CN112632501A - Data processing method and device - Google Patents
Data processing method and device Download PDFInfo
- Publication number
- CN112632501A CN112632501A CN202011625771.1A CN202011625771A CN112632501A CN 112632501 A CN112632501 A CN 112632501A CN 202011625771 A CN202011625771 A CN 202011625771A CN 112632501 A CN112632501 A CN 112632501A
- Authority
- CN
- China
- Prior art keywords
- data
- organization
- belongs
- employee
- determining
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000003672 processing method Methods 0.000 title abstract description 9
- 230000008520 organization Effects 0.000 claims abstract description 121
- 238000012545 processing Methods 0.000 claims abstract description 7
- 238000000034 method Methods 0.000 claims description 24
- 230000004044 response Effects 0.000 claims description 6
- 230000001960 triggered effect Effects 0.000 claims description 6
- 238000011161 development Methods 0.000 description 13
- 238000012423 maintenance Methods 0.000 description 3
- 238000010586 diagram Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000011160 research Methods 0.000 description 2
- 230000006978 adaptation Effects 0.000 description 1
- 230000006872 improvement Effects 0.000 description 1
- 238000012827 research and development Methods 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/22—Indexing; Data structures therefor; Storage structures
- G06F16/2228—Indexing structures
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/24—Querying
- G06F16/245—Query processing
- G06F16/2457—Query processing with adaptation to user needs
- G06F16/24573—Query processing with adaptation to user needs using data annotations, e.g. user-defined metadata
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/28—Databases characterised by their database models, e.g. relational or object models
- G06F16/284—Relational databases
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Databases & Information Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Data Mining & Analysis (AREA)
- Software Systems (AREA)
- Computer Security & Cryptography (AREA)
- Library & Information Science (AREA)
- Computational Linguistics (AREA)
- Computer Hardware Design (AREA)
- Storage Device Security (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
The application discloses a data processing method and a data processing device.A server firstly obtains an identifier of a first employee and then determines an organization to which the first employee belongs according to the identifier of the first employee, wherein the organization to which the first employee belongs can be a department in which the first employee is located or an organization level of the first employee. Then, the server obtains a system tag of the first data, where the system tag of the first data is used to indicate a data system to which the first data belongs, and the data system differs according to a data source, and may be, for example, a financial system, a user information system, and the like. Then, the server further determines the organization to which the data system belongs, and the organization to which the data system belongs may also be a department or an organization level. And if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
Description
Technical Field
The present application relates to the field of data processing, and in particular, to a data processing method and apparatus.
Background
Currently, when an enterprise employee accesses a certain data in a server database, a server first determines whether the employee has an authority to access the data, and in order to determine whether the employee has the authority to access the data, the server usually determines according to an employee tag of the data. The employee tag of the data shows which employee can view the data, and if the information of the employee who requests to view the data is consistent with the information of a certain employee tag on the data, the data can be viewed by the employee. However, as the number of employees in an enterprise increases, the employee tags of data in the database will expand continuously, and a large number of employee tags will cause great problems in storing and operating the database.
Therefore, a method for solving the above problems is urgently needed.
Disclosure of Invention
The technical problem to be solved by the application is to provide a data processing method and device, so as to solve the problems that the data in a server database can be marked with a large number of employee tags to increase the storage pressure of the database and slow down the running speed of the current server for judging whether an employee has the right to access the data in the database.
In a first aspect, an embodiment of the present application provides a data processing method, where the method includes:
acquiring an identifier of a first employee;
determining an organization to which the first employee belongs according to the identifier of the first employee;
acquiring a system label of first data, wherein the system label of the first data is used for indicating a data system to which the first data belongs;
determining an organization to which the data system belongs;
and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
Optionally, the method further includes:
and adding a corresponding system label for the first data.
Optionally, the determining an organization to which the data system belongs includes:
and determining the organization to which the data system belongs according to a pre-stored corresponding relationship and the system label of the first data, wherein the corresponding relationship comprises the corresponding relationship between the data system to which the first data belongs and the organization to which the data system belongs.
Optionally, the organization to which the data system belongs includes:
the data system attribution department and the superior organization to which the department belongs.
