Permission Determination Method, Device, Medium, and Program Product

By determining the permissions of the target hub node based on the decryption results of the target address and alternative activation code, the problems of software privatization deployment and permission authentication in offline scenarios in the prior art are solved, and low-cost and efficient permission management is achieved.

CN119783063BActive Publication Date: 2025-06-10INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510294649.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-10
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

When the software serial number is used for permission authentication, the prior art lacks technical support for software privatized deployment and offline scenarios, resulting in high costs and inability to effectively manage permissions.

Method used

By responding to the user's target function call request, the target hub node is determined based on the target address, and based on the decryption results of multiple alternative activation codes, the number of nodes and the availability of activation codes are determined to determine whether the target hub node has permission to call the target function.

Benefits of technology

It realizes permission authentication in software privatized deployment and offline scenarios, reduces costs, and improves the efficiency and flexibility of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119783063B_ABST
    Figure CN119783063B_ABST
Patent Text Reader

Abstract

The present invention provides a method, device, medium, and program product for determining permissions, which can be applied to the technical fields of information security and permission management. The method includes: in response to a call request from a user for a target function, determining a target central node for providing the target function based on the target address in the call request; based on the decryption results of multiple alternative activation codes for the target function, determining the number of nodes currently calling the target function in the multi-cluster platform when it is determined that the set of available hardware addresses of the multiple alternative activation codes includes the hardware address of the target central node; and when the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, determining that the target central node has the permission to call the target function, so that the user can call the target function through the target central node, thereby realizing the efficient management of the permissions of multiple sub-clusters, reducing the isolation between multiple sub-clusters, and improving the utilization rate of alternative activation codes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of information security and permission management, and particularly to a permission determination method, device, medium, and program product. Background Art

[0002] With the rapid development of information technology, the authorization management of various software and devices has become increasingly important. To prevent the illegal use and copying of software and devices, various authorization management technologies have emerged. Among them, managing permissions through authorization codes is a common method. In related technologies, software serial numbers are usually used as authorization codes, and the server for permission management needs to perform real-time verification with the software through remote connections regularly to ensure that the software is controlled, thereby ensuring the accuracy of permission authentication.

[0003] However, the method of using software serial numbers for permission authentication requires ensuring that both communication parties are online in real time. Therefore, it lacks technical support for permission authentication in the scenarios of software private deployment and offline, and the cost is relatively high. Summary of the Invention

[0004] In view of the above problems, the present invention provides a permission determination method, device, medium, and program product.

[0005] According to a first aspect of the present invention, a permission determination method is provided, including: in response to a call request from a user for a target function, determining a target central node for providing the target function based on the target address in the call request; based on the decryption results of multiple alternative activation codes for the target function, determining the number of nodes currently calling the target function in the multi-cluster platform when it is determined that the available hardware address set of the multiple alternative activation codes includes the hardware address of the target central node; and determining that the target central node has the permission to call the target function when the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, so that the user can call the target function through the target central node.

[0006] According to an embodiment of the present invention, the permission determination method further includes: determining a sub-cluster corresponding to the call request in multiple sub-clusters of the multi-cluster platform based on the target central node; determining the call permission of the main cluster for the sub-cluster based on the callable cluster set of the main cluster of the multi-cluster platform; and when the call permission indicates that the main cluster can call the sub-cluster, performing permission determination on the sub-cluster using multiple alternative activation codes configured by the main cluster.

[0007] According to an embodiment of the present invention, determining a target central node for providing the target function based on the target address in the call request includes: parsing the target address to determine the hardware address corresponding to the target address; and determining the target central node from multiple central nodes of the multi-cluster platform based on the hardware address.

[0008] According to an embodiment of the present invention, the target address includes a virtual address; resolving the target address to determine the hardware address corresponding to the target address includes: determining the hardware address corresponding to the target address based on the mapping relationship between the target address and the hardware address, wherein, when the hardware address corresponding to the target address changes, the mapping relationship is updated.

[0009] According to an embodiment of the present invention, based on the decryption results of multiple alternative activation codes for a target function, when it is determined that the set of available hardware addresses of the multiple alternative activation codes includes the hardware address of the target central node, determining the number of nodes in the multi-cluster platform that currently invoke the target function includes: determining multiple alternative activation codes used to invoke the target function in the multi-cluster platform; determining the total available parallelism of the multi-cluster platform for invoking the target function based on the respective first available parallelisms of the multiple alternative activation codes, wherein the first available parallelism represents the maximum number of nodes in the multi-cluster platform that are allowed to simultaneously use the alternative activation code to invoke the target function, and the total available parallelism represents the maximum number of nodes in the multi-cluster platform that are allowed to use the multiple alternative activation codes to invoke the target function, and the total available parallelism is obtained by summing the respective first available parallelisms of the multiple alternative activation codes; and traversing the nodes in the multi-cluster platform to determine the number of nodes that invoke the target function from the multiple nodes in the multi-cluster platform.

