Permission control method, device, equipment, medium and program product

By obtaining and updating the permission configuration information of the bucket in the cloud storage service, the problem of the existing permissions being overwritten when the permissions are updated in the existing technology is solved, and more flexible and efficient permission control is achieved.

CN114611144BActive Publication Date: 2025-05-13BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210237987.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-05-13
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

When existing cloud storage services handle permission update requests, they can easily cause existing permissions to be overwritten by new permissions, and the original permission configuration cannot be effectively retained and updated.

Method used

By responding to permission update requests, obtain the original configuration information with the existing permissions, update the information to generate new configuration information, and update the existing permissions based on the new configuration information, ensuring that existing permissions that do not need to be updated are retained when permissions are updated.

Benefits of technology

Improves the flexibility of permission control, allows cloud storage users to flexibly manage the control permissions of the storage bucket, reduces the workload of users when permission updates, and improves the efficiency of permission control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114611144B_ABST
    Figure CN114611144B_ABST
Patent Text Reader

Abstract

The present disclosure provides a permission control method, device, equipment, medium and program product, which relate to the field of computer technology, and in particular to the field of cloud storage technology. The specific implementation scheme is: in response to a permission update request, the original configuration information of the existing permission is obtained; the original configuration information includes at least one permission configuration data of the existing permission; based on the permission update request, the original configuration information is updated to obtain the updated configuration information; based on the updated configuration information, the existing permission is updated. The technical solution of the embodiment of the present disclosure can improve the flexibility of permission control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, in particular to the field of cloud storage technology, and specifically to a permission control method, device, equipment, medium and program product. Background Art

[0002] With the rapid development of the Internet, the amount of data available to Internet users has exploded. The traditional way of managing and storing data through file systems can no longer meet user needs.

[0003] To address the above issues, cloud storage services came into being. Cloud storage services can provide enterprises with highly available, scalable, and highly secure storage services. In order to ensure the security of user data stored in cloud storage services, it is very important to set bucket permissions. Summary of the invention

[0004] The present disclosure provides a permission control method, apparatus, device, medium and program product.

[0005] According to one aspect of the present disclosure, there is provided a permission control method, comprising:

[0006] In response to the permission update request, obtaining original configuration information of the existing permission; the original configuration information includes permission configuration data of at least one item of the existing permission;

[0007] Based on the permission update request, the original configuration information is updated to obtain updated configuration information;

[0008] The existing permissions are updated according to the update configuration information.

[0009] According to another aspect of the present disclosure, there is provided a permission control device, comprising:

[0010] An original configuration information acquisition module, used to obtain original configuration information of existing permissions in response to a permission update request; the original configuration information includes permission configuration data of at least one existing permission;

[0011] An updated configuration information acquisition module, used to update the original configuration information based on the permission update request to obtain updated configuration information;

[0012] The existing permission updating module is used to update the existing permission according to the update configuration information.

[0013] According to another aspect of the present disclosure, there is provided an electronic device, comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to at least one processor; wherein,

[0016] The memory stores instructions that can be executed by at least one processor, and the instructions are executed by at least one processor so that the at least one processor can execute the permission control method of any embodiment of the present disclosure.

[0017] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable a computer to execute the permission control method of any embodiment of the present disclosure.

[0018] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the permission control method of any embodiment of the present disclosure is implemented.

[0019] The embodiments of the present disclosure can improve the flexibility of authority control.

[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings are used to better understand the present solution and do not constitute a limitation of the present disclosure.

[0022] Figure 1a is a schematic diagram of a permission control method provided according to an embodiment of the present disclosure;

[0023] Figure 1b It is a permission list display interface provided according to an embodiment of the present disclosure;

[0024] Figure 2 is a schematic diagram of a permission control method provided according to an embodiment of the present disclosure;

[0025] Figure 3 is a schematic diagram of a permission control method provided according to an embodiment of the present disclosure;

[0026] Figure 4 is a schematic diagram of a permission control method provided according to an embodiment of the present disclosure;

[0027] Figure 5 is a schematic diagram of a permission control device provided according to an embodiment of the present disclosure;

