CN110263558A - Service authority management method, device, electronic equipment and computer-readable medium - Google Patents

Service authority management method, device, electronic equipment and computer-readable medium Download PDF

Info

Publication number
CN110263558A
CN110263558A CN201910509910.5A CN201910509910A CN110263558A CN 110263558 A CN110263558 A CN 110263558A CN 201910509910 A CN201910509910 A CN 201910509910A CN 110263558 A CN110263558 A CN 110263558A
Authority
CN
China
Prior art keywords
user
service authority
level
target
secondary user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201910509910.5A
Other languages
Chinese (zh)
Inventor
银广博
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Taikang Insurance Group Co Ltd
Original Assignee
Taikang Insurance Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Taikang Insurance Group Co Ltd filed Critical Taikang Insurance Group Co Ltd
Priority to CN201910509910.5A priority Critical patent/CN110263558A/en
Publication of CN110263558A publication Critical patent/CN110263558A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems

Abstract

This disclosure relates to a kind of service authority management method, device, electronic equipment and computer-readable medium.This method comprises: obtaining the subscription information of target secondary user;At least one primary user that the target secondary user subscribes to is determined according to the subscription information, and obtains at least one service authority that at least one described primary user issues;Obtain at least one target three-level user of the target secondary user subordinate;At least one described service authority is allocated at least one target three-level user, so that the target three-level user executes service management work according at least one described service authority.This disclosure relates to service authority management method, device, electronic equipment and computer-readable medium, multiple tissues can be belonged in same mechanism, in the case that each tissue subscribes to different systems, efficiently manage the service authority issued inside it.