[0010] According to an embodiment of the present invention, the permission determination method further includes: using the main cluster to decrypt the multiple alternative activation codes to obtain the set of available hardware addresses, the available expiration period, and the first available parallelism of each of the multiple alternative activation codes.

[0011] According to an embodiment of the present invention, when the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, determining that the target central node has the permission to invoke the target function so that the user can invoke the target function through the target central node includes: deleting the alternative activation codes that have reached the available expiration period from the multiple alternative activation codes based on the respective available expiration periods of the multiple alternative activation codes to obtain multiple available alternative activation codes; when it is determined that the multiple available alternative activation codes and the number of nodes satisfy the first preset relationship, determining a target activation code from the multiple available alternative activation codes, wherein the set of available hardware addresses of the target activation code includes the hardware address, and the first preset relationship means that the total available parallelism determined according to the multiple available alternative activation codes is greater than the sum of the number of nodes and the number of target central nodes; and determining that the target central node has the permission to invoke the target function.

[0012] According to an embodiment of the present invention, the permission determination method further includes: based on the current system time, when it is determined that there are expired activation codes among the multiple alternative activation codes that have reached the available expiration date, determining the second available parallelism of the multi-cluster platform based on the total available parallelism and the first available parallelism of the expired activation codes, where the second available parallelism represents the maximum number of nodes in the multi-cluster platform that are allowed to call the target function using the remaining alternative activation codes except the expired activation codes; when it is determined that the second available parallelism and the number of nodes do not satisfy the first preset relationship, determining that the permissions of the multiple nodes that call the target function in the multi-cluster platform are invalidated; and determining the permissions of the multiple nodes with invalidated permissions based on the second available parallelism.

[0013] According to an embodiment of the present invention, the permission determination method further includes: in response to the target cluster in the multi-cluster platform closing the multi-cluster state, determining the alternative activation codes of the target cluster; based on the alternative activation codes of the target cluster, determining the set of available hardware addresses, the available expiration date, and the first available parallelism of the alternative activation codes; when it is determined that the set of available hardware addresses includes the hardware address of the target central node, determining the number of nodes that call the target function in the target cluster; and when the first available parallelism and the number of nodes satisfy the second preset relationship, determining that the target central node has the permission to call the target function, so that the user can call the target function through the target central node, where the second preset relationship means that the first available parallelism of the alternative activation codes of the target cluster is greater than the sum of the number of nodes that call the target function in the target cluster and the number of target central nodes.

[0014] According to an embodiment of the present invention, when there is a newly created activation code in the multi-cluster platform, encrypting the available expiration date, the first available parallelism, and the set of available hardware addresses of the newly created activation code to obtain a ciphertext activation code; based on the function corresponding to the newly created activation code and the first available parallelism and the set of available hardware addresses of the newly created activation code, updating the total available parallelism and the set of available hardware addresses of the function corresponding to the newly created activation code in the multi-cluster platform to obtain the updated total available parallelism and the total set of available hardware addresses; adding the ciphertext activation code to the multiple alternative activation codes to obtain multiple updated alternative activation codes; and using the multiple updated alternative activation codes to update the authentication tokens of the users in the multi-cluster platform.

[0015] According to an embodiment of the present invention, using the multiple updated alternative activation codes to update the authentication tokens of the users in the multi-cluster platform includes: updating the authorization information in the authentication tokens of the multiple users respectively based on the updated multiple alternative activation codes.

[0016] According to an embodiment of the present invention, the permission determination method further includes: configuring multiple sub-clusters with the multi-cluster status enabled in the multi-cluster platform into the cluster set saved in the master cluster; and configuring the address and port of the master cluster into multiple sub-clusters with the multi-cluster status enabled respectively.

[0017] A second aspect of the present invention provides a permission determination device, including: a node determination module, configured to respond to a call request from a user for a target function, and determine a target central node for providing the target function based on the target address in the call request. A quantity determination module, configured to determine the number of nodes currently invoking the target function in the multi-cluster platform when it is determined that the available hardware address set of multiple alternative activation codes for the target function includes the hardware address of the target central node based on the decryption results of the multiple alternative activation codes for the target function. A permission determination module, configured to determine that the target central node has the permission to invoke the target function when the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, so that the user can invoke the target function through the target central node.