[0028] Figure 6 It is a block diagram of an electronic device used to implement the permission control method of the embodiment of the present disclosure. DETAILED DESCRIPTION

[0029] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0030] Figure 1a This is a flowchart of a permission control method disclosed in an embodiment of the present disclosure. This embodiment can be applied to the situation where existing permissions are updated by updating the original configuration information of the existing permissions. The method of this embodiment can be executed by a permission control device, which can be implemented in software and / or hardware, and is specifically configured in an electronic device with certain data computing capabilities. The electronic device can be a client device or a server device, and the client device can be a mobile phone, a tablet computer, a car terminal, a desktop computer, etc.

[0031] S110. In response to a permission update request, obtain original configuration information of an existing permission; the original configuration information includes permission configuration data of at least one item of the existing permission.

[0032] In cloud storage (object storage), buckets are the carriers of objects. Objects are stored in buckets in a flat structure without the concept of folders and directories. Users can choose to store objects in one or more buckets. To ensure the security of data in cloud storage services, access control lists (ACLs) are usually used to describe the permissions that users can have on buckets or objects in buckets.

[0033] Basic bucket permissions include private read and write, public read and private write, and public read and write. Among them, private read and write means that only the creator of the bucket and the authorized account can have read and write permissions to the objects in the bucket; public read and private write means that anyone has read permissions to the objects in the current bucket, but only the creator of the bucket and the authorized account can have write permissions to the objects in the bucket; public read and write means that anyone has read and write permissions to the objects in the bucket.

[0034] In addition to the above basic bucket permissions, this embodiment can also provide users with more sophisticated customized permission control solutions. Specifically, the permission configuration data includes user authorization, authorization effect, permission settings, fine-grained settings, resources, protocol header information Referer, IP address, and access time, etc. You can specify permissions such as read, list, write, and full control for specified user devices, and you can also specify the resources that permissions can access, the blacklist and whitelist of IPs with permissions, the blacklist and whitelist of Referer, and the access time limit.

[0035] The permission update request is initiated by the user of the cloud storage service, and is used to instruct the cloud storage service to add, modify or delete existing permissions. The original configuration information contains permission configuration data for at least one existing permission. Specifically, the original configuration information is in Jason data format. Exemplarily, the cloud storage service contains three permissions, namely permissions A, B and C. The original configuration information contains the permission configuration data of the above three permissions. The permission configuration data of each permission may include user authorization, authorization effect, permission settings, fine-grained settings, resources, protocol header information Referer, IP address and access time, etc.

[0036] After receiving the permission update request initiated by the user, if the cloud storage service directly adds permissions by calling the permission adding interface (putBucketPolicy), the existing permissions will be overwritten by the newly added permissions. For example, the existing permissions include permissions A, B, and C, and the current permission update request is to add permission D. If the permission adding interface is directly called to add permission D, the existing permissions A, B, and C will be overwritten by permission D, and only permission D will be left in the permission list, which cannot meet the effect required by the permission update request.

[0037] In the disclosed embodiment, after obtaining a permission update request initiated by a user, the cloud storage service first obtains the original configuration information of the existing permission through the permission acquisition interface (getBucketPolicy). Specifically, when the cloud storage service obtains a permission addition request, permission modification request, or permission deletion request initiated by a user, it can obtain the permission configuration data of at least one existing permission by calling the permission acquisition interface. By obtaining the original configuration information of the existing permission, the permission configuration data of the existing permission can be stored to avoid the situation where the existing permission is overwritten by the new permission and cannot be restored due to the direct call of the permission addition interface.

[0038] In a specific example, Figure 1b As shown, in response to the user clicking the Add Custom Permission button in the permission list display interface, an interface for adding custom permissions is displayed to the user, which includes input boxes or items to be selected for multiple permission configuration data. The user fills in or selects the permission configuration data in the interface, and after completing the filling, initiates a permission addition request by clicking the OK button. After the cloud storage service obtains the permission addition request initiated by the user, it calls the permission acquisition interface to obtain the original configuration information of the existing permissions. Similarly, when a single permission deletion request or permission modification request initiated by the user is obtained, the original configuration information of the existing permissions also needs to be obtained.