Description

Service authority management method, device, electronic equipment and computer-readable medium
Technical field
This disclosure relates to computer information processing field, in particular to a kind of service authority management method, device, Electronic equipment and computer-readable medium.
Background technique
With the development of internet technology, more and more enterprises have carried out business in network, so that user can be in net Network end transacting business at any time.For facing greatly with multiple systems, tissue and the large enterprise of affiliated institutions or work organization It, need to be according to the concrete condition of each tissue ordering system and the affiliated institutions of each system to every when measuring different business function The permission of one business function is distributed, so that corresponding tissue or affiliated institutions are managed the business that it is responsible for.
By taking HealthCare Enterprise as an example, multiple systems, such as hepatopathy system, tuberculosis system etc., medical treatment enterprise are included in HealthCare Enterprise Again comprising multiple conjuncted tissues of doctor in industry, such as region doctor is conjuncted, trans-regional doctor is conjuncted etc..Each conjuncted subordinate of doctor may include more A medical institutions, such as city-level medical institutions, Health Institutions at County Level etc..In each system, there is multinomial business to be managed, The service authority that the conjuncted tissue of the doctor of its subordinate or medical institutions have according to it is managed corresponding business.Currently, industry The way to manage for permission of being engaged in is single line management, and when type of business is more, single line way to manage has been unable to satisfy convenient and fast demand. Such as when a medical institutions be responsible for manage two systems in multiple business when, need to log into respectively each system with It is managed.Single line management method has been unable to satisfy when same mechanism belongs to multiple tissues, respectively organizes to subscribe to different systems Regulatory requirement.
Therefore, it is necessary to a kind of new service authority management method, device, electronic equipment and computer-readable mediums.
Above- mentioned information are only used for reinforcing the understanding to the background of the disclosure, therefore it disclosed in the background technology part It may include the information not constituted to the prior art known to persons of ordinary skill in the art.
Summary of the invention
In view of this, the disclosure provides a kind of service authority management method, device, electronic equipment and computer-readable Jie Matter can efficiently manage its interior subordinate in the case where same mechanism belong to multiple tissues, respectively tissue subscribes to different systems The service authority of hair.
Other characteristics and advantages of the disclosure will be apparent from by the following detailed description, or partially by the disclosure Practice and acquistion.
According to the one side of the disclosure, it proposes a kind of service authority management method, is applied to Rights Management System, this method It include: the subscription information for obtaining target secondary user, wherein the target secondary user has subscribed at least one primary user, It include at least one service authority in each primary user;Determine what the target secondary user subscribed to according to the subscription information At least one primary user, and obtain at least one service authority that at least one described primary user issues;Obtain the mesh Mark at least one target three-level user of secondary user subordinate, wherein each three-level user is subordinated at least one secondary user; At least one described service authority is allocated at least one target three-level user, so that the target three-level user is according to described At least one service authority executes service management work.
In a kind of exemplary embodiment of the disclosure, further includes: receive the second registration Shen for registering secondary user It please information;The second application for registration information is sent to the primary user, with according to the second application for registration information into Row qualification examination;Receive qualification examination as a result, the qualification examination result be by when, create second application for registration letter Cease corresponding secondary user.
In a kind of exemplary embodiment of the disclosure, the corresponding secondary user of the second application for registration information is created also It include: at least one primary user to be subscribed to for the secondary user based on the second application for registration information, and determine the second level At least one three-level user of user underling.
In a kind of exemplary embodiment of the disclosure, the secondary user is tenant's form.
In a kind of exemplary embodiment of the disclosure, further includes: receive the third for registering three-level user and register Shen It please information;The third application for registration information is sent to the secondary user, with according to the third application for registration information into Row qualification examination;Receive qualification examination as a result, the qualification examination result be by when, create third application for registration letter Cease corresponding three-level user.
In a kind of exemplary embodiment of the disclosure, creates and correspond to three-level user in the third application for registration information also It include: at least one secondary user that three-level user's subordinate is determined based on the third application for registration information, wherein each two The service authority that grade user is had is issued at least one three-level user of secondary user subordinate.
In a kind of exemplary embodiment of the disclosure, at least one industry that at least one described primary user issues is obtained Business permission includes: at least one message queue for obtaining photos and sending messages under at least one primary user;In at least one described message At least one service authority is obtained in queue.
According to the one side of the disclosure, a kind of service authority managing device is proposed, which includes: that subscription information obtains mould Block, for obtaining the subscription information of target secondary user, wherein the target secondary user has subscribed at least one level-one use Family includes at least one service authority in each primary user;Service authority obtains module, for true according to the subscription information At least one primary user that the fixed target secondary user subscribes to, and obtain at least one described primary user and issue at least One service authority;Three-level user's determining module, for obtaining at least one target three-level of the target secondary user subordinate User, wherein each three-level user is subordinated at least one secondary user;Service authority issues module, is used for by described at least One service authority is allocated at least one target three-level user, so that the target three-level user is according at least one described industry Permission of being engaged in executes service management work.
According to the one side of the disclosure, a kind of electronic equipment is proposed, which includes: one or more processors; Storage device, for storing one or more programs;When one or more programs are executed by one or more processors, so that one A or multiple processors realize method as described above.
According to the one side of the disclosure, it proposes a kind of computer-readable medium, is stored thereon with computer program, the program Method as described above is realized when being executed by processor.
According to service authority management method, device, electronic equipment and the computer-readable medium of the disclosure, used by second level The subscription information at family determines the primary user that secondary user subscribes to, to obtain the service authority that primary user issues, and by business Permission is issued to the three-level user of secondary user subordinate, can belong to multiple tissues in same mechanism, respectively organize subscription different In the case where system, the service authority issued inside it is efficiently managed.
It should be understood that the above general description and the following detailed description are merely exemplary, this can not be limited It is open.
Detailed description of the invention
Its example embodiment is described in detail by referring to accompanying drawing, above and other target, feature and the advantage of the disclosure will It becomes more fully apparent.Drawings discussed below is only some embodiments of the present disclosure, for the ordinary skill of this field For personnel, without creative efforts, it is also possible to obtain other drawings based on these drawings.
Fig. 1 is the system scenarios frame of a kind of service authority management method shown according to an exemplary embodiment and device Figure.
Fig. 2 is a kind of flow chart of service authority management method shown according to an exemplary embodiment.
Fig. 3 is a kind of flow chart of the service authority management method shown according to another exemplary embodiment.
Fig. 4 is a kind of schematic diagram of the service authority management method shown according to another exemplary embodiment.
Fig. 5 is a kind of block diagram of service authority managing device shown according to an exemplary embodiment.
Fig. 6 is the block diagram of a kind of electronic equipment shown according to an exemplary embodiment.
Fig. 7 is that a kind of computer readable storage medium schematic diagram is shown according to an exemplary embodiment.
Specific embodiment
Example embodiment is described more fully with reference to the drawings.However, example embodiment can be real in a variety of forms It applies, and is not understood as limited to embodiment set forth herein;On the contrary, thesing embodiments are provided so that the disclosure will be comprehensively and complete It is whole, and the design of example embodiment is comprehensively communicated to those skilled in the art.Identical appended drawing reference indicates in figure Same or similar part, thus repetition thereof will be omitted.
In addition, described feature, structure or characteristic can be incorporated in one or more implementations in any suitable manner In example.In the following description, many details are provided to provide and fully understand to embodiment of the disclosure.However, It will be appreciated by persons skilled in the art that can with technical solution of the disclosure without one or more in specific detail, Or it can be using other methods, constituent element, device, step etc..In other cases, it is not shown in detail or describes known side Method, device, realization or operation are to avoid fuzzy all aspects of this disclosure.
