds out the maximum character data permission of permission, and judge the permissionMaximum character data permission is any products-tree for accessing enough wide remote databases, if it is then verifying the user'sRole's operating right.Alternatively, user terminal judge login user character data permission be it is a kind of or a variety of, if it is determined that moreKind, then each character data permission of login user is successively verified, and find out and be able to access that one or more in remote data baseAll character data permissions of producing line tree, and then judge role's operating right of all data permissions.
Embodiment 2
Referring to Fig. 2, the method that the present embodiment accesses remote data base is as follows:
For teledata lab setting functional module, functional module is formed into one or more producing line trees;For user terminal configurationIt may have access to the character data permission of remote data base producing line tree, configure one or more role's operating rights for user terminal, and beEvery kind of role's operating right setting may have access to or the functional module of editor;
When user logs in, user terminal verifies the character data permission of login user;If it is determined that the character data permission is notAny producing line tree of remote data base can be accessed, then user terminal terminates the login of the user;If it is determined that the character data permissionIt is able to access that the producing line tree of remote data base, then user terminal verification is allocated to the functional module of role's operating right of the user.
Wherein, user terminal judge role's operating right of the user be it is a kind of or a variety of, if it is a kind of role operatePermission then sends to remote data base and instructs, and calls in remote data base the role's operating right that is allocated on producing line treeFunctional module, if it is various rolls operating right, then user terminal will be allocated to the functional module of the various rolls operation moduleMaximum intersection is taken, sends and instructs to remote data base, calls in remote data base and is allocated to various rolls behaviour on producing line treeMake the intersection of the functional module of permission.
Remote data base checks whether producing line tree presets the function in need of transferring after the instruction for receiving user terminal transmissionModule is called if presetting the functional module in need transferred for user terminal.It is transferred if producing line tree Non-precondition is in needFunctional module, then verify whether role's operating right is able to access that or edits the functional module, if it is then user terminal fromThe functional module is transferred in remote data base, accesses for user or is edited on producing line tree.
Embodiment 2
Referring to Fig. 2, the method that the present embodiment accesses remote data base is as follows:
For teledata lab setting functional module, functional module is formed into one or more producing line trees;For user terminal configurationIt may have access to the character data permission of remote data base producing line tree, configure one or more role's operating rights for user terminal, and beEvery kind of role's operating right setting may have access to or the functional module of editor;
When user logs in, user terminal verifies the character data permission of login user;If it is determined that the character data permission is notAny producing line tree of remote data base can be accessed, then user terminal terminates the login of the user;If it is determined that the character data permissionIt is able to access that the producing line tree of remote data base, then user terminal verification is allocated to the functional module of role's operating right of the user;User terminal judge role's operating right of the user be it is a kind of or a variety of, if it is a kind of role's operating right, then Xiang YuanchengDatabase sends instruction, calls the functional module for being allocated to role's operating right in remote data base on producing line tree, ifIt is various rolls operating right, then the functional module for being allocated to the various rolls operation module is taken maximum intersection by user terminal, toRemote data base sends instruction, calls the function mould for being allocated to the various rolls operating right in remote data base on producing line treeThe intersection of block;
Remote data base checks the character data permission of login user, if sentenced after the instruction for receiving user terminal transmissionThe character data permission of breaking cannot access the producing line tree of remote data base, then transmission of the remote data base to user forbids user to step onThe instruction of record;If it is determined that the character data permission is able to access that the producing line tree of remote data base, then user terminal is allowed to call functionIt can module.
Wherein, remote data base is after the instruction for receiving user terminal transmission, or is judging that the character data permission canAfter the producing line tree for accessing remote data base, checks role's operating right of the user, if it is a kind of role-security, then allow to useThe functional module of role's operating right is allocated to described in the calling of family end, if it is various rolls operating right, then database willThe functional module for being allocated to the various rolls operation module takes maximum intersection, and allows to be allocated to this described in user terminal calling a variety ofThe intersection of the functional module of role's operating right.
Specific embodiments of the present invention are described in detail above, but it is merely an example, the present invention is simultaneously unlimitedIt is formed on particular embodiments described above.To those skilled in the art, any couple of present invention carries out equivalent modifications andSubstitution is also all among scope of the invention.Therefore, without departing from the spirit and scope of the invention made by equal transformation andModification, all should be contained within the scope of the invention.