[0039] In the permission list display interface, the relevant information of the existing permissions is displayed in the form of a list. Specifically, the list may include permission configuration data such as the authorized user, resource, authorization effect, permission, referer, IP address, and allowed time. In addition, the permission list display interface also includes a button for adding custom permissions, as well as buttons for modifying and deleting existing permissions.

[0040] S120: Based on the permission update request, the original configuration information is updated to obtain updated configuration information.

[0041] The permission update request may include relevant information of the permission to be updated, such as the identifier of the permission to be updated or the permission configuration data, etc., which is used to update the permission to be updated. Exemplarily, when the permission update request is of the permission addition type, the permission update request includes the permission configuration data of the permission to be added; when the permission update request is of the permission modification type, the permission update request includes the identifier of the permission to be modified and the modified permission configuration data; when the permission update request is of the permission deletion type, the permission update request includes the identifier of the permission to be deleted.

[0042] In the disclosed embodiment, after the original configuration information of the existing permission is obtained, the original configuration information of the existing permission is updated based on the information related to the permission to be updated in the permission update request to obtain the updated configuration information. Specifically, permission configuration data can be added, modified or deleted in the original configuration information according to the permission update request.

[0043] In a specific example, when the permission update request is a permission addition type, the permission update request includes permission configuration data of the permission to be added. At this time, the permission configuration data of the permission to be added can be added to the original configuration information to obtain the updated configuration information.

[0044] In another specific example, when the permission update request belongs to the permission modification type, the permission update request includes the modified permission configuration data of the permission to be modified. At this time, the permission configuration data of the permission to be modified in the original configuration information can be modified according to the modified permission configuration data to obtain the updated configuration information.

[0045] In another specific example, when the permission update request belongs to the permission deletion type, the permission update request includes the identifier of the permission to be deleted. At this time, the permission configuration data of the permission to be deleted can be searched and deleted in the original configuration information according to the identifier of the permission to be deleted to obtain the updated configuration information.

[0046] S130: Update the existing permissions based on the updated configuration information.

[0047] In the disclosed embodiment, after the original configuration information is updated according to the permission update request and the updated configuration information is obtained, the existing permissions are further updated according to the updated configuration information. Specifically, by calling the permission adding interface (putBucketPolicy), at least one updated permission is added to the permission list according to the permission configuration data of at least one updated permission contained in the updated configuration information, and the existing permissions are overwritten by the updated permissions. The updated configuration information is obtained by adding, modifying or deleting the permission configuration information in the original configuration information, that is, the updated configuration information retains the permission configuration data of the existing permissions that do not need to be updated, and also contains the updated permission configuration data of the existing permissions that need to be updated. By calling the permission adding interface, according to the updated configuration information, not only can the existing permissions be updated, but also the existing permissions that do not need to be updated can be retained, reducing the inconvenience caused to users by the updated permissions overwriting the existing permissions.

[0048] The technical solution of the disclosed embodiment obtains the original configuration information of the existing permissions in response to the permission update request, and then updates the original configuration information based on the permission update request to obtain the updated configuration information, and finally updates the existing permissions based on the updated configuration information, which can improve the flexibility of permission control and facilitate cloud storage users to flexibly manage the control permissions of storage buckets.

[0049] Figure 2 This is a schematic diagram of a permission control method in an embodiment of the present disclosure, which is further refined on the basis of the above embodiment, and provides specific steps for updating the original configuration information based on the permission update request to obtain the updated configuration information, and specific steps for updating the existing permissions based on the updated configuration information. Figure 2 A permission control method provided by an embodiment of the present disclosure is described, including the following:

[0050] S210. In response to a permission update request, obtain original configuration information of an existing permission; the original configuration information includes permission configuration data of at least one existing permission.

[0051] Optionally, the permission configuration data includes at least one of user authorization, authorization effect, permission setting, fine-grained setting, resource, protocol header information Referer, IP address and access time.