Block diagram shown in the drawings is only functional entity, not necessarily must be corresponding with physically separate entity. I.e., it is possible to realize these functional entitys using software form, or realized in one or more hardware modules or integrated circuit These functional entitys, or these functional entitys are realized in heterogeneous networks and/or processor device and/or microcontroller device.
Flow chart shown in the drawings is merely illustrative, it is not necessary to including all content and operation/step, It is not required to execute by described sequence.For example, some operation/steps can also decompose, and some operation/steps can close And or part merge, therefore the sequence actually executed is possible to change according to the actual situation.
It should be understood that although herein various assemblies may be described using term first, second, third, etc., these groups Part should not be limited by these terms.These terms are to distinguish a component and another component.Therefore, first group be discussed herein below Part can be described as the second component without departing from the teaching of disclosure concept.As used herein, term " and/or " include associated All combinations for listing any of project and one or more.
It will be understood by those skilled in the art that attached drawing is the schematic diagram of example embodiment, module or process in attached drawing Necessary to not necessarily implementing the disclosure, therefore it cannot be used for the protection scope of the limitation disclosure.
In the scene of the service authorization management of medical system, in the prior art, mainly by single line management to every The permission of one business is issued.Presently, there are following disadvantages: the service authority issued is very more;Service management line Number of passes amount (concurrency) is very big;The system and its target that each business adheres to separately issue mechanism or tissue is different.
Current single line management may cause following phenomenon:
When a mechanism needs to manage multiple business, frequent switching is obtained into service authority;
When issuing to service authority, the sending down service of multithreading will generate high concurrent amount, and platform response is caused to become Slowly;
Currently, can not cope with the technical solution of frequent switching and high concurrent amount.
In view of defect in the prior art, present applicant proposes a kind of service authority management method and devices, with second level User subscribes at least one primary user, three-level user is subordinated at least one secondary user as basic framework, realizes that level-one is used The service authority at family issues management.
Fig. 1 is the system scenarios frame of a kind of service authority management method shown according to an exemplary embodiment and device Figure.
As shown in Figure 1, system architecture 100 may include terminal device 101,102,103, network 104 and server 105. Network 104 between terminal device 101,102,103 and server 105 to provide the medium of communication link.Network 104 can be with Including various connection types, such as wired, wireless communication link or fiber optic cables etc..
User can be used terminal device 101,102,103 and be interacted by network 104 with server 105, to receive or send out Send message etc..Various telecommunication customer end applications, such as the application of shopping class, net can be installed on terminal device 101,102,103 The application of page browsing device, searching class application, instant messaging tools, mailbox client, social platform software etc..
Terminal device 101,102,103 can be the various electronic equipments with display screen and supported web page browsing, packet Include but be not limited to smart phone, tablet computer, pocket computer on knee and desktop computer etc..
Server 105 can be to provide the server of various services, such as utilize terminal device 101,102,103 to user The service request proposed provides the right management server supported.Right management server 105 can be to the business received Request and related data carry out the processing such as analyzing, and processing result is fed back to terminal device.
User can generate service request by terminal device 101,102,103, and terminal device 101,102,103 can such as industry Business authority information is forwarded in right management server 105, and right management server 105 can for example obtain target secondary user Subscription information, wherein the target secondary user has subscribed at least one primary user, includes at least one in each primary user A service authority;Server 105 for example can determine that the target secondary user subscribes to according to the subscription information at least one Primary user, and obtain at least one service authority that at least one described primary user issues;Server 105 can be obtained for example At least one target three-level user of the target secondary user subordinate, wherein each three-level user be subordinated at least one two Grade user;And at least one described service authority for example can be sent at least one target three-level user by server 105, with Toilet states target three-level user and executes service management work according at least one described service authority.
Service authority management result also for example can be returned to terminal device 101,102,103, terminal device by server 105 101,102,103 can also for example service authority management result be further processed.
It should be noted that service authority management method provided by the embodiment of the present disclosure can be executed by server 105, Correspondingly, service authority managing device can be set in server 105.And it is supplied to page end that user is browsed and mentions The request end of service authority management request is normally in terminal device 101,102,103 out.
According to the service authority management method and device of the disclosure, secondary user is determined by the subscription information of secondary user Service authority to obtain the service authority that primary user issues, and is issued to secondary user subordinate's by the primary user of subscription Three-level user can efficiently manage it in the case where same mechanism belong to multiple tissues, respectively tissue subscribes to different systems The service authority that inside issues.The service authority management method of the disclosure can be applied to multi-stage user Rights Management System, example Such as, in the scene of the service authorization management of medical system, three-level user (i.e. medical institutions) subordinate further includes that level Four user (divides Branch organization user) and Pyatyi user (department under branch), six grades of users (doctor in section room under branched structure), the disclosure Service authority management method can be applied to the Rights Management System between level Four user, Pyatyi user, six grades of users, additionally it is possible to answer For the Rights Management System between three-level user, level Four user, Pyatyi user etc. any three users with relationship between superior and subordinate. Fig. 2 is a kind of flow chart of service authority management method shown according to an exemplary embodiment.This method can be applied to permission Management system.Service authority management method 20 includes at least step S202 to S208.
As shown in Fig. 2, obtaining the subscription information of target secondary user in step S202, wherein the target second level is used Family has subscribed at least one primary user, includes at least one service authority in each primary user.Wherein, service authority information It is issued by primary user.For example, in HealthCare Enterprise, in multiple pathology systems such as hepatopathy system be primary user, liver The service authority that sick system issues may include hepatic diseases business, such as, but not limited to hepatopathy follow-up business, clinical liver disease pipe Reason business etc..Hepatopathy system is by issuing the service authority information, so that relevant tissue or affiliated institutions pass through this Service authority is managed corresponding business.Wherein, the conjuncted tissue of relevant doctor can be secondary user, such as region doctor is conjuncted Tissue, the conjuncted tissue of transregional doctor etc..Service authority information is settlement of exchange business in foreign exchange system, outer in another example in financial company The technical solution of service authority information of coin finance services etc. etc., the disclosure is not limited thereto.In another example in HealthCare Enterprise In, medical institutions subordinate further includes medical institutions, branch, subordinate department, medical institutions, branch, subordinate department, medical institutions, branch Doctor can respectively correspond, the service authority manager of the application with the primary user of the present embodiment, secondary user, three-level user Method is to the specific level of user and is not particularly limited.
It wherein, may include business information in service authority information, business information is that the execution side of business function is somebody's turn to do in management The information needed when business, the such as, but not limited to capability identification of business side's identification code, business function interface and the business Code etc..
In step S204, determine that at least one level-one that the target secondary user subscribes to is used according to the subscription information Family, and obtain at least one service authority that at least one described primary user issues.
In one embodiment, obtaining at least one service authority that at least one described primary user issues includes: to obtain Take at least one message queue of photos and sending messages under at least one primary user;It is obtained at least at least one described message queue One service authority.Wherein, it subscribes to and is derived from Publish-subscribe mode.Publish-subscribe mode is a kind of message normal form, the hair of message The person of sending (referred to as publisher) will not send messages directly to specific recipient (referred to as subscriber).But by the message of publication Be divided into different classifications, without understand which subscriber (if any) there may be.Likewise, subscriber can express pair The interest of one or more classifications only receives interested message, exists without understanding which publisher (if any).Hair Publisher and subscriber's loose coupling in cloth-subscribing mode, in this embodiment it is not even necessary to know their presence.In traditional tightly coupled visitor In family end-server mode, when server processes are not run, client can not send messages to server, server also without Method receives message when client is not run.Many publish/subscribe systems not only decouple publisher and subscriber from position, Also them are decoupled from the time.
