CN101335745A - Method and apparatus for data authorizing and authorized data access in Web application program system - Google Patents

Method and apparatus for data authorizing and authorized data access in Web application program system Download PDF

Info

Publication number
CN101335745A
CN101335745A CNA2007101233795A CN200710123379A CN101335745A CN 101335745 A CN101335745 A CN 101335745A CN A2007101233795 A CNA2007101233795 A CN A2007101233795A CN 200710123379 A CN200710123379 A CN 200710123379A CN 101335745 A CN101335745 A CN 101335745A
Authority
CN
China
Prior art keywords
data
user
authorized
data grant
authorization
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CNA2007101233795A
Other languages
Chinese (zh)
Inventor
潘广和
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Priority to CNA2007101233795A priority Critical patent/CN101335745A/en
Publication of CN101335745A publication Critical patent/CN101335745A/en
Pending legal-status Critical Current

Links

Images

Abstract

The invention relates to a method and a device of data authorization and authorized data access in a Web application program system; the method comprises the steps of selecting a table or a plurality of tables to be authorized from a server; setting the authority of data authorization; selecting a user or a plurality of users from the user management apparatus of the server or a user group including at least one user; and saving the data authorization information which at least comprises the identification of a data authorization user, the identification of obtaining of the data authorization user, the identification of the tables to be authorized, and the authority to an authorization record management apparatus.