[0052] In this optional embodiment, the specific content of the permission configuration data is provided, including at least one of user authorization, authorization effect, permission setting, fine-grained setting, resource, protocol header information Referer, IP address, and access time. By customizing multiple permission configuration data, the bucket permission configuration can be made more flexible and can meet the user's more diverse permission control needs.

[0053] The specific explanation of the above permission configuration data is as follows:

[0054] 1) User authorization can include all users or custom users;

[0055] 2) The authorization effect may include permission or denial;

[0056] 3) Permission settings can include read (READ), list (LIST), write (WRITE) or full control (FULL_CONTROL);

[0057] 4) Advanced settings can include management of buckets, management of objects in buckets, and management of access control lists (ACLs):

[0058] More specifically, Bucket management can include obtaining the location information of a bucket (GetBucketLocation), obtaining the cross-origin resource sharing of a bucket (GetBucketCORS), adding a bucket cross-origin resource sharing (PutBucketCORS), obtaining a list of files in a bucket (ListBucket), obtaining a list of buckets (ListAllMyBuckets), obtaining the lifecycle rules of a bucket (GetLifecycleConfiguration), adding a lifecycle rule of a bucket (PutLifecycleConfiguration), obtaining a list of multipart uploads in a bucket (ListBucketMultipartUploads), obtaining a list of uploaded parts (ListMultipartUploadParts), adding bucket permissions (PutBucketPolicy), and deleting bucket permissions (DeleteBucketPolicy), etc.

[0059] Object management can include getting objects (GetObject), adding objects (PutObject), and deleting objects (DeleteObject);

[0060] ACL management can include getting object access control list (GetObjectAcl), getting bucket access control list (GetBucketAcl), adding object access control list (PutObjectAcl), and adding bucket access control list (PutBucketAcl);

[0061] 5) One or more resources using the current permissions can be added to the resource;

[0062] 6) Protocol header information Referer can customize the parameter Referer in one or more protocol headers. Each referer is separated by a line break. It only supports Hyper Text Transfer Protocol (HTTP) and HTTP channel (Hyper Text Transfer Protocol over Secure Socket Layer) with security as the goal.

[0063] 7) You can also set the Referer to be empty or not.

[0064] 8) The IP address can be customized to use the IP address of the current authority;

[0065] 9) The access time may specifically include the minimum time allowed for access and the maximum time allowed for access.

[0066] S220: When the permission update request is of a permission addition type, obtain permission configuration data of the permission to be added from the permission update request.

[0067] In the embodiment of the present disclosure, when the permission update request is of the permission addition type, the permission configuration data of the permission to be added can be obtained from the permission update request, so as to add the permission according to the permission configuration data of the permission to be added.

[0068] Specifically, in response to the user clicking the Add Custom Permission button in the permission list interface, an interface for adding custom permissions is displayed to the user, which may include input boxes or items to be selected for the various permission configuration data mentioned in S210. After the user completes filling in or selecting the permission configuration data in the interface, the user clicks the OK button to send a permission update request. At this time, the permission update request belongs to the permission addition type, and the permission update request includes the permission configuration data added by the user in the Add Custom Permission interface. When the cloud storage service obtains the permission update request initiated by the user, it obtains the permission configuration data of the permission to be added contained in the permission update request, and is used to add the above-mentioned permission to be added to the permission list.

[0069] In a specific example, after obtaining a permission update request, the type of the permission update request is first determined by reading the type identifier of the permission update request. For example, a type identifier of 1 indicates that the current permission update request belongs to a permission addition type, a type identifier of 2 indicates that the current permission update request belongs to a permission modification type, and a type identifier of 3 indicates that the current permission update request belongs to a permission deletion type. In the case where the permission update request belongs to a permission addition type, the permission configuration data of the permission to be added contained in the permission update request is read.

[0070] S230: Add the permission configuration data of the permission to be added to the original configuration information to obtain updated configuration information.