Wherein, intermediate conveyor mechanism of the message queue between publisher and subscriber.Each queue has a theme, only connects Receive the service authority information with corresponding subject information.A service authority is issued when publisher, that is, primary user business side is sent When information, it can will be sent in message queue according to its subject information.Subscriber can subscribe to one or more theme message queues, The theme subscribed to according to it receives the corresponding message in message queue to receive its subscription, in the disclosure, in message queue Message can be service authority information.
In step S206, at least one target three-level user of the target secondary user subordinate is obtained, wherein each Three-level user is subordinated at least one secondary user.Such as aforementioned citing, in HealthCare Enterprise, each secondary user is cured in such as region Under conjuncted tissue, it may include at least one medical institutions, such as certain the People's Hospital, city, certain area, city health center etc., such doctor Treating mechanism can be three-level user.In one embodiment, three-level user (medical institutions) subordinate may also include level Four user (branch Organization user) and Pyatyi user (department under branch), six grades of users (doctor in section room under branched structure), the present embodiment Service authority management method applies also for the service authority management system between three-level user, level Four user, Pyatyi user, this Shen Please to this and it is not particularly limited.It in one embodiment, can be according to the business processing capacity of each three-level user to the three-level User's issuing service permission.Business processing capacity is the total capacity for the number of services being capable of handling that three-level user has.For example, Multiple service authorities in hepatopathy system are being issued to certain as the Health Institutions at County Level of the first object and the therapeutic machine at county level When the hepatopathy department of structure, the business processing capacity of Health Institutions at County Level is 10, and the business processing capacity of hepatopathy department is 5.By liver 10 service authorities in sick system are sent to Health Institutions at County Level, and 5 service authorities are sent to hepatopathy department.Wherein, at county level 5 service authorities that 10 service authorities and hepatopathy department that medical institutions receive receive can have non-empty intersection, this Disclosed technical solution is to this and is not particularly limited.
In step S208, at least one described service authority is sent at least one target three-level user, with toilet It states target three-level user and service management work is executed according at least one described service authority.Wherein, target three-level user can be Business information is extracted in service authority, for example, target three-level user can login the business interface according to business information and according to it The permission having executes service management work.
In one embodiment, further includes: receive the second application for registration information for registering secondary user;By described Two application for registration information are sent to the primary user, to carry out qualification examination according to the second application for registration information;It receives Qualification examination as a result, the qualification examination result be by when, create the corresponding second level of the second application for registration information and use Family.Wherein, include the pending nuclear material of application for registration in the second application for registration information, can be legal person's data etc..For example, curing In the application scenarios for treating enterprise, when third party user cures conjuncted group by the conjuncted tissue of one new doctor of system registry such as region When knitting, material can be registered to it by primary user such as system user and audited.
In one embodiment, the corresponding secondary user of the second application for registration information is created further include: based on described Second application for registration information is that at least one primary user is subscribed to by the secondary user, and determines secondary user subordinate at least One three-level user.It wherein, may include that the level-one use of subscription it is expected by the secondary user of the new registration in the second application for registration information The three-level user at family and its subordinate.The secondary user is added according to above- mentioned information, at least one level-one is subscribed to secondary user User, three-level user are subordinated in the architecture of at least one secondary user.For example, in the application scenarios of HealthCare Enterprise, When third party user is by one new doctor of system registry conjuncted tissue such as conjuncted tissue of region doctor, the conjuncted tissue of the doctor The primary user to pull subscription in second application for registration information includes: hepatopathy system, cardiovascular disease system;The three-level of subordinate is used When family (i.e. medical institutions) includes: Health Institutions at County Level A, Health Institutions at County Level B, the subscribing relationship and subordinate relation can be carried out It audits and creates.
In one embodiment, the secondary user is tenant's form.Wherein, multiple secondary users will constitute multi-tenant shape Formula.Multi-tenant technology (Multi-Tenancy Technology) or multiple leasing techniques are a kind of software architecture technologies, it It is to share identical system or program assembly in the environment of how inquiring into realization in multi-user, and still can ensure that each user Between data isolation.Shared system example between multiple tenants may be implemented in multi-tenant technology, while tenant may be implemented again System example personalized customization.It can guarantee that the part of system general character is shared by using multi-tenant technology, individual character Part is chambers are individually isolated.
In one embodiment, the method also includes: receive the third application for registration information for registering three-level user; The third application for registration information is sent to the secondary user, is examined with carrying out qualification according to the third application for registration information Core;Receive qualification examination as a result, the qualification examination result be by when, it is corresponding to create the third application for registration information Three-level user.Wherein, include the pending nuclear material of application for registration in third application for registration information, can be legal person's data etc..Example Such as, in the application scenarios of HealthCare Enterprise, when third party user passes through one new medical institutions of system registry such as certain city people When people hospital, conjuncted organizing user can be such as cured by secondary user material is registered to it and audited.
In one embodiment, it creates in the third application for registration information and corresponds to three-level user further include: based on described Third application for registration information determines at least one secondary user of three-level user's subordinate, wherein each secondary user is had Some service authorities are issued at least one three-level user of secondary user subordinate.It may include this in third application for registration information The three-level user of new registration it is expected the secondary user of subordinate.Three-level user is added according to above- mentioned information and is subscribed to secondary user At least one primary user, three-level user are subordinated in the architecture of at least one secondary user.For example, in HealthCare Enterprise In application scenarios, when third party user passes through such as certain the People's Hospital, city, one new medical institutions of system registry, the medical treatment The secondary user that subordinate is requested in the third application for registration information of mechanism includes: that conjuncted tissue C, trans-regional conjuncted group of doctor are cured in region When knitting D, which can be audited and created.
According to the service authority management method of the disclosure, determine what secondary user subscribed to by the subscription information of secondary user Primary user to obtain the service authority that primary user issues, and the three-level that service authority is issued to secondary user subordinate is used Family, it can be ensured that service authority is issued to secondary user by primary user and is issued to the three-level of its subordinate by secondary user Accuracy when customer service.The response of system caused by high concurrent amount will be avoided slowly based on this, and raising issues efficiency;Avoid frequency Numerous switching obtains the complex operations of service authority, enhances user experience;Multiple tissues, each tissue can be belonged in same mechanism In the case where subscribing to different systems, the service authority issued inside it is efficiently managed.The service authority manager of the disclosure Method can be applied to multi-stage user Rights Management System, for example, three-level is used in the scene of the service authorization management of medical system Family (i.e. medical institutions) subordinate further includes level Four user (branch office customer) and Pyatyi user (department under branch), six grades User (doctor in section room under branched structure), the service authority management method of the disclosure can be applied to level Four user, Pyatyi is used Rights Management System between family, six grades of users, additionally it is possible to be applied to any three of three-level user, level Four user, Pyatyi user etc. Rights Management System between user with relationship between superior and subordinate.
It will be clearly understood that the present disclosure describes how to form and use particular example, but the principle of the disclosure is not limited to These exemplary any details.On the contrary, the introduction based on disclosure disclosure, these principles can be applied to many other Embodiment.
Fig. 3 is a kind of flow chart of the service authority management method shown according to another exemplary embodiment.Fig. 3 is schematic Show the flow chart of one embodiment of the step S204 in Fig. 2.