Description

The method and apparatus of data grant and access authorization data in the web application system
Technical field
The present invention relates to the network data management field, more specifically, the present invention relates in data are authorized and the method and apparatus of access authorization data based on the application program system of Web.
Background technology
Along with the popularization and application of the Internet and high-speed wideband, application program by standalone version to providing the trend that changes based on the application service of Web more and more obvious.The Salesforce.com of u s company has made remarkable effect providing aspect the CRM of Web management application service.Google company has released a series of office softwares based on Web such as Google company by the mode of purchase also carrying out positive trial aspect the exploitation web application.
In the application program system based on Web, each user is the independently individuality in the whole system, and each user account can only be managed the data under this account.And in real life, between the user and the demand that has data sharing and collaborative work between Team Member again.For example, selling group requires customer data to share between Team Member, and each Team Member also is not quite similar to the rights of using of the customer data of each part, the team leader wishes and can carry out comprehensive management to all customer datas, and Team Member has senior administration authority and the customer data in other Team Member's compasss of competency is only had the authority of browsing the customer data in the own compass of competency; And for example, the kinsfolk is based on the account who independently has oneself in the application service system of Web separately, but they wish the consumer spending of energy managed together family again.
Therefore; in application service system, need to provide a kind of data grant method for registered user's data sharing and managed together data based on Web; make and in this web application system, can carry out data sharing and coordinated management easily between the registered user, and can protect the privacy and the safety of data separately effectively.
Summary of the invention
Therefore, the objective of the invention is to provides a kind of for the method for carrying out data grant or request mandate and authorization requests reply between the registered user to the application program system based on Web, so that can shared data and managed together data between the registered user in the application program system of Web.
According to the present invention, above-mentioned purpose is by providing a kind of method of carrying out data grant in based on the application program system of Web to realize that the method according to data grant of the present invention comprises step: choose one or more tables to be authorized from server; The authority of data grant is set; Choose one or more users in the user management device from server or comprise at least one user's user group; And with data grant information, comprise at least: sign, the authorization privilege of data grant user's sign, the sign of obtaining the data grant user, table to be authorized are saved in the authority record management devices.
Another object of the present invention is to provide a kind of equipment that carries out data grant in based on the application program system of Web.
Equipment according to data grant of the present invention comprises: the authorization list choice device is used for selecting one or more tables to be authorized from server; The authorization privilege setting device is used to be provided with the authorization privilege of table to be authorized; The user management device is used for organizing server storage registered user and user the database of data; Select user's set, be used for user's group of from the user management device of described server, choosing one or more users or comprising at least one user; The authority record management devices is used for preserving the authority record database of information at server.
A further object of the present invention be to provide a kind of in based on the application program system of Web the method for access authorization data.
Method according to access authorization data of the present invention comprises step: calling party is chosen a database table to be visited from server; Choose an authorized user that gives the mandate of database table to be visited in the authority record management devices of calling party from server; Reading authorized user from the authority record management devices gives the set access rights of database table to be visited and authorizes catalogue; Read the data under the mandate catalogue of the authorized user in the database table to be visited in the data set from server; The access rights of data are set according to the access rights that read; And, data are presented to the user;
In addition, a further object of the present invention be to provide a kind of in based on the application program system of Web the device of access authorization data.
The authorization list choice device is used for calling party and selects a database table to be visited from server; The authority record reading device is used for reading authorized user and gives the set access rights of calling party database table to be visited and authorize catalogue from the authority record management devices of server; The authority record management devices is used for preserving the authority record database of information at server; The authorized user choice device is used for calling party and chooses an authorized user that gives the mandate of calling party database table to be visited from the authority record management devices of server; Data set is used for the database at server preservation user data; Data fetch device is used for reading from data set the data of the authorized user under the mandate catalogue the database table to be visited; The access rights setting device is provided with the access rights of data according to the access rights that read; Data present device, are used for data are presented to the user.
Make based on reaching shared data and managed together data purpose and can protect the privacy and the safety of data separately simultaneously again effectively by carrying out data grant mutually between the registered user in the application program system of Web according to method and apparatus provided by the present invention.
Description of drawings
As the accompanying drawing of a part of the present invention, with this specification, be used to illustrate embodiments of the present invention, be used to explain principle of the present invention.
Fig. 1 is the schematic diagram according to the equipment of the data grant in one embodiment of the present invention;