[0071] In the disclosed embodiment, after obtaining the permission configuration data of the permission to be added, the permission configuration data of the permission to be added is added to the original configuration information to form the updated configuration information. Exemplarily, the original configuration information includes permission configuration data of 3 existing permissions. After obtaining the permission configuration data of the permission to be added, it is added to the original configuration information to obtain the updated configuration information containing 4 permission configuration data. Among them, the original configuration information and the updated configuration information are in Jason data format. By modifying the original configuration information, the addition of permissions can be achieved. Compared with the prior art calling the permission addition interface, which will overwrite the existing permissions after adding permissions, a more convenient permission addition solution is provided, which can reduce the user's workload.

[0072] S240: Generate at least one update permission based on the permission configuration data of at least one update permission included in the update configuration information, and overwrite the existing permission.

[0073] When calling the permission adding interface (putBucketPolicy) to add new permissions, the existing permissions will be overwritten and only the new permissions will be retained. For example, if the existing permissions include existing permissions A, B, and C, and the permission to be added is permission D, if the permission adding interface is directly called to add permission D, the existing permissions A, B, and C will be overwritten. If the user needs to add permission D while retaining the existing permissions A, B, and C, it is necessary to enter the permission configuration data corresponding to permissions A, B, C, and D in the permission adding interface at the same time, so that permissions A, B, C, and D can be added to the permission list at the same time. Obviously, the permission control method is not flexible enough, which causes inconvenience to users.

[0074] Similarly, when the permission update request is a permission modification or permission deletion type, at least one updated permission is still generated based on the permission configuration data of at least one updated permission contained in the update configuration information to overwrite the existing permission. Since the update configuration information contains both the modified permission configuration data of the existing permission that needs to be updated and the permission configuration data of the existing permission that does not need to be updated, while implementing partial permission updates, the use of other existing permissions in the permission category that do not need to be updated is not affected.

[0075] In the disclosed embodiment, the updated configuration information is obtained by pre-acquiring the original configuration information of the existing permissions and adding the permission configuration data of the permissions to be added to the original configuration information. Furthermore, by calling the permission adding interface, the updated permissions associated with at least one set of permission configuration data in the updated configuration information are added to the permission list, overwriting the existing permissions. Permission D can be added to the permission list while ensuring that the existing permissions A, B, and C are not affected. Users do not need to re-enter the permission configuration data of the existing permissions every time they add new permissions, which improves the flexibility of permission control and the user experience.

[0076] The technical solution of the disclosed embodiment obtains original configuration information of existing permissions in response to a permission update request, and when the permission update request is of a permission addition type, obtains permission configuration data of the permission to be added from the permission update request, and adds the permission configuration data of the permission to be added to the original configuration information to obtain updated configuration information, and finally generates at least one updated permission based on the permission configuration data of at least one updated permission contained in the updated configuration information, overwriting the existing permissions, thereby achieving the effect of flexibly adding permissions to resources in a storage bucket.

[0077] Figure 3 This is a schematic diagram of a permission control method in an embodiment of the present disclosure, which is further refined on the basis of the above embodiment and provides specific steps for updating the original configuration information based on the permission update request to obtain the updated configuration information. Figure 3 A permission control method provided by an embodiment of the present disclosure is described, including the following:

[0078] S310. In response to a permission update request, obtain original configuration information of an existing permission; the original configuration information includes permission configuration data of at least one existing permission.

[0079] S320: When the permission update request is of the permission modification type, the permission configuration data of the permission to be modified is obtained from the original configuration information according to the permission identifier to be modified associated with the permission update request.

[0080] In the embodiment of the present disclosure, when the permission update request belongs to the permission modification type, the permission configuration data of the permission to be modified can be first obtained in the original configuration information based on the identifier of the permission to be modified associated with the permission update request, so as to facilitate the subsequent modification of the permission configuration data of the permission to be modified.

[0081] Specifically, in response to the user clicking the permission modification button for the permission to be modified in the permission list interface, the permission configuration data of the permission to be modified in an editable form is displayed to the user. The user can modify the permission configuration data, and after the modification is completed, send a permission update request by clicking the OK button. At this time, the permission update request belongs to the permission modification type, and the permission update request contains the identifier of the permission to be modified and the permission configuration data after the permission to be modified is modified. When the cloud storage service receives a permission update request of the permission modification type, it obtains the permission configuration data of the permission to be modified from the original configuration information based on the identifier of the permission to be modified associated with the permission update request.