[0018] A third aspect of the present invention provides an electronic device, including: one or more processors; a memory, configured to store one or more computer programs, wherein the above one or more processors execute the above one or more computer programs to implement the steps of the above method.

[0019] A fourth aspect of the present invention further provides a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.

[0020] A fifth aspect of the present invention further provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the above method are implemented.

[0021] According to an embodiment of the present invention, by sharing the respective alternative activation codes of multiple sub-clusters in the multi-cluster platform, the efficient management of the permissions of multiple sub-clusters is realized, and the isolation between multiple sub-clusters can also be reduced. The number of times the alternative activation code of a single sub-cluster allows the invocation of the target function is split and provided to other sub-clusters, improving the utilization rate of the alternative activation code. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Through the following description of the embodiments of the present invention with reference to the drawings, the above content and other objects, features and advantages of the present invention will become clearer. In the drawings:

[0023] Figure 1 The application scenario diagram of the permission determination method, device, medium and program product according to the embodiment of the present invention is shown.

[0024] Figure 2 The flowchart of the permission determination method according to an embodiment of the present invention is shown.

[0025] Figure 3 The correspondence between the target address and the central node according to an embodiment of the present invention is shown.

[0026] Figure 4 The communication flowchart of the permission determination according to an embodiment of the present invention is shown.

[0027] Figure 5 The structural block diagram of the permission determination device according to an embodiment of the present invention is shown.

[0028] Figure 6 The block diagram of the electronic device suitable for implementing the permission determination method according to an embodiment of the present invention is shown. Detailed implementation manners

[0029] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present invention. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present invention.

[0030] The terms used herein are merely for describing specific embodiments and are not intended to limit the present invention. The terms "including", "comprising" and the like used herein indicate the presence of the described features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.

[0031] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0032] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C).

[0033] In the technical solution of the present invention, the user information involved (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, invention, and application, all complies with relevant laws, regulations, and standards, adopts necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or reject.

[0034] In the related art, usually the computer cluster is taken as the smallest granularity of authorization, that is, the maximum number of authorizations restricted by one authorization code can only be used in one computer cluster. When the number of computer nodes using this permission in the current computer cluster does not reach the maximum number of authorizations, the remaining authorization quantity cannot be used by other computer clusters either, resulting in a waste of authorization resources.

[0035] An embodiment of the present invention provides a permission determination method, including: in response to a call request from a user for a target function, determining a target central node for providing the target function based on the target address in the call request; based on the decryption results of multiple alternative activation codes for the target function, determining the number of nodes currently calling the target function in the multi-cluster platform when it is determined that the available hardware address set of the multiple alternative activation codes includes the hardware address of the target central node; and when the multiple alternative activation codes and the number of nodes meet a first preset relationship, determining that the target central node has the permission to call the target function, so that the user can call the target function through the target central node.

[0036] Figure 1 FIG. shows an application scenario diagram of a permission determination method, device, medium, and program product according to an embodiment of the present invention.

[0037] As Figure 1 shown, the application scenario 100 according to this embodiment may include a multi-cluster platform 110, a cloud platform 120, and a network 130. The multi-cluster platform includes a main cluster 111, a first sub-cluster 112, a second sub-cluster 113, and a third sub-cluster 114.

[0038] The main cluster 111 is used to count the respective alternative activation codes of the first sub-cluster 112, the second sub-cluster 113, and the third sub-cluster 114, and configure them in the main cluster 111.

[0039] The first sub-cluster 112, the second sub-cluster 113, and the third sub-cluster 114 each include one or more central nodes and multiple ordinary nodes. Among them, the central nodes are used to call and manage the multiple ordinary nodes in their respective sub-clusters. Taking the second sub-cluster 113 as an example, it includes the first central node 1131, the second central node 1132, the first ordinary node 1133, the second ordinary node 1134, and the third ordinary node 1135.

[0040] The cloud platform 120 is used to respond to a function call request from a user, communicate with the multi-cluster platform 110 through the network 130, so as to determine whether to provide a function to the user based on the activation code configured in the main cluster 111 and the current state of the multi-cluster platform 110, and control the main cluster 111 to allocate the usage permission of the function to the corresponding sub-cluster. Among them, the permission determination process includes determining the function call permission according to the activation code and directly determining the saved permission through the user identity token.