As shown in figure 3, in step s 302, obtaining at least one message team of photos and sending messages under at least one primary user Column.Wherein, each message queue has been endowed a theme, and the service authority information with identical subject information will be sent to this Queue.After service authority information is sent to queue, business, which sends hair such as system, can continue normal operating without concern The subsequent transmission process of the service authority information.In addition, client can still believe service authority when server processes are not run Breath is sent to queue, receives the service authority information when server processes are run again, then through queue.
In step s 304, at least one service authority is obtained at least one described message queue.Wherein, each to order Reader (i.e. secondary user) can subscribe to multiple themes, its corresponding message queue be determined by the theme of Subscriber subscriptions, to obtain Take the service authority information in message queue.Subscriber can occur in the form of tenant.
In one embodiment, secondary user can be managed by top secondary user, such as to secondary user Register audit, audit of institutional framework etc..When subscriber is the form of tenant, each tenant has a self contained data base, There is shared data bank simultaneously.All subject informations and the subscription situation of subscriber etc. can be stored in shared data bank, it is independent Subordinate's three-level user, institutional framework and its list for subscribing to theme, the industry having had of the subscriber can be stored in database Business authority information etc..
It will be appreciated by those skilled in the art that realizing that all or part of the steps of above-described embodiment is implemented as being executed by CPU Computer program.When the computer program is executed by CPU, above-mentioned function defined by the above method that the disclosure provides is executed Energy.The program can store in a kind of computer readable storage medium, which can be read-only memory, magnetic Disk or CD etc..
Further, it should be noted that above-mentioned attached drawing is only the place according to included by the method for disclosure exemplary embodiment Reason schematically illustrates, rather than limits purpose.It can be readily appreciated that above-mentioned processing shown in the drawings is not indicated or is limited at these The time sequencing of reason.In addition, be also easy to understand, these processing, which can be, for example either synchronously or asynchronously to be executed in multiple modules.
Following is embodiment of the present disclosure, can be used for executing embodiments of the present disclosure.It is real for disclosure device Undisclosed details in example is applied, embodiments of the present disclosure is please referred to.
Fig. 4 is a kind of block diagram of service authority managing device shown according to an exemplary embodiment.Service authority management Device 40 includes: that subscription information obtains module 402, and service authority obtains module 404, three-level user determining module 406, operational authority Limit issues module 408.
In service authority managing device 40, subscription information obtains the subscription that module 402 is used to obtain target secondary user Information, wherein the target secondary user has subscribed at least one primary user, includes at least one industry in each primary user Business permission.It wherein, may include business information in service authority information, business information is that the execution side of business function is managing the industry The information needed when business, such as, but not limited to the capability identification code of business side's identification code, business function interface and the business Deng.The service authority information issues destination to subject information for identification.
Service authority obtains module 404 and is used to determine that the target secondary user subscribes at least according to the subscription information One primary user, and obtain at least one service authority that at least one described primary user issues.
In one embodiment, it may include message queue determining module that service authority, which obtains module 404, for obtaining at least At least one message queue of photos and sending messages under one primary user;Service authority determining module, for it is described at least one disappear At least one service authority is obtained in breath queue.
At least one target three-level that three-level user determining module 406 is used to obtain the target secondary user subordinate is used Family, wherein each three-level user is subordinated at least one secondary user.In one embodiment, three-level user determining module 406 It can be used for according to the business processing capacity of each three-level user to three-level user's issuing service permission.
Service authority issues module 408 and uses at least one described service authority to be allocated at least one target three-level Family, so that the target three-level user executes service management work according at least one described service authority.
In one embodiment, service authority managing device 40 may also include secondary user's registration auditing module, can be used for Receive the second application for registration information for registering secondary user;The second application for registration information is sent to the level-one to use Family, to carry out qualification examination according to the second application for registration information;Qualification examination is received as a result, in the qualification examination result For by when, create the corresponding secondary user of the second application for registration information.
In one embodiment, secondary user register auditing module can also be used in based on the second application for registration information as At least one primary user is subscribed to by the secondary user, and determines at least one three-level user of secondary user subordinate.
In one embodiment, the secondary user is tenant's form.
In one embodiment, service authority managing device 40 may also include three-level user's registration auditing module, can be used for Receive the third application for registration information for registering three-level user;The third application for registration information is sent to the second level to use Family, to carry out qualification examination according to the third application for registration information;Qualification examination is received as a result, in the qualification examination result For by when, create the corresponding three-level user of the third application for registration information.
In one embodiment, three-level user's registration auditing module can be used for determining based on the third application for registration information At least one secondary user of three-level user's subordinate, wherein the service authority that each secondary user is had is issued to this At least one three-level user of secondary user subordinate.
According to the service authority managing device of the disclosure, determine what secondary user subscribed to by the subscription information of secondary user Primary user to obtain the service authority that primary user issues, and the three-level that service authority is issued to secondary user subordinate is used Family, it can be ensured that service authority is issued to secondary user by primary user and is issued to the three-level of its subordinate by secondary user Accuracy when customer service.The response of system caused by high concurrent amount will be avoided slowly based on this, and raising issues efficiency;Avoid frequency Numerous switching obtains the complex operations of service authority, enhances user experience;Multiple tissues, each tissue can be belonged in same mechanism In the case where subscribing to different systems, the service authority issued inside it is efficiently managed.The service authority management of the disclosure fills It sets and can be applied to multi-stage user Rights Management System, for example, three-level is used in the scene of the service authorization management of medical system Family (i.e. medical institutions) subordinate further includes level Four user (branch office customer) and Pyatyi user (department under branch), six grades User (doctor in section room under branched structure), the service authority management method of the disclosure can be applied to level Four user, Pyatyi is used Rights Management System between family, six grades of users, additionally it is possible to be applied to any three of three-level user, level Four user, Pyatyi user etc. Rights Management System between user with relationship between superior and subordinate.
Fig. 5 is a kind of block diagram of the service authority managing device shown according to another exemplary embodiment.Service authority pipe The technical solution that reason device 50 describes the disclosure is applied to schematic diagram when medical institutions, and service authority managing device 50 is at least Including platform class line module 502, tenant's grade line module 504 and mechanism grade line module 506.Wherein, medical institutions W, Both belong to member in the conjuncted tissue A of the doctor in administrative division, and also belong to member in the trans-regional conjuncted B of doctor, while the section in hospital Room also may belong to the member that people's training in administrative division cures conjuncted C, also may belong to trans-regional training cure conjuncted D at Member.Medical institutions W, the conjuncted tissue of doctor have an administrator to cope with rights management work.Platform class user is management system Management user, it is 1 pair 1 or 1 pair 0 of relationship with conjuncted tissue is cured that tenant grade user, which is the user of tenant's form,.1 pair 0 The case where relationship is tenant top-level administrator.Tenant top-level administrator manages all tenants.Mechanism grade user is medical institutions' grade User, such as mechanism responsible person, department responsible person etc..
As shown in figure 5, platform class line module 502 be used for platform class user, platform feature, tenant registration and examine Core, the registration of system and management, micro services directory management, the audit of tenant's ordering system, tenant top-level administrator the works such as permission It is managed.Wherein, micro services directory management refers to the business function for being exposed to third party user, such as, but not limited to looks into The catalogue of the functions such as inquiry, uploading pictures.
Platform class line module is responsible for the registration management of system and module, such as by the function mould in system and system Block is registered respectively, and concentration is managed by the user that platform is responsible for O&M.
Tenant grade line module 504 is used to registering tenant and submitting audit, subscription and dissemination system and micro services, note The work such as volume, audit tenant's grade institutional framework, setting Lower Establishment permission are managed.
