Multi-cluster resource authority management method and system based on cardinal number tree
By building a radix tree model and combining it with a dynamic weight value adjustment strategy, the problems of permission synchronization delay and inconsistency in multi-cluster resource permission management are solved, and efficient and reliable permission synchronization and management are achieved.
Patent Information
- Application Number
- CN202511163594.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-08-20
AI Technical Summary
Existing multi-cluster resource permission management methods are prone to delays and inconsistencies during cross-cluster permission synchronization. Especially under the influence of network latency and cluster load, the asynchronous synchronization of permission synchronization policies may result in permissions being effective but not synchronized to all clusters, posing security risks.
A multi-cluster resource permission management method based on radix tree is adopted. By constructing an initial radix tree model, the network topology structure and historical permission synchronization records of the multi-cluster system are obtained, the cluster synchronization strategy is dynamically adjusted, and the cluster performance is monitored in real time. Hash verification is used to ensure the consistency of permission change information.
It minimizes delays and ensures consistency during permission synchronization. By adjusting the synchronization strategy through dynamic weight values, it optimizes the accuracy and reliability of cluster resource permission management and avoids synchronization failures caused by network fluctuations and cluster resource consumption in traditional methods.
Smart Images

Figure CN120671167A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a multi-cluster resource authority management method and system based on a radix tree. Background Art
[0002] Multi-cluster resource permission management refers to a method for managing resource access and permissions across multiple clusters (such as multiple Kubernetes clusters or other distributed system clusters). This management approach typically involves controlling access to users, services, or applications across multiple clusters, ensuring that resources in different clusters are properly authorized and securely managed. In multi-cluster scenarios, different clusters may have different resource and permission requirements. Single-cluster permission management methods cannot meet the needs of unified management of resources across multiple clusters. Therefore, multi-cluster resource permission management requires cross-cluster permission identification, authorization, and control mechanisms.
[0003] Currently, the primary approach to managing multi-cluster resource permissions is to achieve unified control across multiple clusters through a federated architecture, combined with a role-based access control model for refined permission allocation. However, permission policies at the federation layer must be asynchronously synchronized across clusters. This synchronization process is affected by network latency and cluster load, potentially leading to inconsistent states where permissions are in effect at the federation layer but not yet updated in some clusters. For example, if an administrator deletes a user's cross-cluster permissions, the user may still be able to operate resources in unsynchronized clusters, posing a security risk. Summary of the Invention
[0004] The main purpose of the present invention is to provide a multi-cluster resource authority management method based on a radix tree, aiming to solve the technical problems in the prior art.
[0005] The present invention proposes a multi-cluster resource authority management method based on a radix tree, comprising: Obtaining network topology structures and historical permission synchronization records of multiple clusters in a multi-cluster system, and constructing an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes, and leaf nodes; Obtain the permission change request of each cluster, and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; Extracting the complete path branch of each change record and obtaining a first hash value of the complete path branch; Obtaining real-time network latency data, CPU usage, memory occupancy, and disk I / O load for each cluster, and obtaining a dynamic weight value for the corresponding cluster based on each of the real-time network latency data, CPU usage, memory occupancy, and disk I / O load; Determine whether the dynamic weight value of each cluster is greater than the preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; Obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and determining whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
[0006] Preferably, the step of constructing an initial radix tree model based on the plurality of network topologies and historical permission synchronization records includes: Obtain the global permission domain, cluster identifier, resource type, resource object, and permission items of the multi-cluster system, and build a hierarchical structure with the global permission domain of the multi-cluster system as the root node, the cluster identifier as the first-level child node, the resource type as the second-level child node, the resource object as the third-level child node, and the permission item as the leaf node; Adding network connection information to the attributes of the first-level child node according to the network topology structure; Extracting the permission change rules of each resource object from the historical permission synchronization records, and optimizing the initial permission configuration of the leaf node according to each permission change rule to obtain an optimized permission configuration; According to the hierarchical structure, network connection information and optimized authority configuration, each node is connected in series through a tree structure generation algorithm to form a complete initial radix tree model.
[0007] Preferably, the step of generating a corresponding change record in the initial radix tree model according to the specific operation type, resource location path, and changed permission parameters in the permission change request includes: Receive a permission change request through a request interface of the multi-cluster permission management system, and extract the specific operation type, resource location path, and changed permission parameters from the permission change request; Obtaining the hierarchical structure of the resource location path, matching layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure, and reading the pre-change permission parameters currently stored in the leaf node; Obtaining metadata according to the permission change request, and extracting an initiating node identifier according to the metadata; The permission change time when the request interface of the multi-cluster permission management system receives the permission change request is obtained, and the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change are associated with the corresponding leaf node to obtain a change record.
[0008] Preferably, the step of obtaining real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtaining a dynamic weight value of the corresponding cluster according to each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load, includes: Sending a preset number of probe packets to each cluster and recording the round trip time of each packet in real time, and obtaining real-time network delay data based on multiple round trip times; Obtain the process statistics file of each cluster, and obtain the CPU user state time, system state time, idle time and IO wait time based on the process statistics file; Obtaining CPU usage based on the CPU user state time, system state time, idle time, and IO waiting time; Obtain the total memory, used memory, and cache memory of each cluster, and obtain the memory usage based on the total memory, used memory, and cache memory; Obtain the disk read / write byte rate and disk bandwidth of each cluster, and obtain the disk I / O load based on the disk read / write byte rate and disk bandwidth; Corresponding weight coefficients are assigned to real-time network delay data, CPU usage, memory occupancy, and disk I / O load, respectively, and a dynamic weight value of the corresponding cluster is obtained based on the real-time network delay data, CPU usage, memory occupancy, disk I / O load, and their corresponding weight coefficients.
[0009] Preferably, the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster includes: Obtaining a first current path branch and a first changed path branch of the priority synchronization group cluster, and extracting first attribute fields of all nodes in the first current path branch to obtain a first structured data set; Extracting the second attribute fields of all nodes in the first change path branch to obtain a second structured data set; Converting the first structured data set and the second structured data set into a first binary data sequence and a second binary data sequence respectively; Obtaining difference data segments according to the first binary data sequence and the second binary data sequence, and updating the first structured data set segment by segment according to the difference data segments to obtain a first updated binary data sequence; Acquire a second changed path branch of the delayed synchronization group cluster, and locate a second current path branch of the delayed synchronization group cluster according to the path identifier of the second changed path branch; A second updated binary data sequence is obtained according to the second current path branch and the second changed path branch, and a second hash value of the second updated binary data sequence and the first updated binary data sequence is obtained using the SHA-256 hash algorithm.
[0010] Preferably, the step of obtaining a difference data segment according to the first binary data sequence and the second binary data sequence includes: performing a byte-by-byte exclusive OR operation on the first binary data sequence and the second binary data sequence to obtain a difference data sequence; Traversing the difference data sequence and recording difference segment starting positions and difference segment lengths of consecutive non-zero bytes to obtain a difference segment information list, wherein the difference segment information list includes a plurality of difference segments whose difference segment starting positions are sorted from small to large; Extracting byte data at a position corresponding to the first change path branch from each of the difference segments to obtain a data block, and splicing the multiple data blocks in the order of the difference segment information list to obtain a spliced data block; The number of difference segments in the difference segment information list is obtained, and the number of difference segments, the starting position of the difference segments, the length of the difference segments and the splicing data block are spliced in sequence to obtain a difference data segment.
[0011] This application also provides a multi-cluster resource rights management system based on a radix tree, including: A construction module is used to obtain the network topology structures and historical permission synchronization records of multiple clusters in the multi-cluster system, and construct an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes and leaf nodes; A generation module is used to obtain the permission change request of each cluster and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; an extraction module, configured to extract a complete path branch of each change record and obtain a first hash value of the complete path branch; An acquisition module is used to obtain real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtain a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load; A first judgment module is used to judge whether the dynamic weight value of each cluster is greater than a preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; A second judgment module is used to obtain the second hash value of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and judge whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
[0012] Preferably, the generating module includes: An extraction unit is configured to receive a permission change request through a request interface of the multi-cluster permission management system, and extract a specific operation type, a resource location path, and a changed permission parameter from the permission change request; A matching unit, configured to obtain a hierarchical structure of the resource location path, and match layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure, and read the pre-change permission parameters currently stored in the leaf node located therein; an acquiring unit, configured to acquire metadata according to the permission change request, and extract an initiating node identifier according to the metadata; The association generation unit is used to obtain the permission change time when the request interface of the multi-cluster permission management system receives the permission change request, and associate the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change to the corresponding leaf node to obtain a change record.