[0041] After the sub-cluster obtains the usage permission, it provides services to the user through the central node corresponding to the function request and displays the service page on the cloud platform.

[0042] It should be understood that Figure 1 the numbers of the multi-cluster platform, cloud platform, network, main cluster, and sub-cluster in

[0043] are merely illustrative. According to the implementation requirements, there can be any number of multi-cluster platforms, cloud platforms, networks, main clusters, and sub-clusters. Figure 1 Based on the scenario described below Figures 2 to 4 the permission determination method of the invention embodiment will be described in detail through

[0044] Figure 2 shows a flowchart of the permission determination method according to an embodiment of the present invention.

[0045] As Figure 2 shown, the permission determination method of this embodiment includes operation S210 to operation S230. This permission determination method can be used to manage the multi-cluster platform and can be applied to the cloud platform for managing the multi-cluster platform.

[0046] In operation S210, in response to a function call request from a user for a target function, based on the target address in the call request, determine the target central node for providing the target function.

[0047] The multi-cluster platform includes multiple sub-clusters, and each sub-cluster includes multiple nodes. One of the multiple sub-clusters is set as the main cluster, and the main cluster can be used to manage other clusters in the multi-cluster platform.

[0048] The multi-cluster platform can provide an interface to the outside through a central node among the multiple nodes included in the multi-cluster platform, so that the user can determine the call request according to the target function to be used through the interface, and call the target function through the interface request. Among them, the multiple nodes included in each sub-cluster include one or more central nodes.

[0049] According to an embodiment of the present invention, the target address can be a virtual address, that is, each subcluster can provide a fixed virtual address to the user, such as an Internet Protocol address (IP address), and the virtual address can be used by one or more hub nodes in the subcluster. In the case where a subcluster includes multiple hub nodes, the user can access the first hub node through the virtual address. In the case where the first hub node is offline or under high load, the virtual address can be mounted to the second hub node. At this time, the user can access the second hub node through the virtual address to improve the high availability of the subcluster.

[0050] According to another embodiment of the present invention, the target address may also be a hardware address, that is, the user may also access the central node of the sub-cluster through the hardware address of the central node.

[0051] After receiving the user's call request for the target function, the artificial intelligence cloud platform for managing the multi-cluster platform can be used to parse the call request and determine the target address corresponding to the call request. If the target address is a virtual address, the target hub node is determined based on the correspondence between the virtual address and the hub node. If the target address is a hardware address, the target hub node is determined based on the hardware address. The call request includes the target address, which is used to represent the address of the provider that provides the target function to the user.

[0052] In operation S220, based on the decryption results of the plurality of candidate activation codes for the target function, when it is determined that the available hardware address sets of the plurality of candidate activation codes include the hardware address of the target hub node, the number of nodes currently calling the target function in the multi-cluster platform is determined.

[0053] The multi-cluster platform can provide multiple functions. In order to manage the permissions of the multiple functions separately, multiple categories of activation codes corresponding to the multiple functions can be set. Each category of activation code includes multiple activation codes, and the multiple activation codes can be configured on different sub-clusters.

[0054] The main cluster of the multi-cluster platform can aggregate the activation codes configured on multiple sub-clusters to obtain multiple activation codes. After the user initiates a call request, the main cluster can select multiple activation codes for the target function from the multiple activation codes as candidate activation codes.

[0055] Since activation codes saved in plaintext are prone to data security issues such as message leakage during data transmission or use, the activation codes on the multi-cluster platform are all encrypted using encryption algorithms. Decrypt the alternative activation codes to obtain the decryption results. The decryption result of each alternative activation code may include the set of available hardware addresses of the alternative activation code. The set of available hardware addresses may include multiple hardware addresses. In the case where it is determined that the hardware address set in the decryption result of a certain alternative activation code includes the hardware address of the target central node, it can be determined that the target central node can use the alternative activation code for permission authentication and function invocation.

[0056] According to the decryption results of multiple alternative activation codes, when it is determined that the set of available hardware addresses of the multiple alternative activation codes includes the hardware address of the target central node, it can be determined that the target central node can use one or more of the multiple alternative activation codes for permission authentication and function invocation. Therefore, subsequent judgments can be continued to determine the number of nodes currently invoking the target function in the multi-cluster platform based on the multiple alternative activation codes.

[0057] In operation S230, when the multiple alternative activation codes and the number of nodes satisfy the first preset relationship, it is determined that the target central node has the permission to invoke the target function, so that the user can invoke the target function through the target central node.

