Method and apparatus for managing permissions, electronic device, and medium
By creating resource groups in the cloud platform and associating them with the target user's account, and configuring permissions, the problem of insufficient flexibility in resource permission management in existing technologies is solved. This enables more granular resource isolation and custom resource partitioning, improving the adaptability of permission management.
Patent Information
- Application Number
- CN202311182040.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-13
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2043-09-13
AI Technical Summary
Existing cloud platform resource permission management methods are not flexible enough to meet complex and diverse resource management needs.
Create a resource group, associate the target user's account with the resource group, configure user permissions, and allow access to resources based on the user permissions of the resource group, thereby achieving isolation at the resource group level.
It improves the flexibility of resource permission management, with finer isolation granularity, and allows for customizable resource division within resource groups, thus enhancing the adaptability of permission management.
Smart Images

Figure CN119628847B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud platform management, and particularly relates to a permission management method and device, electronic equipment and a medium. BACKGROUND
[0002] Under the trend of digital transformation, cloud computing technology has been widely applied and popularized. A cloud management platform is a product for providing management of private clouds, shared clouds and hybrid clouds, and mainly manages resources in the cloud platform, which can include hosts, hard disks, network resources, etc.
[0003] In the related art, resources are usually divided according to the regions to which they belong, such as resources in region A and region B. The resources under each region are isolated, and the resources under the same region are set with corresponding permissions. Users under each region can access the resources under the region based on the set permissions.
[0004] However, with the development of cloud technology, the resources under the cloud platform have gradually become more complex and diverse. The flexibility of the permission management method for the resources in the related art is poor, and cannot adapt to complex and diverse resource management requirements. Therefore, it is important to improve the flexibility of the permission management of the resources. SUMMARY
[0005] Embodiments of the present application provide a permission management method, device, electronic equipment and medium, which aims to improve the flexibility of the permission management of the resources.
[0006] In a first aspect, the present application provides a permission management method, which includes: creating at least one resource group; determining at least one target user of the resources from users of a cloud management platform for each resource group; associating the resource group with at least one user account of each target user; configuring user permissions of the target user under the resource group; assigning resources created by a user based on a user account to a resource group associated with the user account; and for each user, if at least one user account is associated with a resource group, accessing resources under the resource group based on the user permissions of the resource group.
[0007] In some embodiments, each resource group has a unique first identifier; and the association of the resource group with at least one user account of each target user includes: determining, for each target user, a first user account to be associated in the user account of the target user; establishing a corresponding relationship between the first identifier and the first user account of each target account; and taking the user account having a corresponding relationship with the first identifier of the resource group as the user account associated with the resource group.
[0008] In some embodiments, after the assigning of the resource created by the user based on the user account to the resource group associated with the user account, the method further comprises: disassociating the first resource group from the first user account of the first user.
[0009] removing the resource created by the first user based on the first user account from the first resource group.
[0010] In some embodiments, after the disassociating of the first resource group from the first user account of the first user, the method further comprises: associating a second resource group with the first user account of the first user, and assigning the resource created by the first user based on the first user account to the second resource group.
[0011] In some embodiments, the assigning of the resource created by the user based on the user account to the resource group associated with the user account comprises: detecting whether there is an associated resource group for the user account used by the user to create the resource; if there is, assigning the resource created by the user based on the user account to the resource group associated with the user account; if there is not, assigning the resource created by the user based on the user account to a default resource group.
[0012] In some embodiments, the configuring of the user permissions of the target users under the resource group comprises: setting the same user permissions for the target users under each resource group.
[0013] In some embodiments, the configuring of the user permissions of the target users under the resource group comprises: setting the user permissions corresponding to each target user under each resource group.
[0014] In a second aspect, the present application provides a permission management apparatus, comprising: a resource group management module configured to create at least one resource group; a user management module configured to determine at least one target user under the resource for each resource group from the users of a cloud management platform, associate the resource group with at least one user account of each target user, and configure the user permissions of the target users under the resource group; the resource group management module is further configured to assign the resource created by the user based on the user account to the resource group associated with the user account; and the user management module is further configured to, for each user, if there is at least one user account associated with a resource group, access the resource under the resource group based on the user permissions of the resource group.