Fig. 2 is the field structure schematic diagram according to the user in one embodiment of the present invention and user's group table;
Fig. 3 is the field structure schematic diagram according to the authority record table in one embodiment of the present invention;
Fig. 4 is the flow chart according to the data grant in one embodiment of the present invention;
Fig. 5 is the flow chart according to the reply of the data grant request in one embodiment of the present invention;
Fig. 6 is the schematic diagram according to the equipment of the access authorization data in one embodiment of the present invention; And
Fig. 7 is the flow chart according to the access authorization data in one embodiment of the present invention;
Embodiment
Below will be described in detail preferred implementation of the present invention with reference to the accompanying drawings, in the accompanying drawings, identical label is represented same or analogous parts.
Fig. 1 is the schematic diagram according to the equipment of the data grant in one embodiment of the present invention.
As shown in Figure 1, comprise authorization list choice device 102 according to data grant equipment 100 in the web application of the present invention system, user management device 103, authorization privilege setting device 104, authority record management devices 105 is selected user's set 106.
Authorization list choice device 102 is used for choosing table to be authorized from server.This table to be authorized is the database table that is used to store data in the web application system, as the table based on memory communicating record in the personal information management system of Web, schedule management, task and memorandum record.
User management device 103 is the databases that are used to store user and user's group in the server.In one embodiment of the invention, this user management device is storage registered user's a database.Fig. 2 is the field structure schematic diagram according to the user in one embodiment of the present invention and user's group table.As shown in Figure 2, subscriber's meter 210 is used to store registered user's information such as surname, name, address, phone or the like.User's group is for comprising one or more users' customer group, user's group table 220 comprises the user ID field 222 that the user organizes id field 221 and user Group administrators at least, the user organizes sublist and is used for user ID in the stored user group, comprises that at least the user organizes id field 231 and user ID field 232.If system does not support the mandate to user group, then user management device 103 does not need to store the user and organizes relevant table.
Authorization privilege setting device 104 is used to be provided with the authorization privilege for the treatment of authorization list.Wherein authorization privilege is one of following several authorities:
Read-only, the user who obtains data grant can only read authorization data;
Editor, the user who obtains data grant can make amendment and deletes and increase data authorizing under the catalogue the authorization data that obtains; And,
Super-ordinate right, the user who obtains data grant has the whole authority of table of authorizing, comprise, increase, deletion and amendment record, and increase, deletion and revise data directory.
Select user's set 106, be used for selecting to wait to obtain user or user's group of authorizing or waiting to authorize from user management device 103.For the operation user during for authorized user for from user management device 103, selecting to wait to obtain user or user's group of mandate, if select user's group, all users during then this user organizes obtain this mandate; For request user or user's group for selecting to wait from user management device 103 to authorize during authorized user, if select user's group, user that then should request mandate after this authorization requests approval obtains user all users' in organizing mandate for the operation user.
Authority record management devices 105 is used for preserving the authority record database of information at server.Fig. 3 is the field structure schematic diagram according to the authority record table in an embodiment of the invention.As shown in Figure 3, whether the authority record table 300 that is used to preserve authority record information comprises authorized person's id field 301, grantee's id field 302, authorization list id field 303, authorizes catalogue id field 304, authorization privilege field 305, allows and device synchronization field 306 and licensing status field 307 and other field.
Authority record management devices 105 as shown in Figure 1 is with authorization list choice device 102, authorization privilege setting device 104 and select user's set 106 to link to each other respectively, the sign (if what select is that the user organizes, then the sign organized for this user of user ID) that is used to preserve the set authorization privilege of the sign, authorization privilege setting device 104 of the table of selecting from authorization list choice device 102 to be authorized and obtains the user that the user's of mandate sign or wait authorizes from waiting of selecting that user's set 106 obtains.The sign of table wherein to be authorized is kept at the authorization list id field 303 in the authority record table 300, authorization privilege is kept at authorization privilege field 305, and the sign of waiting to obtain the user of mandate is kept in grantee's id field 302 or the user's that waits to authorize sign is kept at authorized person's id field 301.
Data grant equipment 100 according to the present invention also comprises choosing authorizes directory device 107, is used for choosing table to be authorized catalogue to be authorized.In an embodiment of the present invention the data in the database are carried out Classification Management by catalogue, as in based on the personal information management system of Web, the contact person in the address list wherein can being classified as " individual " and catalogues such as " commercial affairs ".When authorizing, can will treat that the one or more catalogues in the authorization list authorize.The user who obtains the authorization can visit the catalogue that is authorized to, and the catalogue that does not have to authorize can not be accessed.The requirement that can satisfy data sharing and cooperation like this can be protected individual's private information again.The catalogue of choosing 107 selections of mandate directory device is kept in the authority record table 300 authorizes in the catalogue id field 304, if chosen a plurality of catalogues, then opens with CSV between each catalogue ID.
