Cloud side-end cooperation-oriented network management platform hierarchical authority control method and platform
By constructing a permission control topology structure and task allocation coefficient formula, combined with real-time resource monitoring and dynamic permission adjustment, the imbalance problem between task scheduling and resource management in the cloud-edge collaborative network is solved, and efficient and secure permission control is achieved.
Patent Information
- Application Number
- CN202510770639.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-12
AI Technical Summary
In the existing technologies of cloud-edge collaborative network management, task scheduling and resource management lack global optimality, and permission control lacks flexibility and precision, resulting in resource imbalance, low security and efficiency.
By building a permission control topology structure, combining task scheduling and resource management algorithms, using task allocation coefficients and collaborative weight formulas, monitoring resource status in real time, dynamically adjusting task allocation strategies, and building a permission matching matrix, permission levels are dynamically adjusted based on user behavior and task requirements.
It achieves precise initial allocation and dynamic optimization of tasks between the cloud, edge and end, improves system processing efficiency and the flexibility and accuracy of authority control, ensures data security and normal business execution, and prevents the risks of resource overload and authority violation.
Smart Images

Figure CN120639646A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of hierarchical control of network management platforms, and in particular to a hierarchical authority control method and platform for network management platforms oriented to cloud-edge-end collaboration. Background Art
[0002] With the rapid development of technologies such as the Internet of Things and big data, cloud-edge-device collaborative network architectures, combining powerful cloud computing power, real-time edge processing capabilities, and flexible terminal device access, have become critical infrastructure supporting complex application scenarios such as intelligent transportation and the Industrial Internet. Within this architecture, network management platforms must centrally manage and control multi-level resources, diverse tasks, and a vast number of users. As a core means of achieving refined management, hierarchical permission control is becoming increasingly important. However, current technologies have numerous limitations and are unable to meet practical needs.
[0003] Existing technologies have significant shortcomings in task scheduling and resource management. Traditional methods often employ static or simple dynamic task allocation strategies, considering only task priority or resource load in isolation, without deeply correlating key factors such as task type, data size, and processing time with the resource characteristics of various cloud-edge and end-to-end platforms. This results in a lack of global optimality in task allocation, easily leading to an imbalance where cloud resources are idle while edge resources are overloaded. This results in low overall system processing efficiency and fails to fully leverage the performance advantages of a cloud-edge-end collaborative architecture.
[0004] At the permission control level, the flexibility and accuracy of existing solutions are difficult to adapt to complex and changing application scenarios. They often use fixed permission level division and allocation rules, and cannot perform adaptive permission optimization based on user access behavior patterns, real-time task processing needs, and dynamic adjustments to the hierarchical architecture of the network management platform. When user needs change, or the network structure changes due to the addition and removal of equipment or hierarchical adjustments, improper permission configuration is prone to occur. Either there is a risk of data leakage due to excessive permission opening, or excessive permission restrictions hinder the normal operation of the business, seriously affecting the security and operational efficiency of the cloud-edge collaborative network. Summary of the Invention
[0005] In order to overcome the shortcomings and deficiencies of the existing technology, the present invention provides a hierarchical authority control method and platform for a network management platform for cloud-edge-end collaboration.
[0006] The technical solution adopted by the present invention is a hierarchical permission control method for a network management platform for cloud-edge-end collaboration, comprising the following steps:
[0007] Step S1: Based on the hierarchical architecture of the network management platform, device resource information, user identity information, and permission level information of each level of the platform are collected to build a permission control topology structure containing multiple levels of nodes, where each node in the topology structure corresponds to a network management platform at a different level;
[0008] Step S2: Based on the task scheduling and resource management algorithm, the task requests in the cloud-edge-end collaboration scenario are analyzed. Based on the task type, data volume, processing time limit, and resource load of each level of platform, the initial task allocation strategy between the cloud, edge, and end is determined, and the tasks are divided into the corresponding level of network management platform for preliminary processing;
[0009] Step S3: Based on the edge-cloud collaborative model, during the task processing process, the resource usage status and task processing progress of each level of platform are monitored in real time. According to the dynamic changes in resources and task priorities, the collaborative weights between nodes are calculated to dynamically adjust the task allocation strategy, and tasks are reasonably migrated and collaboratively processed between the cloud, edge, and end.
[0010] Step S4: During the task execution process, the permission level information of the network management platforms at all levels is used to verify the user's request to access resources and perform operations. Based on the user's permission level and task requirements, it is determined whether the user is allowed to access or perform operations on the corresponding resources.
[0011] Step S5: When task processing is completed or an exception occurs, the resources occupied by platforms at all levels are recovered and released according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, resource usage status information is updated, and the task processing results are fed back to relevant users;
[0012] Step S6: Regularly collect and analyze various data in the hierarchical authority control process of the network management platform, and optimize and adjust the task scheduling and resource management algorithm, edge-cloud collaboration model and authority control strategy based on the analysis results to adapt to the dynamic needs of the hierarchical authority control of the network management platform.