[0082] In a specific example, after obtaining a permission update request, the permission update request is determined to be a permission modification type by reading the type identifier of the permission update request. Furthermore, in the case where the permission update request belongs to the permission modification type, the permission configuration data of the permission to be modified is obtained in the original configuration information based on the permission identifier to be modified associated with the permission update request. Exemplarily, the permission update request contains the permission identifier of the permission A to be modified, and based on the permission identifier, the permission configuration data of the permission A to be modified is obtained in the original configuration information, so as to facilitate the subsequent modification of the permission configuration data of the permission A to be modified.

[0083] S330. Modify the permission configuration data of the permission to be modified in the original configuration information according to the modified permission configuration data of the permission to be modified in the permission update request to obtain updated configuration information.

[0084] In the disclosed embodiment, after obtaining the permission configuration data of the permission to be modified in the original configuration information, the permission configuration data of the permission to be modified in the original configuration information is updated to the modified permission configuration data according to the modified permission configuration data of the permission to be modified in the permission update request, and the updated configuration information is obtained. By modifying the original configuration information, the permission can be modified. Compared with the prior art permission modification method that can only delete first and then add, a more convenient permission modification scheme is provided, which can reduce the user workload and improve the efficiency of permission control.

[0085] S340: Update the existing permissions based on the updated configuration information.

[0086] The technical solution of the disclosed embodiment obtains original configuration information of existing permissions in response to a permission update request, and when the permission update request belongs to a permission modification type, obtains permission configuration data of the permission to be modified from the original configuration information based on the permission identifier to be modified associated with the permission update request, and further modifies the permission configuration data of the permission to be modified in the original configuration information based on the modified permission configuration data of the permission to be modified in the permission update request to obtain updated configuration information, and finally updates the existing permissions based on the updated configuration information, so that the permissions of resources in the storage bucket can be flexibly modified, reducing the workload of users in permission control.

[0087] Figure 4 This is a schematic diagram of a permission control method in an embodiment of the present disclosure, which is further refined on the basis of the above embodiment and provides specific steps for updating the original configuration information based on the permission update request to obtain the updated configuration information. Figure 4 A permission control method provided by an embodiment of the present disclosure is described, including the following:

[0088] S410. In response to a permission update request, obtain original configuration information of an existing permission; the original configuration information includes permission configuration data of at least one existing permission.

[0089] S420: When the permission update request is of the permission deletion type, the permission configuration data of the permission to be deleted is deleted from the original configuration information according to the permission identifier to be deleted associated with the permission update request, to obtain updated configuration information.

[0090] In the disclosed embodiment, when the permission update request belongs to the permission deletion type, the permission configuration data of the permission to be deleted can be deleted from the original configuration information according to the permission identifier to be deleted associated with the permission update request to obtain the updated configuration information.

[0091] Specifically, the user initiates a permission update request by clicking the permission deletion button for the permission to be deleted in the permission list interface. At this time, the permission update request belongs to the permission deletion type. Furthermore, based on the permission to be deleted identifier associated with the permission update request, the permission configuration data of the permission to be deleted is deleted from the original configuration information to obtain the updated configuration information. Compared with the method of directly calling the permission deletion interface to delete all permissions in the list, this solution can delete a single permission by updating the existing permissions through updating the configuration information, thereby improving the flexibility of permission deletion.

[0092] In a specific example, after obtaining a permission update request, the permission update request is determined to be a permission deletion type by reading the type identifier of the permission update request. Furthermore, in the case where the permission update request belongs to the permission deletion type, the permission configuration data of the permission to be modified is searched and deleted in the original configuration information based on the permission identifier to be deleted associated with the permission update request. Exemplarily, the permission update request contains the permission identifier of the permission A to be modified, and based on the permission identifier, the permission configuration data of the permission A to be deleted is searched and deleted in the original configuration information. By modifying the original configuration information, a single permission can be deleted, which provides a more flexible permission deletion solution compared to the prior art that can only delete all permissions in the list at once by calling the permission deletion interface.

[0093] S430: Update the existing permissions based on the updated configuration information.