[0058] The decryption result of each alternative activation code may also include the number of nodes in the multi-cluster platform that are allowed to use the alternative activation code for permission authentication and invoke the target function simultaneously. Therefore, based on the multiple alternative activation codes, the number of nodes in the multi-cluster platform that are allowed to invoke the target function simultaneously can be determined.

[0059] Based on the number of nodes currently invoking the target function in the multi-cluster platform determined in operation S220 and the number of nodes in the multi-cluster platform that are allowed to invoke the target function simultaneously, when it is determined that the current target central node invokes the target function, the number of nodes that are currently invoking the target function in the multi-cluster platform is determined. And when this number does not exceed the number of nodes in the multi-cluster platform that are allowed to invoke the target function simultaneously, it can be determined that the target central node has the permission to invoke the target function, so that the user can invoke the target function through the target central node.

[0060] According to the embodiments of the present invention, by sharing the respective alternative activation codes of each sub-cluster among multiple sub-clusters in the multi-cluster platform, efficient management of the permissions of multiple sub-clusters is achieved, and the isolation between multiple sub-clusters can also be reduced. The number of times the alternative activation code of a single sub-cluster is allowed to invoke the target function is split and provided to other sub-clusters, improving the utilization rate of the alternative activation code.

[0061] The multi-cluster platform manages and invokes multiple sub-clusters through the master cluster. The master cluster can store the sub-clusters it can manage in the callable cluster set, so as to quickly determine the call and management scope of the master cluster based on the callable cluster set. Among them, the content stored in the callable cluster set can be the cluster marks that can uniquely identify the sub-cluster, such as the number of the sub-cluster, the Universally Unique Identifier (UUID) of the sub-cluster, the domain name of the sub-cluster, the IP address, etc.

[0062] When determining permissions, if the master cluster does not have the management and call permissions for a certain sub-cluster, the master cluster cannot share information such as the alternative activation code with the sub-cluster, and the sub-cluster cannot use the above alternative activation code to determine permissions. Therefore, the permission determination method further includes: determining the sub-cluster corresponding to the call request among the multiple sub-clusters of the multi-cluster platform based on the target central node; determining the call permission of the master cluster for the sub-cluster based on the callable cluster set for the master cluster; and when the call permission indicates that the master cluster can call the sub-cluster, using multiple alternative activation codes configured by the master cluster to determine the permissions of the sub-cluster.

[0063] Based on the hardware address of the target central node, the sub-cluster corresponding to the call request can be determined from the multiple sub-clusters of the multi-cluster platform by matching, that is, the sub-cluster to which the target central node belongs. Traverse the callable cluster set of the master cluster to determine whether there is a cluster mark of the sub-cluster corresponding to the call request, so as to determine the call permission of the master cluster for the sub-cluster.

[0064] If there is a cluster mark of the sub-cluster corresponding to the call request in the callable cluster set, it can be determined that the call permission indicates that the master cluster can call the sub-cluster, and use multiple alternative activation codes configured by the master cluster to determine the permissions of the sub-cluster.

[0065] If there is no cluster mark of the sub-cluster corresponding to the call request in the callable cluster set, it can be determined that the call permission indicates that the master cluster cannot call the sub-cluster. Therefore, the multiple alternative activation codes configured by the master cluster cannot be used to determine the permissions of the sub-cluster.

[0066] When the target address is a virtual address, since the virtual address can be switched among multiple central nodes, the corresponding relationship between the virtual address and the central node is not fixed.

[0067] According to an embodiment of the present invention, the target address can be resolved through the Address Resolution Protocol (ARP protocol) to determine the hardware address currently corresponding to the virtual address, and based on the hardware address, a match is made among the respective hardware addresses of multiple central nodes in the multi-cluster platform, so as to determine the target central node from the multiple central nodes of the multi-cluster platform.

[0068] According to another embodiment of the present invention, a mapping relationship between the target address and the hardware address can be created, and when it is determined that the hardware address corresponding to the target address has changed, the mapping relationship is updated. So that when it is necessary to resolve the target address to determine the hardware address corresponding to the target address, the hardware address corresponding to the target address can be directly determined based on the mapping relationship between the target address and the hardware address.

[0069] Figure 3 Shows the correspondence between the target address and the central node according to an embodiment of the present invention.