Optionally, the method further includes:
receiving a first request, and sending the first data to a terminal device based on the first request, wherein the first request is generated by the terminal device in response to an operation triggered by the first user and requesting to access the first data.
In a second aspect, an embodiment of the present application provides a data processing apparatus, where the apparatus includes:
a first obtaining module to: acquiring an identifier of a first employee;
a first determination module to: determining an organization to which the first employee belongs according to the identifier of the first employee;
a second obtaining module to: acquiring a system label of first data, wherein the system label of the first data is used for indicating a data system to which the first data belongs;
a second determination module to: determining an organization to which the data system belongs;
a third determination module to: and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
Optionally, the apparatus further includes an adding module, configured to:
and adding a corresponding system label for the first data.
Optionally, the second determining module is configured to:
and determining the organization to which the data system belongs according to a pre-stored corresponding relationship and the system label of the first data, wherein the corresponding relationship comprises the corresponding relationship between the data system to which the first data belongs and the organization to which the data system belongs.
Optionally, the organization to which the data system belongs includes:
the data system attribution department and the superior organization to which the department belongs.
Optionally, the apparatus further includes a sending module, configured to:
receiving a first request, and sending the first data to a terminal device based on the first request, wherein the first request is generated by the terminal device in response to an operation triggered by the first user and requesting to access the first data.
Compared with the prior art, the embodiment of the application has the following advantages:
in order to judge whether a first employee has the authority to access first data, a server first obtains an identifier of the first employee, and then determines an organization to which the first employee belongs according to the identifier of the first employee, wherein the organization to which the first employee belongs may be a department in which the first employee is located or an organization level of the first employee. Then, the server obtains a system tag of the first data, where the system tag of the first data is used to indicate a data system to which the first data belongs, and the data system differs according to a data source, and may be, for example, a financial system, a user information system, and the like. Then, the server further determines the organization to which the data system belongs, and the organization to which the data system belongs may also be a department or an organization level. And if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data. Therefore, when the server judges according to the label of the first data, the server does not judge according to the staff label of the first data, but judges whether the organization to which the first staff belongs is consistent with the organization to which the system label belongs according to the system label of the first data, and if so, the first staff has the authority of accessing the first data. When the number of the staff is increased, the number of the system tags on the first data cannot be influenced, and by the method, the storage pressure of the database is reduced, and the running speed is increased.
Drawings
In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings needed to be used in the description of the embodiments or the prior art will be briefly described below, it is obvious that the drawings in the following description are only some embodiments described in the present application, and other drawings can be obtained by those skilled in the art without creative efforts.
FIG. 1 is a schematic flow chart illustrating a data processing method according to an embodiment of the present application;
fig. 2 is a schematic structural diagram of a data processing apparatus according to an embodiment of the present application.
Detailed Description
In order to make the technical solutions of the present application better understood, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application, and it is obvious that the described embodiments are only a part of the embodiments of the present application, and not all of the embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present application.
The inventor of the present application finds, through research, that currently, when an enterprise employee accesses a certain data in a server database, a server first needs to determine whether the employee has an authority to access the data, and in order to determine whether the employee has the authority to access the data, the server generally determines according to an employee tag of the data. The employee tag of the data shows which employee can view the data, and if the information of the employee who requests to view the data is consistent with the information of a certain employee tag on the data, the data can be viewed by the employee. However, as the number of employees in an enterprise increases, the employee tags of data in the database will expand continuously, and a large number of employee tags will cause great problems in storing and operating the database.
In order to solve the above problem, an embodiment of the present application provides a data processing method and apparatus, where to determine whether a first employee has an authority to access first data, a server first obtains an identifier of the first employee, and then determines an organization to which the first employee belongs according to the identifier of the first employee, where the organization to which the first employee belongs may be a department in which the first employee is located, or may be an organization hierarchy of the first employee. Then, the server obtains a system tag of the first data, where the system tag of the first data is used to indicate a data system to which the first data belongs, and the data system differs according to a data source, and may be, for example, a financial system, a user information system, and the like. Then, the server further determines the organization to which the data system belongs, and the organization to which the data system belongs may also be a department or an organization level. And if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data. Therefore, when the server judges according to the label of the first data, the server does not judge according to the staff label of the first data, but judges whether the organization to which the first staff belongs is consistent with the organization to which the system label belongs according to the system label of the first data, and if so, the first staff has the authority of accessing the first data. When the number of the staff is increased, the number of the system tags on the first data cannot be influenced, and by the method, the storage pressure of the database is reduced, and the running speed is increased.
