Object information management method and device, electronic equipment and storage medium

By converting user platform accounts into user system accounts in the cloud platform, the challenge of managing multiple object storage systems is solved, enabling efficient management of multiple object storage systems.

CN116149555BActive Publication Date: 2025-11-07MASHANG CONSUMER FINANCE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310093166.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-09
Publication Date
2025-11-07
Estimated Expiration
2043-02-09

AI Technical Summary

Technical Problem

Existing technologies cannot achieve management operations across object storage systems, resulting in low management efficiency as the number and types of object storage systems increase.

Method used

By acquiring user platform account and object information, the system converts user platform accounts into user system accounts using a preset account mapping relationship, and generates object management instructions to manage multiple object storage systems across systems.

Benefits of technology

It enables cross-system object management operations, improving the convenience and efficiency of managing multiple object storage systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116149555B_ABST
    Figure CN116149555B_ABST
Patent Text Reader

Abstract

The present disclosure provides an object information management method and device, electronic equipment and storage medium, which are used to implement cross-system object management operations. The method comprises: obtaining a user platform account and object information; determining a user system account corresponding to the user platform account according to a preset account mapping relationship in a case where it is determined that the user platform account has a permission to manage the object information; the user system account refers to identification information of the user in multiple object storage systems; combining the user system account and the object information into instruction parameters to generate an object management instruction containing the instruction parameters; selecting a target storage system corresponding to the object information from the multiple object storage systems and sending the object management instruction to the target storage system; the target storage system is used to perform an object information management operation; and the user system account has a permission to manage storage objects in the multiple object storage systems.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of data processing, and particularly relates to a management method and device of object information, an electronic device and a storage medium. BACKGROUND

[0002] With the rapid development of Internet applications, PB-level or even EB-level mass data storage becomes particularly important. As a new type of distributed storage system, an object storage system provides convenience for mass data storage. Among them, an object is a basic entity in the object storage system, and through providing an object-based access interface, any type of data can be stored, such as pictures, videos, audios, texts, etc. The object storage system effectively solves the problems of limited sharing capability and poor scalability of traditional storage.

[0003] In the related art, in order to manage the objects in the object storage system, an authentication operation needs to be performed inside the object storage system, and the management operation can be performed only after the authentication is passed. Since the authentication operation is implemented inside the object storage system, the identity information required for authentication can only be identified inside the object storage system. As can be seen, this method can only manage the objects in a single object storage system and cannot implement object management operations across systems. However, with the increasing number and types of object storage systems, there is an urgent need for a management method that can be applied to various object storage systems. SUMMARY

[0004] The present disclosure provides a management method and device of object information, an electronic device and a storage medium, which are used to implement object management operations across systems.

[0005] In a first aspect, the present disclosure provides a management method of object information, comprising the following steps:

[0006] Obtaining a user platform account and object information; the user platform account refers to the identification information of the user in the cloud platform;

[0007] In a case where it is determined that the user platform account has the permission to manage the object information, determining a user system account corresponding to the user platform account according to a preset account mapping relationship; the user system account refers to the identification information of the user in a plurality of object storage systems; the user system account has the permission to manage the storage objects in the plurality of object storage systems;

[0008] Combining the user system account and the object information into instruction parameters, and generating an object management instruction containing the instruction parameters;

[0009] The sending module is adapted to screen a target storage system corresponding to the object information from a plurality of object storage systems, and send the object management instruction to the target storage system; wherein the target storage system is configured to perform a management operation on the object information according to the object management instruction after successfully authenticating the user system account.

[0010] In a second aspect, the present disclosure provides a device for managing object information, comprising:

[0011] The obtaining module is adapted to obtain a user platform account and object information; the user platform account refers to identification information of a user in a cloud platform;

[0012] The mapping module is adapted to determine a user system account corresponding to the user platform account according to a preset account mapping relationship in a case where it is determined that the user platform account has a permission to manage the object information; the user system account refers to identification information of a user in a plurality of object storage systems; the user system account has a permission to manage storage objects in the plurality of object storage systems;

[0013] The generating module is adapted to combine the user system account and the object information into an instruction parameter, and generate an object management instruction containing the instruction parameter;

[0014] The sending module is adapted to screen a target storage system corresponding to the object information from a plurality of object storage systems, and send the object management instruction to the target storage system; wherein the target storage system is configured to perform a management operation on the object information according to the object management instruction after successfully authenticating the user system account.

[0015] In a third aspect, the present disclosure provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores one or more computer programs executable by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to perform the above method.

[0016] In a fourth aspect, the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor / processing core, implements the above method.

[0017] According to the embodiment provided in the present disclosure, first, a user platform account and object information are acquired, and an authentication operation is performed according to the user platform account and the object information. If the authentication result indicates that the user platform account has a permission matched with the object information, a user system account corresponding to the user platform account is determined according to a preset account mapping relationship. Then, an object management instruction is generated according to the user system account and the object information, and a target storage system corresponding to the object information is selected from a plurality of object storage systems. The object management instruction is sent to the target storage system. Since the user system account in the embodiment has the permission of managing the storage objects in the plurality of object storage systems, the user in the cloud platform can perform the object management operation across the storage systems by converting the user platform account into the user system account, thereby providing the convenience for the management of the plurality of object storage systems.

[0018] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0019] The accompanying drawings are included to provide a further understanding of the present disclosure and constitute a part of the specification, which together with the embodiments of the present disclosure are used to explain the present disclosure and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art from the detailed description of the specific example embodiments with reference to the accompanying drawings, in which:

[0020] Figure 1 A flowchart of an object information management method provided for an embodiment of the present disclosure is shown;

[0021] Figure 2 An implementation manner of an object information management method of a related technology is shown;

[0022] Figure 3 A structural schematic diagram of one specific example of the present application is shown;

[0023] Figure 4 A block diagram of an object information management device provided for an embodiment of the present disclosure is shown;

[0024] Figure 5 A block diagram of an electronic device provided for an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0025] For those skilled in the art to better understand the technical solutions of the present disclosure, the exemplary embodiments of the present disclosure are described below in conjunction with the drawings, which include various details of the embodiments of the present disclosure to help understanding, and should be considered only as exemplary. Therefore, those skilled in the art should realize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Also, for the sake of clarity and conciseness, the description below omits the description of well-known functions and structures.

[0026] In the case of no conflict, each embodiment of the present disclosure and each feature in the embodiments can be combined with each other.

[0027] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0028] The terms used herein are only used to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. The terms "connected" or "coupled" or similar terms are not limited to a physical or mechanical connection, but can include an electrical connection, whether direct or indirect.

[0029] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted in an overly literal or overly formal sense unless expressly so defined herein.

[0030] The object information management method according to the embodiments of the present disclosure can be executed by an electronic device such as a terminal device or a server. The terminal device can be a vehicle-mounted device, a User Equipment (UE), a mobile device, a user terminal, a terminal, a cellular phone, a cordless phone, a Personal Digital Assistant (PDA), a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. The server can be a standalone physical server, a server cluster composed of multiple physical servers, or a distributed system, or a cloud server providing cloud computing services. The method can be specifically implemented by a processor invoking a computer program stored in a memory.

[0031] In the related art, in order to manage the objects in the object storage system, it is necessary to perform an authentication operation inside the object storage system first, and the management operation can be performed after the authentication is passed. Since the authentication operation is implemented inside the object storage system, the identity information required for authentication can only be identified inside the object storage system. As can be seen, this method can only manage the objects in a single object storage system and cannot realize object management operations across systems. However, with the increasing number and types of object storage systems, there is an urgent need for a management method that can be applied to various object storage systems. To solve the above problems, the present application provides a method for managing object information, in which the user in the cloud platform can perform cross-storage system object management operations by converting the user platform account into a user system account, thereby providing convenience for the management of multiple object storage systems.

[0032] Figure 1 A flowchart of a method for managing object information is provided for one embodiment of the present disclosure. Referring to Figure 1 The method comprises:

[0033] Step S110: obtaining a user platform account and object information; the user platform account refers to the identification information of the user in the cloud platform.

[0034] The user platform account refers to the identification information of the user in the cloud platform, specifically the account allocated by the cloud platform for the user, which is used for authentication and identity recognition operations inside the cloud platform. The object information at least includes the object type and object storage location of the business object to be managed, and any information associated with the business object to be managed can be used as object information.

[0035] The user platform account and object information can be obtained in various ways, for example, it can be obtained through a user input object management request, or it can be obtained through other types of requests or messages, and the present application does not limit the specific obtaining method. The object management request is used to manage the objects in the object storage system. The object storage system includes various distributed storage systems, and the objects in the object storage system include various resource objects such as buckets, files, and directories.

[0036] In order to realize the object management operation, the object management request needs to be authenticated to confirm whether the user sending the request has the corresponding management authority. Accordingly, the object management request at least contains the user platform account and the object information.

[0037] The object management device can include an electronic device, or the object management device can be deployed in the electronic device. In an optional implementation manner, in order to avoid the problems of great bandwidth consumption and long processing delay caused by processing all object management requests by the same network node, the object management device is further divided into a first object management module and a second object management module. The first object management module and the second object management module can be respectively implemented by different servers or communication interfaces.

[0038] Correspondingly, in order to implement the shunting operation of the object management request, before obtaining the user platform account and the object information contained in the received object management request, the following operation is further performed: receiving the object management request by a front-end server, and determining the request type of the object management request. The front-end server is a server facing users. If the request type belongs to a first type, the front-end server forwards the object management request to the first object management module, and the first object management module performs the step of obtaining the user platform account and the object information contained in the received object management request and subsequent steps; if the request type belongs to a second type, the front-end server forwards the object management request to the second object management module, and the second object management module performs the step of obtaining the user platform account and the object information contained in the received object management request and subsequent steps.

[0039] The bandwidth resource required by the object management request of the first type is greater than the bandwidth resource required by the object management request of the second type. For example, the first type includes an upload type and a download type; and the second type includes a query type and a modification type. As can be seen, in this manner, the object management request for uploading or downloading a file is shunted to the first object management module for processing, and the object management request of the query type or the modification type is shunted to the second object management module for processing. Since uploading or downloading a file requires occupying more bandwidth and has a greater impact on system resources, performing the management operation of this type by a separate network module can avoid the delay of the query or modification type operation. In other words, the real-time requirement of the object management request of the first type is lower, and the real-time requirement of the object management request of the second type is higher. That is, the real-time requirement of the object management request of the first type is lower than the real-time requirement of the object management request of the second type.

[0040] In a case where it is determined that the user platform account has the permission to manage the object information, a user system account corresponding to the user platform account is determined according to a preset account mapping relationship. The user system account refers to the identification information of the user in multiple object storage systems.

[0041] In this step, it is necessary to authenticate the user platform account to determine whether the user platform account has the permission matched with the object information. In an optional implementation, the authentication operation is implemented by means of the authentication management system. Correspondingly, in this step, first, the object information is parsed to obtain the object identifier and the management behavior identifier contained in the object information. The object identifier is used to uniquely identify the business object to be managed, and can be specifically various information such as the name, ID, storage location, etc. of the object; the management behavior identifier is used to uniquely identify the specific behavior type of the management operation, which can include, for example: query type behavior identifier, modification type behavior identifier, upload type behavior identifier, download type behavior identifier, etc. Then, the user platform account, object identifier and management behavior identifier are sent to the authentication management system, and whether the user platform account has the permission matched with the object information is determined according to the authentication result returned by the authentication management system. The authentication management system is used to authenticate according to the pre-stored permission correspondence relationship between the user platform account and the object information. Specifically, the permission correspondence relationship between the user platform account and the object information can be pre-configured by the user, which can be directly stored in the authentication management system, or can be stored in a database accessible to the authentication management system. In short, the pre-configured permission correspondence relationship can realize the authentication of the user identity, so that the subsequent operation is only executed in the case that the user platform account has the management permission for the object information.

[0042] Next, in the case that it is determined that the user platform account has the permission matched with the object information, the user system account corresponding to the user platform account is determined according to the preset account mapping relationship. The account mapping relationship is used to store the correspondence relationship between the user platform account and the user system account of the same user; the user platform account of the same user includes at least one main platform account and a plurality of sub-platform accounts; and the user system account corresponding to the at least one main platform account and the plurality of sub-platform accounts of the same user is the same. As introduced above, the user platform account is allocated by the cloud platform for the user, and is used to identify the user identity in the cloud platform. Unlike the user platform account, the user system account is allocated by the object storage system for the user, and is used to identify the user identity in the object storage system. In this embodiment, only one user system account is allocated for the same user, and the main platform account and the plurality of sub-platform accounts of the user all correspond to the user system account. As can be seen, in this embodiment, it is necessary to distinguish the main account and the sub-account of the user in the cloud platform, while in the plurality of object storage systems, it is not necessary to distinguish the main account and the sub-account of the user, and both the main account and the sub-account directly correspond to the user system account.

[0043] Through this step, the user platform account is converted into the user system account, so that the subsequent management of the object storage system can be realized.

[0044] Step S130: combine the user system account and the object information into instruction parameters, and generate an object management instruction containing the instruction parameters.

[0045] Specifically, the user system account and the object information can be combined to obtain combined instruction parameters, so as to generate an object management instruction containing the combined instruction parameters. Unlike the object management request facing the cloud platform, the object management instruction faces the underlying object storage system, and therefore should carry the user system account instead of the user platform account.

[0046] In addition, in order to improve security, the instruction parameters can also be encrypted by a preset platform key to obtain encrypted instruction parameters, so as to generate an object management instruction containing the encrypted instruction parameters. By performing encryption and decryption operations, the network security can be improved to avoid malicious attacks.

[0047] Step S140: select a target storage system corresponding to the object information from a plurality of object storage systems, and send the object management instruction to the target storage system; wherein the target storage system is used to perform an object information management operation after the user system account is successfully authenticated; and the user system account has the permission to manage the storage objects in the plurality of object storage systems.

[0048] The object storage system includes a plurality of distributed storage systems with different storage architectures. Since the number of object storage systems is multiple, the target storage system corresponding to the object management instruction needs to be selected. In an optional implementation, the target storage system corresponding to the object information is selected from the plurality of storage systems according to the object attribute of the object information; wherein the object attribute includes an object storage format and / or an object storage location. As can be seen, the object attribute can be used to determine the object storage system where the object is located, so as to send the object management instruction to the corresponding object storage system (i.e. the target storage system).

[0049] Correspondingly, the target storage system first authenticates the user system account, and performs the object information management operation after the authentication is successful. Since the user system account has the permission to manage the storage objects in the plurality of object storage systems, the result of the authentication of the user system account by the target storage system must be successful.

[0050] Through the above method, the cross-system management function for the plurality of object storage systems can be realized.

[0051] In an optional implementation, the user needs to register an account first, and can perform the object management operation described above after successful registration. Correspondingly, before obtaining the user platform account and the object information contained in the received object management request, the following account registration operation is further performed:

[0052] First, in response to the received account registration request, the user identifier contained in the account registration request is obtained. Then, it is queried whether the main platform account corresponding to the user identifier has been stored in the account management system. The account management system is used to store the account data of each user. If not, it means that the user identifier has not been registered, and accordingly, the main platform account and the user system account are allocated for the user identifier, and the mapping relationship between the user identifier, the main platform account and the user system account is stored in the account management system; if yes, it means that the user identifier has been registered, and the sub-platform account is allocated for the user identifier, and the mapping relationship between the user identifier and the sub-platform account is stored in the account management system; wherein the sub-platform account and the main platform account correspond to the same user system account. As can be seen, the sub-platform account and the main platform account both belong to the user platform account of the user, and the sub-platform account and the main platform account correspond to the same user system account.

[0053] Among them, the object information in the embodiment includes: data buckets, file objects, directory objects and various objects.

[0054] As can be seen, in this way, first, the user platform account and the object information contained in the received object management request are obtained, and an authentication operation is performed according to the user platform account and the object information. If it is determined according to the authentication result that the user platform account has the permission matched with the object information, the user system account corresponding to the user platform account is determined according to the preset account mapping relationship; then, the object management instruction is generated according to the user system account and the object information, and the target storage system corresponding to the object information is selected from the plurality of object storage systems, and the object management instruction is sent to the target storage system. Since the user system account in the embodiment has the management permission of the plurality of object storage systems, by converting the user platform account into the user system account, the user in the cloud platform can perform the object management operation across the storage systems, thereby providing convenience for the management of the plurality of object storage systems.

[0055] For ease of understanding, the following will take a specific example as an example to introduce the specific implementation details of the object information management method in the application in detail:

[0056] Figure 2This paper illustrates an implementation method for managing object information in a related technology. This method manages read-only, read-write, and private permissions for various objects by main accounts, sub-accounts, and anonymous users. In this method, the object storage system is Ceph, and object uploads and downloads rely on Ceph accounts for authentication. Buckets are treated as resources, and operations such as bucket creation, deletion, querying, and file details all depend on authentication by the resource access control management device. The authentication process relies on accounts and resources. When a user registers a user platform account (including main and sub-accounts), they use a Ceph access tool (such as Ceph-go) to call the Ceph system's account management interface, mapping a Ceph account to each main account and each sub-account for later permission management. Therefore, it can be seen that... Figure 2 In the illustrated approach, assuming a single user's platform account includes one main account and N sub-accounts, then the Ceph system's account management interface needs to be called to create N+1 Ceph accounts. That is, each main account or sub-account corresponds to a unique Ceph account.

[0057] In this approach, the lifecycle of buckets is managed through a primary access tool (such as AWS SDK Go) when creating, updating, and deleting buckets. Resource reporting and deletion of buckets are also required. Furthermore, the authorization of sub-accounts for creating, updating, and deleting buckets is controlled by a resource access control management device. This device uses user roles (main and sub-accounts), resources, and resource access behaviors as the basis for authentication. Bucket owners and the main account can grant other accounts access to or deny certain resources based on specific criteria. This resource access control management device can be implemented through a cloud platform's Resource Access Management (RAM).

[0058] In addition, file uploads and downloads are managed with permissions through the Ceph account. When generating an object download link, the Ceph account information is encrypted and added to the link's query string. Uploading or downloading files is subject to permission checks based on the Ceph account associated with the user's platform account.

[0059] like Figure 2 As shown, in the account registration process, the cloud platform receives the user-triggered account registration request and stores the event information for creating the user's platform account in the message queue. Then, the front-end access layer consumes the event information for creating the user's platform account stored in the message queue. Next, the resource orchestration layer performs the following operations: calls the Ceph access tool to create a Ceph account and stores the created Ceph account in the storage service, thus completing the account creation process. Therefore, it can be seen that in...Figure 2 The account registration process generates not only a user platform account but also a Ceph account, which is used for authentication in the storage service. The storage service can be the Ceph object storage system.

[0060] Furthermore, when performing operations such as creating, deleting, querying, or authorizing resources like buckets, objects, and directories, it is necessary to access the resource access control management device through the user platform account (such as a main account or sub-account). The resource access control management device then calls the front-end access layer and resource orchestration layer to perform the following operations: On one hand, it generates and stores object download links and stores basic information about resources such as buckets and objects, storing the object download links and basic information about resources such as buckets and objects in a database (e.g., a MySQL database). On the other hand, it calls the first access tool to perform management operations on buckets, objects, and directories, thereby carrying account information to call the interface and storing the management results in the storage service.

[0061] Furthermore, users can also use their platform accounts (including main accounts, sub-accounts, anonymous users, etc.) to call the API interface via download links to access the business service interface layer. The download links carry encrypted Ceph account information. Correspondingly, the business service interface layer calls a second access tool to access the service and obtain the download object. To simplify the business process and improve security, the business service interface layer can also obtain the upload object via cookies, thereby enabling upload or download functionality.

[0062] This shows that, Figure 2 In the illustrated method, each main account and sub-account in the user platform account corresponds to a different Ceph account. Furthermore, authentication within the Ceph system requires the Ceph account. Therefore, this method is only applicable to the Ceph system as a single object storage system. When the cloud platform no longer uses Ceph as its object storage system, this authentication method will become ineffective. Moreover, when the cloud platform supports multiple object storage systems simultaneously, other object storage systems cannot use the Ceph account as an authentication condition, resulting in the authentication method being incompatible across different object storage systems.

[0063] To solve the above problems, Figure 3 A schematic diagram of a specific example of the structure of this application is shown.

[0064] In this example, a user of the cloud platform creates an account corresponding to a "storage system". The master account and the sub-account (both are user platform accounts) under the same user share a storage system account (i.e., a user system account), wherein the "storage system" supported by the cloud platform includes various distributed storage systems such as ceph, hdfs, fastHdfs, etc. Different users have their own independent storage system accounts. In this embodiment, the bucket, file, and directory are also regarded as resources, and the resource management system manages the life cycle of the resources.

[0065] In this example, the front-end access layer first performs resource access control authentication through the RAM when creating, updating, or deleting a bucket. After the authentication, the resource orchestration layer is called to integrate the resources. The resource orchestration layer assembles the parameters of the resources and the storage system account, and sends the request parameters to the corresponding "storage system". Because the storage system account has the management authority of the buckets and files in all storage systems, the permission verification result of the storage system account in the storage system is necessarily passed. Therefore, the user can manage the resources (i.e., objects) in each storage system by means of the storage system account. Correspondingly, the resource orchestration layer analyzes and saves the returned data after receiving the result returned by the "storage system".

[0066] In addition, in this example, the application program interface module is further used to implement the uploading and downloading of file objects. Correspondingly, the front-end user calls the application program interface module to upload and download files, and carries the user platform account (the master account or the sub-account of the cloud platform), the resources, and the operation behavior in the calling request. The application program interface module calls the RAM service to verify the permission. When the permission verification is passed, the application program interface module integrates the file and the storage system account information. Because the storage system account has the authority of all objects in the storage system, the permission verification of the storage system account is necessarily passed. The application program interface module analyzes and saves the returned data after receiving the result returned by the storage system.

[0067] In this example, the application program interface module corresponds to the first object management module mentioned above, and the front-end access layer and the resource orchestration layer together correspond to the second object management module mentioned above. In addition, the front-end server mentioned above is omitted in this example. In the case of omitting the front-end server, the user directly calls different modules according to different types of object management requests for processing. Because the file uploading and downloading requests occupy a large bandwidth, the application program interface module is provided separately for the user to call instead of being processed through the gateway of the cloud platform. In summary, this example provides an access control management method independent of the storage system, which can be applied to various object storage systems and provides convenience for cross-system object management operations.

[0068] It can be understood that the above-mentioned various method embodiments mentioned in the disclosure can be combined with each other to form combined embodiments without deviating from the principle logic. Limited by the length of the disclosure, the disclosure will not be described again. Those skilled in the art can understand that in the above-mentioned method of the specific embodiment, the specific execution order of each step should be determined according to its function and possible internal logic.

[0069] In addition, the disclosure also provides an object information management device, an electronic device, and a computer readable storage medium, which can be used to implement any one of the object information management methods provided by the disclosure. The corresponding technical solutions and descriptions are described in the method part and are not described again.

[0070] Figure 4 The object information management device provided by the embodiment of the disclosure has the block diagram shown in the figure.

[0071] Reference Figure 4 The object information management device 40 provided by the embodiment of the disclosure comprises:

[0072] The acquisition module 41 is adapted to acquire a user platform account and object information. The user platform account refers to the identification information of the user in the cloud platform.

[0073] The mapping module 42 is adapted to determine a user system account corresponding to the user platform account according to a preset account mapping relationship in the case that it is determined that the user platform account has the right to manage the object information. The user system account refers to the identification information of the user in a plurality of object storage systems. The user system account has the right to manage the storage objects in the plurality of object storage systems.

[0074] The generation module 43 is adapted to combine the user system account and the object information into an instruction parameter, and generate an object management instruction containing the instruction parameter.

[0075] The sending module 44 is adapted to filter a target storage system corresponding to the object information from a plurality of object storage systems, and send the object management instruction to the target storage system. The target storage system is used to perform the management operation of the object information according to the object management instruction after the user system account is successfully authenticated.

[0076] In an optional implementation, the account mapping relationship is used to store the corresponding relationship between the user platform account and the user system account of the same user.

[0077] The user platform account of the same user includes at least one main platform account and a plurality of sub-platform accounts, and the user system account corresponding to the at least one main platform account and the plurality of sub-platform accounts of the same user is the same.

[0078] In an optional implementation, the plurality of object storage systems include a plurality of distributed storage systems of different storage architectures; the object information includes object attributes; and the object attributes include an object storage format and / or an object storage location.

[0079] The sending module 44 is specifically adapted to:

[0080] According to the object attributes in the object information, a target storage system corresponding to the object attributes is filtered from the plurality of object storage systems.

[0081] In an optional implementation, the object management request is received by a front-end server, and a request type of the object management request is determined; if the request type belongs to a first type, the front-end server forwards the object management request to a first object management module, and the first object management module performs the steps of obtaining the user platform account and the object information contained in the received object management request and subsequent steps; if the request type belongs to a second type, the front-end server forwards the object management request to a second object management module, and the second object management module performs the steps of obtaining the user platform account and the object information contained in the received object management request and subsequent steps; wherein the bandwidth resource required by the object management request of the first type is greater than the bandwidth resource required by the object management request of the second type; wherein the first type includes an upload type and a download type; and the second type includes a query type and a modification type.

[0082] In an optional implementation, the mapping module 42 is specifically adapted to:

[0083] The object information is parsed to obtain an object identifier and a management behavior identifier contained in the object information.

[0084] The user platform account, the object identifier, and the management behavior identifier are sent to an authentication management system.

[0085] It is determined whether the user platform account has the permission to manage the object information according to an authentication result returned by the authentication management system.

[0086] In an optional implementation, the obtaining module 41 is further configured to: in response to the received account registration request, obtain a user identifier included in the account registration request; query whether a primary platform account corresponding to the user identifier has been stored in an account management system; if not, allocate a primary platform account and a user system account for the user identifier, and store a mapping relationship between the user identifier, the primary platform account and the user system account in the account management system; if yes, allocate a sub-platform account for the user identifier, and store a mapping relationship between the user identifier and the sub-platform account in the account management system; wherein the sub-platform account and the primary platform account both belong to the user platform account of the user, and the sub-platform account and the primary platform account correspond to the same user system account.

[0087] In the embodiment, first, a user platform account and object information are obtained, and an authentication operation is performed according to the user platform account and the object information, and if it is determined according to an authentication result that the user platform account has a permission matching the object information, a user system account corresponding to the user platform account is determined according to a preset account mapping relationship; then, an object management instruction is generated according to the user system account and the object information, and a target storage system corresponding to the object information is selected from a plurality of object storage systems, and the object management instruction is sent to the target storage system. Since the user system account in the embodiment has a management permission of the plurality of object storage systems, the user in the cloud platform can perform an object management operation across the storage systems by converting the user platform account into the user system account, thereby providing convenience for management of the plurality of object storage systems.

[0088] Figure 5 A block diagram of an electronic device is provided in the embodiments of the present disclosure.

[0089] Reference Figure 5 The embodiments of the present disclosure provide an electronic device, which comprises: at least one processor 501; at least one memory 502, and one or more I / O interfaces 503 connected between the processor 501 and the memory 502; wherein the memory 502 stores one or more computer programs executable by the at least one processor 501, and the one or more computer programs are executed by the at least one processor 501 to implement the above-mentioned object information management method.

[0090] The embodiments of the present disclosure also provide a computer readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor / processing core, implements the above-mentioned object information management method. The computer readable storage medium can be a volatile or non-volatile computer readable storage medium.

[0091] The embodiments of the present disclosure further provide a computer program product, comprising computer readable code, or a nonvolatile computer readable storage medium carrying the computer readable code, when the computer readable code is run in a processor of an electronic device, the processor in the electronic device performs the above-mentioned object information management method.

[0092] Those of ordinary skill in the art understand that all or some of the steps in the above-disclosed methods, the functions of the modules / units in the systems and devices can be implemented as software, firmware, hardware and appropriate combinations thereof. In hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be performed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer readable storage medium, which can include computer storage media (or non-transitory media) and communication media (or transitory media).

[0093] As known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable program instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM), static random access memory (SRAM), flash memory or other memory technology, portable compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. Furthermore, it is known to those of ordinary skill in the art that communication media typically includes computer readable program instructions, data structures, program modules or other data in modulated data signals such as carrier waves or other transport mechanisms, and can include any information delivery medium.

[0094] The computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.

[0095] Computer readable program instructions for carrying out operations of the present disclosure can be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computing / processing device, partly on the user's computing / processing device, as a stand-alone software package, partly on the user's computing / processing device and partly on a remote computing / processing device or entirely on the remote computing / processing device or server. In the latter scenario, the remote computing / processing device can be connected to the user's computing / processing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing / processing device, for example, through the Internet using an Internet Service Provider. In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.

[0096] The computer program product described herein can be embodied in a specific manner by hardware, software, or a combination thereof. In an optional embodiment, the computer program product is embodied in a specific manner as a computer storage medium, and in another optional embodiment, the computer program product is embodied in a specific manner as a software product, such as a software development kit (SDK), and the like.

[0097] The computer program product described herein can be embodied in a specific manner by hardware, software, or a combination thereof. In an optional embodiment, the computer program product is embodied in a specific manner as a computer storage medium, and in another optional embodiment, the computer program product is embodied in a specific manner as a software product, such as a software development kit (SDK), and the like.

[0098] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can include a non-transitory computer readable storage medium that can be a computer- readable storage medium having no data storage cycles that change state. The instructions can be executed by one or more processors of a computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions which execute via the one or more processors of the computer or other programmable data processing devices create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0099] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0100] The flow and block diagrams in the drawings show architectural, functional, and operational aspects of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow and block diagrams can represent a module, a segment, or a portion of instructions which comprise one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may

[0101] Example embodiments have been disclosed and, although a specific terminology is employed, it is merely for the convenience of the reader and is not intended to be limiting. In some instances, specific details have been included for the purpose of providing a thorough understanding of the embodiments presented, but it will be apparent to those skilled in the art that embodiments of the application can be practiced without these specific details. In some instances, features, characteristics and / or elements described in connection with a particular embodiment can be used in conjunction with, or switched to, features, characteristics and / or elements described in connection with other embodiments, unless otherwise explicitly stated. Accordingly, it will be understood that various changes in form and details can be made without departing from the scope of the disclosure as set forth in the appended claims.

Claims

1. A management method of object information, characterized by, The method comprises the following steps: obtaining a user platform account and object information; the user platform account refers to identification information of a user in a cloud platform, and is used for performing authentication and identity recognition operations in the cloud platform; in a case where it is determined that the user platform account has a permission to manage the object information, determining a user system account corresponding to the user platform account according to a preset account mapping relationship; the user system account refers to identification information of a user in a plurality of object storage systems, and is used for recognizing the identity of the user in the object storage systems; the user system account has a permission to manage storage objects in the plurality of object storage systems; combining the user system account and the object information into instruction parameters, and generating an object management instruction containing the instruction parameters; filtering a target storage system corresponding to the object information from the plurality of object storage systems, and sending the object management instruction to the target storage system; wherein the target storage system is used to perform a management operation on the object information according to the object management instruction after successfully authenticating the user system account.

2. The method of claim 1, wherein, the account mapping relationship is used to store the corresponding relationship between the user platform account and the user system account of the same user; wherein the user platform account of the same user includes at least one main platform account and a plurality of sub-platform accounts; and the user system accounts corresponding to the at least one main platform account and the plurality of sub-platform accounts of the same user are the same.

3. The method of claim 1, wherein, The plurality of object storage systems include a plurality of distributed storage systems with different storage architectures; the object information includes object attributes; the object attributes include object storage formats and / or object storage locations; and the filtering of the target storage system corresponding to the object information from the plurality of object storage systems comprises: filtering the target storage system corresponding to the object attributes from the plurality of object storage systems according to the object attributes in the object information.

4. The method of claim 1, wherein, Before the step of obtaining the user platform account and the object information, the method further comprises the following steps: receiving the object management request through a front-end server, and determining the request type of the object management request; if the request type belongs to a first type, the front-end server forwards the object management request to a first object management module, and the first object management module performs the step of obtaining the user platform account and the object information contained in the received object management request and subsequent steps; if the request type belongs to a second type, the front-end server forwards the object management request to a second object management module, and the second object management module performs the step of obtaining the user platform account and the object information contained in the received object management request and subsequent steps; wherein the bandwidth resource required by the object management request of the first type is greater than the bandwidth resource required by the object management request of the second type; wherein the first type includes an upload type and a download type; and the second type includes a query type and a modification type.

5. The method of claim 1, wherein, the step of determining that the user platform account has a permission to manage the object information comprises: Analyzing the object information to obtain an object identifier and a management behavior identifier contained in the object information; sending the user platform account, the object identifier, and the management behavior identifier to an authentication management system; determining whether the user platform account has the permission to manage the object information according to an authentication result returned by the authentication management system.

6. The method of claim 1, wherein, Before the user platform account and the object information are obtained, the method further includes: obtaining a user identifier contained in the received account registration request; querying whether a main platform account corresponding to the user identifier has been stored in an account management system; if not, assigning a main platform account and a user system account to the user identifier, and storing a mapping relationship between the user identifier, the main platform account, and the user system account in the account management system; if yes, assigning a sub-platform account to the user identifier, and storing a mapping relationship between the user identifier and the sub-platform account in the account management system; wherein the sub-platform account and the main platform account both belong to the user platform account of the user, and the sub-platform account and the main platform account correspond to the same user system account.

7. The method according to any of claims 1 to 6, characterized in that, The object information includes a data bucket, a file object, and a directory object.

8. An object information management apparatus characterized by comprising: The method includes: a obtaining module adapted to obtain a user platform account and object information; the user platform account refers to identification information of a user in a cloud platform, and is used for authentication and identity recognition operations in the cloud platform; a mapping module adapted to determine a user system account corresponding to the user platform account according to a preset account mapping relationship in a case where it is determined that the user platform account has the permission to manage the object information; the user system account refers to identification information of a user in a plurality of object storage systems, and is used for recognizing the identity of the user in the object storage systems; the user system account has the permission to manage storage objects in the plurality of object storage systems; a generating module adapted to combine the user system account and the object information into instruction parameters, and generate an object management instruction containing the instruction parameters; a sending module adapted to filter a target storage system corresponding to the object information from the plurality of object storage systems, and send the object management instruction to the target storage system; wherein the target storage system is used to perform a management operation on the object information according to the object management instruction after the user system account is successfully authenticated.

9. An electronic device, comprising: The method includes: at least one processor; and a memory in communication with the at least one processor; wherein the memory stores one or more computer programs that can be executed by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-7.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the method of any one of claims 1-7. The computer program, when executed by the processor, implements the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Multi-service-domain authority management method, device and platform and readable storage medium

    CN109670768A