[0070] As Figure 3 shown, the sub-cluster includes hardware address 1, hardware address 2, hardware address 3, and hardware address 4, as well as central node 1, central node 2, central node 3, and central node 4. When the target address is a virtual address, the target address corresponds to hardware address 1. Therefore, after resolving the target address, it can be determined that the hardware address corresponding to the target address is hardware address 1. According to the correspondence between the hardware address and the central node, central node 1 can be determined as the target central node.

[0071] In the case where central node 1 fails or central node 1 is overloaded, it is difficult for central node 1 to continue to provide services externally. Therefore, the mapping relationship between the target address and the hardware address can be modified to make the target address correspond to hardware address 4. When a new call request is received again, by resolving the target address, it can be determined that the hardware address corresponding to the target address is hardware address 4. According to the correspondence between the hardware address and the central node, central node 4 can be determined as the target central node. Thus, it is realized to locate the appropriate central node at different times using the same target address.

[0072] According to an embodiment of the present invention, by parsing the target address, the hardware address corresponding to the target address and the target central node can be determined, so as to determine whether the available hardware address set of multiple alternative activation codes includes the hardware address of the target central node based on the hardware address. The virtual address is set as the target address. In the case where the central node is damaged or busy, the target address can be redirected to the remaining central nodes that can provide services, so that the user only needs to send a request to the target address and does not need to pay attention to the hardware status to request services from the multi-cluster platform, simplifying the user's operation, improving the user experience, and improving the high availability of the multi-cluster platform.

[0073] According to an embodiment of the present invention, based on the decryption results of multiple alternative activation codes corresponding to the target function, in the case where it is determined that the available hardware address set of multiple alternative activation codes includes the hardware address of the target central node, determining the number of nodes in the multi-cluster platform that call the target function includes: determining multiple alternative activation codes used to call the target function in the multi-cluster platform; determining the total available parallelism of the multi-cluster platform to call the target function based on the first available parallelism of each of the multiple alternative activation codes; traversing the nodes in the multi-cluster platform, and determining the number of nodes that call the target function from the multiple nodes in the multi-cluster platform.

[0074] Determine multiple alternative activation codes used to call the target function in the multi-cluster platform configured by the master node, and determine the first available parallelism of each of the multiple alternative activation codes. The first available parallelism of the alternative activation code represents the maximum number of nodes in the multi-cluster platform that are allowed to simultaneously use the alternative activation code to call the target function. The plaintext data can be obtained by decrypting the alternative activation code, and the first available parallelism of the alternative activation code can be determined from the plaintext data.

[0075] By summing the first available parallelism of each of the multiple alternative activation codes, the total available parallelism of the multi-cluster platform to call the target function can be determined.

[0076] Traverse multiple nodes in the multi-cluster platform, determine whether the multiple nodes are currently calling the target function, and count the number of nodes currently calling the target function.

[0077] After determining the total available parallelism of the multi-cluster platform to call the target function and the number of nodes in the multi-cluster platform that are currently calling the target function, the relationship between the total available parallelism and the number of nodes can be further determined. In the case where the total available parallelism is greater than the sum of the number of nodes and the number of target central nodes, it can be determined that the total available parallelism or the alternative activation code and the number of nodes satisfy the first preset relationship, and it can be determined that the target central node has the permission to call the target function, so that the user can call the target function through the target central node.

[0078] Due to the attribute of the available expiration date of the alternative activation codes, it is possible to determine whether multiple alternative activation codes have expired based on the available expiration date and the current system time, and to determine the current total available parallelism of the multi-cluster platform in real time.

[0079] Decrypting the alternative activation codes can obtain the available expiration dates of the alternative activation codes. Among them, the alternative activation codes are unavailable after reaching the expiration date. Based on the respective available expiration dates of multiple alternative activation codes, the alternative activation codes that have reached the available expiration date are deleted from the multiple alternative activation codes to obtain multiple available alternative activation codes. According to the multiple available alternative activation codes, the total available parallelism for the current multi-cluster platform to call the target function can be determined, and it can be judged whether the total available parallelism and the number of nodes satisfy the first preset relationship.

[0080] When it is determined that the multiple available alternative activation codes and the number of nodes satisfy the first preset relationship, from the multiple available alternative activation codes, the available alternative activation codes whose available hardware address set includes the hardware address of the target central node are determined as the target activation codes. Among them, decrypting the alternative activation codes can obtain the available hardware address set of the alternative activation codes, and the available hardware address set includes multiple hardware addresses that can use this alternative activation code to determine permissions. It is determined that the target central node has the permission to call the target function.