[0013] The present invention also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the multi-cluster resource authority management method based on a radix tree when executing the computer program.
[0014] The present invention also provides a computer-readable storage medium storing a computer program, which implements the steps of the multi-cluster resource authority management method based on the radix tree when executed by a processor.
[0015] The beneficial effects of the present invention are as follows: the present invention minimizes delays and ensures consistency in the process of permission synchronization by dynamically adjusting cluster synchronization strategies and monitoring cluster performance in real time; automatically determines the dynamic weight of the cluster by comprehensively considering the network delay, CPU usage, memory occupancy, and disk I / O load of each cluster; and divides the clusters into priority synchronization groups and delayed synchronization groups according to the weight values, so that permission synchronization requests of clusters with heavier loads or larger delays are given priority processing, effectively reducing the lag of permission synchronization; and constructing a hierarchical permission management structure by using a radix tree model, which can accurately record and synchronize permission change information, and ensure the consistency of permission change data in different clusters through hash verification, significantly improving the accuracy and reliability of permission management in a multi-cluster environment, and avoiding the synchronization failure problem caused by network fluctuations and cluster resource consumption in traditional permission synchronization methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 Schematic diagram of a method flow according to an embodiment of the present invention.
[0017] Figure 2 FIG. 1 is a schematic diagram of a system structure according to an embodiment of the present invention.
[0018] Figure 3 This is a schematic diagram of the internal structure of a computer device according to an embodiment of the present application.
[0019] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0020] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0021] like Figure 1 As shown, the present application provides a multi-cluster resource permission management method based on a radix tree, comprising: S1. Obtain network topology structures and historical permission synchronization records for multiple clusters in a multi-cluster system, and construct an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes, and leaf nodes; S2. Obtain the permission change request of each cluster, and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; S3. Extract the complete path branch of each change record and obtain the first hash value of the complete path branch; S4. Obtain real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtain a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load; S5. Determine whether the dynamic weight value of each cluster is greater than a preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; S6. Obtain the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and determine whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
[0022] As described in the above steps S1-S6, the root node of the initial radix tree model corresponds to the global permission domain of the multi-cluster system, the first-level child node corresponds to each cluster identifier, the second-level child node corresponds to the resource type in the cluster, the third-level child node corresponds to the specific resource object, the leaf node stores the permission item and the initial version number, and the purpose of embedding the dynamic weight value into the attribute field of the corresponding cluster identifier node, constructing the initial radix tree and calculating the dynamic weight value is to provide basic support for the dynamic scheduling of the subsequent permission synchronization strategy. Specifically, the hierarchical design of the initial radix tree is used to manage the multi-cluster resource permissions in a logical layered manner according to the global, cluster, resource type, and resource object, so that the permissions The path is clear and traceable, laying a structural foundation for the subsequent precise positioning of permission change nodes and efficient extraction of the first change path branch. By collecting real-time load data such as network latency and CPU usage and calculating dynamic weight values, the cluster's operating status is converted into a quantifiable numerical indicator. This indicator can intuitively reflect the cluster's current load pressure (e.g., a high weight value indicates low load and strong synchronization capability, while a low weight value indicates high load and weak synchronization capability), providing a data basis for distinguishing between priority synchronization groups and delayed synchronization groups. The dynamic weight value is embedded in the attribute field of the cluster identification node, so that the radix tree not only carries permission information, but also can be associated with the cluster load status in real time. In the subsequent synchronization process, the cluster priority can be directly judged based on the weight value in the node attribute, avoiding the increased delay caused by forcibly pushing synchronization data to the high-load cluster, thereby reducing synchronization inconsistencies caused by uneven cluster load at the source; Among them, the step of extracting the complete path branch of each change record and obtaining the first hash value of the complete path branch is the same as the step of matching layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure. Starting from the root node, a depth-first traversal is performed along the above matching path, and the complete data of all nodes on the path (including the attribute fields of nodes at each level, such as the dynamic weight value of the cluster identification node, the metadata of the resource object node, the permission items and version numbers of the leaf nodes, etc.) are recorded in sequence to form the first change path branch data from the root node to the target leaf node (including the hierarchical relationship and data content of all nodes on the path). Then, the extracted complete path branch data is converted into a binary data stream in hierarchical order, and the SHA-256 algorithm is used to perform a hash operation on the above binary data stream to generate a first hash value of a fixed length (256 bits). The first hash value uniquely corresponds to the complete data of this path branch and can be used as a change verification identifier for subsequent synchronization verification; The present invention obtains the network topology structure and historical permission synchronization records of multiple clusters in a multi-cluster system, and constructs an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, a first-level child node, a second-level child node, a third-level child node and a leaf node. By collecting the network topology structure and historical permission synchronization records of the cluster, a preliminary radix tree model is constructed. Through the network topology structure, potential bottlenecks such as connectivity, bandwidth, and latency between clusters can be identified, and the historical permission synchronization records provide the background of permission changes, which can help the system predict synchronization problems that may occur in the future. Compared with the existing technology, this initial data acquisition based on network topology and historical synchronization records provides a reliable basis for subsequent dynamic optimization, rather than relying solely on single real-time information, thereby improving The entire synchronization process is intelligent and predictive. By obtaining permission change requests from each cluster and generating corresponding change records in the initial radix tree model based on the specific operation type, resource location path, and changed permission parameters in the permission change request, the corresponding change records and change paths are generated in the radix tree model based on the operation type, resource location path, and changed permission parameters in the permission change request. This not only simply records permission changes, but also embeds the change path into the radix tree model to form a clear historical operation chain that can accurately reflect the evolution process of each permission change and provide a clear traceability path for permission consistency judgment. Existing technologies usually only consider single permission changes or static data records, but ignore the accumulation and interaction of historical change paths, and lack systematic modeling of dynamic permission flows. By extracting the full path branch of each change record and obtaining the first hash value of the full path branch, the system establishes an unalterable digital fingerprint (first hash value) for each permission change by extracting the full path and calculating the first hash value, which ensures the accuracy and consistency of permission synchronization. This first hash value provides a reliable comparison standard for subsequent synchronization operations, which is used to judge the synchronization status of different clusters. Compared with existing technologies, hash values are not just a tool for data verification. Their role in permission synchronization is given higher credibility and tamper-proof capabilities, which enhances the security of the system. By obtaining real-time network delay data, CPU usage, memory occupancy, and disk I / O load for each cluster, and obtaining the dynamic weight value of the corresponding cluster based on each real-time network delay data, CPU usage, memory occupancy, and disk I / O load, real-time collection of cluster resource status is the key to dynamic optimization based on the actual load situation of the cluster. Network delay and cluster Group load is the main cause of multi-cluster permission synchronization delays and inconsistencies. By introducing this real-time data, the system can intelligently judge the cluster load status and decide whether to prioritize synchronization of the cluster. Existing technologies often only make synchronization judgments based on static configurations. This step automatically adjusts the synchronization priority when the system load is high through real-time data collection and dynamic weight calculation, thereby reducing synchronization delays and data inconsistencies caused by resource limitations. The dynamic weight value of the cluster combines real-time network latency and resource usage, which can effectively quantify the synchronization priority of the cluster. By calculating the dynamic weight value and comparing it with the preset threshold, it can flexibly determine which clusters should be added to the priority synchronization group and which should be postponed. Existing technologies usually fix the synchronization processing and ignore the dynamic changes in load and latency differences between clusters. Through dynamic weight scheduling, automatic optimization based on the current load status of the cluster is achieved, thereby minimizing resource consumption and maximizing system efficiency. By judging whether the dynamic weight value of each cluster is greater than the preset threshold, if the dynamic weight value is greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; if the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster. By dividing the priority synchronization group and the delayed synchronization group, intelligent scheduling of cluster resources is achieved. The clusters in the priority synchronization group will be given priority synchronization processing, thereby avoiding conflicts in synchronization operations under high load conditions, and the delayed synchronization group can postpone operations to avoid unnecessary synchronization contention. The synchronization operations in the existing technology are often static or globally consistent, and fail to be optimized for the actual load. Through cluster classification management, it can Effectively avoid synchronization resource competition between clusters and improve the efficiency of the overall system. By respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster, and judging whether the second hash value of each cluster is consistent with the first hash value, if the second hash value is consistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch. If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value. If not, the step of parsing and replacing the difference data segment is re-executed. The position offset or byte error in the data replacement process is checked until the calculation result is consistent with the first hash value (change verification mark). The second hash value is generated and the consistency verification step further ensures the accuracy and consistency of the synchronization operation. By performing hash calculation on each path in the permission synchronization process and comparing it with the first hash value, the problem in the synchronization process can be accurately identified. If the hash value is inconsistent, it means that the synchronization of the path is not completed and needs to be resynchronized. In the prior art, hash values are mostly used for data verification, but the present invention ensures that the permission synchronization between clusters is consistent at any time through multiple hash value comparisons, prevents permission data inconsistency caused by delays or network problems, and ensures that the system is consistent in each cluster. The final consistency can be guaranteed during the group's permission synchronization process. If the second hash value is inconsistent with the first hash value, it means that there is a problem with synchronization. The system will automatically retry until consistency is restored. Unlike the existing technology, this retry mechanism combines real-time resource load and network delay judgment to intelligently decide whether to retry synchronization, rather than simply relying on a fixed synchronization strategy. The present invention can dynamically adjust according to the actual network and resource conditions, avoiding redundant and inefficient synchronization attempts and improving the stability of the entire system. In summary, the present invention comprehensively considers the real-time resource conditions, permission change records and network topology of multiple clusters, and adopts innovative radix tree models, dynamic priority judgments and hash value consistency verification and other technical means.This approach solves the common latency and inconsistency issues found in existing multi-cluster permission synchronization methods. Through intelligent decision-making, real-time data collection, dynamic adjustments, and adaptive fault-tolerance mechanisms, the system can efficiently and reliably synchronize permissions even under complex network conditions and cluster loads. This permission synchronization mechanism, based on real-time dynamic resource weights and path hash value verification, offers higher accuracy, lower latency, and greater system stability compared to existing technologies.