Various non-limiting embodiments of the present application are described in detail below with reference to the accompanying drawings.
Exemplary method
Referring to fig. 1, a schematic flow chart of a data processing method in an embodiment of the present application is shown. The method illustrated in FIG. 1, in one implementation, may be performed by a server.
In this embodiment, the method shown in fig. 1 can be implemented by, for example, the following steps S101 to S105, and the first data is taken as an example for description. The method shown in fig. 1 may be applied to all data in the server database, such as the second data, the third data, and the like.
S101: an identification of a first employee is obtained.
S102: and determining the organization to which the first employee belongs according to the identifier of the first employee.
In this embodiment, to determine whether the first employee has the authority to access the first data, the server first obtains an identifier of the first employee, where the identifier of the first employee may be an employee number of the first employee, and the identifier of the first employee is used to identify an organization to which the first employee belongs. The organization to which the first employee belongs may be a department in which the first employee is located, or may be an organization level of the first employee, such as an organization level of developing a group, an organization of application and development, a department of office, and a department of the organization, which is an organization of beijing research and development center. When determining the organization to which the first employee belongs, the server may search, according to the identifier of the first employee, for the organization corresponding to the identifier of the first employee in the database.
S103: the method comprises the steps of obtaining a system label of first data, wherein the system label of the first data is used for indicating a data system to which the first data belongs.
The server may obtain a system tag of the first data after determining an organization to which the first employee belongs, where the system tag of the first data is used to indicate a data system to which the first data belongs, and the data system is different according to a data source, and may be, for example, a financial system, a user information system, and the like. In one example, a corresponding system tag may be added to the first data in advance. As can be seen, when the server determines based on the tag of the first data, the server does not determine based on the employee tag of the first data, but determines based on the system tag of the first data. When the number of the employees is increased, the number of the system tags on the first data is not influenced. By adopting the method, the increase of the number of the staff can not bring problems to the storage and the operation of the database.
S104: determining an organization to which the data system belongs.
In this example, after determining the data system to which the first data belongs, the server may further determine an organization to which the data system belongs, where the organization to which the data system belongs may also be a department or organization level, such as a room-department organization level of a group of development-part of application development-part of beijing research and development center-part of organization. In one example, the organization to which the data system belongs includes a department to which the data system belongs and a superior organization to which the department belongs. For example, in the above example, if the first data belongs to one part of application development, the first data belongs to a higher-level organization, that is, beijing research and development center, of the one part of application development in addition to the directly-affiliated organization.
When determining the organization to which the data system belongs, in an example, the server may determine the organization to which the data system belongs according to a pre-stored correspondence relationship and a system tag of the first data, where the correspondence relationship includes a correspondence relationship between the data system to which the first data belongs and the organization to which the data system belongs.
S105: and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
It can be understood that, after determining the organization to which the first employee belongs and the organization to which the data system belongs, the server may determine whether the organization to which the first employee belongs hits the organization to which the data system belongs. Considering that an employee of an organization generally has the authority to access data of the organization, if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data; and if the organization to which the first employee belongs does not hit the organization to which the data system belongs, the first employee does not have the authority of accessing the first data.
For example, if the first employee is a general employee who develops a group, the organization to which the first employee belongs is assumed to be a research and development group-application development department-beijing research and development center; if the system label of the first data is a development system and the organization to which the development system belongs is an application development part, namely Beijing research and development center, the organization to which the first employee belongs does not hit the organization to which the data system belongs, and the first employee does not have the right to access the first data.
For another example, if the first employee is a master of an application development department, the organization to which the first employee belongs is the beijing research and development center; if the system label of the first data is a development system and the organization to which the development system belongs is an application development part, namely Beijing research and development center, the organization to which the first employee belongs hits the organization to which the data system belongs, and the first employee has the right to access the first data. If the system label of the first data is a development system, the organization to which the development system belongs is a group of research and development-part of application and development-Beijing research and development center. The organization to which the first employee belongs also hits the organization to which the data system belongs, and the first employee also has the right to access the first data.