[0015] In some embodiments, each resource group has a unique first identifier; the user management module is specifically configured to determine, for each target user, a first user account in the user account of the target user to be associated; the user management module is further configured to establish a correspondence between the first identifier and the first user account of each target account, and take the user account having a correspondence with the first identifier of the resource group as the user account associated with the resource group.
[0016] In some embodiments, the resource group management module is further configured to, after the user account-based resource created by the user is allocated to the resource group associated with the user account, disassociate the first resource group from the first user account of the first user; and remove the resource created by the first user based on the first user account from the first resource group.
[0017] In some embodiments, the resource group management module is further configured to, after the disassociation of the first resource group from the first user account of the first user, further include: associating a second resource group with the first user account of the first user, and allocating the resource created by the first user based on the first user account to the second resource group.
[0018] In some embodiments, the resource group management module is specifically configured to detect whether there is an associated resource group for the user account used by the user to create a resource; if there is, allocate the resource created by the user based on the user account to the resource group associated with the user account; if not, allocate the resource created by the user based on the user account to a default resource group.
[0019] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory connected to the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method as described above.
[0020] In a fourth aspect, the present application provides a computer readable storage medium, the computer readable storage medium stores computer execution instructions, the computer execution instructions are executed by a processor to implement the method as described above.
[0021] The permission management method, device, electronic device and medium provided by the embodiments of the present application create at least one resource group; for each resource group, at least one target user under the resource group is determined, and at least one user account of the target user is associated with the resource group, the user permission of the target user under the resource group is configured, the resource created by the target user based on the user account is allocated to the resource group associated with the user account, and for each user, if at least one user account is associated with the resource group, the user permission of the resource group is used to access the resource under the resource group. In the scheme, the user account creating the resource is associated with the resource group, and based on the association relationship, the resource created by the user account can be allocated to the associated resource group, and the resources under the resource group are isolated in units of resource groups, the isolation granularity is smaller, and the division of resources in each resource group can be customized, so that the flexibility of the permission management of the resources can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0022] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present embodiments and, together with the specification, serve to explain the principles of the present embodiments.
[0023] Through the above drawings, the specific embodiments of the present embodiments have been shown, and more detailed descriptions will be given hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present embodiments in any way, but to illustrate the concept of the present embodiments to those skilled in the art by referring to specific embodiments.
[0024] Figure 1 A flowchart of a permission management method provided by the first embodiment of the present application;
[0025] Figure 2 A flowchart of another permission management method provided by the first embodiment of the present application;
[0026] Figure 3 A structure diagram of another permission management method provided by the present application;
[0027] Figure 4 A structure diagram of a permission management device provided by the first embodiment of the present application;
[0028] Figure 5 A structure diagram of an electronic device provided by the third embodiment of the present application.
[0029] Through the above drawings, the specific embodiments of the present embodiments have been shown, and more detailed descriptions will be given hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present embodiments in any way, but to illustrate the concept of the present embodiments to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0030] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0031] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0032] It should also be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0033] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities and do not necessarily imply a specific order or sequence, unless otherwise indicated. It should be understood that such terms can be used interchangeably where appropriate, for example, to implement the application in a sequence other than those given in the embodiments illustrated or described herein.
[0034] Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to be inclusive but not exclusive. For example, a product or device that includes a series of components is not necessarily limited to those explicitly listed, but may include other components not explicitly listed or inherent to such product or device. As used in this application, the term "circuit" means any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code capable of performing the functions associated with that element.
[0035] With the trend of digital transformation, cloud computing technology has been widely applied and popularized. Cloud management platforms are products that provide management of private clouds, public clouds, and hybrid clouds. They mainly manage resources within the cloud platform, which can include hosts, hard drives, network resources, etc.
[0036] In related technologies, resources are usually divided according to their respective regions, such as resources in region A and region B. Resources within a region are isolated on a regional basis, and corresponding permissions are set for resources within the same region. Users in each region can access resources within that region based on the set permissions.