[0013] Furthermore, in step S2, when determining the initial task allocation strategy among the cloud, edge, and end, the following model formula is used:
[0014]
[0015] Among them, A ij represents the allocation coefficient of task i to platform j, W i is the weight of task i, which is determined by the task type and priority; R j is the remaining resources of platform j, including computing resources, storage resources and network bandwidth resources; T i is the processing time limit of task i; Dj is the estimated processing delay of task i on platform j; P i is the priority coefficient of task i, which is determined by the task scheduling and resource management algorithm. According to the size of the allocation coefficient, the task is allocated to the platform with the largest allocation coefficient for preliminary processing.
[0016] Furthermore, in step S3, the collaborative weights between nodes are calculated using the following model formula:
[0017]
[0018] Among them, C mn represents the collaborative weight between node m and node n; U m and U n are the resource utilization rates of node m and node n respectively; L m and L n are the task loads of node m and node n respectively; S mn is the network communication speed between node m and node n, S max is the maximum communication speed between nodes in the network; α, β, and γ are weight coefficients, and α+β+γ=1. Its value is set according to the edge-cloud collaboration model and the hierarchical parameters of the network management platform. The collaborative weight is used to determine whether the task needs to be migrated and collaboratively processed between nodes.
[0019] Furthermore, in step S4, when verifying the user's request to access resources and perform operations, the permission level information of the platforms at all levels is combined and judged through the permission matching matrix. The permission matching matrix is constructed according to the hierarchical permission parameters of the network management platform. The elements in the matrix represent the access permission status of users with different permission levels to different resources and operations. If the user's permission level and the elements corresponding to the resources and operations requested to be accessed in the matrix are in the allowed state, the user is allowed to access or operate, otherwise it is denied.
[0020] Furthermore, in step S5, when recycling and releasing the resources occupied by platforms at all levels, the resource recycling order and release strategy are determined based on the task scheduling and resource management algorithm, according to the resource occupation time, resource utilization efficiency and task priority parameters, and resources with long occupation time and low utilization efficiency are recycled first to ensure the reasonable allocation and efficient utilization of resources.
[0021] Furthermore, in step S6, when optimizing the task scheduling and resource management algorithm, an adaptive adjustment strategy based on hierarchical platform parameters is adopted according to the collected task processing data to dynamically adjust the task allocation rules and resource scheduling threshold parameters in the algorithm to improve the adaptability of the algorithm to different tasks and resource conditions.
[0022] Furthermore, in step S6, when optimizing the edge-cloud collaborative model, the hierarchical topology structure and resource parameters of the network management platform are combined, and the weight coefficient and communication delay parameters in the collaborative weight calculation formula in the model are adjusted to optimize the collaborative processing efficiency and migration strategy of tasks between the cloud and the edge.
[0023] Furthermore, in step S6, when optimizing the authority control strategy, the authority level division, authority allocation rules and authority verification process of each level of platform are adjusted according to user access behavior data and task processing requirements.
[0024] Furthermore, during the entire permission control process, a risk assessment model is constructed using resource monitoring data and task processing information from platforms at all levels. The risk assessment model is based on the parameters of the network management platform hierarchy. By quantitatively assessing the risk of resource overload, task timeout, and permission violation, corresponding risk prevention measures are taken in advance to ensure the stable operation of the hierarchical permission control of the network management platform.
[0025] A hierarchical permission control platform for network management platforms oriented to cloud-edge-end collaboration, including:
[0026] Resource information collection unit, used to collect equipment resource information, user identity information and authority level information of network management platforms at all levels;
[0027] The task initial allocation unit is connected to the resource information collection unit and is used to analyze the task requests in the cloud-edge-end collaboration scenario based on the task scheduling and resource management algorithm, and determine the initial allocation strategy of tasks between the cloud, edge, and end according to the task type, data volume, processing time limit, and resource load of each level of platform;
[0028] A task collaborative processing unit is connected to the task initial allocation unit. Based on the edge-cloud collaborative model, it monitors the resource usage status and task processing progress of each platform in real time during the task processing process, and dynamically adjusts the task allocation strategy according to the dynamic changes of resources and task priorities.
[0029] The authority verification unit is connected to the resource information collection unit and the task collaborative processing unit, and during the task execution process, uses the authority level information of the network management platform at all levels to verify the user's request to access resources and perform operations;
[0030] A resource recovery and feedback unit is connected to the task collaborative processing unit. When task processing is completed or an abnormal situation occurs, it recovers and releases the resources occupied by platforms at all levels according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, updates resource usage status information, and feeds back task processing results to relevant users.