[0023] In one embodiment, step S1 of constructing an initial radix tree model based on the plurality of network topologies and historical permission synchronization records includes: S11. Obtain the global permission domain, cluster identifier, resource type, resource object, and permission item of the multi-cluster system. Using the global permission domain of the multi-cluster system as the root node, divide the nodes according to the hierarchical relationship of cluster identifier, resource type, resource object, and permission item to construct a hierarchical structure. First-level child nodes correspond to each cluster identifier. Each identifier is associated with the hardware configuration parameters of the cluster (such as server model, number of CPU cores, memory capacity, etc.) and stored as node attributes. Second-level child nodes correspond to resource types within the cluster (such as computing resources, storage resources, network resources, etc.). Node attributes include hardware configuration details of the resource type (such as disk capacity and read / write speed of storage resources). Third-level child nodes correspond to specific resource objects (such as a server, a hard disk, a network port, etc.). Attribute fields record the hardware identifier of the object (such as device ID, IP address, etc.). Leaf nodes store specific permission items (such as read permission, write permission, management permission, etc.) and are associated with an initial version number. S12. Add network connection information to the attributes of each cluster identification node (first-level child node) based on the network topology. Record the physical connection method between the cluster and other clusters (such as direct connection, connection through a switch, etc.). Store parameters such as the network bandwidth and default routing path between clusters. For clusters with a hierarchical relationship (such as a parent cluster and child clusters), establish association pointers between corresponding nodes to reflect the topological hierarchy. S13. Extract the permission change patterns of each resource object from historical permission synchronization records, optimize the initial permission configuration of leaf nodes, and obtain an optimized permission configuration. If a historical permission item of a resource object has not changed for a long time, set its default permission value to a historical stable value. For permission items that frequently conflict in historical synchronization, add a conflict marker attribute to the leaf node to provide a basis for subsequent synchronization strategy adjustments. Based on the average delay time of historical synchronization, set an initial weight coefficient for each cluster identification node (which serves as the basis for dynamic weight calculation); S14. According to the above hierarchical structure, optimized permission configuration, attribute configuration and association relationship, each node is connected in series through a tree structure generation algorithm (such as a tree construction method based on an adjacency list) to form a complete initial radix tree model.
[0024] As described in the above steps S11-S14, the present invention uses the global authority domain of the multi-cluster system as the root node, divides the nodes according to the hierarchical relationship of cluster identification, resource type, resource object, and authority item to construct a hierarchical structure. By using the global authority domain as the root node to construct the hierarchical structure of the multi-cluster system, unified management and control of resources can be achieved. In the prior art, multi-cluster management usually adopts the management method of a single cluster, which cannot effectively handle the problem of authority synchronization and control between multiple clusters. By defining the global authority domain as the root node, a unified framework can be provided for the authority allocation of multiple clusters at the top level, avoiding the management confusion caused by inconsistent authority allocation. The existing methods often have a lot of manual configuration when managing permissions between clusters, and lack global unified management. The present invention uses the global authority domain as the root node. As the root node, the hierarchical structure of the permissions and resource objects of the management cluster helps to reduce manual intervention and improve the automation and accuracy of permission management. This hierarchical structure allows the permission management system to be decomposed layer by layer from cluster identification to resource objects and permission items. The nodes of each layer are associated with their specific resources or permission items, with a clear hierarchical structure, which is easy to manage and maintain. Through this hierarchical node division, the resources and permission configuration of each cluster can be clearly identified, avoiding confusion or repeated configuration of permissions. In existing cluster management methods, the permissions of cluster resources are usually difficult to manage in a hierarchical manner, resulting in redundant permissions and lack of targeted configuration. The present invention divides permission items into levels, which can more accurately adjust the permissions of each layer, thereby improving the flexibility and accuracy of permission configuration; The first-level child nodes correspond to each cluster identifier. Each identifier is associated with the hardware configuration parameters of the cluster and stored as node attributes. By storing the hardware configuration parameters of the cluster in the first-level child nodes, it is possible to ensure that the permission management system can dynamically adjust the permission configuration according to the hardware characteristics. The hardware configuration of the cluster is an important factor affecting the permission allocation. By storing the hardware configuration of the cluster, more targeted resource management can be achieved, avoiding permission conflicts or resource shortages between different hardware environments. In the existing technology, the hardware configuration of the cluster is often not closely integrated with the permission management system, which may cause the permission management to fail to take into account the actual hardware configuration. By using the hardware configuration as a node attribute, the system can more intelligently optimize resource permission allocation based on hardware conditions, improving the performance and response speed of the system. The second-level child nodes correspond to the resource types in the cluster. The node attributes contain the hardware configuration details of the resource type. In the cluster, the hardware configuration of the resource type affects the efficiency and performance of resource utilization. By storing the hardware configuration details in the node of the resource type, more accurate resource information can be provided to the permission management system, thereby improving the efficiency of resource utilization and avoiding permission conflicts caused by over-allocation or under-allocation of resources. The existing methods do not fully utilize the hardware details of the resource type, which easily leads to uneven resource allocation or unreasonable permission settings. The present invention adds hardware details to the second-level nodes. The third-level sub-nodes correspond to specific resource objects, and the attribute fields record the hardware identification of the object. By recording the hardware identification of the specific resource object, the hardware characteristics of each object can be accurately tracked at the resource level. This approach avoids the confusion and inaccuracy of permission allocation in large-scale resource management. The hardware identification can help the system identify the status and requirements of different resource objects and achieve accurate resource management. The existing technology often fails to accurately distinguish the hardware identification of different resources at the resource level, resulting in insufficiently detailed permission settings for resources. By recording the hardware identification in the third-level nodes, the hardware characteristics of each object can be accurately tracked at the resource level. Identification can accurately identify each resource object, improving the accuracy and efficiency of resource management. Leaf nodes store specific permission items and associate them with initial version numbers. By associating permission items with initial version numbers and storing them in leaf nodes, it is possible to better track the history of permission changes and provide a basis for subsequent permission optimization. Version control of permission items ensures that permission updates and backtracking are clearer and more traceable. Permission updates in traditional methods are difficult to trace and optimize, resulting in inconsistencies or misconfigurations in frequent permission changes. The present invention, by adding version numbers to leaf nodes, enables permission changes to be managed more systematically, thereby improving the efficiency and accuracy of permission updates. By adding network connection information to the properties of the first-level child nodes through the network topology structure, the system can better understand the network performance and connection stability between clusters by adding network connection information, especially the physical connection method and bandwidth parameters between clusters. This provides data support for optimizing network delays and bandwidth bottlenecks in the permission synchronization process, and helps reduce synchronization delays and inconsistency problems. In the existing technology, the network connection information between clusters is often not fully utilized, and it is difficult to optimize in time when network delays and loads change. The present invention can dynamically adjust the permission synchronization strategy between clusters by adding network topology information to node properties, reduce synchronization delays, improve the overall performance of the system, and record the physical connection method between the cluster and other clusters. Parameters such as network bandwidth and default routing paths are stored between clusters. For clusters with hierarchical relationships, association pointers are established between corresponding nodes to reflect the topological hierarchy. By establishing association pointers between cluster nodes, the hierarchical relationship between clusters can be clearly defined, and the physical and logical connections between clusters can be reflected. This approach enables the system to better handle dependencies between clusters during permission synchronization and avoid permission management problems caused by topological changes between clusters. In traditional methods, the topological relationship between clusters is often not clearly reflected, resulting in unstable permission synchronization between clusters. By establishing association pointers, the present invention can ensure that the system clearly understands the hierarchical relationship between clusters, thereby improving the stability and consistency of permission synchronization between clusters. By extracting the permission change patterns of each resource object from historical permission synchronization records, the initial permission configuration of the leaf node is optimized to obtain an optimized permission configuration. By extracting the permission change patterns from the historical permission synchronization records, it is possible to identify which permission items are long-term stable and which are frequently changing, thereby implementing different permission optimization strategies for different resource objects. This can significantly improve the accuracy and efficiency of permission management, especially in large-scale clusters, and can avoid redundancy and inconsistency in permission configuration. Existing methods generally lack analysis of historical permission change patterns, resulting in permission management relying solely on static configuration and difficulty in responding to dynamic changes. By extracting historical change patterns, the present invention can optimize according to actual permission