[0037] However, with the development of cloud technology, resources on cloud platforms have gradually become more complex and diverse. The resource access control methods in related technologies lack flexibility and cannot adapt to the complex and diverse resource management needs. Therefore, improving the flexibility of resource access control is crucial.
[0038] In view of this, in the permission management method provided in this application embodiment, a resource group is created. The resource group can be associated with the user account of the target user. Based on the association, the resources created by the user account can be allocated to the associated resource group, and the resources under the resource group can be isolated on a unit basis. The isolation granularity is smaller, and the division of resources in each resource group can be customized. Therefore, this solution can improve the flexibility of resource permission management.
[0039] It should be noted that the permission management method, apparatus, device and storage medium improved in this application can be used in the field of cloud platform management, or in any field other than cloud platform management. This application does not limit the application field of the permission management method and apparatus.
[0040] The technical solutions of this application will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. In the description of this application, unless otherwise expressly specified and limited, the terms should be broadly understood within the art. The embodiments of this application will now be described with reference to the accompanying drawings.
[0041] Example 1
[0042] Figure 1 This is a flowchart illustrating a permission management method provided in Embodiment 1 of this application. The executing entity of this method can be a permission management system in a cloud management platform, which can be implemented in hardware or in a combination of hardware and software. Figure 1 As shown, the method includes:
[0043] S101. Create at least one resource group;
[0044] S102. For each resource group, identify at least one target user under the resource from the users of the cloud management platform; associate the resource group with at least one user account of each target user; and configure the user permissions of the target user under the resource group.
[0045] S103. Assign the resources created by the user based on the user account to the resource group associated with the user account;
[0046] S104. For each user, if the user has at least one user account associated with a resource group, then the user can access the resources under the resource group based on the user permissions of the resource group.
[0047] The resources in this embodiment may include, but are not limited to, hosts, hard drives, servers, etc. In S101, at least one resource group is created. That is, different resource groups can be established based on the attributes or categories of resources in the cloud management platform. For example, each resource group has its own category, name, etc. The number of resource groups can be set based on actual needs. As an example, resource groups may include: hardware resource groups, computing resource groups, etc.
[0048] In S102, in practical applications, the cloud management platform includes multiple users, who may be from different companies or different departments within those companies. Each user can have multiple accounts, and users can create different resources based on different accounts. For example, Company A may have a first account and a second account, where the first account is used to create hardware resources and the second account is used to create computing resources. For each resource group, target users are determined from the users under the cloud management platform, and the number of target users can be one or more. The resource group is associated with one account of the target user; that is, based on this association, all target users under the resource group can be obtained. It should be noted that the same account of a target user can be associated with multiple accounts. For example, user A's first account can be associated with the first resource group or the second resource group. This embodiment does not impose any restrictions on this.
[0049] There can be multiple methods for establishing a connection. As one implementation method, S102 includes:
[0050] For each target user, determine the first user account to be associated among the user accounts of the target user;
[0051] Establish a correspondence between the first identifier and the first user account of each target account, and use the user account that corresponds to the first identifier of the resource group as the user account associated with the resource group.
[0052] For example, the target users include 10 user accounts, with accounts 1 through 5 designated as the first user accounts to be associated. The first identifier can be a unique resource group ID. By setting the resource group ID in the account information of accounts 1 through 5, the target user can determine the resource group associated with that account based on the resource group ID in the account information.
[0053] Configure permissions for target users. This means that only target users within a resource group have access to the resources in that resource group. User permissions can include adding, deleting, modifying, and querying resources. It's worth noting that in some examples, the same user permissions are set for all target users within each resource group. This example sets the same user permissions for all target users within a resource group, treating all target users in the same resource group the same, which facilitates target user management. In other examples, user permissions are set for each target user within each resource group. In this example, different users within the same resource group can be assigned the same permissions or different permissions. For example, target user A in resource group 1 has access to resources within resource group 1, while target user B in resource group 1 has the permission to delete and modify resources within resource group 1. This further improves the flexibility of permission management.