Mechanism grade line module 506 is used for institute registration and tissue audit is added, and setting department and mechanism parameter are set The work such as organization user and permission are set to be managed.Wherein, its system-level ginseng oneself can be arranged after ordering system in tenant Number, such as by the part of tenant's administrator setting, and the part of the administrator setting by Lower Establishment.
Fig. 6 is the block diagram of a kind of electronic equipment shown according to an exemplary embodiment.
The electronic equipment 200 of this embodiment according to the disclosure is described referring to Fig. 6.The electronics that Fig. 6 is shown Equipment 200 is only an example, should not function to the embodiment of the present disclosure and use scope bring any restrictions.
As shown in fig. 6, electronic equipment 200 is showed in the form of universal computing device.The component of electronic equipment 200 can wrap It includes but is not limited to: at least one processing unit 210, at least one storage unit 220, (including the storage of the different system components of connection Unit 220 and processing unit 210) bus 230, display unit 240 etc..
Wherein, the storage unit is stored with program code, and said program code can be held by the processing unit 210 Row, so that the processing unit 210 executes described in this specification above-mentioned electronic prescription circulation processing method part according to this The step of disclosing various illustrative embodiments.For example, the processing unit 210 can be executed such as Fig. 2, walked shown in Fig. 3 Suddenly.
The storage unit 220 may include the readable medium of volatile memory cell form, such as random access memory Unit (RAM) 2201 and/or cache memory unit 2202 can further include read-only memory unit (ROM) 2203.
The storage unit 220 can also include program/practical work with one group of (at least one) program module 2205 Tool 2204, such program module 2205 includes but is not limited to: operating system, one or more application program, other programs It may include the realization of network environment in module and program data, each of these examples or certain combination.
Bus 230 can be to indicate one of a few class bus structures or a variety of, including storage unit bus or storage Cell controller, peripheral bus, graphics acceleration port, processing unit use any bus structures in a variety of bus structures Local bus.
Electronic equipment 200 can also be with one or more external equipments 300 (such as keyboard, sensing equipment, bluetooth equipment Deng) communication, can also be enabled a user to one or more equipment interact with the electronic equipment 200 communicate, and/or with make Any equipment (such as the router, modulation /demodulation that the electronic equipment 200 can be communicated with one or more of the other calculating equipment Device etc.) communication.This communication can be carried out by input/output (I/O) interface 250.Also, electronic equipment 200 can be with By network adapter 260 and one or more network (such as local area network (LAN), wide area network (WAN) and/or public network, Such as internet) communication.Network adapter 260 can be communicated by bus 230 with other modules of electronic equipment 200.It should Understand, although not shown in the drawings, other hardware and/or software module can be used in conjunction with electronic equipment 200, including but unlimited In: microcode, device driver, redundant processing unit, external disk drive array, RAID system, tape drive and number According to backup storage system etc..
Through the above description of the embodiments, those skilled in the art is it can be readily appreciated that example described herein is implemented Mode can also be realized by software realization in such a way that software is in conjunction with necessary hardware.Therefore, according to the disclosure The technical solution of embodiment can be embodied in the form of software products, which can store non-volatile at one Property storage medium (can be CD-ROM, USB flash disk, mobile hard disk etc.) in or network on, including some instructions are so that a calculating Equipment (can be personal computer, server or network equipment etc.) executes the above method according to disclosure embodiment.
Figure, 7 schematically show a kind of computer readable storage medium schematic diagram in disclosure exemplary embodiment.
Refering to what is shown in Fig. 7, describing the program product for realizing the above method according to embodiment of the present disclosure 400, can using portable compact disc read only memory (CD-ROM) and including program code, and can in terminal device, Such as it is run on PC.However, the program product of the disclosure is without being limited thereto, in this document, readable storage medium storing program for executing can be with To be any include or the tangible medium of storage program, the program can be commanded execution system, device or device use or It is in connection.
Described program product can be using any combination of one or more readable mediums.Readable medium can be readable letter Number medium or readable storage medium storing program for executing.Readable storage medium storing program for executing for example can be but be not limited to electricity, magnetic, optical, electromagnetic, infrared ray or System, device or the device of semiconductor, or any above combination.The more specific example of readable storage medium storing program for executing is (non exhaustive List) include: electrical connection with one or more conducting wires, portable disc, hard disk, random access memory (RAM), read-only Memory (ROM), erasable programmable read only memory (EPROM or flash memory), optical fiber, portable compact disc read only memory (CD-ROM), light storage device, magnetic memory device or above-mentioned any appropriate combination.
The computer readable storage medium may include in a base band or the data as the propagation of carrier wave a part are believed Number, wherein carrying readable program code.The data-signal of this propagation can take various forms, including but not limited to electromagnetism Signal, optical signal or above-mentioned any appropriate combination.Readable storage medium storing program for executing can also be any other than readable storage medium storing program for executing Readable medium, the readable medium can send, propagate or transmit for by instruction execution system, device or device use or Person's program in connection.The program code for including on readable storage medium storing program for executing can transmit with any suitable medium, packet Include but be not limited to wireless, wired, optical cable, RF etc. or above-mentioned any appropriate combination.
Can with any combination of one or more programming languages come write for execute the disclosure operation program Code, described program design language include object oriented program language-Java, C++ etc., further include conventional Procedural programming language-such as " C " language or similar programming language.Program code can be fully in user It calculates and executes in equipment, partly executes on a user device, being executed as an independent software package, partially in user's calculating Upper side point is executed on a remote computing or is executed in remote computing device or server completely.It is being related to far Journey calculates in the situation of equipment, and remote computing device can pass through the network of any kind, including local area network (LAN) or wide area network (WAN), it is connected to user calculating equipment, or, it may be connected to external computing device (such as utilize ISP To be connected by internet).
Above-mentioned computer-readable medium carries one or more program, when said one or multiple programs are by one When the equipment executes, so that the computer-readable medium implements function such as: the subscription information of target secondary user is obtained, In, the target secondary user has subscribed at least one primary user, includes at least one service authority in each primary user; Determine at least one primary user that the target secondary user subscribes to according to the subscription information, and obtain it is described at least one At least one service authority that primary user issues;At least one the target three-level for obtaining the target secondary user subordinate is used Family, wherein each three-level user is subordinated at least one secondary user;At least one described service authority is allocated at least one A target three-level user, so that the target three-level user executes service management work according at least one described service authority.
It will be appreciated by those skilled in the art that above-mentioned each module can be distributed in device according to the description of embodiment, it can also Uniquely it is different from one or more devices of the present embodiment with carrying out corresponding change.The module of above-described embodiment can be merged into One module, can also be further split into multiple submodule.
By the description of above embodiment, those skilled in the art is it can be readily appreciated that example embodiment described herein It can also be realized in such a way that software is in conjunction with necessary hardware by software realization.Therefore, implemented according to the disclosure The technical solution of example can be embodied in the form of software products, which can store in a non-volatile memories In medium (can be CD-ROM, USB flash disk, mobile hard disk etc.) or on network, including some instructions are so that a calculating equipment (can To be personal computer, server, mobile terminal or network equipment etc.) it executes according to the method for the embodiment of the present disclosure.
It is particularly shown and described the exemplary embodiment of the disclosure above.It should be appreciated that the present disclosure is not limited to Detailed construction, set-up mode or implementation method described herein;On the contrary, disclosure intention covers included in appended claims Various modifications and equivalence setting in spirit and scope.
In addition, structure shown by this specification Figure of description, ratio, size etc., only to cooperate specification institute Disclosure, for skilled in the art realises that be not limited to the enforceable qualifications of the disclosure with reading, therefore Do not have technical essential meaning, the modification of any structure, the change of proportionate relationship or the adjustment of size are not influencing the disclosure Under the technical effect and achieved purpose that can be generated, it should all still fall in technology contents disclosed in the disclosure and obtain and can cover In the range of.Meanwhile cited such as "upper" in this specification, " first ", " second " and " one " term, be also only and be convenient for Narration is illustrated, rather than to limit the enforceable range of the disclosure, relativeness is altered or modified, without substantive change Under technology contents, when being also considered as the enforceable scope of the disclosure.