Data grant equipment 100 according to the present invention also comprises synchronous authority device 109 is set, be used to be provided with and whether allow the user who obtains data grant that authorization data is synchronized to mobile device, as palmtop PC and smart mobile phone, and third party application, as going among the Outlook.Synchronous authority that synchronous authority device 109 is provided with is set to be kept in the whether permission and device synchronization field 306 in the authority record table 300.
Data grant equipment 100 according to the present invention also comprises determines action type device 101, and being used to determine carry out Authorized operation still is the authorization requests operation.
In addition, this data grant equipment 100 also comprises reply authorization requests device 108, is used to wait that the user who authorizes gives an written reply request authorized person's authorization requests.After receiving authorization requests, the user who waits to authorize ratifies or vetos this authorization requests; If ratify this authorization requests, also comprise the respective field in following operation and the change authority record table 300 when needed: the authority of the request mandate in the change authorization requests, the catalogue of the request mandate in the change authorization requests, and whether allowing in the change authorization requests will be authorized to the setting of data sync to mobile device.To change the licensing status field 307 in the authority record table 300 after approval or the rejection authorization requests.
Fig. 4 is the flow chart according to the data grant in one embodiment of the present invention.
As shown in Figure 4, data grant starts from step 401.In step 402, determine action type, promptly carrying out Authorized operation still is the authorization requests operation.
Then, in step 403, the user chooses a table to be authorized from server.Then, in step 404, authorization privilege is set.In embodiment of the present invention, be provided with the authority of three kinds of mandates, that is:
Read-only, the user who obtains this data grant can only read authorization data;
Editor, the user who obtains this data grant can make amendment and deletes and create record authorizing under the catalogue authorization data; And,
Super-ordinate right, the user who obtains this data grant has the whole authority of database table of authorizing, comprise, increase, deletion and amendment record, and increase, deletion and revise catalogue.
Then, in step 405, choose user or user's group or the user who authorizes or the user's group of obtaining mandate.There are two kinds of situations in this step, if Authorized operation, what choose is user or the user's group of obtaining mandate; If the request Authorized operation, what choose is user or the user's group of waiting to give data grant.
Then, in step 406, the user chooses catalogue to be authorized.Data in the database table are pressed the catalog classification management, and each database table is provided with one or more catalogues.The user can choose one or more catalogue in this step.Because super-ordinate right has the authority that all data and catalogue are managed, so when authorization privilege step 403 being set selecting super-ordinate right, then be defaulted as whole catalogues and can not change in this step catalogue to be authorized.
Then, in step 407, synchronous restriction is set.The data of authorizing are for to browse and to manage by the application program of Web, if browse in mobile device or third party software such as Outlook and the supervisor authority data then need authorization data from the server sync to the mobile device or third party software.This step be provided with restriction whether allow authorized user with data sync in mobile device or third party software.
Next, in step 408, authorization message is saved in the authority record table 300.Wherein, the ID of the table of choosing in step 403 to be authorized is saved in the authorization list id field 303; The authorization privilege that is provided with in step 404 is saved in the authorization privilege field 305; The selected user of step 405 is that authorized person or grantee will determine according to action type, if Authorized operation, the operation user is the authorized person, and selected user is the grantee in step 405; If authorization requests operation, then operating the user is the grantee, and is the authorized person the selected user of step 405; Authorized person ID and grantee ID are kept at respectively in field 301 and the field 302.If user selected in the step 405 then organizes ID as authorized person ID or grantee ID (deciding on action type) with this user for user's group; Being kept at field 304 at the ID of the selected catalogue to be authorized of step 406 authorizes among the catalogue ID; The determined synchronous restriction of step 407 be kept at field 306 whether allow with device synchronization in; Field 307 licensing statuss are preserved the state of authorizing, if the request that is operating as is authorized, then preserve the state that waits for ratification in this field, if for being operating as mandate, then preserve the state of approved in this field.
At last, the method according to data grant of the present invention finishes in step 409.
In an embodiment of the present invention, once only choose a user or user group and authorize or ask mandate.But the present invention does not limit and once can only choose a user or user's group and authorize or ask and authorize, and both can choose a user or user group, can choose a plurality of users or user group yet.If choose a plurality of users or user group, then when preserving authorization message, each user or user's group are needed to preserve an authority record.
In addition, step 403 is in an embodiment of the present invention chosen table to be authorized, authorization privilege is set step 404 and step 405 is chosen the requirement that the user there is no precedence, can operate according to the order in the present embodiment, also can adopt different order of operation.
A kind of method of data grant request reply is provided according to another aspect of the present invention.
Fig. 5 is the flow chart according to the reply of the data grant request in one embodiment of the present invention.
As shown in Figure 5, from step 501; Then, in step 502, read a data grant request record to be given an written reply in the authority record management devices 105 of user from server of waiting to authorize.The user who authorizes that waits who selects for the request authorized user is the situation that the user organizes, and then gives an written reply the keeper for this user's group of operation, and this keeper is a user in the user management device 103, and he sets up and safeguard this user's group
