Large enterprise cloud operation and maintenance platform rights management method, system, equipment and storage medium
By adopting user group and resource group group management based on permission model in the cloud operation and maintenance platform of large enterprises, the problem of inefficient permission management in the existing technology is solved, and automated authorization of new users and equipment is realized, and management efficiency and adaptability are improved.
Patent Information
- Application Number
- CN202211309427.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-25
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2042-10-25
AI Technical Summary
The existing permission management system cannot adapt to the complex organizational structure and diversified needs of large enterprises, especially in automated operation and maintenance, and cannot achieve unified management of a large operation and maintenance object, and cannot effectively manage equipment permissions.
Using a permission model-based method, the new user and device permissions are automatically configured through group management of user groups and resource groups, and the pre-built organization tables, user group tables and resource group tables are used to realize unified permission management of the cloud operation and maintenance platform.
It improves the efficiency of permission management, supports rapid iteration of multiple applications and automatic configuration of device permissions, and realizes the automated operation and maintenance of cloud operation and maintenance platforms of large enterprises.
Smart Images

Figure CN115694941B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rights management, and in particular to a method, system, device and storage medium for rights management of a cloud operation and maintenance platform for a large enterprise. Background Art
[0002] Large enterprises have complex organizational structures and responsibilities, and their needs are diverse. Their operations and maintenance involve multiple areas, such as change, process, and configuration management, all of which require unified integration and planning. Large enterprises face a heavy workload, and traditional manual operations and maintenance methods are no longer up to par. Automated operations and maintenance are essential, and permission management is fundamental to achieving automated operations and maintenance. Given the vast scope of operations and maintenance, permission management also needs to be automated. Existing permission management systems are generally not adaptable to these scenarios. Permission management itself is typically managed individually for each user, with permissions configured for each user individually. Device permission management is generally not considered, and automation is not implemented. This results in low management efficiency and quality, making it prone to untimely permission updates. Summary of the Invention
[0003] In view of the shortcomings of the above-mentioned prior art, the present invention provides a method, system, device and storage medium for managing permissions of a cloud operation and maintenance platform for a large enterprise, so as to provide an efficient permissions management solution.
[0004] The first aspect of the present application provides a method for managing permissions on a large enterprise cloud operation and maintenance platform, including:
[0005] When a new user is added to any SaaS application, the new user is added to a target user group based on the organization to which the new user belongs, as recorded in the user table and organization table of the pre-built permission model. This allows the new user to be assigned permissions corresponding to the target user group. The target user group is the user group corresponding to the organization to which the new user belongs, as recorded in the user group table of the permission model. SaaS stands for Software as a Service.
[0006] When a new device is added, obtain the device information of the new device;
[0007] Determining a target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type; wherein the target resource group is recorded in the resource group table of the permission model;
[0008] The device information of the newly added device is added to the target resource group so that the permissions of the newly added device are configured for users in the user group corresponding to the target resource group; the users corresponding to the target resource group are determined according to the correspondence between the user group and the resource group.
[0009] Optionally, the method further includes:
[0010] When there is a deleted user, the deleted user is removed from the user group to which the deleted user belongs.
[0011] Optionally, the method further includes:
[0012] When there is a deleted device, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
[0013] Optionally, adding the device information of the newly added device to the target resource group includes:
[0014] The device information of the newly added device is assigned to any thread in the thread pool, so that the thread is called to add the device information to the target resource group.
[0015] The second aspect of the present application provides a large enterprise cloud operation and maintenance platform rights management system, including an operation and maintenance user management module, an operation and maintenance resource management module, and a role rights management module for recording the correspondence between user groups and resource groups;
[0016] The operation and maintenance user management module is used to:
[0017] When a new user is added to any SaaS application, the new user is added to a target user group based on the organization to which the new user belongs, as recorded in the user table and organization table of the pre-built permission model. This allows the new user to be assigned permissions corresponding to the target user group. The target user group is the user group corresponding to the organization to which the new user belongs, as recorded in the user group table of the permission model. SaaS stands for Software as a Service.