[0081] According to an embodiment of the present invention, the total available parallelism at this moment is determined according to the respective first available parallelisms of the alternative activation codes that have not reached the expiration date currently. Then, by comparing the total available parallelism with the number of nodes in the current multi-cluster platform that call the target function, when it is determined that the multi-cluster platform responds to the user request and the number of nodes in the multi-cluster platform that call the target function has not reached the total available parallelism, it is determined that the target central node has the permission to call the target function. Thereby, the number of nodes calling the target function is accurately restricted, and the situation of over-authorization is avoided.

[0082] Figure 4 Shows the communication flowchart of permission determination according to an embodiment of the present invention.

[0083] As Figure 4 shown, the user sends a call request to the cloud platform. The cloud platform reads the database of the main cluster and determines that the target central node corresponding to the call request belongs to the first sub-cluster. The cloud platform determines whether the current multi-cluster platform can still provide the target function to the user through the target central node according to the multiple alternative activation codes stored in the main cluster database. Among them, multiple sub-clusters in the multi-cluster platform synchronize their locally configured alternative activation codes to the main cluster database in advance.

[0084] When it is determined through judgment that the current multi-cluster platform can still provide the target function to the user through the target central node, the cloud platform reads the alternative activation codes from the main cluster database and provides the target activation codes to the target sub-cluster, so that the target central node can provide the target function to the user based on the target activation codes.

[0085] When there are nodes in the multi-cluster platform that use alternative activation codes to call the target function, when the alternative activation codes expire, it may occur that the number of nodes currently calling the target function exceeds the sum of the first available parallel numbers of the remaining alternative activation codes, and it is necessary to re-determine the permissions of each node.

[0086] Based on the current system time, when it is determined that there are expired activation codes that have reached the available expiration date among multiple alternative activation codes, the second available parallel number of the multi-cluster platform is determined based on the total available parallel number and the first available parallel number of the expired activation codes. Among them, when the current system time reaches the available expiration date, it can be determined that the alternative activation codes have reached the available expiration date, and the second available parallel number represents the maximum number of nodes in the multi-cluster platform that are allowed to use the remaining alternative activation codes except the expired activation codes to call the target function.

[0087] When it is determined that the second available parallel number and the number of nodes do not satisfy the first preset relationship, it is determined that the permissions of multiple nodes in the multi-cluster platform that call the target function are invalid. That is, when it is determined that the number of nodes is greater than the second available parallel number, it can be determined that the permissions of multiple nodes are invalid.

[0088] After determining that the permissions of multiple nodes are invalid, since the tasks being executed by multiple nodes may not have ended yet, it is necessary to re-authorize the nodes to continue executing the tasks. Since the nodes cannot call the target function after the permissions are invalid, they cannot continue to execute the tasks currently being executed. The task progress can be temporarily saved so that there is no need to re-execute the tasks after re-authorization.

[0089] Based on the second available parallel number, the permissions of multiple nodes with invalid permissions can be determined. At this time, since the number of nodes is greater than the second available parallel number, there will be nodes that cannot be authorized temporarily. According to the priorities of the tasks being executed by multiple nodes, the nodes with higher priorities can be authorized first to ensure that the tasks with higher priorities are executed first.

[0090] According to an embodiment of the present invention, in the case where there is an expired activation code among multiple alternative activation codes, according to the first available parallel number of the expired activation code, determine the maximum number of nodes in the multi-cluster platform that are allowed to call the target function using the remaining alternative activation codes except the expired activation code, and compare this number with the number of nodes in the current multi-cluster platform that call the target function. In the case where it is determined that the number of nodes exceeds the maximum number, invalidate the permissions of the nodes that call the target function and re-determine the permissions. It can ensure that after the activation code expires, even if it is judged whether the number of nodes using the target function in the multi-cluster platform exceeds the maximum number, and timely adjustment is made after exceeding the maximum number, so as to ensure the accuracy of permission management.

[0091] Since in the case where the target cluster shares multiple alternative activation codes configured in the main cluster with other sub-clusters, the target cluster can have more nodes that can call the target service. However, since each alternative activation code can be used by all sub-clusters, the problem of node disconnection will occur after the above-mentioned alternative activation code expires. Therefore, a multi-cluster switch can be set for each sub-cluster. For some services that do not require a large number of nodes to execute simultaneously but need to ensure the stable operation of each node, the multi-cluster state of the target cluster can be turned off, and only the alternative activation codes local to the target cluster are used for permission authentication to improve the stability of service execution.

[0092] In addition, in the case where the call permission indicates that the main cluster cannot call the sub-cluster, the multi-cluster state of the target cluster can also be turned off so as to use the alternative activation codes local to the target cluster for permission authentication.