[0054] After configuring permissions for the target user, step S103 can be executed to assign resources created by the user based on their user account to the resource groups associated with that user account. Resources created based on a user account can be created before the resource group is created, or created after the resource group is created based on actual needs. In the example where resources are created before the resource group is created, the resource information for each resource includes the user account that created the resource group. After the resource group is created, resources are assigned to the resource groups associated with that user account based on the created user account and according to the association relationships. After the resource group is created, resources are created according to needs, and then the created resources are assigned to the corresponding resource groups. It should be noted that a user can include multiple user accounts, and each account can be associated with resource groups. For each user, all resource groups associated with that user's accounts can be displayed in a list, and the user can select the corresponding resource group from the list to access the resources under that resource group.
[0055] It should also be noted that in practical applications, not all users are associated with resource groups; therefore, in some examples, Figure 2 This is a flowchart illustrating another permission management method provided in an embodiment of this application, such as... Figure 2 As shown, S103 may include:
[0056] S1031. Detect whether the user account used by the user to create the resource is associated with a resource group;
[0057] S1032. If it exists, the resources created by the user based on the user account are allocated to the resource group associated with the user account.
[0058] S1033. If it does not exist, the resources created by the user based on the user account will be assigned to the default resource group.
[0059] In this example, for scenarios where the user account that creates the resource is associated with a resource group, the resource is directly assigned to the resource group associated with the user account. For scenarios where the user account that creates the resource is not associated with a resource group, the resource can be directly assigned to the default resource group. This makes it easier to maintain the various resources under the cloud platform.
[0060] After the resource allocation is completed as described above, step S104 is executed. For each user, if a user has at least one user account associated with a resource group, then the user can access the resources under that resource group based on the user permissions set for that resource group. In other words, as long as a user account is associated with a resource group, the user can access all resources under that resource group according to the permissions set for that resource group.
[0061] For example, user A includes user account 1 and user account 2, where user account 1 is associated with the first resource group and user account 2 is associated with the second resource group. User B includes user account 3, which is associated with both the first and third resource groups. Then, user A can access resources under the first and second resource groups, and user B can access resources under both the first and third resource groups.
[0062] In this solution, the user account of the user who creates the resource is associated with the resource group. Based on the association, the resources created by the user account can be assigned to the associated resource group, and the resources under the resource group can be isolated on a per-resource-group basis. The isolation granularity is smaller, and the division of resources in each resource group can be customized. Therefore, this solution can improve the flexibility of resource permission management.
[0063] Based on the above embodiments, in some embodiments, after S103, the method of this embodiment may further include:
[0064] Remove the association between the first resource group and the first user's first user account;
[0065] Remove the resources created by the first user based on the first user account from the first resource group.
[0066] In this embodiment, by detaching the first user account from the resource group, all resources created by the first user account are removed from the first resource group. It should be noted that if other user accounts are associated with the first resource group, the first user can still access the resources under the first resource group; if no other user accounts are associated with the first resource group, the first user cannot access the resources under the first resource group. This solution further improves the flexibility of access control.
[0067] Based on the above embodiments, in some other embodiments, after deassociating the first resource group with the first user's first user account, the method further includes:
[0068] The second resource group is associated with the first user's first user account, and the resources created by the first user based on the first user account are allocated to the second resource group.
[0069] In this embodiment, as can be seen from the above embodiments, a method for transferring resources between groups is provided. This solution achieves resource group transfer by establishing or disassociating user accounts from resource groups, thereby further improving the flexibility of access control.
[0070] The following will provide an exemplary description of this embodiment in conjunction with a real-world scenario: Figure 3 This is a schematic diagram of another permission management method provided in the embodiments of this application, as shown below. Figure 3 As shown, firstly, resource groups are created, including the group name and resource group ID. For each resource group, at least one target user is identified from the cloud management platform's users, and the resource group is associated with at least one user account of each target user. User permissions for the target users under the resource group are then configured. Next, it is checked whether the user account used to create the resource is associated with a resource group. If it is, the resource created by the user based on that user account is assigned to the resource group associated with that user account. If not, the resource created by the user based on that user account is assigned to the default resource group. In later maintenance, the association between the first resource group and the first user's first user account can be removed, and the resource created by the first user based on that first user account can be removed from the first resource group. Then, the second resource group is associated with the first user's first user account, and the resource created by the first user based on that first user account is assigned to the second resource group, thus transferring the resource and maintaining the resource groups.