change trends, greatly improving the intelligence and adaptability of the system. By optimizing the initial permission configuration of the leaf node, it can ensure that the system has high accuracy at the initial configuration, avoiding frequent permission adjustments and revisions in the later stage, helping to reduce debugging and maintenance work during system deployment, and improving the stability and reliability of the system. In existing methods, the initial configuration of permission items generally lacks intelligent adjustment, which may lead to unreasonable initial permission configuration, thereby increasing the cost of later adjustment. By optimizing the initial permission configuration, the present invention can ensure that the system has high configuration accuracy at the startup stage, reducing the workload of subsequent tuning. If the historical permission items of a resource object have not changed for a long time, its default permission value is set to a historical stable value. For permission items that frequently conflict in historical synchronization, a conflict marker attribute is added to the leaf node to provide a basis for subsequent synchronization strategy adjustments. Based on the average delay time of historical synchronization, an initial weight coefficient is set for each cluster identification node. Through the data of historical delay time, a reasonable initial weight coefficient is set to optimize the permission synchronization strategy between clusters, ensure that the priority of permission update matches the delay time, and reduce invalid synchronization requests. Traditional synchronization methods do not consider delay factors, which may cause synchronization requests to occur frequently when the network delay is large, increasing the system burden. The present invention sets the weight coefficient according to the historical delay time, which can speed up synchronization when the network condition is good and reduce the synchronization frequency when the network delay is high, thereby achieving more intelligent and efficient permission management. By following the above The hierarchical structure, optimized permission configuration, attribute configuration and association relationship are connected in series by a tree structure generation algorithm to form a complete initial radix tree model. By utilizing the tree structure generation algorithm, multiple clusters, resources, permissions and network information can be efficiently connected in series to form a complete initial radix tree model. This structure has high scalability and maintainability, which is convenient for subsequent permission management and optimization. The permission management structure in the existing technology is usually scattered and difficult to manage and expand efficiently, especially when the number of clusters continues to increase, which can easily cause management chaos. The present invention can connect all node information in an orderly manner through the generation of a tree structure model, making the permission management structure of the entire system clearer, and the tree structure is convenient for later modification, expansion and optimization, especially when the cluster scale gradually expands. The tree structure can easily handle new clusters or resources while maintaining efficient management.
[0025] In one embodiment, the step S2 of generating a corresponding change record in the initial radix tree model according to the specific operation type, resource location path, and changed permission parameters in the permission change request includes: S21. Receive a permission change request through a request interface of the multi-cluster permission management system, and extract the specific operation type, resource location path, and changed permission parameters from the permission change request; S22: Obtain the hierarchical structure of the resource location path, and perform layer-by-layer matching starting from the root node of the initial radix tree model according to the hierarchical structure. The matching steps are: S23. Locate the corresponding first-level child node based on the cluster identifier in the resource location path, locate the corresponding second-level child node based on the resource type under the first-level child node, locate the corresponding third-level child node based on the resource object under the second-level child node, and find the leaf node that stores the specific permission item corresponding to the changed permission parameter in the permission change request under the third-level child node; S24. Read the permission parameters before the change currently stored in the leaf node; S25. Obtain metadata according to the permission change request, and extract an initiating node identifier according to the metadata; S26. Obtain the permission change time when the request interface of the multi-cluster permission management system receives the permission change request, and associate the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change to the corresponding leaf node to obtain a change record, and at the same time assign a unique ID to the change record for subsequent synchronization tracking.
[0026] As described in the above steps S21-S26, the permission change request includes the initiating node identification information, the request body content (including the operation type, the target resource path, the changed permission parameters) and the request timestamp (i.e., the permission change time). The system will then perform a legitimacy check on the permission change request (such as verifying the permission management qualifications of the initiating node and the integrity of the request format). Only after the check is passed can the parsing process be entered. The specific operation type is obtained by extracting the specific type of permission change from the request, including but not limited to, adding permissions, modifying permissions, deleting permissions, adjusting the validity period of permissions, etc., to clarify the operation logic for the target node. The resource location path is obtained by parsing the resource location path in the request. The path must conform to the hierarchical structure of the initial radix tree (i.e., root node, first-level child node, second-level child node, third-level child node and leaf node). The changed permission parameters are obtained by extracting specific permission parameters, including operation permissions, permission effective time, permission expiration time, Permission priority, etc., must be consistent with the format of permission items stored in the leaf node. Each leaf node uniquely corresponds to detailed information of a permission. The permission change time is the current system time automatically recorded by the system when the change record is generated. Specifically, it is the real-time time when the permission change operation is received by the system and passes the legitimacy verification and enters the parsing and leaf node positioning process. It is used to mark the specific moment when the permission change occurs to ensure the uniqueness of the time dimension of the change record. The initiating node identifier comes from the header information of the permission change request or the initiator metadata carried in the request body, including the unique ID of the initiating node (a fixed identifier pre-assigned by the multi-cluster system to each node that can initiate permission changes, which is globally unique), the IP address of the initiating node (extracted from the source address of the request through the network protocol, used to locate the network location of the initiating node), and the initiator's identity information (parsed from the identity authentication information carried in the request, used to confirm the initiator's permission qualifications); The present invention receives permission change requests through the request interface of the multi-cluster permission management system, and extracts the specific operation type, resource location path and changed permission parameters from the permission change request. Through the receiving interface of the permission change request, the system can capture key information such as the specific operation type, resource location path and changed permission parameters of the permission change, ensuring that the system can accurately receive and parse the information in the request, thereby avoiding error processing caused by unclear request parsing. In the prior art, permission requests often lack a systematic parameter extraction method, and no detailed structured parsing of the request is performed, which may lead to inaccurate resource positioning or permission matching errors. The present invention can ensure the system's accurate understanding of permission changes by clearly extracting operation types, paths and permission parameters, thereby avoiding errors caused by improper request parsing. To prevent delays or errors, we obtain the hierarchical structure of the resource location path and match it layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure. Traditional permission management systems usually only handle superficial path matching and may ignore the hierarchy and structural relationship of the path, which may lead to permission matching errors or missed matches. By obtaining the hierarchical structure of the resource location path and matching it layer by layer, we can achieve accurate positioning of resources. The matching of each layer is not only based on cluster identification, resource type and object location, but also fully considers the hierarchical structure of the path to ensure fine-grained matching of resources. This layer-by-layer matching method is more detailed and reliable than traditional single path matching. Through layer-by-layer matching, we can gradually and accurately lock each resource location and adapt to more complex resource hierarchical structures, reducing the occurrence of inconsistencies or errors. The matching step is to locate the corresponding first-level child node through the cluster identifier in the resource location path, locate the corresponding second-level child node according to the resource type under the first-level child node, locate the corresponding third-level child node according to the resource object under the second-level child node, and find the leaf node under the third-level child node that stores the specific permission item corresponding to the changed permission parameter in the permission change request. In traditional permission management systems, permission matching may be performed directly through a single resource identifier or cluster identifier, which may lead to resource identifier conflicts in multiple clusters, or permission omissions or incorrect matches in resource structures with more layers. Through multi-level node positioning, the system can accurately start from the root node and search downward layer by layer, and can accurately locate the permission item of each resource, ensuring that in a complex multi-cluster environment, each permission request can be accurately located to the target resource, rather than relying on a simple matching condition. The level-by-level positioning of child nodes improves the accuracy of multi-cluster permission management, especially when the resource hierarchy is complex, which can ensure the refined management of the system. By reading and locating the permission parameters before the change currently stored in the leaf node, in the prior art, there may be no direct storage of the permission parameters before the change or no clear way to trace the data. However, the present invention clearly reads the permission parameters before the change, so that each permission change can be clearly reflected in the system, which is conducive to the traceability of data and the audit function of permission management. After locating the leaf node, the permission parameters before the change currently stored are read, making the permission change process more transparent and accurately recording the current permission status, which is crucial for subsequent permission change records and audit functions, ensuring that the system can obtain the status before the change in a timely manner and track and trace permission changes through historical data; The metadata is obtained through the permission change