Claims (10)

CN201811615673.2A2018-12-272018-12-27Method and system for accessing remote number libraryActiveCN109657436B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201811615673.2ACN109657436B (en)2018-12-272018-12-27Method and system for accessing remote number library

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201811615673.2ACN109657436B (en)2018-12-272018-12-27Method and system for accessing remote number library

Publications (2)

Publication NumberPublication Date
CN109657436Atrue CN109657436A (en)2019-04-19
CN109657436B CN109657436B (en)2020-07-07

Family

ID=66117270

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201811615673.2AActiveCN109657436B (en)2018-12-272018-12-27Method and system for accessing remote number library

Country Status (1)

CountryLink
CN (1)CN109657436B (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102654864A (en)*2011-03-022012-09-05华北计算机系统工程研究所Independent transparent security audit protection method facing real-time database
CN106778345A (en)*2016-12-192017-05-31网易(杭州)网络有限公司The treating method and apparatus of the data based on operating right
US20170195572A1 (en)*2016-01-062017-07-06Orcam Technologies Ltd.Systems and methods for automatically varying privacy settings of wearable camera systems
CN107133516A (en)*2017-04-242017-09-05深信服科技股份有限公司A kind of authority control method and system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102654864A (en)*2011-03-022012-09-05华北计算机系统工程研究所Independent transparent security audit protection method facing real-time database
US20170195572A1 (en)*2016-01-062017-07-06Orcam Technologies Ltd.Systems and methods for automatically varying privacy settings of wearable camera systems
CN106778345A (en)*2016-12-192017-05-31网易(杭州)网络有限公司The treating method and apparatus of the data based on operating right
CN107133516A (en)*2017-04-242017-09-05深信服科技股份有限公司A kind of authority control method and system

Also Published As

Publication numberPublication date
CN109657436B (en)2020-07-07

Similar Documents

PublicationPublication DateTitle
JP6990534B2 (en) Process control communication between portable field maintenance tools and process control devices
US7289994B2 (en)Interconnected zones within a process control system
CN106878459B (en)Self-adaptive Internet of things intelligent gateway implementation method and equipment thereof
CN112422555B (en)Kubernetes-based resource authority management system and method for distributed system
CN106134143A (en)Method, apparatus and system for dynamic network access-in management
CN101952830A (en)Methods and systems for user authorization
CN1552148A (en) Apparatus and method for automatically configuring user profiles
CN101369979B (en)Communication method and system for network camera and user terminal
CN110727938B (en)Configuration method and device of intelligent equipment, electronic equipment and storage medium
CN110021086A (en)A method of the temporary Authorization opening gate based on openid
CN113973275A (en) Data processing method, apparatus and medium
CN113992406A (en) A permission access control method for consortium chain cross-chain
CN1601954B (en)Moving principals across security boundaries without service interruption
CN109657436A (en)A kind of method and system in the long-range number library of access
CN111131324A (en)Login method and device of business system, storage medium and electronic device
CN112702743B (en)Network data monitoring and protecting method based on artificial intelligence
CN115104294A (en) Onboarding devices in a multi-tenant virtual network in an industrial network
JP2021525908A (en) System on chip firewall memory architecture
CN109672754A (en)SaaSization platform
US20250138503A1 (en)Method for identifying a field device to be operated in automation technology
WO2020240769A1 (en)Connection management device, connection management system, connection management method, and program
CN119295029B (en) An integrated platform, integrated method and business processing method for multiple business systems
CN116263866B (en)Automatic burning method and equipment
CN114095379B (en)Rapid modeling method and system based on Internet of things
CN109104294B (en)Single board configuration method and device, single board and computer readable storage medium

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
GR01Patent grant
GR01Patent grant

[8]ページ先頭

©2009-2025 Movatter.jp