[0094] The technical solution of the disclosed embodiment obtains the original configuration information of the existing permission in response to the permission update request. When the permission update request belongs to the permission deletion type, the permission configuration data of the permission to be deleted is deleted from the original configuration information according to the permission identifier to be deleted associated with the permission update request to obtain the updated configuration information. Finally, the existing permission is updated according to the updated configuration information. The permissions of the resources in the storage bucket can be flexibly deleted, thereby improving the flexibility of permission control.

[0095] According to an embodiment of the present disclosure, Figure 5 1 is a structural diagram of a permission control device in an embodiment of the present disclosure. The embodiment of the present disclosure is applicable to the situation where the existing permission control is realized by updating the original configuration information of the existing permission. The device is implemented by software and / or hardware and is specifically configured in an electronic device with certain data computing capabilities.

[0096] like Figure 5 The authority control device 500 shown in the figure comprises: an original configuration information acquisition module 510, an updated configuration information acquisition module 520 and an existing authority update module 530; wherein,

[0097] The original configuration information acquisition module 510 is used to obtain the original configuration information of the existing permission in response to the permission update request; the original configuration information includes at least one permission configuration data of the existing permission;

[0098] An updated configuration information acquisition module 520 is used to update the original configuration information based on the permission update request to obtain updated configuration information;

[0099] The existing permission updating module 530 is used to update the existing permission according to the update configuration information.

[0100] The technical solution of the disclosed embodiment obtains the original configuration information of the existing permissions in response to the permission update request, and then updates the original configuration information based on the permission update request to obtain the updated configuration information, and finally updates the existing permissions based on the updated configuration information, which can improve the flexibility of permission control and facilitate cloud storage users to flexibly manage the control permissions of storage buckets.

[0101] Further, the update configuration information acquisition module 520 includes:

[0102] A permission data acquisition unit to be added, configured to acquire permission configuration data of the permission to be added from the permission update request when the permission update request belongs to a permission new addition type;

[0103] The first updated configuration information acquiring unit is used to add the permission configuration data of the permission to be added to the original configuration information to obtain updated configuration information.

[0104] Furthermore, the update configuration information acquisition module 520 further includes:

[0105] a permission data acquisition unit for acquiring permission configuration data of the permission to be modified from the original configuration information according to the permission identifier to be modified associated with the permission update request when the permission update request belongs to the permission modification type;

[0106] The second updated configuration information obtaining unit is used to modify the permission configuration data of the permission to be modified in the original configuration information according to the modified permission configuration data of the permission to be modified in the permission update request, so as to obtain updated configuration information.

[0107] Furthermore, the update configuration information acquisition module 520 further includes:

[0108] The third updated configuration information acquiring unit, when the permission update request belongs to the permission deletion type, deletes the permission configuration data of the permission to be deleted in the original configuration information according to the permission identifier to be deleted associated with the permission update request, to obtain the updated configuration information.

[0109] Furthermore, there is an existing permission update module 530, including:

[0110] The existing permission updating unit is used to generate at least one update permission according to the permission configuration data of at least one update permission included in the update configuration information, so as to cover the existing permission.

[0111] Furthermore, the permission configuration data includes at least one of user authorization, authorization effect, permission setting, fine-grained setting, resource, protocol header information Referer, IP address and access time.

[0112] The permission control device provided in the embodiments of the present disclosure can execute the permission control method provided in any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method.

[0113] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0114] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.

[0115] Figure 6 A schematic block diagram of an example electronic device 600 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0116] like Figure 6 As shown, the device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0117] A number of components in the device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a disk, an optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the device 600 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0118] The computing unit 601 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 601 performs the various methods and processes described above, such as the permission control method. For example, in some embodiments, the permission control method may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the permission control method described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform the permission control method in any other appropriate manner (e.g., by means of firmware).