Then, in step 503, wait that the user who authorizes gives an written reply the request of (i.e. approval or rejection) this data grant.Wherein veto the licensing status field 307 that is operating as in the data grant request record that this is to be given an written reply and be set to the rejection state, and ratify to be operating as field 307 is set to sanctions status.One or multi-mode operation and change respective field in the authority record table 300 below the request of this data grant of approval also comprises under the situation of needs:
Authorization privilege in the change data grant request;
Catalogue to be authorized in the table to be authorized in the change data grant request;
In the change data grant request whether permission is synchronized to mobile device with authorization data, as palmtop PC and smart mobile phone, and third party application, as going among the Outlook.
At last, the method according to data grant request reply of the present invention ends at step 504.
A kind of equipment of access authorization data also is provided according to another aspect of the present invention.
Fig. 6 is the schematic diagram according to the equipment of the access authorization data in one embodiment of the present invention.
As shown in Figure 6, according to of the present invention in the web application system equipment 600 of access authorization data comprise authorization list choice device 601, authority record reading device 602, authority record management devices 603, authorized user choice device 604, data set 605, data fetch device 606, access rights setting device 607, data present device 608.
Authorization list choice device 601 is used for calling party and selects a database table to be visited.
Authority record reading device 602 is used for reading authorized user and gives the set access rights of this database table to be visited of this calling party and authorize catalogue from the authority record management devices of server.
Authority record management devices 603 is used for preserving the authority record database of information at server.Authority record management devices 105 among this device and Fig. 1 is same devices.
Authorized user choice device 604 is used for calling party and chooses an authorized user that gives the mandate of this database table to be visited of this calling party from the authority record management devices 603 of server.
Data set 605 is used for the database at server preservation user data.
Data fetch device 606 is used for reading from data set the data of this authorized user under the mandate catalogue the database table to be visited.
Access rights setting device 607 is provided with the access rights of data according to the access rights that read from authority record management devices 603.
Data present device 608, are used for data are presented to the user.
Wherein authority record reading device 602 links to each other with authorization list choice device 601 and authorized user choice device 604, and the authorized user ID that authority record reading device 602 is obtained according to the ID of the authorization database table that is obtained from authorization list choice device 601 and/or from authorized user choice device 604 and the ID (being grantee ID) of calling party oneself read authority record information from authority record management devices 603; Wherein the list of authorized users of obtaining according to authorization list ID of giving this authorization list mandate passes to authorized user choice device 604; Mandate catalogue and the authorization privilege Data transmission reading device 606 in the authority record information that reads according to authorization list ID and authorized user ID wherein.
Authority record management devices 603 links to each other with authority record reading device 602, authority record reading device 602 will read the required parameter of authority record information, grantee ID, authorization list ID and/or authorized person ID, pass to authority record management devices 603, and therefrom read qualified authority record.
Data fetch device 606 links to each other with authorization list choice device 601, authority record reading device 602, authorized user choice device 604, data set 605 and access rights setting device 607, the authorized person ID that obtains according to the authorization list ID that obtains from authorization list choice device 601, from authorized user choice device 604 and obtain authorization data from data set 605 from the mandate catalogue that authority record reading device 602 obtains.
Access rights setting device 607 is provided with access rights for the authorization data that obtains from data fetch device 606 according to the authorization privilege that obtains from authority record reading device 602.
A kind of method of access authorization data also is provided according to a further aspect of the invention.
Fig. 7 is the flow chart according to the access authorization data in one embodiment of the present invention.
As shown in Figure 7, access authorization data start from step 701.In step 702, from server, select database table to be visited.Then, in step 703, from the authorized user of the mandate that gives this database table, select a user.
Then, in step 704, the ID of the authorized user of selecting according to the ID of the database table of selecting in step 702 to be visited with in step 703 and the user ID of calling party oneself read an authority record information from authority record management devices 603, comprise mandate catalogue and authorization privilege.
Then, in step 705, the ID of the authorized user of selecting according to the ID of the database table of selecting in step 702 to be visited with in step 703 and from data set 605, read the data of mandate in the mandate catalogue that step 704 read.
Next, in step 706, according to access rights being set for the authorization data that in step 705, is read at the authorization privilege that step 704 read.
Then, in step 707, the authorization data that will be read in step 705 is presented to the user.
At last, the method according to access authorization data of the present invention ends at step 708.
By as can be known to the description of above present embodiment, the invention provides that a cover is complete authorizes, authorizes and give an written reply the required method and apparatus of visit authorization data from data grant, request, make the user can be in part or all data grant in its database table be given other people or obtain the data of other people mandate and the mandate that obtains of visit based on the application program system of Web.
Do not break away from design of the present invention and scope and can make many other changes and remodeling.Should be appreciated that to the invention is not restricted to specific execution mode, scope of the present invention is defined by the following claims.