request, and the initiating node identifier is extracted based on the metadata. Traditional permission management systems often ignore the identifier of the request initiating node and lack control and audit of the request source. This may make it difficult to trace which node initiated the permission change request when an exception occurs in the permission change. The present invention can ensure the transparency of permission management and enhance security and anti-tampering capabilities by recording the initiating node identifier. The metadata is obtained and the initiating node identifier is extracted to ensure the traceability of the source of the permission change request. This not only helps the system track the source of each permission request and ensure the transparency and security of the permission change process, but also provides an important basis for subsequent permission audits. The permission change time when the request interface of the multi-cluster permission management system receives the permission change request is obtained, and the permission change time, initiating node identifier, permission parameters before change and permission parameters after change are associated with the corresponding leaf node to obtain a change record, and at the same time assign a unique ID to the change record. In the prior art, there may be no mandatory requirement to assign a unique ID for each permission change or there is no accurate time record, which will affect the permission management system. The traceability of the system, especially when there is a dispute over permission changes, lacks an effective basis. The present invention can accurately trace each permission change by assigning a unique ID to each change and recording the change time, avoiding data loss or inconsistent permission changes. By obtaining the timestamp of the permission change and assigning a unique ID, not only can the timing of the permission change be accurately recorded, but also a unique identifier can be assigned to each change, so that all permission change records can be searched and traced through the unique ID, ensuring the accuracy and traceability of each change operation. In traditional technology, change records may be stored separately in other database tables, and additional matching and association operations are required during query, which increases the complexity of data access. The present invention not only simplifies the query process by directly associating permission change records with leaf nodes, but also reduces permission synchronization delays and inconsistency problems that may be caused by data synchronization asynchrony. By associating change records with leaf nodes, change information can be directly stored in the corresponding resource permission items, which not only makes permission change records more intuitive and easy to query, but also ensures the integrity and consistency of resource management.
[0027] In one embodiment, the step S4 of obtaining real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtaining a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load, includes: S41, sending a preset number of probe data packets to each cluster and recording each round trip time in real time, and obtaining real-time network delay data based on the multiple round trip times; S42. Obtain a process statistics file for each cluster, and obtain CPU user state time, system state time, idle time, and IO wait time based on the process statistics file; S43, obtaining CPU usage according to the CPU user state time, system state time, idle time and IO waiting time; S44. Obtain the total memory, used memory, and cache memory of each cluster, and obtain the memory occupancy rate based on the ratio of the sum of the used memory and cache memory to the total memory; S45. Obtain the disk read / write byte rate and disk bandwidth of each cluster, and obtain the disk I / O load based on the ratio of the disk read / write byte rate to the disk bandwidth; S46. Assign corresponding weight coefficients to the real-time network delay data, CPU usage, memory occupancy and disk I / O load respectively, and perform weighted sum calculation based on the real-time network delay data, CPU usage, memory occupancy, disk I / O load and their corresponding weight coefficients to obtain the dynamic weight value of the corresponding cluster.
[0028] As described in steps S41-S46 above, when calculating the real-time network delay data, it is necessary to remove the maximum and minimum values and then calculate the average value of all remaining round-trip times to obtain the real-time network delay data. The calculation formula for the CPU usage is: ;in, Indicates CPU usage. Indicates idle time, Indicates CPU user state time, Indicates the system state time, Represents IO waiting time; before calculating the dynamic weight value, it is necessary to normalize the real-time network delay data, CPU usage, memory occupancy and disk I / O load. The present invention sends a preset number of detection packets to each cluster and records the round-trip time of each time in real time, and obtains real-time network delay data based on multiple round-trip times. Traditional delay monitoring may be affected by instantaneous fluctuations and it is difficult to fully reflect changes in network quality. Through the preset number of detections, the reliability of the data is greatly improved, which helps the system to make optimization adjustments based on the actual network status. By sending a preset number of detection packets and recording the round-trip time of each time in real time, stable network delay data can be obtained over a long period of time, which can fully capture dynamic changes in the network environment, including short-term sudden delay fluctuations and network congestion, ensuring accurate grasp of network delay. In multi-cluster resource permission management, round-trip time directly affects the real-time performance of data synchronization. Through multiple detections, accidental network fluctuations can be effectively filtered out to obtain an average, more stable network delay data, thereby reducing permission synchronization errors caused by delays. By obtaining the process statistics file of each cluster and obtaining the CPU user state time, system state time, idle time and IO wait time according to the process statistics file, the CPU usage in different states can be accurately analyzed by obtaining the process statistics file. The subdivision of user state time, system state time, idle time and IO wait time makes the understanding of cluster load more comprehensive and helps to accurately identify performance bottlenecks. The CPU usage in different states reflects the current workload of the cluster and can reflect the execution status of each process in the cluster in real time, so as to perform load prediction and optimization. Analyzing various types of CPU time can help the system determine whether there is unreasonable resource contention, such as excessive system calls or frequent IO operations, so as to achieve optimized configuration and improve the overall performance of the cluster. By refining the monitoring of CPU status, potential problems of excessive system load can be discovered in time to avoid synchronization errors. The CPU utilization rate is a comprehensive indicator that takes into account multiple dimensions such as user state, system state and idle time, which helps to comprehensively analyze the CPU load status. This comprehensive analysis can help the system more accurately judge the current computing power of the cluster. High CPU utilization rate is usually a sign that the cluster is overloaded or the computing tasks are busy. By calculating the CPU utilization rate, the computing resource status of the cluster can be monitored in real time, and computing resources can be adjusted or task scheduling can be optimized in time to avoid performance degradation due to resource overload. When the system detects abnormal CPU utilization rate, it can actively trigger the load balancing mechanism, reasonably schedule tasks, and improve the overall performance of the cluster. Compared with relying solely on memory or disk usage to judge the load, CPU utilization rate can more directly reflect the changes in computing performance. By obtaining the total memory, used memory, and cache memory of each cluster, and obtaining the memory utilization rate based on the ratio of the sum of used memory and cache memory to total memory, memory is one of the core resources of cluster performance. By performing a detailed analysis of total memory, used memory, and cache memory, the actual memory utilization of the cluster can be more accurately determined to avoid performance degradation caused by insufficient memory. Although cache memory occupies physical memory in some scenarios, it does not occupy actual computing resources. In the calculation of memory utilization rate, distinguishing cache memory from used memory can better reflect the memory utilization efficiency of the cluster. By accurately calculating the memory utilization rate, the system can adjust the memory allocation strategy in a timely manner to avoid swapping and overflow caused by excessive memory utilization, thereby improving the utilization rate of cluster resources. Memory utilization rate is often closely related to CPU utilization rate. By jointly analyzing these two indicators, cluster bottlenecks can be more accurately identified and reasonable resource scheduling can be made. By obtaining the disk read / write byte rate and disk bandwidth for each cluster, and then calculating the disk I / O load based on the ratio of the disk read / write byte rate to the disk bandwidth, disk I / O performance directly affects data transmission and processing speed. By combining the disk read / write byte rate and disk bandwidth, we can comprehensively evaluate disk read / write performance and ensure that the cluster does not encounter bottlenecks when processing large amounts of data. Excessive disk I / O load can lead to decreased performance of the entire system, or even a crash. By monitoring the disk I / O load in real time, problems can be discovered in time and measures can be taken (such as expanding storage, adjusting data flow, etc.) to reduce the risk of disk overload. The disk I / O load data can provide a basis for disk optimization solutions, such as using more efficient storage devices or redesigning the storage layout, thereby improving the overall performance of the cluster. By assigning corresponding weight coefficients to real-time network latency data, CPU usage, memory occupancy and disk I / O load respectively, and performing weighted summation calculation based on real-time network latency data, CPU usage, memory occupancy, disk I / O load and its corresponding weight coefficients, the dynamic weight value of the corresponding cluster is obtained. In multi-cluster resource permission management, multiple factors such as network latency, CPU, memory, disk I / O, etc. will affect performance. By assigning weight coefficients to each indicator, the comprehensive performance of each cluster can be comprehensively evaluated to ensure that each resource The sources are balanced and scheduled. The resource conditions of different clusters are different. The weighted summation method can dynamically adjust the weight of each cluster to reflect its current actual performance condition. Compared with static resource allocation, the dynamic adjustment method can more flexibly adapt to changes in cluster load and avoid resource waste or shortage. The weight value can help the system intelligently adjust resource allocation and authority synchronization strategy according to the real-time resource status of the cluster, thereby effectively avoiding synchronization delays and inconsistency problems caused by network delays or resource overloads. The present invention uses multi-dimensional data collection and weighted algorithms to dynamically adjust resource allocation according to the real-time performance status of the cluster during asynchronous synchronization, solving the problem of authority synchronization delay and inconsistency caused by network delays and uneven loads. Compared with the existing technology, it can perform resource management more accurately and flexibly, thereby improving cluster resource utilization and the overall reliability of the system.