[0119] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0120] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0121] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0122] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0123] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0124] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0125] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0126] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A permission control method, comprising: In response to the permission update request, obtaining original configuration information of the existing permission; The original configuration information includes permission configuration data of at least one existing permission; The permission update request is initiated by a user of the cloud storage service and is used to instruct the cloud storage service to add, modify or delete existing permissions. The cloud storage service uses an access control list to describe the permissions that a user can perform on a storage bucket in the cloud storage service or an object in a storage bucket. Based on the permission update request, the original configuration information is updated to obtain updated configuration information; the updated configuration information includes permission configuration data of existing permissions that do not need to be updated, and updated permission configuration data; At least one update permission is generated according to the permission configuration data of at least one update permission included in the update configuration information, covering the existing permission.

2. The method according to claim 1, wherein: Based on the permission update request, the original configuration information is updated to obtain updated configuration information, including: In the case where the permission update request is of a permission addition type, obtaining permission configuration data of the permission to be added from the permission update request; The permission configuration data of the permission to be added is added to the original configuration information to obtain updated configuration information.

3. The method according to claim 1, wherein: Based on the permission update request, the original configuration information is updated to obtain updated configuration information, further comprising: In the case where the permission update request belongs to the permission modification type, obtaining the permission configuration data of the permission to be modified from the original configuration information according to the permission identifier to be modified associated with the permission update request; According to the modified permission configuration data of the permission to be modified in the permission update request, the permission configuration data of the permission to be modified in the original configuration information is modified to obtain updated configuration information.

4. The method according to claim 1, wherein: Based on the permission update request, the original configuration information is updated to obtain updated configuration information, further comprising: In the case that the permission update request belongs to the permission deletion type, the permission configuration data of the permission to be deleted is deleted from the original configuration information according to the permission identifier to be deleted associated with the permission update request to obtain the updated configuration information.

5. The method according to any one of claims 1 to 4, wherein: The permission configuration data includes at least one of user authorization, authorization effect, permission setting, fine-grained setting, resource, protocol header information Referer, IP address and access time.

6. A permission control device, comprising: The original configuration information acquisition module is used to obtain the original configuration information of the existing permissions in response to the permission update request; The original configuration information includes permission configuration data of at least one existing permission; the permission update request is initiated by a user of the cloud storage service and is used to instruct the cloud storage service to add, modify or delete an existing permission; the cloud storage service uses an access control list to describe the user's permission to operate a storage bucket in the cloud storage service or an object in the storage bucket; An updated configuration information acquisition module, used to update the original configuration information based on the permission update request to obtain updated configuration information; The update configuration information includes permission configuration data of existing permissions that do not need to be updated, and updated permission configuration data; The existing permission updating module is used to generate at least one update permission according to the permission configuration data of at least one update permission included in the update configuration information, so as to cover the existing permission.

7. The device according to claim 6, wherein: The update configuration information acquisition module includes: A permission data acquisition unit to be added, configured to acquire permission configuration data of the permission to be added from the permission update request when the permission update request belongs to a permission new addition type; The first updated configuration information acquiring unit is used to add the permission configuration data of the permission to be added to the original configuration information to obtain updated configuration information.

8. The device according to claim 6, wherein: The update configuration information acquisition module also includes: a permission data acquisition unit for acquiring permission configuration data of the permission to be modified from the original configuration information according to the permission identifier to be modified associated with the permission update request when the permission update request belongs to the permission modification type; The second updated configuration information obtaining unit is used to modify the permission configuration data of the permission to be modified in the original configuration information according to the modified permission configuration data of the permission to be modified in the permission update request, so as to obtain updated configuration information.

9. The device according to claim 6, wherein: The update configuration information acquisition module also includes: The third updated configuration information acquiring unit, when the permission update request belongs to the permission deletion type, deletes the permission configuration data of the permission to be deleted in the original configuration information according to the permission identifier to be deleted associated with the permission update request, to obtain the updated configuration information.

10. The device according to any one of claims 6 to 9, wherein: The permission configuration data includes at least one of user authorization, authorization effect, permission setting, fine-grained setting, resource, protocol header information Referer, IP address and access time.

11. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the permission control method described in any one of claims 1 to 5.

12. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable the computer to execute the permission control method according to any one of claims 1-5.

13. A computer program product, comprising a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the permission control method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Application permission management method and device and storage medium

    CN111222153A