[0071] The permission management method provided in this application involves creating at least one resource group; for each resource group, identifying at least one target user within that resource group, associating at least one user account of the target user with the resource group, configuring user permissions for the target user within the resource group, and allocating resources created by the target user based on their user account to the resource group associated with that user account. For each user, if at least one user account is associated with a resource group, then the user can access resources within that resource group based on their user permissions. In this solution, the user account of the user who creates the resource is associated with the resource group. Based on this association, resources created by the user account can be allocated to the associated resource group, and resources within a resource group are isolated on a per-resource-group basis. This provides finer granularity of isolation, and the division of resources within each resource group can be customized, thus improving the flexibility of resource permission management.
[0072] Example 2
[0073] Figure 4 This is a schematic diagram of the permission management device provided in Embodiment 1 of this application, as shown below. Figure 4 As shown, the authorization device includes:
[0074] Resource group management module 41 is used to create at least one resource group;
[0075] User management module 42 is used to determine at least one target user under the resource from the users of the cloud management platform for each resource group; associate the resource group with at least one user account of each target user; and configure the user permissions of the target user under the resource group.
[0076] The resource group management module 43 is also used to allocate the resources created by the user based on the user account to the resource group associated with the user account;
[0077] The user management module 42 is also used to access resources under the resource group based on the user permissions of the resource group if the user has at least one user account associated with the resource group.
[0078] As one way of implementation,
[0079] User management module 42 is specifically used to determine the first user account to be associated among the user accounts of each target user;
[0080] The user management module 42 is further used to establish a correspondence between the first identifier and the first user account of each target account, and to use the user account that corresponds to the first identifier of the resource group as the user account associated with the resource group.
[0081] In some examples, the user management module 42 is specifically used to set the same user permissions for target users under each resource group. This example sets the same user permissions for all target users under a resource group; that is, all target users under the same resource group are treated the same, which facilitates the management of target users.
[0082] In other examples, the user management module is specifically used to set user permissions for each target user under each resource group. This further improves the flexibility of permission management.
[0083] It should also be noted that in practical applications, not all users are associated with resource groups; therefore, in some examples,
[0084] Resource group management module 43 is specifically used to detect whether the user account used by the user to create resources is associated with a resource group;
[0085] The resource group management module 43 is specifically used to allocate the resources created by the user based on the user account to the resource group associated with the user account if they still exist.
[0086] The resource group management module 43 is specifically used to allocate the resources created by the user based on the user account to the default resource group if they do not exist.
[0087] In this example, for scenarios where the user account that creates the resource is associated with a resource group, the resource is directly assigned to the resource group associated with the user account. For scenarios where the user account that creates the resource is not associated with a resource group, the resource can be directly assigned to the default resource group. This makes it easier to maintain the various resources under the cloud platform.
[0088] Based on the above embodiments, in some embodiments, the resource group management module 43 is further configured to allocate the resources created by the user based on the user account to the resource group associated with the user account.
[0089] Remove the association between the first resource group and the first user's first user account;
[0090] Remove the resources created by the first user based on the first user account from the first resource group.
[0091] Based on the above embodiments, in other embodiments, the resource group management module 43 is further configured to, after the first resource group is unlinked from the first user account of the first user,
[0092] The second resource group is associated with the first user's first user account, and the resources created by the first user based on the first user account are allocated to the second resource group.
[0093] In this embodiment, as can be seen from the above embodiments, a method for transferring resources between groups is provided. This solution achieves resource group transfer by establishing or disassociating user accounts from resource groups, thereby further improving the flexibility of access control.