[0031] The policy optimization unit is connected to the resource information collection unit, the task initial allocation unit, the task collaborative processing unit, the authority verification unit and the resource recovery feedback unit, and regularly collects and analyzes various data in the hierarchical authority control process of the network management platform, and optimizes and adjusts the task scheduling and resource management algorithm, the edge-cloud collaborative model and the authority control strategy based on the analysis results.
[0032] Beneficial effects: The present invention proposes a hierarchical authority control method and platform for a network management platform for cloud-edge-end collaboration. In terms of task scheduling and resource management, by comprehensively considering multiple factors such as task type, data volume, processing time limit, etc., combining task scheduling and resource management algorithms and edge-cloud collaboration models, and using innovative task allocation coefficient formulas and node collaboration weight formulas, accurate initial allocation and dynamic optimization adjustment of tasks between the cloud and the edge are achieved. It changes the drawbacks of the traditional method of single consideration factors, avoids resource imbalance, improves the overall processing efficiency of the system, and gives full play to the performance advantages of the cloud-edge-end collaboration architecture. At the authority control level, by building a permission matching matrix, user permissions are verified according to the hierarchical authority parameters of the network management platform. At the same time, combined with user access behavior data and task processing requirements, the authority level division, allocation rules and verification process are dynamically adjusted. Compared with the existing fixed authority control method, the flexibility and accuracy of authority control are greatly improved, which can not only ensure data security and prevent authority from crossing the line, but also meet the needs of normal business execution. In addition, by regularly collecting and analyzing data, optimizing algorithms, models, and permission control strategies, and building risk assessment models, we can proactively prevent risks such as resource overload and task timeouts, ensuring efficient, stable, and secure operation of the network management platform's hierarchical permission control. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 is a flow chart of the method steps of the present invention;
[0034] Figure 2 This is a diagram of the platform unit composition of the present invention. DETAILED DESCRIPTION
[0035] It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of this application can be combined with each other. The present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0036] like Figure 1 As shown, the hierarchical permission control method for the network management platform for cloud-edge-end collaboration includes the following steps:
[0037] Step S1: Based on the hierarchical architecture of the network management platform, device resource information, user identity information, and permission level information of each level of the platform are collected to build a permission control topology structure containing multiple levels of nodes, where each node in the topology structure corresponds to a network management platform at a different level;
[0038] Specifically, under the hierarchical architecture of the cloud-edge-end collaborative network management platform, device resource information covers the hardware resource parameters such as computing resources, storage resources, network bandwidth, etc. owned by platforms at all levels. These parameters directly reflect the processing power and carrying capacity of the platform. User identity information includes the user's unique identification code, organization or department, and other information, which is used to accurately distinguish different users. The permission level information defines the scope and level of operations and resource access that each user or user group can perform in the network management platform. By collecting this information, the resources and user status of the network management platform can be fully understood.
[0039] In terms of implementation, sensors or monitoring programs deployed on various platforms can collect relevant information periodically or in real time. Once this information is collected, each platform is abstracted into nodes based on the hierarchical architecture of the network management platform. A permission control topology is constructed based on the hierarchical relationships and connections. Each node corresponds to a network management platform at a different level, and the connections between nodes represent data exchange and permission associations between platforms. This topology provides a foundational framework for subsequent operations such as task allocation and permission verification. This allows permission control to be performed based on a clear network architecture, ensuring accurate and efficient operations.
[0040] Step S2: Based on the task scheduling and resource management algorithm, the task requests in the cloud-edge-end collaboration scenario are analyzed. Based on the task type, data volume, processing time limit, and resource load of each level of platform, the initial task allocation strategy between the cloud, edge, and end is determined, and the tasks are divided into the corresponding level of network management platform for preliminary processing;
[0041] Specifically, the task scheduling and resource management algorithm is the core of this step, which achieves reasonable task allocation through in-depth analysis of task requests. The task type determines the processing resources and technical support required for the task. For example, the resource requirements of compute-intensive tasks and data-intensive tasks differ significantly. The amount of data affects the time and resource usage of task processing, and the processing time limit requires that the task must be completed within the specified time. The resource load of each platform includes the current computing resource utilization rate, the remaining storage resources, and the network bandwidth usage. Combining these factors, the algorithm can evaluate the suitability of each task for processing on different platforms, thereby determining the initial allocation strategy.
[0042] During implementation, when a task request enters the system, the algorithm first extracts information such as the task type, data volume, and processing time limit. Simultaneously, it obtains real-time resource load data for cloud, edge, and end platforms. Then, according to the algorithm's defined rules and evaluation models, the feasibility and efficiency of task processing on different platforms are calculated and compared. For example, tasks with high real-time requirements and small data volumes are prioritized for edge processing to reduce data transmission delays. Tasks with high computational complexity and high resource requirements are assigned to the cloud for processing. Ultimately, tasks are assigned to the most appropriate network management platform for preliminary processing, laying the foundation for efficient task execution.