Claims (16)

1. method of carrying out data grant in based on the application program system of Web comprises step:
Choose one or more tables to be authorized from server;
The authority of data grant is set;
Choose one or more users in the user management device from described server or comprise at least one user's user group; And,
With data grant information, comprise at least: data grant user's sign, the sign of obtaining the data grant user, the sign of table described to be authorized, the authority of described mandate are saved in the authority record management devices.
2. the method for data grant according to claim 1, the data in the table wherein said to be authorized are carried out Classification Management according to catalogue.
3. the method for data grant according to claim 1 also comprises step: choose the catalogue one or more to be authorized in the table described to be authorized.
4. the method for data grant according to claim 1, also comprise step: set and whether to allow describedly to wait to obtain the data grant user being authorized to data and mobile device, as palmtop PC and smart mobile phone, and third party application, as Outlook, carry out synchronously.
5. the method for data grant according to claim 1, the authority of wherein said data grant are a kind of in the following authority,
Read-only, describedly wait to obtain the data grant user and can only read authorization data;
Editor describedly waits to obtain the data grant user and can make amendment and delete and create record authorizing under the catalogue authorization data; And,
Super-ordinate right is describedly waited to obtain the data grant user and is had the authority whole to table described to be authorized, comprise, increase, deletion and amendment record, and increase, deletion and revise data directory.
6. the method for data grant according to claim 1 also comprises step: determine action type, promptly carrying out Authorized operation still is the authorization requests operation.
7. the method for data grant according to claim 1 also comprises step:
Read data grant request record to be given an written reply in the described authority record management devices of user from described server of waiting to give data grant;
Data grant request record described to be given an written reply is promptly changed in the described request of waiting to give user's approval of data grant or vetoing described data grant, comprises change licensing status and following one or more contents of change when needed:
Authorization privilege in the described data grant request;
Catalogue to be authorized in the table described to be authorized in the described data grant request;
Whether permission in the described data grant request will be authorized to data sync to mobile device, as palmtop PC and smart mobile phone, and third party application, as going among the Outlook.
8. equipment that carries out data grant in based on the application program system of Web comprises:
The authorization list choice device is used for selecting one or more tables to be authorized from server;
The authorization privilege setting device is used to be provided with the authorization privilege of table described to be authorized;
The user management device is used for organizing described server storage registered user and user the database of data;
Select user's set, be used for user's group of from the user management device of described server, choosing one or more users or comprising at least one user;
The authority record management devices is used for preserving the authority record database of information at described server;
9. the equipment of data grant according to claim 8, the data in the table wherein said to be authorized are carried out Classification Management according to catalogue.
10. the equipment of data grant according to claim 8 also comprises: choose the mandate directory device, be used for choosing the one or more catalogues to be authorized of table described to be authorized.
11. the equipment of data grant according to claim 8, also comprise: synchronous authority device is set, be used for setting and whether allow describedly to wait to obtain the data grant user being authorized to data and mobile device, as palmtop PC and smart mobile phone, and third party application, as Outlook, carry out synchronously.
12. the equipment of data grant according to claim 8, the authority of wherein said data grant are a kind of in the following authority,
Read-only, describedly wait to obtain the data grant user and can only read authorization data;
Editor describedly waits to obtain the data grant user and can make amendment and delete and create record authorizing under the catalogue authorization data; And,
Super-ordinate right is describedly waited to obtain the data grant user and is had the authority whole to table described to be authorized, comprise, increase, deletion and amendment record, and increase, deletion and revise data directory.
13. the equipment of data grant according to claim 8 also comprises: determine the action type device, being used to determine carry out Authorized operation still is the authorization requests operation.
14. the equipment of data grant according to claim 8, also comprise: reply authorization requests device, be used for the described request that gives the data grant of authorized user approval or rejection described request authorized user, promptly change described authority record information, comprise change licensing status and following one or more contents of change when needed:
Authorization privilege in the described data grant request;
Catalogue to be authorized in the table described to be authorized in the described data grant request;
Whether permission in the described data grant request will be authorized to data sync to mobile device, as palmtop PC and smart mobile phone, and third party application, as going among the Outlook.
15. the method for access authorization data in based on the application program system of Web comprises step:
Calling party is chosen a table to be visited from server;
Choose an authorized user that gives the mandate of described table to be visited in the authority record management devices of described calling party from described server;
From the authority record management devices, read described authorized user and give described set access rights and the mandate catalogue of table to be visited;
Read the data under the described mandate catalogue of the described authorized user in the described table to be visited in the data set from described server;
The access rights of described data are set according to the described access rights that read; And,
Described data are presented to described calling party;
16. the equipment of access authorization data in based on the application program service system of Web comprises:
The authorization list choice device is used for calling party and selects a table to be visited from server;
The authority record reading device is used for reading authorized user and gives described calling party described set access rights and the mandate catalogue of table to be visited from the authority record management devices of described server;
The authority record management devices is used for preserving the authority record database of information at described server;
The authorized user choice device is used for described calling party and chooses an authorized user that gives the mandate of the described table to be visited of described calling party from the authority record management devices of described server;
Data set is used for the database at described server preservation user data;
Data fetch device is used for reading from described data set the data of the described authorized user under the described mandate catalogue the described table to be visited;
The access rights setting device is provided with the access rights of described data according to the described access rights that read;
Data present device, are used for described data are presented to described calling party.
CNA2007101233795A 2007-06-27 2007-06-27 Method and apparatus for data authorizing and authorized data access in Web application program system Pending CN101335745A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNA2007101233795A CN101335745A (en) 2007-06-27 2007-06-27 Method and apparatus for data authorizing and authorized data access in Web application program system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNA2007101233795A CN101335745A (en) 2007-06-27 2007-06-27 Method and apparatus for data authorizing and authorized data access in Web application program system

Publications (1)

Publication Number Publication Date
CN101335745A true CN101335745A (en) 2008-12-31

Family

ID=40198053

Family Applications (1)

Application Number Title Priority Date Filing Date
CNA2007101233795A Pending CN101335745A (en) 2007-06-27 2007-06-27 Method and apparatus for data authorizing and authorized data access in Web application program system

Country Status (1)

Country Link
CN (1) CN101335745A (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102129539A (en) * 2011-03-11 2011-07-20 清华大学 Data resource authority management method based on access control list
CN102447682A (en) * 2010-10-12 2012-05-09 深圳市专才信息技术有限公司 System and method for obtaining network personal information
CN103020505A (en) * 2012-12-03 2013-04-03 鹤山世达光电科技有限公司 Information management system and information management method based on fingerprint identification
CN103679009A (en) * 2012-09-19 2014-03-26 珠海市君天电子科技有限公司 Terminal security defense method and terminal security defense device
CN105337974A (en) * 2015-10-28 2016-02-17 腾讯科技(深圳)有限公司 Account authorization method, account login method, account authorization device and client end
CN108604279A (en) * 2016-04-11 2018-09-28 惠普发展公司,有限责任合伙企业 Using approval

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102447682A (en) * 2010-10-12 2012-05-09 深圳市专才信息技术有限公司 System and method for obtaining network personal information
CN102129539A (en) * 2011-03-11 2011-07-20 清华大学 Data resource authority management method based on access control list
CN103679009A (en) * 2012-09-19 2014-03-26 珠海市君天电子科技有限公司 Terminal security defense method and terminal security defense device
CN103020505A (en) * 2012-12-03 2013-04-03 鹤山世达光电科技有限公司 Information management system and information management method based on fingerprint identification
WO2014086111A1 (en) * 2012-12-03 2014-06-12 鹤山世达光电科技有限公司 Fingerprint authentication based information management system and information management method
CN105337974A (en) * 2015-10-28 2016-02-17 腾讯科技(深圳)有限公司 Account authorization method, account login method, account authorization device and client end
CN105337974B (en) * 2015-10-28 2020-06-23 腾讯科技(深圳)有限公司 Account authorization method, account login method, account authorization device and client
CN108604279A (en) * 2016-04-11 2018-09-28 惠普发展公司,有限责任合伙企业 Using approval

Similar Documents

Publication Publication Date Title
US11960594B2 (en) Journaling system with segregated data access
CN100474263C (en) Access control protocol for user profile management
CN103916454B (en) Method and device for extending organizational boundaries throughout a cloud architecture
Bowles Corruption
CN101335745A (en) Method and apparatus for data authorizing and authorized data access in Web application program system
WO2008141307A1 (en) System and method for providing services via a network in an emergency context
CN102307185A (en) Data isolation method used in storage cloud
CN102333111A (en) E-government affairs service system based on cloud computing
US20080312962A1 (en) System and method for providing services via a network in an emergency context
CN105190592A (en) E-commerce networking with depth and security factors
CN104679812A (en) Method and system for filtering application content
Agbebi China’s digital Silk Road and Africa’s technological future
CN107944291A (en) Information acquisition method, system and computer-readable recording medium
Borden Covering Your Digital Assets: Why the Stored Communications Act Stands in the Way of Digital Inheritance
CN108737371A (en) Hive data access control methods, server and computer storage media
Shapiro Occupational safety and health regulation
WO2007142063A2 (en) Access control system
Yang et al. System architecture of Library 2.0
Ruan When the winner takes it all
JP3846994B2 (en) Mall server and computer-readable recording medium on which mall server program is recorded
KR100734841B1 (en) Fancy sticker-type RFID tag, privacy-secured on/off-line linking method, using the same and terminal device therefor
KR101870417B1 (en) Method of managing contact list of electronic device using mutual dependence of network relation
Chen Data protection principles governing OBA
Weder Corporate storytelling
Maddern Syndicalism

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
DD01 Delivery of document by public notice

Addressee: Pan Guanghe

Document name: Notification of before Expiration of Request of Examination as to Substance

C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Open date: 20081231