It should be noted that, in order to enable the system maintenance staff to have the right to access all data of a certain department, and thus maintain the data of the department, the organization to which the system maintenance staff belongs may be set to be a certain department, such as the beijing research and development center, and at this time, the system maintenance staff all have the right to access data of any organization and department of the beijing research and development center.
In one example, the server may perform the above steps after receiving a first request sent by a terminal device, where the first request is generated by the terminal device in response to an operation triggered by the first user to request to access the first data. In other words, the first request may indicate that the first user requests access to the first data. If it is determined that the first user has the right to access the first data after the above steps are performed, the server may send the first data to the terminal device. If it is determined that the first user does not have the right to access the first data after the above steps are performed, the first request may be denied.
Exemplary device
Based on the method provided by the above embodiment, the embodiment of the present application further provides an apparatus, which is described below with reference to the accompanying drawings.
Referring to fig. 2, a schematic structural diagram of a data processing apparatus in an embodiment of the present application is shown. Applied to a server, the apparatus may specifically include:
the first obtaining module 201: the system comprises a server and a server, wherein the server is used for acquiring an identifier of a first employee;
the first determination module 202: the organization used for determining the first employee attribution according to the identification of the first employee;
the second obtaining module 203: the system tag of the first data is used for indicating a data system to which the first data belongs;
the second determination module 204: an organization for determining attribution of the data system;
the third determination module 205: and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
With this apparatus, when the server performs the determination based on the tag of the first data, the server does not perform the determination based on the employee tag of the first data, but determines whether the organization to which the first employee belongs is identical to the organization to which the system tag belongs, based on the system tag of the first data, and if so, the first employee has the right to access the first data. When the number of the staff is increased, the number of the system tags on the first data cannot be influenced, and by the method, the storage pressure of the database is reduced, and the running speed is increased.
In one implementation, the apparatus further includes an adding module configured to:
and adding a corresponding system label for the first data.
In one implementation, the second determining module is configured to:
and determining the organization to which the data system belongs according to a pre-stored corresponding relationship and the system label of the first data, wherein the corresponding relationship comprises the corresponding relationship between the data system to which the first data belongs and the organization to which the data system belongs.
In one implementation, the organization to which the data system belongs includes:
the data system attribution department and the superior organization to which the department belongs.
In one implementation, the apparatus further includes a sending module configured to:
receiving a first request, and sending the first data to a terminal device based on the first request, wherein the first request is generated by the terminal device in response to an operation triggered by the first user and requesting to access the first data.
Since the apparatus 200 is an apparatus corresponding to the method provided in the above method embodiment, and the specific implementation of each unit of the apparatus 200 is the same as that of the above method embodiment, for the specific implementation of each unit of the apparatus 200, reference may be made to the description part of the above method embodiment, and details are not repeated here.
Other embodiments of the present application will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the invention following, in general, the principles of the application and including such departures from the present disclosure as come within known or customary practice in the art to which the invention pertains. It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the application being indicated by the following claims.
It will be understood that the present application is not limited to the precise arrangements described above and shown in the drawings and that various modifications and changes may be made without departing from the scope thereof. The scope of the application is limited only by the attached claims
The above description is only exemplary of the present application and should not be taken as limiting the present application, as any modification, equivalent replacement, or improvement made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims (10)
1. A method of data processing, the method comprising:
acquiring an identifier of a first employee;
determining an organization to which the first employee belongs according to the identifier of the first employee;
acquiring a system label of first data, wherein the system label of the first data is used for indicating a data system to which the first data belongs;
determining an organization to which the data system belongs;
and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
2. The method of claim 1, further comprising:
and adding a corresponding system label for the first data.
3. The method of claim 1, wherein the determining an organization to which the data system belongs comprises:
and determining the organization to which the data system belongs according to a pre-stored corresponding relationship and the system label of the first data, wherein the corresponding relationship comprises the corresponding relationship between the data system to which the first data belongs and the organization to which the data system belongs.
4. The method of claim 1, wherein the organization to which the data system belongs comprises:
the data system attribution department and the superior organization to which the department belongs.