[0043] Step S3: Based on the edge-cloud collaborative model, during the task processing process, the resource usage status and task processing progress of each level of platform are monitored in real time. According to the dynamic changes in resources and task priorities, the collaborative weights between nodes are calculated to dynamically adjust the task allocation strategy, and tasks are reasonably migrated and collaboratively processed between the cloud, edge, and end.
[0044] Specifically, the edge-cloud collaboration model emphasizes the collaborative work between the cloud, edge, and end to cope with dynamic changes in the task processing process. During the task processing process, the resource usage status of each level of platform is monitored in real time, including the utilization rate of computing resources, the remaining space of storage resources, the occupancy of network bandwidth, etc., as well as the task processing progress, such as completed processing steps and remaining processing time. Dynamic changes in resources may cause the originally appropriate task allocation to no longer be optimal, and the level of task priority determines the urgency of task processing. By calculating the collaborative weight between nodes, the feasibility and benefits of task migration and collaborative processing between different nodes can be evaluated.
[0045] During implementation, monitoring tools deployed on platforms at all levels are used to continuously collect resource usage and task progress data. When a platform's resources are found to be overloaded or task processing is delayed, and other platforms have better processing conditions, the collaborative weight of the task and other nodes is calculated based on the task priority and resource status. The collaborative weight takes into account factors such as resource complementarity between nodes and network communication quality. If the collaborative weight meets the preset conditions, the task migration mechanism is triggered, and the task is partially or fully migrated to a more suitable platform for processing, or collaboratively processed with other platforms, thereby ensuring the efficient completion of the task and improving the resource utilization and processing performance of the entire system.
[0046] Step S4: During the task execution process, the permission level information of the network management platforms at all levels is used to verify the user's request to access resources and perform operations. Based on the user's permission level and task requirements, it is determined whether the user is allowed to access or perform operations on the corresponding resources.
[0047] Specifically, within the cloud-edge-end collaborative network management platform, each level of the platform has clear permission level information set. This information specifies the access rights of different users or user groups to various resources and operations. During task execution, users will continuously request to access resources and perform operations, such as reading data and modifying configurations. To ensure network security and the proper use of resources, these requests must be strictly verified. The verification process determines whether the user has the corresponding permissions to perform the operation or access the resource based on the user's permission level and the requirements of the current task.
[0048] In terms of implementation, when a user initiates a request, the system first obtains the user's identity and then determines the level of authority to which they belong. At the same time, it analyzes the resource and operation requirements of the current task. Then, the user's authority level is matched with the task requirements, and compared with the pre-set authority rules and authority matching matrix (if any) to determine whether the user's request complies with the authority regulations. If the user's authority level meets the task's requirements for resources and operations, the user is allowed to access or operate; otherwise, the request is rejected and relevant logs are recorded for subsequent auditing and management. In this way, illegal access and unauthorized operations are effectively prevented, ensuring the security and stability of the network management platform.
[0049] Step S5: When task processing is completed or an exception occurs, the resources occupied by platforms at all levels are recovered and released according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, resource usage status information is updated, and the task processing results are fed back to relevant users;
[0050] Specifically, task completion means the task was successfully executed according to the intended objectives, while exceptions include errors, timeouts, insufficient resources, and other issues encountered during task execution. In either case, the resources occupied by platforms at all levels during task processing must be properly handled. Based on task scheduling and resource management algorithms and edge-cloud collaborative models, resource recovery and release strategies can be determined to ensure the rational reuse of resources and accurate updates of system resource status. Task processing results are also promptly fed back to relevant users, allowing them to understand the execution status of the tasks.
[0051] In actual operation, when task processing completion or an exception is detected, the system initiates the resource recovery process. Based on the resource recovery rules set in the task scheduling and resource management algorithm, the order and method of resource recovery are determined according to parameters such as resource occupation time, resource utilization efficiency, and task priority. For example, resources that have been occupied for a long time and have low utilization efficiency are prioritized for recovery, or resources occupied by low-priority tasks are released based on task priority. After resource recovery, resource usage status information is promptly updated on all levels of the platform to ensure accurate resource data is available for subsequent task allocation and scheduling. Finally, the task processing results, including normal completion results or detailed information on abnormal situations, are fed back to the relevant users through specific communication channels, allowing users to proceed to the next step or take corresponding measures based on the results.
[0052] Step S6: Regularly collect and analyze various data in the hierarchical authority control process of the network management platform, and optimize and adjust the task scheduling and resource management algorithm, edge-cloud collaboration model and authority control strategy based on the analysis results to adapt to the dynamic needs of the hierarchical authority control of the network management platform.
[0053] Specifically, the operating environment and task requirements of network management platforms are constantly changing. To ensure the effectiveness and efficiency of hierarchical permission control, it is necessary to regularly collect and analyze various data from the permission control process. This data includes task processing data, such as task allocation, processing time, and resource consumption; resource usage data, such as resource utilization and load changes at each level of the platform; and user access data, such as user permission usage and access frequency. Through in-depth analysis of this data, problems and shortcomings in existing task scheduling and resource management algorithms, edge-cloud collaboration models, and permission control strategies can be identified.
[0054] When implementing optimization and adjustments, based on the results of data analysis, dynamic adjustments are made to parameters such as task allocation rules and resource scheduling thresholds for task scheduling and resource management algorithms to better adapt to different tasks and resource conditions. For the edge-cloud collaborative model, the collaborative weight calculation method and communication delay parameters in the model are adjusted to optimize the collaborative processing efficiency and migration strategy of tasks between the cloud and the edge. In terms of permission control strategy, based on user access behavior data and task processing requirements, the permission level division, permission allocation rules, and permission verification process of platforms at all levels are optimized to achieve more accurate permission control. Through continuous optimization and adjustment, the hierarchical permission control of the network management platform can adapt to dynamically changing needs and continuously improve the performance, security, and reliability of the system.
[0055] Preferably, in step S2, when determining the initial task allocation strategy among the cloud, edge, and end, the following model formula is used:
[0056]
[0057] Among them, A ij represents the allocation coefficient of task i to platform j, W i is the weight of task i, which is determined by the task type and priority; R j is the remaining resources of platform j, including computing resources, storage resources and network bandwidth resources; T i is the processing time limit of task i; D j is the estimated processing delay of task i on platform j; P i is the priority coefficient of task i, which is determined by the task scheduling and resource management algorithm. According to the size of the allocation coefficient, the task is allocated to the platform with the largest allocation coefficient for preliminary processing.
[0058] Specifically, an allocation coefficient evaluation system is constructed by comprehensively considering parameters such as task weight, remaining platform resources, processing time limit, estimated processing delay, and priority coefficient. Task weight is determined by both type and priority, reflecting the varying importance of different tasks; remaining platform resources encompass computing, storage, and network bandwidth resources, reflecting the platform's current carrying capacity; processing time limit and estimated processing delay ensure task timeliness requirements. This strategy uses multi-dimensional parameter evaluation to allocate tasks to the most suitable platform, achieving efficient resource utilization and a reasonable division of tasks, avoiding the resource imbalance caused by traditional single-metric allocation.
[0059] Preferably, in step S3, the collaborative weights between nodes are calculated using the following model formula:
[0060]
[0061] Among them, C mn represents the collaborative weight between node m and node n; U m and U n are the resource utilization rates of node m and node n respectively; L m and L n are the task loads of node m and node n respectively; S mn is the network communication speed between node m and node n, S max is the maximum communication speed between nodes in the network; α, β, and γ are weight coefficients, and α+β+γ=1. Its value is set according to the edge-cloud collaboration model and the hierarchical parameters of the network management platform. The collaborative weight is used to determine whether the task needs to be migrated and collaboratively processed between nodes.
[0062] Specifically, the collaborative potential between nodes is quantified by analyzing parameters such as resource utilization, task load, and network communication speed. Resource utilization comparisons reflect differences in node resource utilization efficiency, task load comparisons reveal processing capacity redundancy, and network communication speed influences data transmission efficiency. Weight coefficients are dynamically adjusted based on the edge-cloud collaborative model and platform tier parameters to ensure accurate determination of the optimal timing and path for task migration and collaborative processing in different network environments and task scenarios, thereby improving the system's overall processing efficiency and flexible resource allocation capabilities.
[0063] Preferably, in step S4, when verifying the user's request to access resources and perform operations, the permission level information of the platforms at all levels is combined and judged through the permission matching matrix. The permission matching matrix is constructed according to the hierarchical permission parameters of the network management platform. The elements in the matrix represent the access permission status of users with different permission levels to different resources and operations. If the user's permission level and the elements corresponding to the resources and operations requested to be accessed in the matrix are in the allowed state, the user is allowed to access or operate, otherwise it is denied.
[0064] Specifically, by constructing a permission matching matrix based on the platform's hierarchical permission parameters, a precise mapping between user permissions and resource operations is achieved. Matrix elements associate user identity, permission level, and specific resource access operations based on strict permission level division and resource classification rules. During the verification process, the system quickly retrieves the status of corresponding matrix elements based on user permission level and task requirements to ensure that all operations are performed within the authorized scope. Compared to traditional rule-based verification methods, this mechanism has greater flexibility and scalability and can adapt to complex and changing cloud-edge-end collaboration scenarios.
[0065] Preferably, in step S5, when recycling and releasing the resources occupied by platforms at all levels, the resource recycling order and release strategy are determined based on the task scheduling and resource management algorithm, according to the resource occupation time, resource utilization efficiency and task priority parameters, and resources with long occupation time and low utilization efficiency are recycled first to ensure the reasonable allocation and efficient utilization of resources.
[0066] Specifically, a dynamic resource recycling system is established by comprehensively evaluating parameters such as resource occupancy time, usage efficiency, and task priority. Resources that have been occupied for a long time and have low utilization rates are prioritized for recycling to avoid resource waste. The recycling order is dynamically adjusted based on task priority to ensure resource availability for critical tasks. This strategy maximizes resource recycling efficiency through refined resource management, while also ensuring system stability under high load, preventing task failures or system crashes due to resource exhaustion.
[0067] Preferably, in step S6, when optimizing the task scheduling and resource management algorithm, an adaptive adjustment strategy based on hierarchical platform parameters is adopted according to the collected task processing data to dynamically adjust the task allocation rules and resource scheduling threshold parameters in the algorithm to improve the adaptability of the algorithm to different tasks and resource conditions.
[0068] Specifically, an adaptive adjustment strategy based on hierarchical platform parameters continuously analyzes task processing data to dynamically optimize task allocation rules and resource scheduling thresholds. Based on historical data and real-time feedback, the algorithm identifies patterns in the correlation between task types and resource requirements and automatically adjusts the allocation strategy to suit different task characteristics. For example, for tasks with high real-time requirements, edge allocation priority is increased; for compute-intensive tasks, cloud resource scheduling thresholds are optimized. This mechanism enables the algorithm to be self-learning and adaptive, significantly improving the system's processing efficiency for diverse tasks.
[0069] Preferably, in step S6, when optimizing the edge-cloud collaborative model, the hierarchical topology structure and resource parameters of the network management platform are combined, and the weight coefficient and communication delay parameters in the collaborative weight calculation formula in the model are adjusted to optimize the collaborative processing efficiency and migration strategy of tasks between the cloud and the edge.
[0070] Specifically, by adjusting the weight coefficients and communication delay parameters used in the collaborative weight calculation, combined with the platform's hierarchical topology and resource parameters, the efficiency of task collaborative processing is maximized. The weight coefficients dynamically reflect the importance of different platforms in collaborative processing, while the communication delay parameters optimize the selection of data transmission paths. For example, when edge node resources are limited, the weight of cloud nodes is increased to guide task migration; in times of network congestion, low-latency paths are prioritized for data exchange. This optimization mechanism ensures that the model maintains efficient collaborative processing capabilities across diverse network environments and load conditions.
[0071] Preferably, in step S6, when optimizing the authority control strategy, the authority level division, authority allocation rules and authority verification process of each level of platform are adjusted according to user access behavior data and task processing requirements.
[0072] Specifically, by analyzing user access behavior data and task processing requirements, the system dynamically adjusts permission levels, allocation rules, and verification processes. Using machine learning algorithms, the system identifies unusual access patterns and adjusts user permissions in real time. Temporary permissions are automatically assigned based on task changes and promptly revoked upon completion. For example, users who frequently access sensitive data are subject to enhanced verification, and temporary permission groups are dynamically generated for short-term collaborative tasks. This strategy enables dynamic and precise permission control, significantly improving business flexibility while ensuring system security.
[0073] Preferably, during the entire permission control process, a risk assessment model is constructed using resource monitoring data and task processing information from platforms at all levels. The risk assessment model is based on the parameters of the network management platform hierarchy. By quantitatively assessing the risk of resource overload, task timeout, and permission violation, corresponding risk prevention measures are taken in advance to ensure the stable operation of the hierarchical permission control of the network management platform.
[0074] Specifically, a risk assessment model based on platform-level parameters is constructed to implement preventative risk management by quantifying risks such as resource overload, task timeouts, and permission violations. The model comprehensively analyzes resource usage trends, task execution status, and permission operation records to establish a risk warning threshold system. For example, when resource utilization consistently exceeds the threshold, a resource expansion warning is triggered; when abnormal permission operations are detected, they are immediately interrupted and audited. By anticipating risks and taking proactive preventive measures, this model avoids system failures and security incidents caused by traditional passive risk management, thereby ensuring the stable operation of the network management platform.
[0075] like Figure 2 As shown in the figure, the hierarchical permission control platform for the network management platform for cloud-edge-end collaboration includes:
[0076] Resource information collection unit, used to collect equipment resource information, user identity information and authority level information of network management platforms at all levels;
[0077] The task initial allocation unit is connected to the resource information collection unit and is used to analyze the task requests in the cloud-edge-end collaboration scenario based on the task scheduling and resource management algorithm, and determine the initial allocation strategy of tasks between the cloud, edge, and end according to the task type, data volume, processing time limit, and resource load of each level of platform;
[0078] A task collaborative processing unit is connected to the task initial allocation unit. Based on the edge-cloud collaborative model, it monitors the resource usage status and task processing progress of each platform in real time during the task processing process, and dynamically adjusts the task allocation strategy according to the dynamic changes of resources and task priorities.