[0029] In one embodiment, the step S6 of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster includes: S61: Acquire a first current path branch and a first changed path branch of a priority synchronization group cluster, and extract first attribute fields of all nodes in the first current path branch to obtain a first structured data set; S62: Extract the second attribute fields of all nodes in the first change path branch to obtain a second structured data set; S63. Convert the first structured data set and the second structured data set into a first binary data sequence and a second binary data sequence respectively; S64: Obtain difference data segments according to the first binary data sequence and the second binary data sequence, and update the first structured data set segment by segment according to the difference data segments to obtain a first updated binary data sequence; S65: Acquire a second changed path branch of the delayed synchronization group cluster, and locate a second current path branch of the delayed synchronization group cluster according to the path identifier of the second changed path branch; S66. Obtain a second updated binary data sequence according to the second current path branch and the second changed path branch, and use the SHA-256 hash algorithm to obtain a second hash value of the second updated binary data sequence and the first updated binary data sequence.
[0030] As described in the above steps S61-S66, the second hash value is a hash value corresponding to the delayed synchronization group cluster and the priority synchronization group cluster obtained by calculating the second updated binary data sequence and the first updated binary data sequence through the SHA-256 hash algorithm. The input of the SHA-256 algorithm is the complete binary stream of the data sequence B, and the output is a hash value of a fixed length of 256 bits. The calculation process follows the compression function, constant and initial hash value setting of the SHA-256 standard. The method for obtaining the second updated binary data sequence is the same as the method for obtaining the first updated binary data sequence. Both are obtained by performing an XOR operation on the binary data sequence of the second current path branch and the binary data sequence of the second changed path branch to generate a difference data segment, and then update it segment by segment. Before obtaining the second updated binary data sequence through the delayed synchronization group cluster, The changed path branch data needs to be compressed and stored in the distributed cache system, and the cache address and expiration time must be recorded. This is because the load status and synchronization priority of the priority synchronization group cluster and the delayed synchronization group cluster differ. A differentiated strategy is needed to balance synchronization efficiency and system stability. Specifically, the dynamic weight value of the delayed synchronization group cluster is lower than the preset threshold and is in a high-load state. The delayed synchronization group cluster has a lower synchronization priority and allows a certain time delay. Using compressed storage, the complete path branch data can be cached at one time to avoid real-time transmission failures caused by high load. The compressed binary stream is smaller in size and is suitable for temporary storage in the cache system. It can be decompressed after the cluster load decreases. Directly using differential data segments for transmission may cause unstable difference calculation results due to cluster load fluctuations (such as real-time changes in local path branch data), which in turn increases the probability of inconsistent hash values. The present invention obtains the first current path branch and the first change path branch of the priority synchronization group cluster, and can accurately locate the current synchronization and change status in the cluster, thereby ensuring that the synchronization process is only focused on the critical path and the necessary change path, avoiding redundant calculations and invalid synchronization caused by full path traversal. Compared with the full path synchronization method that may be involved in the prior art, this selective synchronization greatly improves data processing efficiency and reduces redundant data transmission. Especially in an asynchronous cluster environment, it can effectively reduce synchronization problems caused by network delay and cluster load, and extract the first attribute field of all nodes in the first current path branch to obtain the first node. The structured data set is obtained by extracting the second attribute fields of all nodes in the first change path branch to obtain a second structured data set. The first attribute fields of all nodes in the first current path branch are extracted. By focusing on the key data fields of the current path, unnecessary data processing and storage burdens can be reduced. By extracting structured data fields instead of data from the entire path node, the targeted and accurate data processing is improved, and unnecessary field extraction is avoided. In the existing technology, the node attribute level is often not refined, resulting in redundant calculations and data consistency issues during the synchronization process. By extracting the second attribute fields of all nodes in the first change path branch, the specific attributes of the changed parts can be accurately obtained for synchronization. By converting the first structured data set and the second structured data set into a first binary data sequence and a second binary data sequence, respectively, the structured data is converted into a binary data sequence, enabling efficient and compressed transmission and storage of the data. Binary data has a smaller storage space and transmission burden. Compared to traditional text data formats, the binary format can significantly reduce data transmission time in the network, especially in asynchronous synchronization scenarios with high network latency, significantly improving the efficiency and response speed of data synchronization. The binary format conversion process not only improves transmission efficiency but also ensures data reliability and consistency. Differential data segments are obtained from the first binary data sequence and the second binary data sequence. Obtaining the differential data segments limits the synchronization process to the updated data rather than synchronizing all data. By comparing the two binary data sequences, the differences between the two can be accurately found, and only the differential portions can be transmitted and updated. This differentiated synchronization method greatly improves the efficiency of the synchronization process and avoids the redundant data transmission and processing burden caused by full synchronization in traditional methods. Differential synchronization is particularly important for multi-cluster resource management systems with high concurrency and low latency requirements. The first structured data set is updated segment by segment based on the difference data segments to obtain a first updated binary data sequence. A second change path branch of the delayed synchronization group cluster is obtained, and the second current path branch of the delayed synchronization group cluster is located based on the path identifier of the second change path branch. A second updated binary data sequence is obtained through the second current path branch and the second change path branch. This segment-by-segment update operation ensures granular control of data synchronization, making the update process more flexible and precise. Unlike full updates in the prior art, segment-by-segment updates not only reduce data transmission volume but also avoid data conflicts and inconsistencies. Especially in complex cluster network environments with limited bandwidth, segment-by-segment updates can significantly reduce the bandwidth required for synchronization and improve overall synchronization efficiency. This gradual update approach improves the system's fault tolerance and real-time performance, and is particularly suitable for large-scale distributed systems. By generating an updated binary data sequence, it ensures that all updated data during the synchronization process has been accurately identified and processed. The updated data sequence provides a clear basis for subsequent synchronization operations, reducing the risk of data loss and erroneous updates. Compared to global updates in the prior art, the updated binary sequence of the present invention enables each cluster to obtain necessary update information and avoids interference from excessive irrelevant data, thereby improving update efficiency and accuracy. The SHA-256 hash algorithm is used to obtain the second hash value of the second updated binary data sequence and the first updated binary data sequence. The SHA-256 hash algorithm is used to hash the updated binary data sequence to ensure data integrity and consistency. The irreversibility of the SHA-256 hash algorithm enables each update step in the synchronization process to be accurately verified and the source of the error to be traced when a problem occurs. Compared with the existing technology that may ignore hash verification, this operation can ensure the security and consistency of the updated data and avoid data corruption or erroneous synchronization caused by external factors such as network problems and cluster failures. This can effectively solve the synchronization delay and permission inconsistency problems caused by factors such as network delay and cluster load in multi-cluster resource permission management.
[0031] In one embodiment, the step S64 of acquiring difference data segments according to the first binary data sequence and the second binary data sequence includes: S641. Perform a byte-by-byte XOR operation on the first binary data sequence and the second binary data sequence to obtain a difference data sequence; S642: traverse the difference data sequence and record the difference segment starting positions and difference segment lengths of consecutive non-zero bytes to obtain a difference segment information list, wherein the difference segment information list includes a plurality of difference segments whose difference segment starting positions are sorted from smallest to largest. S643: Extract byte data corresponding to a position in the first change path branch from each difference segment to obtain a data block, and concatenate the multiple data blocks in the order of the difference segment information list to obtain a concatenated data block. S644: Obtain the number of difference segments in the difference segment information list, and sequentially concatenate the number of difference segments, the starting position of the difference segments, the length of the difference segments, and the concatenated data blocks to obtain a difference data segment.
[0032] As described in the above steps S641-S644, the order of the difference fragment information list is sorted from small to large according to the starting position of the difference fragment in the binary data sequence, that is, the difference fragments are arranged in the order of appearance in the binary data sequence of the first current path branch of the target cluster, and the order of splicing the number of difference fragments, the starting position of the difference fragments, the length of the difference fragments and the splicing data blocks in sequence to obtain the difference data segments is to first write the number of difference fragments, then write the starting position of each difference fragment, then write the length of each difference fragment, and finally write the splicing data block to obtain the difference data segment. Then, the difference data segment needs to be CRC32 checked, and the check value is calculated and attached to the end of the data segment for the receiving end to verify the data integrity. The binary data sequence refers to the priority synchronization group set. The complete path branch (hierarchical data from the cluster identification node to the specific permission item leaf node) corresponding to the permission change request in the local radix tree copy of the group is digitally converted to form a byte stream set. The binary data sequence can be determined by matching the corresponding nodes layer by layer in the local radix tree copy of the target cluster according to the target resource path in the permission change request. Then, all nodes of the path branch are traversed, and the attribute fields of each node are extracted to form a structured data set. Finally, a preset serialization protocol is used to convert the structured data set into a continuous binary byte sequence. If the path branch data length is less than the preset value, it is supplemented by filling with fixed bytes; if it exceeds the preset value, it is compressed using a lossless compression algorithm to form the final binary data sequence to ensure that the sequence length is uniform and comparable. The present invention obtains a difference data sequence by performing a byte-by-byte XOR operation on a first binary data sequence and a second binary data sequence. The byte-by-byte XOR operation can accurately capture the bit-by-bit difference between the two data sequences. Unlike traditional comparison methods, this method can accurately detect changes in every byte, rather than relying solely on simple bit or byte-level comparisons. This accuracy helps reduce errors, especially when the data sequences are long or complex, and can avoid misjudgments. The difference data sequence can be quickly generated through the XOR operation, eliminating the need for complex multiple comparison processes, saving computing resources. Unlike traditional byte-by-byte comparison, the XOR operation is a highly parallelized operation that can improve overall efficiency. The XOR operation directly converts identical byte positions to zero, effectively eliminating redundant data and focusing only on the differences in the data, thereby reducing the computational burden of subsequent processing. Common comparison methods in the prior art may rely on string matching, hash value comparison, etc., which are often inefficient when the data volume is large or cause significant delays during synchronous updates. The present invention can directly obtain the difference data sequence through the XOR operation, thereby accelerating subsequent processing. By traversing the difference data sequence and recording the difference segment starting position and difference segment length of continuous non-zero bytes, a difference segment information list is obtained, wherein the difference segment information list includes multiple difference segments whose starting positions are sorted from small to large. Recording difference segments with continuous non-zero bytes can effectively reduce the storage space occupied and highlight those data blocks that have differences in multiple positions. Compared with traditional methods, it avoids redundant recording of a single byte, can further optimize the data storage structure, and aggregates continuous difference bytes into a difference segment, which can effectively reduce the complexity of subsequent data processing. In the subsequent splicing, modification, update and other processes, the amount of data that needs to be operated is reduced, thereby improving the processing speed. By recording the starting position and length of the difference segment, the data that needs to be operated can be accurately specified during data transmission or update. Data segments avoid unnecessary data transmission and calculation, and improve transmission efficiency. Traditional methods may require byte-by-byte comparison and transmission, which will lead to inefficiency and inconsistency in large-scale data synchronization. The present invention reduces the complexity and delay of data processing by aggregating difference fragments, and sorts the difference fragment information list by starting position to ensure that subsequent splicing operations are performed in the correct order. This can avoid data confusion or splicing errors during the processing process, and ensure that the final generated data block is accurate. By sorting the difference fragments, the final synchronized data block can be guaranteed to be smoothly and efficiently spliced and updated. After sorting by the starting position of the difference fragments, the system can execute tasks more orderly, avoid conflicts caused by multi-threaded operations or data processing within the cluster, thereby improving the stability of concurrent processing; By extracting the byte data corresponding to the position in the first change path branch from each difference segment to obtain a data block, and splicing multiple data blocks in the order of the difference segment information list to obtain a spliced data block, by extracting the byte data related to the difference segment and splicing it together, it can ensure that the permission change data only includes the necessary parts, avoiding unnecessary data redundancy and processing. For large-scale data updates, it avoids excessive repeated calculations and improves efficiency. By splicing data blocks in the order of difference segments, it can minimize the consumption of memory and computing resources. In the process of synchronizing multiple clusters, it can effectively reduce bandwidth usage and memory pressure. The splicing operation ensures the integrity of the data block and avoids permission inconsistency caused by loss or confusion during the data synchronization process. The existing technology may be relatively rough in data synchronization, which may cause the synchronized data range to be too large, thereby affecting efficiency. By fine-tuning the difference data, the accuracy and speed of data synchronization can be effectively improved. By obtaining the number of difference fragments in the difference fragment information list, and splicing the number of difference fragments, the starting position of the difference fragments, the length of the difference fragments and the spliced data blocks in sequence to obtain the difference data segments, by recording the number of difference fragments, the starting position, the length and other information, the difference data can be accurately described and synchronized, which not only ensures the accuracy of data synchronization, but also helps the system to perform efficient data synchronization and update in a multi-cluster environment. By splicing the number, position and length of the difference fragments together with the data blocks, multiple communications and data transmissions can be reduced, and the synchronization efficiency can be improved. At the same time, the amount of data transmitted between clusters is compressed, thereby reducing the network burden. The difference data segments obtained by splicing can be used as the basis for incremental updates, avoiding unnecessary repeated calculations caused by full updates. Incremental updates help to quickly respond to permission change requirements and shorten update delays. Traditional permission synchronization methods often rely on full updates or complex permission record management, resulting in synchronization delays and inconsistency problems. The incremental synchronization method of the present invention can significantly improve efficiency, reduce network delays, and solve the permission synchronization inconsistency problem in the prior art.
[0033] like Figure 2 As shown, the present application also provides a multi-cluster resource authority management system based on a radix tree, comprising: A construction module is used to obtain the network topology structures and historical permission synchronization records of multiple clusters in the multi-cluster system, and construct an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes and leaf nodes; A generation module is used to obtain the permission change request of each cluster and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; an extraction module, configured to extract a complete path branch of each change record and obtain a first hash value of the complete path branch; An acquisition module is used to obtain real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtain a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load; A first judgment module is used to judge whether the dynamic weight value of each cluster is greater than a preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; A second judgment module is used to obtain the second hash value of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and judge whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
[0034] In one embodiment, the generating module includes: An extraction unit is configured to receive a permission change request through a request interface of the multi-cluster permission management system, and extract a specific operation type, a resource location path, and a changed permission parameter from the permission change request; A matching unit, configured to obtain a hierarchical structure of the resource location path, and match layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure, and read the pre-change permission parameters currently stored in the leaf node located therein; an acquiring unit, configured to acquire metadata according to the permission change request, and extract an initiating node identifier according to the metadata; The association generation unit is used to obtain the permission change time when the request interface of the multi-cluster permission management system receives the permission change request, and associate the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change to the corresponding leaf node to obtain a change record.
[0035] It should be noted that each module and unit in the radix tree-based multi-cluster resource authority management system corresponds one-to-one to the steps in the radix tree-based multi-cluster resource authority management method.
[0036] like Figure 3 As shown, the present application also provides a computer device, which can be a server, and its internal structure can be as shown in FIG. Figure 3 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store all data required for the process of the multi-cluster resource permission management method based on the radix tree. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the multi-cluster resource permission management method based on the radix tree is implemented.
[0037] Those skilled in the art will understand that Figure 3 The structure shown in is merely a block diagram of a portion of the structure related to the present application solution and does not constitute a limitation on the computer device to which the present application solution is applied.
[0038] An embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, any of the above-mentioned multi-cluster resource permission management methods based on a radix tree is implemented.
[0039] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided in this application and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct RAM bus dynamic RAM (DRDRAM), and RAM bus dynamic RAM (RDRAM).
[0040] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, apparatus, article, or method comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, apparatus, article, or method. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, apparatus, article, or method comprising the element.
[0041] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A multi-cluster resource authority management method based on radix tree, characterized in that: include: Obtaining network topology structures and historical permission synchronization records of multiple clusters in a multi-cluster system, and constructing an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes, and leaf nodes; Obtain the permission change request of each cluster, and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; Extracting the complete path branch of each change record and obtaining a first hash value of the complete path branch; Obtaining real-time network latency data, CPU usage, memory occupancy, and disk I / O load for each cluster, and obtaining a dynamic weight value for the corresponding cluster based on each of the real-time network latency data, CPU usage, memory occupancy, and disk I / O load; Determine whether the dynamic weight value of each cluster is greater than the preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; Obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and determining whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
2. The multi-cluster resource authority management method based on radix tree according to claim 1 is characterized in that: The step of constructing an initial radix tree model according to the plurality of network topology structures and historical permission synchronization records includes: Obtain the global permission domain, cluster identifier, resource type, resource object, and permission items of the multi-cluster system, and build a hierarchical structure with the global permission domain of the multi-cluster system as the root node, the cluster identifier as the first-level child node, the resource type as the second-level child node, the resource object as the third-level child node, and the permission item as the leaf node; Adding network connection information to the attributes of the first-level child node according to the network topology structure; Extracting the permission change rules of each resource object from the historical permission synchronization records, and optimizing the initial permission configuration of the leaf node according to each permission change rule to obtain an optimized permission configuration; According to the hierarchical structure, network connection information and optimized authority configuration, each node is connected in series through a tree structure generation algorithm to form a complete initial radix tree model.
3. The multi-cluster resource authority management method based on radix tree according to claim 1 is characterized in that: The step of generating a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request includes: Receive a permission change request through a request interface of the multi-cluster permission management system, and extract the specific operation type, resource location path, and changed permission parameters from the permission change request; Obtaining the hierarchical structure of the resource location path, matching layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure, and reading the pre-change permission parameters currently stored in the leaf node; Obtaining metadata according to the permission change request, and extracting an initiating node identifier according to the metadata; The permission change time when the request interface of the multi-cluster permission management system receives the permission change request is obtained, and the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change are associated with the corresponding leaf node to obtain a change record.
4. The multi-cluster resource authority management method based on radix tree according to claim 1 is characterized in that: The steps of obtaining real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtaining a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load, include: Sending a preset number of probe packets to each cluster and recording the round trip time of each packet in real time, and obtaining real-time network delay data based on multiple round trip times; Obtain the process statistics file of each cluster, and obtain the CPU user state time, system state time, idle time and IO wait time based on the process statistics file; Obtaining CPU usage based on the CPU user state time, system state time, idle time, and IO waiting time; Obtain the total memory, used memory, and cache memory of each cluster, and obtain the memory usage based on the total memory, used memory, and cache memory; Obtain the disk read / write byte rate and disk bandwidth of each cluster, and obtain the disk I / O load based on the disk read / write byte rate and disk bandwidth; Corresponding weight coefficients are assigned to real-time network delay data, CPU usage, memory occupancy, and disk I / O load, respectively, and a dynamic weight value of the corresponding cluster is obtained based on the real-time network delay data, CPU usage, memory occupancy, disk I / O load, and their corresponding weight coefficients.
5. The multi-cluster resource authority management method based on radix tree according to claim 1 is characterized in that: The steps of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster include: Obtaining a first current path branch and a first changed path branch of the priority synchronization group cluster, and extracting first attribute fields of all nodes in the first current path branch to obtain a first structured data set; Extracting the second attribute fields of all nodes in the first change path branch to obtain a second structured data set; Converting the first structured data set and the second structured data set into a first binary data sequence and a second binary data sequence respectively; Obtaining difference data segments according to the first binary data sequence and the second binary data sequence, and updating the first structured data set segment by segment according to the difference data segments to obtain a first updated binary data sequence; Acquire a second changed path branch of the delayed synchronization group cluster, and locate a second current path branch of the delayed synchronization group cluster according to the path identifier of the second changed path branch; A second updated binary data sequence is obtained according to the second current path branch and the second changed path branch, and a second hash value of the second updated binary data sequence and the first updated binary data sequence is obtained using the SHA-256 hash algorithm.
6. The multi-cluster resource authority management method based on radix tree according to claim 5, characterized in that: The step of obtaining a difference data segment according to the first binary data sequence and the second binary data sequence includes: performing a byte-by-byte exclusive OR operation on the first binary data sequence and the second binary data sequence to obtain a difference data sequence; Traversing the difference data sequence and recording difference segment starting positions and difference segment lengths of consecutive non-zero bytes to obtain a difference segment information list, wherein the difference segment information list includes a plurality of difference segments whose difference segment starting positions are sorted from small to large; Extracting byte data at a position corresponding to the first change path branch from each of the difference segments to obtain a data block, and splicing the multiple data blocks in the order of the difference segment information list to obtain a spliced data block; The number of difference segments in the difference segment information list is obtained, and the number of difference segments, the starting position of the difference segments, the length of the difference segments and the splicing data block are spliced in sequence to obtain a difference data segment.
7. A multi-cluster resource authority management system based on a radix tree, used to implement the method according to any one of claims 1 to 6, characterized in that: include: A construction module is used to obtain the network topology structures and historical permission synchronization records of multiple clusters in the multi-cluster system, and construct an initial radix tree model based on the multiple network topology structures and historical permission synchronization records, wherein the initial radix tree model includes a root node, first-level child nodes, second-level child nodes, third-level child nodes and leaf nodes; A generation module is used to obtain the permission change request of each cluster and generate a corresponding change record in the initial radix tree model according to the specific operation type, resource location path and changed permission parameters in the permission change request; an extraction module, configured to extract a complete path branch of each change record and obtain a first hash value of the complete path branch; An acquisition module is used to obtain real-time network delay data, CPU usage, memory occupancy, and disk I / O load of each cluster, and obtain a dynamic weight value of the corresponding cluster based on each of the real-time network delay data, CPU usage, memory occupancy, and disk I / O load; A first judgment module is used to judge whether the dynamic weight value of each cluster is greater than a preset threshold; If the dynamic weight value is greater than a preset threshold, the cluster corresponding to the dynamic weight value is divided into a priority synchronization group cluster; If the dynamic weight value is not greater than the preset threshold, the cluster corresponding to the dynamic weight value is divided into a delayed synchronization group cluster; A second judgment module is used to obtain the second hash value of the priority synchronization group cluster and the delayed synchronization group cluster respectively, and judge whether the second hash value of each cluster is consistent with the first hash value; If the second hash value is consistent with the first hash value, determining that the first current path branch of the cluster corresponding to the hash value is synchronized with the changed path branch; If the second hash value is inconsistent with the first hash value, it is determined that the first current path branch of the cluster corresponding to the hash value is not synchronized with the changed path branch and the process returns to the step of respectively obtaining the second hash values of the priority synchronization group cluster and the delayed synchronization group cluster until the second hash value is consistent with the first hash value.
8. The multi-cluster resource authority management system based on radix tree according to claim 7, characterized in that: The generation module includes: An extraction unit is configured to receive a permission change request through a request interface of the multi-cluster permission management system, and extract a specific operation type, a resource location path, and a changed permission parameter from the permission change request; A matching unit, configured to obtain a hierarchical structure of the resource location path, and match layer by layer starting from the root node of the initial radix tree model according to the hierarchical structure, and read the pre-change permission parameters currently stored in the leaf node located therein; an acquiring unit, configured to acquire metadata according to the permission change request, and extract an initiating node identifier according to the metadata; The association generation unit is used to obtain the permission change time when the request interface of the multi-cluster permission management system receives the permission change request, and associate the permission change time, the initiating node identifier, the permission parameters before the change, and the permission parameters after the change to the corresponding leaf node to obtain a change record.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Remote dynamic data processing and verifying method and system
CN103793391A
Database data integrity verification method suitable for block chain efficient query
CN118227661A
Distributed Memory Pooling
US20250138883A1
Data stream load balancing method and apparatus, network topology and data center
WO2024146148A1