Claims (10)

1. a kind of service authority management method, which is characterized in that be applied to Rights Management System, comprising:
Obtain the subscription information of target secondary user, wherein the target secondary user has subscribed at least one primary user, often It include at least one service authority in one primary user;
At least one primary user that the target secondary user subscribes to is determined according to the subscription information, and acquisition is described at least At least one service authority that one primary user issues;
Obtain at least one target three-level user of the target secondary user subordinate, wherein each three-level user be subordinated to A few secondary user;
At least one described service authority is allocated at least one target three-level user, so as to the target three-level user according to At least one described service authority executes service management work.
2. the method as described in claim 1, which is characterized in that further include:
Receive the second application for registration information for registering secondary user;
The second application for registration information is sent to the primary user, to be provided according to the second application for registration information Lattice audit;
Receive qualification examination as a result, the qualification examination result be by when, it is corresponding to create the second application for registration information Secondary user.
3. method according to claim 2, which is characterized in that the corresponding secondary user of creation the second application for registration information Further include:
It is that at least one primary user is subscribed to by the secondary user, and determines that the second level is used based on the second application for registration information At least one three-level user of family subordinate.
4. the method as described in claim 1, which is characterized in that the secondary user is tenant's form.
5. the method as described in claim 1, which is characterized in that further include:
Receive the third application for registration information for registering three-level user;
The third application for registration information is sent to the secondary user, to be provided according to the third application for registration information Lattice audit;
Receive qualification examination as a result, the qualification examination result be by when, it is corresponding to create the third application for registration information Three-level user.
6. method as claimed in claim 5, which is characterized in that create in the third application for registration information and correspond to three-level user Further include:
At least one secondary user of three-level user's subordinate is determined based on the third application for registration information, wherein each two The service authority that grade user is had is issued at least one three-level user of secondary user subordinate.
7. the method as described in claim 1, which is characterized in that obtain at least one that at least one described primary user issues Service authority includes:
Obtain at least one message queue of photos and sending messages under at least one primary user;
At least one service authority is obtained at least one described message queue.
8. a kind of service authority managing device characterized by comprising
Subscription information obtains module, for obtaining the subscription information of target secondary user, wherein the target secondary user subscribes to At least one primary user includes at least one service authority in each primary user;
Service authority obtains module, for determining that the target secondary user subscribes to according to the subscription information at least one one Grade user, and obtain at least one service authority that at least one described primary user issues;
Three-level user's determining module, for obtaining at least one target three-level user of the target secondary user subordinate, wherein Each three-level user is subordinated at least one secondary user;
Service authority issues module, at least one described service authority to be allocated at least one target three-level user, with Toilet states target three-level user and executes service management work according at least one described service authority.
9. a kind of electronic equipment characterized by comprising
One or more processors;
Storage device, for storing one or more programs;
When one or more of programs are executed by one or more of processors, so that one or more of processors are real The now method as described in any in claim 1-7.
10. a kind of computer-readable medium, is stored thereon with computer program, which is characterized in that described program is held by processor The method as described in any in claim 1-7 is realized when row.
CN201910509910.5A 2019-06-13 2019-06-13 Service authority management method, device, electronic equipment and computer-readable medium Pending CN110263558A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910509910.5A CN110263558A (en) 2019-06-13 2019-06-13 Service authority management method, device, electronic equipment and computer-readable medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910509910.5A CN110263558A (en) 2019-06-13 2019-06-13 Service authority management method, device, electronic equipment and computer-readable medium