[0094] The permission management device provided in this application creates at least one resource group; for each resource group, it identifies at least one target user under that resource group and associates at least one user account of the target user with the resource group; it configures the user permissions of the target user under the resource group; and it allocates resources created by the target user based on the user account to the resource group associated with that user account. For each user, if at least one user account is associated with a resource group, the user can access the resources under the resource group based on the user permissions of the resource group. In this solution, the user account of the user who creates the resource is associated with the resource group. Based on the association relationship, the resources created by the user account can be allocated to the associated resource group, and the resources under the resource group are isolated on a resource group basis. The isolation granularity is smaller, and the division of resources in each resource group can be customized. Therefore, this solution can improve the flexibility of resource permission management.
[0095] Example 3
[0096] Figure 5 This is a schematic diagram of the structure of the electronic device provided in Embodiment 3 of this application, as shown below. Figure 5 As shown, the electronic device includes:
[0097] The electronic device includes a processor 291 and a memory 292; it may also include a communication interface 293 and a bus 294. The processor 291, memory 292, and communication interface 293 can communicate with each other via the bus 294. The communication interface 293 can be used for information transmission. The processor 291 can invoke logical instructions stored in the memory 292 to execute the methods of the above embodiments.
[0098] Furthermore, the logic instructions in the aforementioned memory 292 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium.
[0099] The memory 292, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of this application. The processor 291 executes functional applications and data processing by running the software programs, instructions, and modules stored in the memory 292, thereby implementing the methods in the above-described method embodiments.
[0100] The memory 292 may include a program storage area and a data storage area. The program storage area may store the operating system and application programs required for at least one function; the data storage area may store data created based on the use of the terminal device. Furthermore, the memory 292 may include high-speed random access memory and may also include non-volatile memory.
[0101] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods described in any of the embodiments.
[0102] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the claims.
[0103] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for managing access permissions, characterized in that, The method includes: Create at least one resource group; For each resource group, identify at least one target user under the resource from the users of the cloud management platform; associate the resource group with at least one user account of each target user; and configure the user permissions for the target user under the resource group. The resources created by the user based on the user account are assigned to the resource group associated with the user account; For each user, if the user has at least one user account associated with a resource group, then the user can access the resources under the resource group based on the user permissions of the resource group.
2. The method according to claim 1, characterized in that, Each resource group has a unique primary identifier; Associating the resource group with at least one user account for each target user includes: For each target user, determine the first user account to be associated among the user accounts of the target user; Establish a correspondence between the first identifier and the first user account of each target account, and use the user account that corresponds to the first identifier of the resource group as the user account associated with the resource group.
3. The method according to claim 1, characterized in that, The step of allocating the resources created by the user based on the user account to the resource group associated with the user account includes: Remove the association between the first resource group and the first user's first user account; Remove the resources created by the first user based on the first user account from the first resource group.
4. The method according to claim 3, characterized in that, After unlinking the first resource group from the first user's first user account, the process also includes: The second resource group is associated with the first user's first user account, and the resources created by the first user based on the first user account are allocated to the second resource group.
5. The method according to any one of claims 1-4, characterized in that, The step of allocating the resources created by the user based on the user account to the resource group associated with the user account includes: Check whether the user account used by the user to create the resource is associated with a resource group; If it exists, the resources created by the user based on the user account will be allocated to the resource group associated with the user account; If it does not exist, the resources created by the user based on the user account will be assigned to the default resource group.
6. The method according to any one of claims 1-4, characterized in that, The configuration of user permissions for the target user under the resource group includes: For each resource group, set the same user permissions for the target users under that resource group.
7. The method according to any one of claims 1-4, characterized in that, The configuration of user permissions for the target user under the resource group includes: For each target user under each resource group, set the corresponding user permissions for that target user.
8. An access control device, characterized in that, include: The resource group management module is used to create at least one resource group. The user management module is used to identify at least one target user for each resource group from the users of the cloud management platform under the resource. Associate the resource group with at least one user account for each target user; Configure the user permissions for the target user under the resource group; The resource group management module is also used to allocate the resources created by the user based on the user account to the resource group associated with the user account; The user management module is also used to access resources under the resource group based on the user permissions of the resource group if the user has at least one user account associated with the resource group.
9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Resource access method and device and electronic equipment
CN112637214A
Resource authorization method and device, electronic equipment and storage medium
CN113282890A