[0018] The operation and maintenance resource management module manages various interface elements and operation and maintenance equipment, where the management of operation and maintenance equipment includes:
[0019] The supply delivery system is used to obtain device information of newly added devices when there are newly added devices;
[0020] A configuration management system, configured to determine a target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type; wherein the target resource group is recorded in the resource group table of the permission model;
[0021] The basic operation and maintenance platform is used to add the device information of the newly added device to the target resource group so that the permissions of the newly added device are configured to the users in the user group corresponding to the target resource group; the users corresponding to the target resource group are determined based on the correspondence between the user group and the resource group.
[0022] Optionally, the operation and maintenance user management module further includes:
[0023] When there is a deleted user, the deleted user is removed from the user group to which the deleted user belongs.
[0024] Optionally, the basic operation and maintenance platform is also used to:
[0025] When there is a deleted device, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
[0026] Optionally, when the basic operation and maintenance platform adds the device information of the newly added device to the target resource group, it is specifically configured to:
[0027] The device information of the newly added device is assigned to any thread in the thread pool, so that the thread is called to add the device information to the target resource group.
[0028] A third aspect of the present application provides an electronic device, including a memory and a processor;
[0029] Wherein, the memory is used to store computer programs;
[0030] The processor is used to execute the computer program, and when the computer program is executed, it is specifically used to implement the large enterprise cloud operation and maintenance platform authority management method provided in any one of the first aspects of this application.
[0031] The fourth aspect of the present application provides a computer storage medium for storing a computer program. When the computer program is executed, it is specifically used to implement the large enterprise cloud operation and maintenance platform authority management method provided in any one of the first aspects of the present application.
[0032] The present application provides a method, system, device and storage medium for permission management of a cloud operation and maintenance platform for a large enterprise, which supports the unified management of a large number of permission elements or objects of multiple SAAS applications on the cloud. Each SAAS application can realize the automated operation and maintenance of operation and maintenance equipment based on this. The present solution is based on a pre-built permission model, which at least includes an organization table, a user group table and a resource group table. When a new user is added to any SaaS application, the new user is added to the user group corresponding to the organization to which the new user belongs recorded in the user group table according to the organization to which the new user belongs recorded in the organization table. When a new device is added, the target resource group to which the new device belongs in the resource group table is determined at least according to the park and product type of the new device. The device information of the new device is added to the target resource group, so that the permissions of the new device are configured to the users in the user group corresponding to the target resource group. The present solution realizes the group management of device permissions by setting user groups and resource groups, and on this basis realizes the automatic authorization of new users and devices, thereby improving the efficiency of permission management. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0034] Figure 1 A schematic diagram of the architecture of a rights management model provided in an embodiment of the present application;
[0035] Figure 2 A schematic diagram of the architecture of a cloud operation and maintenance management platform provided in an embodiment of the present application;
[0036] Figure 3 A schematic diagram of the relationship between data tables in a rights management system for a large enterprise cloud operation and maintenance platform provided in an embodiment of the present application;
[0037] Figure 4 A flowchart of a method for managing permissions on a large enterprise cloud operation and maintenance platform provided in an embodiment of the present application;
[0038] Figure 5 A schematic diagram of the structure of a large enterprise cloud operation and maintenance platform rights management system provided in an embodiment of the present application;
[0039] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0041] In order to facilitate understanding of the technical solution of this application, some terms that may be involved in this application are first briefly explained.
[0042] Role, a collection of interface permissions.
[0043] Interface permissions, menus, pages, buttons, data and other interface elements.
[0044] A resource group can be understood as a special role, which is a collection of specific operation and maintenance objects, namely devices.
[0045] Resources and operation and maintenance objects, such as operating system equipment and database equipment.
[0046] Having permissions on operation and maintenance objects means that you can perform operation and maintenance operations on the operation and maintenance objects, such as changing configurations, while having permissions on interfaces means that you can use related menus, pages, buttons, data, etc.
[0047] Permission management solves the problem of what kind of users are allowed to do what operations.
[0048] SaaS is the abbreviation of Software-as-a-Service, which means software as a service, that is, software services are provided through the Internet.
[0049] PaaS is the abbreviation of Platform as a Service, which means Platform as a Service. It is a business model that provides the server platform as a service.
[0050] The beneficial effects of the present invention are:
[0051] This invention fully considers the various complex user needs of large enterprises, designs and implements a more universal permission model, and facilitates the realization of automated operation and maintenance.
[0052] The present invention can realize unified and centralized authority management of a complex system with multiple applications, which is beneficial to the rapid iteration of applications.
[0053] The present invention can automatically authorize frequently changing permissions, which is more efficient.
[0054] Large enterprises have complex organizational structures and responsibilities, and diverse needs, so permission management models need to be more adaptable. The operation and maintenance of large enterprises involve multiple fields and applications, such as change, process, and configuration management. The interactions between various applications are diverse and require unified integration and planning. Permission management also needs to be considered in combination with the characteristics of multiple systems and applications. Large enterprises have heavy operation and maintenance tasks, and traditional manual operation and maintenance methods can no longer keep up with the pace of the times. Automated operation and maintenance methods need to be considered, and permission management is the basis for achieving automated operation and maintenance. At the same time, faced with huge operation and maintenance objects, permission management also needs to be automated.
[0055] Existing technologies are more focused on implementing permission management for small-scale systems through simple user information management, role authorization management, and user group management. Those with resource management modules are more focused on managing resources such as software menus and files. Permission models are also more based on the relatively simple business needs of small-scale systems. Permission management for the operation and maintenance field, especially automated operation and maintenance, is less common, and automatic configuration of resource permissions is rarely achieved.
[0056] In addition, since most existing technologies are designed for small-scale systems, the corresponding models and implementation methods tend to be simple, and are more from the developer's perspective, with little consideration of user needs, and are unable to accurately meet user needs. The database design structure is simple and cannot meet the needs of more scenarios, and is not suitable for large-scale systems; existing technologies rarely manage operation and maintenance object resources, and mostly manage software menus, files, etc.; existing technologies are rarely used in the operation and maintenance field, especially in the field of automated operation and maintenance, and rarely implement automatic configuration of resource permissions, relying on manual work and low efficiency.
[0057] The permission management solution provided in the embodiment of the present application is mainly used in large-scale cloud operation and maintenance management platforms. Cloud operation and maintenance management platforms have the characteristics of many applications, many user types, and many usage scenarios. Therefore, the construction of the permission model requires a thorough investigation and analysis of the user's application usage habits. In this application, the inventor found through analysis that the permission management of the cloud operation and maintenance management platform includes the permission management of the software interface, and also includes the management of the resource permissions of the operation and maintenance equipment (hereinafter referred to as the equipment), that is, it is necessary to manage which users have the permission to perform operation and maintenance operations on which devices.
[0058] As mentioned above, the scale of cloud operation and maintenance management platforms is huge, and the use of role-based access control (RBAC) to manage permissions for each operation and maintenance personnel (user) in the cloud operation and maintenance management platform one by one is very inefficient.
[0059] There is also another problem, that is, the permission management of the cloud operation and maintenance management platform involves not only the permission management of the software interface, but also the permission management of physical devices.
[0060] In response to the above two issues, this application first proposes a permission management model, see Figure 1 , which is a schematic diagram of the architecture of the permission management model.
[0061] It can be seen that the permission management model provided by this application defines the concepts of user groups and resource groups, where each user group includes one or more users with the same role. For example, multiple administrator users within an operation and maintenance team may belong to the same user group, and multiple ordinary staff users within an operation and maintenance team may belong to another user group. The roles correspond to the permissions, and each specific role has one or more specific permissions. Therefore, it can be considered that the users in each user group have the same permissions.
[0062] It should be noted that a user can have multiple roles. For example, user A is an administrator in a department and an ordinary user in a higher-level department. Therefore, a user can belong to at least one user group.
[0063] The permissions corresponding to the role are the permissions for the software interface and elements in the interface in the cloud operation and maintenance management platform. For example, assuming that a certain role has the permission for interface 1 in the cloud operation and maintenance management platform, the user with this role can perform operation and maintenance operations on interface 1 after logging into the cloud operation and maintenance management platform, including but not limited to changing the information, layout and properties of interface 1.
[0064] In some optional embodiments, the authority of a specific interface can also be further subdivided into the authority of each menu in the interface. On this basis, when a certain role has the authority of an interface, the user with this role can perform corresponding operations on the partial menu on this interface.
[0065] It is not difficult to see that based on the above permission management model, the permission management system does not need to manage permissions for each user one by one. It only needs to add new users to a specific user group when they join the cloud operation and maintenance management platform. Then, the permissions of multiple users with the same role can be managed in batches based on user groups, thereby improving the efficiency of permission management.
[0066] Further, Figure 1 The illustrated permissions management model also defines resource groups. Each resource group can include at least one device. In practice, resource groups can be divided based on device type or location (e.g., campus). User groups and resource groups have a corresponding relationship. One user group can correspond to multiple resource groups, and vice versa. By establishing a corresponding relationship between resource groups and user groups, users within a user group can have operation and maintenance permissions for devices within the resource group.
[0067] Based on the above architecture, the permission management system can batch manage the operation and maintenance permissions of multiple users to the device in user groups.
[0068] At the same time, the permission management model of this application manages the interface permissions and device permissions through roles and resource groups respectively, thereby decoupling the permission management of the two and avoiding mutual interference in actual applications.
[0069] See Figure 2 , is a schematic diagram of the architecture of a cloud operation and maintenance management platform provided in an embodiment of the present application. It can be seen that the cloud operation and maintenance management platform includes a PaaS platform, and the PaaS platform provides multiple SaaS applications, such as Figure 2 Three SaaS applications are provided, designated SaaS Application 1 through SaaS Application 3. The automated permission management system provided in this application is connected to the PaaS platform to manage operational permissions for the software interfaces within the PaaS platform and SaaS applications, as well as for the devices running the PaaS platform and SaaS applications. After logging into the PaaS platform, users of the cloud operation and maintenance management platform can perform operational operations on the interfaces, menus, and devices of the authorized applications, based on the permissions assigned by the automated permission management system.
[0070] In a specific implementation, the above rights management model can be represented by a plurality of mutually corresponding data tables, which can be stored in and maintained by the rights management system of the present application.
[0071] according to Figure 2 As can be seen from the architectural diagram of the cloud operation and maintenance management platform shown, the cloud operation and maintenance management platform provided by this solution can simultaneously manage the user permissions of each SaaS application in the platform. As a result, each SaaS application does not need to consider its own permission management, which achieves lightweight application and makes the version iteration and update of SaaS applications more convenient.
[0072] See Figure 3 , which is a relationship diagram of a cloud operation and maintenance management platform data table for implementing the above-mentioned permission management model provided in an embodiment of the present application.
[0073] It can be seen that the above-mentioned permission management model can specifically include: user group and user association table, user table, user group table, and organization table belonging to the operation and maintenance user management module; user role association table, user group and role association table, role table, role permission association table, permission table, permission menu association table, permission page element association table, and operation and maintenance resource association table belonging to the role permission management module; menu table, page element table, and various operation and maintenance resource tables belonging to the operation and maintenance resource management module.
[0074] The user table is used to record the users in the current cloud operation and maintenance management platform. The user table includes fields such as user type and relationship with the organization, which facilitates the automatic assignment of users to user groups and automatic association with accessible applications.
[0075] The user table supports the creation of virtual users to support functional expansion of multiple applications.
[0076] The user group table is used to record the user groups currently in the cloud operation and maintenance management platform. The user group table contains the application ID, global / private attributes, and type fields (used to distinguish between departments and departments), thereby supporting unified and efficient management of multi-application permissions and differentiated management by type.
[0077] The user group and user association table is used to record which users are included in each user group.
[0078] The organization table is used to record the organizations currently divided within the cloud operation and maintenance management platform.
[0079] User role association table, used to record the correspondence between users and roles.
[0080] The user group and role association table is used to record the correspondence between user groups and roles.
[0081] The role table is used to record the roles currently set in the cloud operation and maintenance management platform.
[0082] The role-permission association table is used to record the correspondence between roles and permissions.
[0083] The permission table is used to record the permissions set in the cloud operation and maintenance management platform.
[0084] The permission menu association table, permission page element association table and operation and maintenance resource association table are used to record the correspondence between permissions and menus, the correspondence between permissions and page (interface) elements, and the correspondence between permissions and resource groups, respectively.
[0085] The menu table is used to record the menus in the cloud operation and maintenance management platform.
[0086] The page element table is used to record the pages in the cloud operation and maintenance management platform and the elements of these pages.
[0087] Various operation and maintenance resource tables are used to record the physical devices in the current cloud operation and maintenance management platform, the device information of these physical devices, and the resource groups to which these physical devices belong.
[0088] For example, each type of operation and maintenance resource table may include a "belonging resource group" field, and the field value of this field indicates to which resource group the corresponding device belongs.
[0089] Figure 3 In , the line between any two data tables indicates that there is a corresponding relationship between the two data tables. Figure 3 The correspondence between any two data tables is many-to-many.
[0090] The effect of using the above-mentioned multiple data tables to implement the permission management model of this solution is to achieve decoupling between users and menus, roles and resource groups. When any one or more of them change, only the information in the corresponding data table needs to be modified, without the need to modify the entire permission management model. This shortens the time spent on permission change operations caused by employee joining or leaving, job transfers, etc. in large enterprises, and improves the efficiency of permission management in large enterprises.
[0091] In combination with the above-mentioned rights management model and the data table implementing the model, the embodiment of the present application provides a rights management method for a large enterprise cloud operation and maintenance platform, see Figure 4 , the method may include the following steps.
[0092] S401: When a new user is added to any SaaS application, the new user is added to the target user group according to the organization to which the new user belongs recorded in the user table and organization table of the pre-built permission model, thereby configuring the permissions corresponding to the target user group to the new user.
[0093] The full name of SaaS is Software as a Service, which means software as a service in Chinese.
[0094] The target user group is the user group corresponding to the organization to which the newly added user belongs, as recorded in the user group table of the permission model.
[0095] Combine Figure 3 The data table in describes the specific execution method of step S301.
[0096] First, when a new user registers in the cloud operation and maintenance management platform, the user information entered during registration will be added to Figure 3 In the user table shown, whether there are new users can be found based on Figure 3 The determination is made based on whether there is a new record in the user table. When there is a new record in the user table, the user corresponding to the new record in the user table can be determined as a new user.
[0097] The organization to which the newly added user belongs can be determined based on the field in the user table that is related to the organization. For example, if the field in the user table that is related to the organization has a value of "belongs to organization A", then it can be determined that the newly added user belongs to organization A.
[0098] The target user group can be determined based on the correspondence between user groups and institutions recorded in the user group table. Specifically, the user group table can record which institutions each user group corresponds to, indicating which institutions' users the user group can include. Therefore, after determining the institution to which the newly added user belongs, the user group corresponding to the institution can be found from the user group table and determined as the target user group.
[0099] It can be understood that one organization may correspond to at least one user group. When there is more than one target user group, the steps of this embodiment are executed for each target user group.
[0100] Adding a new user to the target user group specifically means adding the correspondence between the new user and the target user group to the user group-user association table. For example, if the target user group to which new user A belongs is user group 1, then in step S401, adding the correspondence "User A belongs to user group 1" to the user group-user association table is equivalent to adding user A to user group 1.
[0101] like Figure 3 As shown, each user group corresponds to at least one role, and the role corresponds to the permissions of menus, page elements and resource groups. Therefore, after adding a new user to the target user group, it is equivalent to automatically establishing a correspondence between the permissions of the new user and the menus, page elements and resource groups corresponding to the target user group, which is equivalent to configuring these permissions corresponding to the target user group to the new user. As a result, the new user can perform operation and maintenance operations on the devices in the menus, page elements and resource groups associated with these permissions.
[0102] S402: When a new device is added, obtain device information of the new device.
[0103] When a new device is connected to the cloud operation and maintenance management platform, the cloud operation and maintenance management platform can read the device information from the newly added device.
[0104] Device information may include unique identifier, device name, device type (configuration item), park location, operating system type, database type, IP address, addition, deletion, and modification marks, etc.
[0105] S403: Determine the target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type.
[0106] The target resource group is recorded in the resource group table of the permission model.
[0107] Combine Figure 3 In the data table, Figure 3The various operation and maintenance resource tables in the table can include the park and product type fields. Each resource group has specific field values in these two fields, indicating that the resource group contains equipment of the corresponding product type or equipment in the corresponding park. For example, the field value of the park field corresponding to resource group 2 can be park C, so it can be determined that resource group 2 contains equipment located in park C.
[0108] According to the above settings, in step S403, you can search in various operation and maintenance resource tables for a resource group whose field value of the park field is the same as the park where the newly added equipment is located, or search for a resource group whose field value of the product type field is the same as the product type of the newly added equipment, and determine the found resource group as the target resource group.
[0109] S404: Add the device information of the newly added device to the target resource group so that the permissions of the newly added device are configured to users in the user group corresponding to the target resource group.
[0110] The user corresponding to the target resource group is determined based on the correspondence between the user group and the resource group.
[0111] Combine Figure 3 In the data table, in step S404, the device information of the newly added device can be recorded in various operation and maintenance resource tables, and at the same time, the field value of the "resource group" field of the newly added device in various operation and maintenance resource tables can be set to the target resource group, thereby adding the device information of the newly added device to the target resource group.
[0112] According to the aforementioned permission management model, it can be understood that the permissions of each resource group will be configured to at least one user in at least one user group. Therefore, after the device information of the newly added device is added to the target resource group, the permissions of the newly added device will be automatically configured to the users in the user group corresponding to the target resource group.
[0113] It should be noted that, in this embodiment, although the description is given in the above order, the order of the process of managing the permissions of the newly added user described in step S401 and the process of managing the permissions of the newly added device described in steps S402 to S404 is not limited.
[0114] That is to say, after applying the system provided by this embodiment, at any time, as long as there is a new user in the cloud operation and maintenance management platform, the large enterprise cloud operation and maintenance platform permission management system of this embodiment can execute step S401 to configure corresponding permissions for the new user; at any time, when there is a new device in the cloud operation and maintenance management platform, the automated permission management system of this embodiment can execute the process described in steps S402 to S404, thereby configuring the permissions of the new device to the corresponding user in the cloud operation and maintenance management platform.
[0115] Optionally, the method further includes:
[0116] When a user is deleted, the deleted user will be removed from the user group to which the deleted user belongs.
[0117] Combined with step S401, when a user is deleted in the cloud operation and maintenance management platform, the cloud operation and maintenance management platform will delete the user information of the user recorded in the user table. Therefore, it is possible to determine whether there is a deleted user based on whether the user information in the user table is deleted. If a piece of user information is deleted, then the user corresponding to this piece of user information is the deleted user.
[0118] Removing the deleted user from the user group to which the deleted user belongs may specifically mean removing the corresponding relationship containing the deleted user from the user group-user association table. For example, assuming the deleted user is User B, and the user group-user association table contains two corresponding relationships containing User B, namely "User B belongs to User Group 1" and "User B belongs to User Group 3," then in the above steps, deleting these two corresponding relationships from the user group-user association table is equivalent to removing User B from the user group to which it belongs.
[0119] Optionally, the method further includes:
[0120] When a device is deleted, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
[0121] The specific implementation of the above steps can be:
[0122] After a device is found to be deleted from the cloud operation and maintenance management platform, the device information corresponding to the deleted device is deleted from various operation and maintenance resource tables, and the field value of the deleted device in the "Resource Group" field is deleted.
[0123] Optionally, add the device information of the newly added device to the target resource group, including:
[0124] Assign the device information of the newly added device to any thread in the thread pool, so that the calling thread adds the device information to the target resource group.
[0125] The thread pool may include multiple pre-created threads. The method of assigning to any thread in the above steps may be to randomly select a thread from multiple idle threads in the thread pool, and then assign the device information of the newly added device to the randomly selected thread, so that the thread adds the device information to the target resource group.
[0126] The advantage of this is that the device information of the newly added devices can be processed in parallel through multiple threads in the thread pool. When there are multiple newly added devices at the same time, the efficiency of adding the device information of the newly added devices to the target resource group can be improved.
[0127] The present application provides a method for managing permissions on a cloud operation and maintenance platform for large enterprises, which supports the unified management of a large number of permission elements or objects for multiple SAAS applications on the cloud. Each SAAS application can realize automated operation and maintenance of operation and maintenance equipment based on this. The present solution is based on a pre-built permission model, which at least includes an organization table, a user group table, and a resource group table. When a new user is added to any SaaS application, the new user is added to the user group corresponding to the organization to which the new user belongs recorded in the user group table according to the organization to which the new user belongs recorded in the organization table. When a new device is added, the target resource group to which the new device belongs in the resource group table is determined at least based on the park and product type where the new device is located. The device information of the new device is added to the target resource group, so that the permissions of the new device are configured to the users in the user group corresponding to the target resource group. The present solution realizes group management of device permissions by setting user groups and resource groups, and on this basis realizes automatic authorization of new users and devices, thereby improving the efficiency of permission management.
[0128] Furthermore, as described in step S401, the method provided in this embodiment can be used to manage the permissions of users in each SaaS application, support horizontal expansion of more applications, avoid data duplication problems caused by each application managing its own permissions separately, and make SaaS applications lightweight, which is conducive to the rapid iteration and update of SaaS applications.
[0129] According to the large enterprise cloud operation and maintenance platform rights management method provided by this application, the embodiment of this application also provides a large enterprise cloud operation and maintenance platform rights management system, see Figure 5 The system includes an operation and maintenance user management module 501, an operation and maintenance resource management module 502, and a role authority management module 503 for recording the correspondence between user groups and resource groups.
[0130] The operation and maintenance user management module 501 is used to:
[0131] When a new user is added to any SaaS application, the new user is added to the target user group based on the organization to which the new user belongs recorded in the user table and organization table of the pre-built permission model, so that the permissions corresponding to the target user group are configured for the new user.
[0132] The target user group is the user group corresponding to the organization to which the newly added user belongs, as recorded in the user group table of the permission model; SaaS stands for Software as a Service, which means software as a service in Chinese.
[0133] The operation and maintenance resource management module 502 includes:
[0134] The supply delivery system 521 is used to obtain device information of newly added devices when there are newly added devices.
[0135] The configuration management system 522 is configured to determine a target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type.
[0136] The target resource group is recorded in the resource group table of the permission model.
[0137] The basic operation and maintenance platform 523 is used to add the device information of the newly added device to the target resource group so that the permissions of the newly added device are configured to the users in the user group corresponding to the target resource group.
[0138] The user corresponding to the target resource group is determined based on the correspondence between the user group and the resource group.
[0139] Optionally, the operation and maintenance user management module also includes:
[0140] When a user is deleted, the deleted user will be removed from the user group to which the deleted user belongs.
[0141] Optionally, the basic operation and maintenance platform is also used for:
[0142] When a device is deleted, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
[0143] Optionally, when the basic operation and maintenance platform adds the device information of the newly added device to the target resource group, it is specifically used for:
[0144] Assign the device information of the newly added device to any thread in the thread pool, so that the calling thread adds the device information to the target resource group.
[0145] The specific working principle of the large enterprise cloud operation and maintenance platform rights management system provided in the embodiment of this application can be found in the relevant steps of the large enterprise cloud operation and maintenance platform rights management method provided in any embodiment of this application, and will not be repeated here.
[0146] The present application provides a large enterprise cloud operation and maintenance platform authority management system, which includes an operation and maintenance user management module 501, an operation and maintenance resource management module 502, and a role authority management module 503 for recording the correspondence between user groups and resource groups, wherein the operation and maintenance resource management module 502 includes a supply delivery system 521, a configuration management system 522 and a basic operation and maintenance platform 523.
[0147] When a new user is added to any SaaS application, the operation and maintenance user management module 501 adds the new user to the target user group based on the organization to which the new user belongs recorded in the user table and organization table of the pre-built permission model, thereby allocating the permissions corresponding to the target user group to the new user; wherein, the target user group is the user group corresponding to the organization to which the new user belongs recorded in the user group table of the permission model; the full name of SaaS is Software as a Service, which means software as a service in Chinese.
[0148] When a new device is added, the supply delivery system 521 obtains the device information for the newly added device. The configuration management system 522 determines the target resource group to which the newly added device belongs, based at least on the park where the newly added device is located and its product type. The target resource group is recorded in the resource group table of the permission model. The basic operation and maintenance platform 523 adds the device information to the target resource group, allocating permissions for the newly added device to users in the user group corresponding to the target resource group. The users corresponding to the target resource group are determined based on the corresponding relationship between user groups and resource groups.
[0149] This solution implements grouped management of device permissions by setting up user and resource groups. Furthermore, it enables automatic authorization of newly added users and devices, improving permission management efficiency. Furthermore, this solution supports unified management of permission elements or objects across multiple SaaS applications on the cloud, enabling SaaS applications to automate the operation and maintenance of their devices.
[0150] The present application also provides an electronic device. Figure 6 , including a memory 601 and a processor 602.
[0151] The memory 601 is used to store computer programs.
[0152] The processor 602 is used to execute a computer program. When the computer program is executed, it is specifically used to implement the large enterprise cloud operation and maintenance platform authority management method provided in any embodiment of the present application.
[0153] An embodiment of the present application also provides a computer storage medium for storing a computer program. When the computer program is executed, it is specifically used to implement the large enterprise cloud operation and maintenance platform authority management method provided in any embodiment of the present application.
[0154] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0155] It should be noted that the concepts of "first" and "second" mentioned in the present invention are only used to distinguish different systems, modules or units, and are not used to limit the order or interdependence of the functions performed by these systems, modules or units.
[0156] The present application is capable of being implemented or used by those skilled in the art. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to be embodied in the widest possible manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for managing permissions on a cloud operation and maintenance platform for a large enterprise, characterized in that: include: When a new user is added to any SaaS application, the new user is added to a target user group based on the organization to which the new user belongs, as recorded in the user table and organization table of the pre-built permission model. This allows the new user to be assigned permissions corresponding to the target user group. The target user group is the user group corresponding to the organization to which the new user belongs, as recorded in the user group table of the permission model. SaaS stands for Software as a Service, which means software as a service in Chinese. The permission model includes at least an organization table, a user group table, and a resource group table. When a new device is added, obtain the device information of the new device; Determining a target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type; wherein the target resource group is recorded in the resource group table of the permission model; The device information of the newly added device is assigned to any thread in the thread pool, so that the thread is called to add the device information to the target resource group, so that the permissions of the newly added device are configured to the users in the user group corresponding to the target resource group; the users corresponding to the target resource group are determined based on the correspondence between the user group and the resource group.
2. The method according to claim 1, characterized in that The method further comprises: When there is a deleted user, the deleted user is removed from the user group to which the deleted user belongs.
3. The method according to claim 1, characterized in that The method further comprises: When there is a deleted device, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
4. A large enterprise cloud operation and maintenance platform rights management system, characterized by: It includes an operation and maintenance user management module, an operation and maintenance resource management module, and a role authority management module for recording the relationship between user groups and resource groups; The operation and maintenance user management module is used to: When a new user is added to any SaaS application, the new user is added to a target user group based on the organization to which the new user belongs, as recorded in the user table and organization table of the pre-built permission model. This allows the new user to be assigned permissions corresponding to the target user group. The target user group is the user group corresponding to the organization to which the new user belongs, as recorded in the user group table of the permission model. SaaS stands for Software as a Service, which means software as a service in Chinese. The permission model includes at least an organization table, a user group table, and a resource group table. The operation and maintenance resource management module manages various interface elements and operation and maintenance equipment, where the management of operation and maintenance equipment includes: The supply delivery system is used to obtain device information of newly added devices when there are newly added devices; A configuration management system, configured to determine a target resource group to which the newly added device belongs based at least on the park where the newly added device is located and the product type; wherein the target resource group is recorded in the resource group table of the permission model; The basic operation and maintenance platform is used to add the device information of the newly added device to the target resource group so that the permissions of the newly added device are configured for users in the user group corresponding to the target resource group; the users corresponding to the target resource group are determined based on the correspondence between the user group and the resource group; The specific implementation method of the basic operation and maintenance platform adding the device information of the newly added device to the target resource group is: The device information of the newly added device is assigned to any thread in the thread pool, so that the thread is called to add the device information to the target resource group.
5. The system according to claim 4, characterized in that The operation and maintenance user management module also includes: When there is a deleted user, the deleted user is removed from the user group to which the deleted user belongs.
6. The system according to claim 4, characterized in that The basic operation and maintenance platform is also used for: When there is a deleted device, the device information of the deleted device is removed from the resource group to which the deleted device belongs.
7. An electronic device, characterized in that: including memory and processor; Wherein, the memory is used to store computer programs; The processor is used to execute the computer program, and when the computer program is executed, it is specifically used to implement the large enterprise cloud operation and maintenance platform authority management method as described in any one of claims 1 to 3.
8. A computer storage medium, characterized in that Used to store computer programs, which, when executed, are specifically used to implement the large enterprise cloud operation and maintenance platform authority management method as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Management method for user rights in video monitoring system, and video monitoring system
CN101753996A
Dynamic management of groups for entitlement and provisioning of computer resources
US20120278903A1