Publications (1)

Publication Number Publication Date
CN110263558A true CN110263558A (en) 2019-09-20

Family

ID=67917975

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910509910.5A Pending CN110263558A (en) 2019-06-13 2019-06-13 Service authority management method, device, electronic equipment and computer-readable medium

Country Status (1)

Country Link
CN (1) CN110263558A (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111339561A (en) * 2020-02-28 2020-06-26 北京字节跳动网络技术有限公司 Data processing method, electronic device and storage medium
CN111600942A (en) * 2020-05-09 2020-08-28 海信集团有限公司 Report processing method, device and equipment
CN112270003A (en) * 2020-10-27 2021-01-26 上海淇馥信息技术有限公司 Multi-service dynamic data source configuration method, platform and electronic equipment
CN114760134A (en) * 2022-04-18 2022-07-15 成都星云智联科技有限公司 Multi-tenant isolation method and related device
CN115296880A (en) * 2022-07-27 2022-11-04 北京快乐茄信息技术有限公司 Data permission determination method and device, electronic equipment and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1787528A (en) * 2005-11-07 2006-06-14 中兴通讯股份有限公司 Method for realizing information grading authorized access in presenting service system
CN103516680A (en) * 2012-06-25 2014-01-15 上海博腾信息科技有限公司 Authority management system of office system and realizing method thereof
CN105359126A (en) * 2013-03-15 2016-02-24 格林伊登美国控股有限责任公司 Hybrid cloud architecture with optimized local delivery
CN106790154A (en) * 2016-12-29 2017-05-31 江西博瑞彤芸科技有限公司 User right information generation method

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1787528A (en) * 2005-11-07 2006-06-14 中兴通讯股份有限公司 Method for realizing information grading authorized access in presenting service system
CN103516680A (en) * 2012-06-25 2014-01-15 上海博腾信息科技有限公司 Authority management system of office system and realizing method thereof
CN105359126A (en) * 2013-03-15 2016-02-24 格林伊登美国控股有限责任公司 Hybrid cloud architecture with optimized local delivery
CN106790154A (en) * 2016-12-29 2017-05-31 江西博瑞彤芸科技有限公司 User right information generation method

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
艾利克斯洪木尔: "《云计算架构设计模式》", 31 December 2017 *

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111339561A (en) * 2020-02-28 2020-06-26 北京字节跳动网络技术有限公司 Data processing method, electronic device and storage medium
CN111339561B (en) * 2020-02-28 2023-04-07 北京字节跳动网络技术有限公司 Data processing method, electronic device and storage medium
CN111600942A (en) * 2020-05-09 2020-08-28 海信集团有限公司 Report processing method, device and equipment
CN112270003A (en) * 2020-10-27 2021-01-26 上海淇馥信息技术有限公司 Multi-service dynamic data source configuration method, platform and electronic equipment
CN112270003B (en) * 2020-10-27 2023-05-02 上海淇馥信息技术有限公司 Multi-service dynamic data source configuration method, platform and electronic equipment
CN114760134A (en) * 2022-04-18 2022-07-15 成都星云智联科技有限公司 Multi-tenant isolation method and related device
CN115296880A (en) * 2022-07-27 2022-11-04 北京快乐茄信息技术有限公司 Data permission determination method and device, electronic equipment and storage medium

Similar Documents

Publication Publication Date Title
CN110263558A (en) Service authority management method, device, electronic equipment and computer-readable medium
Kuperman Health-information exchange: why are we doing it, and what are we doing?
Lenert et al. Shifts in the architecture of the Nationwide Health Information Network
GB2559521A (en) Platform for the delivery of content and services to networked connected computing devices
Symons et al. From EHR to PHR: let’s get the record straight
AU2020282947B2 (en) Interoperability test environment
Wang et al. The external and internal barriers to E-government Implementation
CN111402045B (en) Account data supervision method and device
US20100293182A1 (en) Method and apparatus for viewing documents in a database
Overhage Health Information Exchange:‘Lex Parsimoniae’ HIE developers must resist the temptation to overspecify, instead allowing local flexibility with some oversight to maintain consistency.
AU2012300188B2 (en) A collaboration computer system
Shah et al. A cost model for personal health records (PHRs)
Barclay et al. Towards a modelling framework for self-sovereign identity systems
Nan et al. Enabling tiered and coordinated services in a health community of primary care facilities and county hospitals based on HL7 FHIR
CN107408267B (en) Access control method, system and storage medium
Ojo et al. Semantic interoperability architecture for Governance 2.0
Al Masud A novel approach to introduce cloud services in healthcare sectors for the medically underserved populations in south asia
Staes et al. A case for using grid architecture for state public health informatics: the Utah perspective
Babu et al. Web Based Hospital Management System
Paiti What are the opportunities and challenges of cloud computing technology in the healthcare information systems
Randolph Blockchain-based Medical Image Sharing and Critical-result Notification
de Sousa Interoperability Between Information Systems of the Results of Clinical Analysis and Electronic Record of the Patient
Agarwal et al. A Cloud Computing Based Patient Centric Medical Information System
Bautista et al. MediLinker: a blockchain-based decentralized health information management platform for patient-centric healthcare
Rahimisadegh et al. Network analysis of Iranian's health insurance ecosystem before and after the introduction of Universal Health Insurance law

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20190920