[0079] The authority verification unit is connected to the resource information collection unit and the task collaborative processing unit, and during the task execution process, uses the authority level information of the network management platform at all levels to verify the user's request to access resources and perform operations;
[0080] A resource recovery and feedback unit is connected to the task collaborative processing unit. When task processing is completed or an abnormal situation occurs, it recovers and releases the resources occupied by platforms at all levels according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, updates resource usage status information, and feeds back task processing results to relevant users.
[0081] The policy optimization unit is connected to the resource information collection unit, the task initial allocation unit, the task collaborative processing unit, the authority verification unit and the resource recovery feedback unit, and regularly collects and analyzes various data in the hierarchical authority control process of the network management platform, and optimizes and adjusts the task scheduling and resource management algorithm, the edge-cloud collaborative model and the authority control strategy based on the analysis results.
[0082] A hierarchical permission control method and platform for network management platforms oriented to cloud-edge-end collaboration. To address the problems of single allocation strategy and low resource utilization in traditional task scheduling, this solution comprehensively considers multiple factors such as task type, data scale, processing time limit, and resource load of platforms at all levels. When initially allocating tasks, it no longer relies solely on a single indicator for decision-making, but instead comprehensively evaluates task requirements and resource characteristics of platforms at all levels, and rationally divides tasks into the most suitable cloud, edge, and end platforms for preliminary processing. During task processing, it continuously monitors the resource usage status and task progress of platforms at all levels, and flexibly adjusts task allocation strategies based on dynamic resource changes and task priorities to achieve reasonable migration and collaborative processing of tasks between cloud, edge, and end, avoiding idle or overloaded resources, significantly improving the overall processing efficiency of the system, and giving full play to the advantages of cloud-edge-end collaborative architecture.
[0083] In terms of permission control, existing technologies lack flexibility and precision due to fixed permission rules. This solution precisely matches user permission levels with resource access and operational requirements by constructing a permission matching matrix based on the hierarchical permission parameters of the network management platform. When verifying user requests, judgments are strictly based on the permission status represented by the matrix elements to ensure the accuracy of permission control. At the same time, based on user access behavior data and task processing requirements, permission level division, allocation rules, and verification processes are dynamically adjusted. This can effectively prevent the risk of data leakage caused by excessive permissions, ensure the smooth execution of business, and significantly enhance the adaptability and security of permission control.
[0084] Furthermore, this solution iteratively optimizes task scheduling and resource management algorithms, edge-cloud collaboration models, and permission control policies by regularly collecting and analyzing data from the permission control process. Based on various parameters of the network management platform hierarchy, a risk assessment model is constructed to quantitatively assess risks such as resource overload, task timeouts, and permission violations. Preventive measures are then taken to ensure the efficient, stable, and secure operation of the network management platform's hierarchical permission control, comprehensively overcoming the shortcomings of existing technologies.
[0085] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," "connected," and "fixed" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0086] Although embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various equivalent changes, modifications, substitutions and variations may be made to these embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A hierarchical permission control method for a network management platform oriented to cloud-edge-end collaboration, characterized in that: The following steps are involved: Step S1: Based on the hierarchical architecture of the network management platform, device resource information, user identity information, and permission level information of each level of the platform are collected to build a permission control topology structure containing multiple levels of nodes, where each node in the topology structure corresponds to a network management platform at a different level; Step S2: Based on the task scheduling and resource management algorithm, the task requests in the cloud-edge-end collaboration scenario are analyzed. Based on the task type, data volume, processing time limit, and resource load of each level of platform, the initial task allocation strategy between the cloud, edge, and end is determined, and the tasks are divided into the corresponding level of network management platform for preliminary processing; Step S3: Based on the edge-cloud collaborative model, during the task processing process, the resource usage status and task processing progress of each level of platform are monitored in real time. According to the dynamic changes in resources and task priorities, the collaborative weights between nodes are calculated to dynamically adjust the task allocation strategy, and tasks are reasonably migrated and collaboratively processed between the cloud, edge, and end. Step S4: During the task execution process, the permission level information of the network management platforms at all levels is used to verify the user's request to access resources and perform operations. Based on the user's permission level and task requirements, it is determined whether the user is allowed to access or perform operations on the corresponding resources. Step S5: When task processing is completed or an exception occurs, the resources occupied by platforms at all levels are recovered and released according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, resource usage status information is updated, and the task processing results are fed back to relevant users; Step S6: Regularly collect and analyze various data in the hierarchical authority control process of the network management platform, and optimize and adjust the task scheduling and resource management algorithm, edge-cloud collaboration model and authority control strategy based on the analysis results to adapt to the dynamic needs of the hierarchical authority control of the network management platform.
2. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S2, when determining the initial task allocation strategy among the cloud, edge, and end, the following model formula is used: Among them, A ij represents the allocation coefficient of task i to platform j, W i is the weight of task i, which is determined by the task type and priority; R j is the remaining resources of platform j, including computing resources, storage resources and network bandwidth resources; T i is the processing time limit of task i; D j is the estimated processing delay of task i on platform j; P i is the priority coefficient of task i, which is determined by the task scheduling and resource management algorithm. According to the size of the allocation coefficient, the task is allocated to the platform with the largest allocation coefficient for preliminary processing.
3. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S3, the collaborative weights between nodes are calculated using the following model formula: Among them, C mn represents the collaborative weight between node m and node n; U m and U n are the resource utilization rates of node m and node n respectively; L m and L n are the task loads of node m and node n respectively; S mn is the network communication speed between node m and node n, S max is the maximum communication speed between nodes in the network; α, β, and γ are weight coefficients, and α+β+γ=1. Its value is set according to the edge-cloud collaboration model and the hierarchical parameters of the network management platform. The collaborative weight is used to determine whether the task needs to be migrated and collaboratively processed between nodes.
4. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S4, when verifying the user's request to access resources and perform operations, the permission level information of each level of the platform is combined and judged through the permission matching matrix. The permission matching matrix is constructed according to the hierarchical permission parameters of the network management platform. The elements in the matrix represent the access rights status of users with different permission levels to different resources and operations. If the user's permission level and the elements corresponding to the resources and operations requested to be accessed in the matrix are in the allowed state, the user is allowed to access or perform the operation; otherwise, the user is denied.
5. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S5, when reclaiming and releasing the resources occupied by platforms at all levels, the resource recovery order and release strategy are determined based on the task scheduling and resource management algorithm, according to the resource occupation time, resource utilization efficiency and task priority parameters, and resources that have been occupied for a long time and have low utilization efficiency are recycled first to ensure the reasonable allocation and efficient utilization of resources.
6. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S6, when optimizing the task scheduling and resource management algorithm, an adaptive adjustment strategy based on hierarchical platform parameters is adopted according to the collected task processing data to dynamically adjust the task allocation rules and resource scheduling threshold parameters in the algorithm to improve the adaptability of the algorithm to different tasks and resource conditions.
7. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S6, when optimizing the edge-cloud collaborative model, the hierarchical topology structure and resource parameters of the network management platform are combined, and the weight coefficient and communication delay parameters in the collaborative weight calculation formula in the model are adjusted to optimize the collaborative processing efficiency and migration strategy of tasks between the cloud and the edge.
8. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: In step S6, when optimizing the authority control strategy, the authority level division, authority allocation rules and authority verification process of each level of platform are adjusted according to user access behavior data and task processing requirements.
9. The hierarchical authority control method for a network management platform for cloud-edge-end collaboration according to claim 1 is characterized in that: During the entire permission control process, a risk assessment model is constructed using resource monitoring data and task processing information from platforms at all levels. The risk assessment model is based on the parameters of the network management platform hierarchy. By quantitatively assessing the risk of resource overload, task timeout, and permission violation, corresponding risk prevention measures are taken in advance to ensure the stable operation of the hierarchical permission control of the network management platform.
10. A hierarchical authority control platform for network management platforms oriented to cloud-edge-end collaboration, characterized by: include: Resource information collection unit, used to collect equipment resource information, user identity information and authority level information of network management platforms at all levels; The task initial allocation unit is connected to the resource information collection unit and is used to analyze the task requests in the cloud-edge-end collaboration scenario based on the task scheduling and resource management algorithm, and determine the initial allocation strategy of tasks between the cloud, edge, and end according to the task type, data volume, processing time limit, and resource load of each level of platform; A task collaborative processing unit is connected to the task initial allocation unit. Based on the edge-cloud collaborative model, it monitors the resource usage status and task processing progress of each platform in real time during the task processing process, and dynamically adjusts the task allocation strategy according to the dynamic changes of resources and task priorities. The authority verification unit is connected to the resource information collection unit and the task collaborative processing unit, and during the task execution process, uses the authority level information of the network management platform at all levels to verify the user's request to access resources and perform operations; A resource recovery and feedback unit is connected to the task collaborative processing unit. When task processing is completed or an abnormal situation occurs, it recovers and releases the resources occupied by platforms at all levels according to the task scheduling and resource management algorithm and the edge-cloud collaborative model, updates resource usage status information, and feeds back task processing results to relevant users. The policy optimization unit is connected to the resource information collection unit, the task initial allocation unit, the task collaborative processing unit, the authority verification unit and the resource recovery feedback unit, and regularly collects and analyzes various data in the hierarchical authority control process of the network management platform, and optimizes and adjusts the task scheduling and resource management algorithm, the edge-cloud collaborative model and the authority control strategy based on the analysis results.
Citation Information
Cited By
Test cabinet resource utilization rate evaluation method
CN121073260A
Trusted cloud native security level treatment system and method
CN121585481A