5. The method according to any one of claims 1-4, further comprising:
receiving a first request, and sending the first data to a terminal device based on the first request, wherein the first request is generated by the terminal device in response to an operation triggered by the first user and requesting to access the first data.
6. A data processing apparatus, characterized in that the apparatus comprises:
a first obtaining module to: acquiring an identifier of a first employee;
a first determination module to: determining an organization to which the first employee belongs according to the identifier of the first employee;
a second obtaining module to: acquiring a system label of first data, wherein the system label of the first data is used for indicating a data system to which the first data belongs;
a second determination module to: determining an organization to which the data system belongs;
a third determination module to: and if the organization to which the first employee belongs hits the organization to which the data system belongs, determining that the first employee has the authority to access the first data.
7. The apparatus of claim 6, further comprising an adding module to:
and adding a corresponding system label for the first data.
8. The apparatus of claim 6, wherein the second determining module is configured to:
and determining the organization to which the data system belongs according to a pre-stored corresponding relationship and the system label of the first data, wherein the corresponding relationship comprises the corresponding relationship between the data system to which the first data belongs and the organization to which the data system belongs.
9. The apparatus of claim 6, wherein the organization to which the data system belongs comprises:
the data system attribution department and the superior organization to which the department belongs.
10. The apparatus according to any one of claims 6-9, wherein the apparatus further comprises a sending module configured to:
receiving a first request, and sending the first data to a terminal device based on the first request, wherein the first request is generated by the terminal device in response to an operation triggered by the first user and requesting to access the first data.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011625771.1A CN112632501A (en) | 2020-12-30 | 2020-12-30 | Data processing method and device |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011625771.1A CN112632501A (en) | 2020-12-30 | 2020-12-30 | Data processing method and device |
Publications (1)
Publication Number | Publication Date |
---|---|
CN112632501A true CN112632501A (en) | 2021-04-09 |
Family
ID=75289809
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011625771.1A Pending CN112632501A (en) | 2020-12-30 | 2020-12-30 | Data processing method and device |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN112632501A (en) |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110569657A (en) * | 2019-09-10 | 2019-12-13 | 北京字节跳动网络技术有限公司 | Data access method, device, equipment and storage medium |
-
2020
- 2020-12-30 CN CN202011625771.1A patent/CN112632501A/en active Pending
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110569657A (en) * | 2019-09-10 | 2019-12-13 | 北京字节跳动网络技术有限公司 | Data access method, device, equipment and storage medium |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11586673B2 (en) | Data writing and reading method and apparatus, and cloud storage system | |
CN111694841B (en) | Order identification generation method, device, server and storage medium | |
CN107133234B (en) | Method, device and system for updating cache data | |
CN108399101B (en) | Method, device and system for scheduling resources | |
US20030229501A1 (en) | Systems and methods for efficient policy distribution | |
JP6160064B2 (en) | Application determination program, failure detection apparatus, and application determination method | |
CN109542894B (en) | User data centralized storage method, device, medium and computer equipment | |
CN110377649B (en) | Construction and query methods, devices, equipment and storage medium of tagged data | |
CN109726533B (en) | User account judgment method and device | |
CN107870802B (en) | Virtual machine migration method and device | |
CN106528578A (en) | An information display method and device | |
CN109039803A (en) | A kind of method, system and the computer equipment of processing readjustment notification message | |
US9501669B2 (en) | Method and apparatus for location-based recovery of stolen mobile devices | |
CN117195297B (en) | ERP-based data security and privacy protection system and method | |
CN114399319A (en) | False enterprise identification method, device, equipment and medium based on prediction model | |
CN107357557A (en) | A kind of information updating method and device | |
CN112802610A (en) | Passenger information big data intelligent processing method and device | |
CN112632501A (en) | Data processing method and device | |
CN116032886B (en) | Data center and domain name switching method, device, equipment and medium | |
CN115086047B (en) | Interface authentication method and device, electronic equipment and storage medium | |
CN111901299A (en) | Application authentication method and device, electronic equipment and storage medium | |
CN115686746A (en) | Access method, task processing method, computing device, and computer storage medium | |
CN115914383A (en) | Service publishing method, system, device and storage medium | |
CN111177501B (en) | Label processing method, device and system | |
CN107180042A (en) | Flow statistical method, the apparatus and system of search engine |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination |