A distributed file system file identity management method, device and system
By recording the application's signature information and identity information in the distributed file server, the problem that applications in the intelligent operating system cannot read shared files in the initial stage is solved, the application's identity management and data access control are realized, and the file identity management efficiency and data security of the distributed system are improved.
Patent Information
- Application Number
- CN202111487441.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-12-07
AI Technical Summary
In an intelligent operating system, since the user identifier and user group identifier of the application are dynamically allocated by the permission management module in the system, the shared file cannot obtain information such as the user identifier and user group identifier of the corresponding application in the initial stage, so the access control list cannot be determined, resulting in the application being unable to mount and read the shared file.
By recording the application's signature information in the distributed file server, and recording its identity information when the application initiates a request to create a shared file; when the application tries to read a shared file, it checks its signature information. If it is consistent, it mounts the shared file directory and writes it to the access control list.
It realizes the identification information of the application in the initial stage, ensures that the application can mount and read shared files, improves the efficiency of file identity management in distributed systems, and ensures data security through signature verification.
Smart Images

Figure CN114138730B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of distributed systems, and in particular to a distributed file system file identity management method, device and system. Background Art
[0002] The existing distributed file system file identity management implementation scheme usually uses the ACL mechanism of NFSv4 to implement it. The ACL mechanism of NFSv4 controls the reading and mounting of shared files by applications by pre-setting the access control list of the user identifier and user group identifier of the shared file. However, in the intelligent operating system, since the user identifier and user group identifier of the application are dynamically allocated by the permission management module in the system, the shared file cannot obtain the user identifier and user group identifier of the corresponding application and other information in the initial stage. Therefore, in the initial stage, the access control list corresponding to the shared file cannot be determined, and the application cannot mount and read the corresponding shared file. Summary of the invention
[0003] In view of this, the present invention provides a distributed file system file identity management method, device and system to solve the problem mentioned in the above background that applications cannot read and mount shared files in the initial stage due to the dynamic allocation of user identifiers and user group identifiers.
[0004] In order to solve the above technical problems, the present invention adopts the following technical solutions:
[0005] A distributed file system file identity management method according to an embodiment of the present invention is applied to a system including a distributed file server, a first electronic device connected to the distributed file server, and a second electronic device, wherein the first electronic device and the second electronic device are respectively installed with a first application and a second application, and includes:
[0006] A first application in a first electronic device initiates a request to create a shared file to a distributed file server;
[0007] The distributed file server creates a shared file locally in response to the request to create a shared file, and records the first signature information of the first application;
[0008] The second application in the second electronic device initiates a read request to the distributed file server to read the shared file, where the read request includes second signature information of the second application in the second electronic device;
[0009] The distributed file server verifies the first signature information and the second signature information in response to the read request;
[0010] If the first signature information is consistent with the second signature information, the distributed file server enables the second application to mount the shared file directory, and writes the identity information of the second application in the second electronic device into the access control list;
[0011] The second application reads the shared file.
[0012] Furthermore, the distributed file server creates a shared file locally in response to the request to create a shared file, including:
[0013] The distributed file server sets a file identity owner attribute for the shared file using the identity information of the first application in the first electronic device.
[0014] Furthermore, the identity information of the first application in the first electronic device includes a user identifier and a user group identifier of the first application, and the identity information of the second application in the second electronic device includes a user identifier and a user group identifier of the second application.
[0015] Furthermore, the signature information is an MD5 code or a SHA1 code.
[0016] Furthermore, if the first signature information is inconsistent with the second signature information, the distributed file server returns a failure message to the second electronic device.
[0017] Another aspect of the present invention provides a distributed file server, including:
[0018] A connection module, used to connect the first electronic device and the second electronic device;
[0019] A shared file creation module, configured to create a shared file locally in response to a request from a first application in a first electronic device;
[0020] A signature verification module, used to record and verify the signature information of the first application in the first electronic device and the second application in the second electronic device;
[0021] A file mounting module, used to enable the second application to mount the shared file directory when the first signature information is consistent with the second signature information;
[0022] The identity information setting module is used to obtain the identity information of the second application in the second electronic device and write it into an access control list, so that the second application can read the shared file based on the identity information in the access control list.
[0023] Furthermore, the identity information setting module is used to:
[0024] The identity information of the first application in the first electronic device is obtained to set a file identity owner attribute for the shared file.
[0025] Furthermore, the file mount module is used to:
[0026] When the first signature information is inconsistent with the second signature information, failure information is returned to the second electronic device.
[0027] Furthermore, the identity information of the first application in the first electronic device includes a user identifier and a user group identifier of the first application, and the identity information of the second application in the second electronic device includes a user identifier and a user group identifier of the second application.
[0028] Furthermore, the signature information includes an MD5 code or a SHA1 code.
[0029] Another aspect of the present invention provides a distributed file system, including:
[0030] Distributed file server, the distributed file server is the above-mentioned distributed file server;
[0031] The first electronic device is used to connect to the distributed file server and create a shared file through the distributed file server.
[0032] The second electronic device is used to connect to the distributed file server and mount the shared file directory through the distributed file server and read the shared file.
[0033] The above technical solution of the present invention has at least one of the following beneficial effects:
[0034] 1. The method of the embodiment of the present invention effectively improves the efficiency of file identity management in the distributed system by setting the identity owner information of the corresponding applications in different devices of the shared file so that the corresponding applications can mount the shared file directory to read the shared file;
[0035] 2. The method of the embodiment of the present invention determines the identity information of the corresponding application in different devices through signature verification. The signature verification is simple and easy and has high verification accuracy.
[0036] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention and implement it according to the contents of the specification, the following is a detailed description of the preferred embodiments of the present invention in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 A schematic diagram of an application scenario of a distributed file system file identity management according to an embodiment of the present invention;
[0038] Figure 2 A flowchart of a distributed file system file identity management method according to an embodiment of the present invention;
[0039] Figure 3 A schematic diagram of the structure of a distributed file server according to an embodiment of the present invention;
[0040] Figure 4 A schematic diagram of the structure of a distributed file system according to an embodiment of the present invention;
[0041] Figure 5 The figure is a SoC block diagram of a distributed file server according to an embodiment of the present invention. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] It will be understood that, as used herein, the term "module" may refer to or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) and / or memory that executes one or more software or firmware programs, a combinational logic circuit, and / or other appropriate hardware components that provide the described functionality, or may be part of these hardware components.
[0044] The NFSv4 ACL mechanism controls access to corresponding files by pre-defining corresponding UID and GID access control lists. However, in intelligent operating systems such as AliOs, since the UID of the application is dynamically assigned by the system's permission management module, the system cannot know the UID, GID and other information of the corresponding application at the initial stage. Therefore, before the application is installed, its corresponding access control list cannot be determined.
[0045] This specification first describes in detail a distributed file system file identity management method according to an embodiment of the present invention in conjunction with the accompanying drawings.
[0046] like Figure 1As shown, a schematic diagram of an application scenario according to an embodiment of the present invention includes: a distributed file server 130, and a first electronic device 100 and a second electronic device 110 connected thereto respectively. The first electronic device includes a first application 101 and a second application 102, and the second electronic device 110 includes a first application 111. The user identifier (User Id, UID) of the first application 101 in the first electronic device 100 is 60001, and the user group identifier (GroupId, GID) is 60001. Specifically, the UID number is used to uniquely identify the user in the system. It is a 32-bit unsigned integer. The Linux operating system stipulates that the UID of the root user is 0, and some other virtual users such as bin, daemon, etc. are assigned to some relatively small UID numbers. These users are usually arranged at the beginning of the passwd file. The GID is used to uniquely identify the user group in the system. It is generally a 32-bit unsigned integer. By default, when the UID is established, a user group with the same name will be established. Generally speaking, in order to provide enough room for virtual users, the UID of real users will start from a larger number, and the system can use UID and GID to determine the owner and user group of the file. After the first application 101 creates a shared file in the distributed file server 130, for example, in intelligent operating systems such as AliOS, UID and GID are dynamically allocated, the UID of the first application 111 in the second electronic device 110 is 60003, and the GID is 60003, and the control read list of the shared file cannot be determined. At this time, the signature information of the first application 101 and the first application 111 is verified. If the verification passes, the first application 111 mounts the shared file directory, and the UID and GID of the first application 111 in the second electronic device 110 are used to set the file identity owner attribute for the shared file. At this time, the first application 111 in the second electronic device 110 is determined in the access control list of the shared file, so that the first application 111 can read the shared file, effectively improving the efficiency of the distributed system file identity management. Since the second electronic device 110 does not have an application with signature information corresponding to the second application 102 in the first electronic device 100, the second electronic device 110 cannot read the file of the second application 102. Thus, the security of the data is effectively guaranteed.
[0047] Combine the following Figure 2 Specifically describe a distributed file system file identity management method according to an embodiment of the present invention. Figure 2 The present invention is a flowchart of a distributed file system file identity management method according to an embodiment of the present invention. The method is applied to a system including a distributed file server, a first electronic device connected to the distributed file server, and a second electronic device, wherein the first electronic device and the second electronic device are respectively equipped with a first application and a second application.
[0048] like Figure 2 As shown, the flowchart includes S210-S260.
[0049] S210: A first application in a first electronic device initiates a request to a distributed file server to create a shared file.
[0050] S220: In response to the request to create a shared file, the distributed file server locally creates a shared file and records the first signature information of the first application.
[0051] Specifically, the distributed file server responds to the request to create a shared file with the first application, creates the shared file locally, and sets the file identity owner attribute for the shared file with the identity information of the first application in the first electronic device. After the creation is successful, the distributed file server returns the creation success information to the first application. At this time, the shared file identity owner is the first application in the first electronic device. At the same time, the distributed file server will record the signature information of the first application to prepare for signature verification.
[0052] More specifically, the identity information of the first application in the first electronic device includes the user identifier UID and the user group identifier GID of the first application, and the identity information of the second application in the second electronic device includes the user identifier UID and the user group identifier GID of the second application.
[0053] For example, the UID of the first application in the first electronic device is 60001, and the GID is 60001. When the distributed file server responds to the request to create a shared file with the first application and creates the shared file locally, the UID of the shared file identity owner attribute is set to 60001, and the GID is set to 60001.
[0054] In addition, the signature information may include an MD5 code or a SHA1 code. Taking the MD5 code as an example, the keytool certificate tool can be used to extract the MD5 code. The MD5 code (MD5 Message-Digest Algorithm) is a widely used cryptographic hash function that can generate a 128-bit (16-byte) hash value, which can effectively ensure the integrity and consistency of information transmission, thereby providing a safe and reliable environment for signature verification.
[0055] S230: A second application in a second electronic device initiates a read request for a shared file to a distributed file server.
[0056] Specifically, the second application in the second electronic device initiates a read request to the distributed file server to read the shared file, and the read request includes the second signature information of the second application in the second electronic device, thereby enabling the distributed file server to verify the first signature information and the second signature information.
[0057] S240: The distributed file server verifies the first signature information and the second signature information in response to the read request.
[0058] Specifically, the certMD5_diff command may be used to compare the MD5 codes in the first signature information and the second signature information. If the MD5 codes are consistent, the first signature information and the second signature information are consistent.
[0059] S250: If the first signature information is consistent with the second signature information, the distributed file server enables the second application to mount the shared file directory, and writes the identity information of the second application in the second electronic device into the access control list of the shared file.
[0060] For example, the UID of the second application in the second electronic device is 60002, and the GID is 60002. If the first signature information is consistent with the second signature information, the distributed file server enables the second application to mount the shared file directory, and sets the UID of the identity owner attribute of the shared file to 60002, and the GID to 60002. In this way, the second application can read the shared file. Furthermore, if the first signature information is inconsistent with the second signature information, the distributed file server returns a failure message to the second electronic device.
[0061] S260: The second application reads the shared file.
[0062] In addition, the present invention also discloses a distributed file server, such as Figure 3 As shown, including:
[0063] A connection module 310, used to connect a first electronic device and a second electronic device;
[0064] A shared file creation module 320, configured to create a shared file locally in response to a request from a first application in a first electronic device;
[0065] The signature verification module 330 is used to record and verify the signature information of the first application in the first electronic device and the second application in the second electronic device;
[0066] A file mounting module 340, configured to enable the second application to mount the shared file directory when the first signature information is consistent with the second signature information;
[0067] The identity information setting module 350 is used to obtain the identity information of the second application in the second electronic device and write it into the access control list, so that the second application can read the shared file based on the identity information in the access control list.
[0068] Furthermore, the identity information setting module 350 is used to:
[0069] The identity information of the first application in the first electronic device is obtained to set a file identity owner attribute for the shared file.
[0070] Furthermore, the file mounting module 340 is used to:
[0071] When the first signature information is inconsistent with the second signature information, failure information is returned to the second electronic device.
[0072] Furthermore, the identity information of the first application in the first electronic device includes a user identifier and a user group identifier of the first application, and the identity information of the second application in the second electronic device includes a user identifier and a user group identifier of the second application.
[0073] Furthermore, the signature information is an MD5 code or a SHA1 code.
[0074] The workflow and functions of each module in the server of the embodiment of the present invention have been described in detail in the above embodiment. Figure 2 The description of the method in will not be repeated here.
[0075] Another aspect of the present invention provides a distributed file system, including:
[0076] Distributed file server, the distributed file server is the above-mentioned distributed file server;
[0077] The first electronic device is used to connect to the distributed file server and create a shared file through the distributed file server.
[0078] The second electronic device is used to connect to the distributed file server and mount the shared file directory and read the shared file through the distributed file server.
[0079] The working process and function of each device in the system of the embodiment of the present invention have been described in detail in the above embodiment. Figure 2 The description of the method in will not be repeated here.
[0080] Reference now Figure 5 , which is a block diagram of a SoC (System on Chip) 1300 according to an embodiment of the present application. Figure 5In the FIG, similar components have the same reference numerals. In addition, the dashed boxes are optional features of more advanced SoCs. Figure 5 In the embodiment, SoC 1300 includes: an interconnect unit 1350, which is coupled to an application processor 1310; a system agent unit 1380; a bus controller unit 1390; an integrated memory controller unit 1340; a group or one or more coprocessors 1320, which may include integrated graphics logic, an image processor, an audio processor, and a video processor; a static random access memory (SRAM) unit 1330; and a direct memory access (DMA) unit 1360. In one embodiment, the coprocessor 1320 includes a dedicated processor, such as, for example, a network or communication processor, a compression engine, a GPGPU, a high throughput MIC processor, or an embedded processor.
[0081] The static random access memory (SRAM) unit 1330 may include one or more computer-readable media for storing data and / or instructions. The computer-readable storage medium may store instructions, specifically, temporary and permanent copies of the instructions. The instructions may include: when executed by at least one unit in the processor, the Soc 1300 performs the calculation method according to the above embodiment, which may be specifically referred to in the above embodiment. Figure 2 The method shown will not be repeated here.
[0082] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A distributed file system file identity management method, It is characterized in that Applied to a system including a distributed file server, a first electronic device connected to the distributed file server, and a second electronic device, wherein the first electronic device is installed with a first application, and the second electronic device is installed with a second application, the method comprising: The first application in the first electronic device initiates a request to the distributed file server to create a shared file; The distributed file server creates a shared file locally in response to the request to create a shared file, and records the first signature information of the first application. The distributed file server sets a file identity owner attribute for the shared file based on the identity information of the first application in the first electronic device, wherein the identity information of the first application in the first electronic device includes a user identifier and a user group identifier of the first application, and the distributed file server sets the user identifier and the user group identifier of the shared file to be consistent with the user identifier and the user group identifier of the first application. The second application in the second electronic device initiates a read request to the distributed file server to read the shared file, wherein the read request includes second signature information of the second application in the second electronic device; The distributed file server verifies the first signature information and the second signature information in response to the read request; If the first signature information is consistent with the second signature information, the distributed file server enables the second application to mount the shared file directory, and writes the identity information of the second application in the second electronic device into an access control list, wherein the identity information of the second application in the second electronic device includes a user identifier and a user group identifier of the second application, and the distributed file server sets the user identifier and the user group identifier of the shared file to be consistent with the user identifier and the user group identifier of the second application, and the user identifiers of the first application and the second application are both dynamically allocated; The second application reads the shared file.
2. The method according to claim 1, It is characterized in that The signature information is an MD5 code or a SHA1 code.
3. The method according to claim 1, It is characterized in that If the first signature information is inconsistent with the second signature information, the distributed file server returns a failure message to the second electronic device.
4. A distributed file server, It is characterized in that include: A connection module, used to connect the first electronic device and the second electronic device; A shared file creation module, configured to create a shared file locally in response to a first application request in the first electronic device; a signature verification module, configured to record and verify first signature information of the first application in the first electronic device and second signature information of the second application in the second electronic device; A file mounting module, configured to enable the second application to mount a shared file directory when the first signature information is consistent with the second signature information; an identity information setting module, for obtaining the identity information of the second application in the second electronic device and writing it into an access control list when the first signature information is consistent with the second signature information and the second application mounts a shared file directory, so that the second application reads the shared file based on the identity information in the access control list, The identity information setting module is also used for obtaining the identity information of the first application in the first electronic device after the shared file creation module responds to the first application request in the first electronic device to create a shared file locally and the signature verification module records the first signature information of the first application in the first electronic device, setting the file identity owner attribute for the shared file with the identity information of the first application in the first electronic device, setting the user identifier and user group identifier of the shared file to be consistent with the user identifier and user group identifier of the first application, and setting the user identifier and user group identifier of the shared file to be consistent with the user identifier and user group identifier of the second application after the first signature information is consistent with the second signature information, the second application mounts the shared file directory and the identity information of the second application in the second electronic device is written into the access control list; The identity information of the first application in the first electronic device includes a user identifier and a user group identifier of the first application, and the identity information of the second application in the second electronic device includes a user identifier and a user group identifier of the second application.
5. The distributed file server according to claim 4, It is characterized in that The file mounting module is used for: When the first signature information is inconsistent with the second signature information, failure information is returned to the second electronic device.
6. The distributed file server according to claim 5, It is characterized in that The signature information includes an MD5 code or a SHA1 code.
7. A distributed file system, It is characterized in that include: A distributed file server, wherein the distributed file server is the distributed file server according to claims 4 to 6; a first electronic device, the first electronic device being used to connect to the distributed file server and create a shared file through the distributed file server; A second electronic device is used to connect to the distributed file server and mount a shared file directory through the distributed file server and read the shared file.