[0093] In response to the multi-cluster state of the target cluster in the multi-cluster platform being turned off, determine the alternative activation codes configured locally in the target cluster. Based on the alternative activation codes of the target cluster, by decrypting the alternative activation codes, the available hardware address set of the alternative activation codes, the available period of the alternative activation codes, and the first available parallel number of the alternative activation codes can be determined. In the case where it is determined that the available hardware address set includes the hardware address of the target central node, determine the number of nodes in the target cluster that call the target function. In the case where the first available parallel number and the number of nodes satisfy a second preset relationship, determine that the target central node has the permission to call the target function, so that the user can call the target function through the target central node, where the second preset relationship means that the first available parallel number of the alternative activation codes of the target cluster is greater than the sum of the number of nodes in the target cluster that call the target function and the number of target central nodes.

[0094] According to an embodiment of the present invention, in the case where a sub-cluster closes the multi-cluster state, the sub-cluster cannot use the alternative activation codes of other sub-clusters to determine permissions. Determine the alternative activation codes local to the sub-cluster, parse the alternative activation codes, and use the parsing results of the alternative activation codes to determine the permissions of the target central node in the sub-cluster. Therefore, the flexible switching of the multi-cluster state according to business requirements or hardware requirements is realized, and the flexibility of permission management and permission determination is improved.

[0095] During the operation of the multi-cluster platform, in order to expand the business scope, the permissions of new functions can be obtained or the number of permissions of existing functions can be expanded by means such as additional purchase. New activation codes can be generated based on the newly added permissions and configured on the central nodes.

[0096] In the case where there are new activation codes in the multi-cluster platform, encrypt the available period, the first available parallel number, and the set of available hardware addresses of the new activation codes to obtain ciphertext activation codes. Based on the function corresponding to the new activation code, the first available parallel number, and the set of available hardware addresses of the new activation code, update the total available parallel number and the set of available hardware addresses of the function corresponding to the new activation code in the multi-cluster platform to obtain the updated total available parallel number and the total set of available hardware addresses; add the ciphertext activation codes to multiple alternative activation codes to obtain multiple updated alternative activation codes; and use the multiple updated alternative activation codes to update the authentication tokens of users in the multi-cluster platform.

[0097] The available period and the first available parallel number can be determined by the provider of the function of the new activation code and are used to limit the number of nodes that obtain the target function using the new activation code and the period for obtaining the target function in the multi-cluster platform. The set of available hardware addresses can be determined by the multi-cluster platform administrator according to the target function and the respective attributes and structures of multiple nodes in the multi-cluster platform. According to the multiple hardware addresses stored in the hardware address set of the new activation code, it is possible to determine the sub-cluster to which the node that can call the service corresponding to the new activation code belongs.

[0098] The encryption algorithm used to encrypt information such as the available period, the first available parallel number, and the set of available hardware addresses of the new activation code corresponds to the decryption algorithm for decrypting the alternative activation codes.

[0099] Update the total available parallel number of the function corresponding to the new activation code in the multi-cluster platform using the first available parallel number of the new activation code, that is, sum the first available parallel number and the total available parallel number to obtain the updated total available parallel number. The updated total available parallel number represents the maximum number of nodes that are allowed to call this function simultaneously in the multi-cluster platform after adding the new activation code.

[0100] Similarly, the available hardware address set corresponding to the function associated with the newly created activation code in the multi-cluster platform is updated using the available hardware address set of the newly created activation code, that is, multiple hardware addresses in the available hardware address set of the newly created activation code are added to the available hardware address set corresponding to the function associated with the newly created activation code.

[0101] After the above processing, the ciphertext activation code can be added to multiple alternative activation codes to obtain multiple updated alternative activation codes, and the authentication tokens of users in the multi-cluster platform are updated using the updated alternative activation codes to ensure that users can accurately obtain the permissions for node call functions using the updated authentication tokens. Among them, the user's identity token can include a user token.

[0102] According to an embodiment of the present invention, updating the authentication tokens of users in the multi-cluster platform using the updated multiple alternative activation codes includes: updating the authorization information in the respective authentication tokens of multiple users based on the updated multiple alternative activation codes.

[0103] The authentication token of the user can be parsed to determine the authorization information therein, and the authorization information in the authentication token is updated based on the updated multiple alternative activation codes. For example, the address of multiple alternative activation codes configured by the main cluster can be used to update the authorization information so that when the user determines the permissions, the multiple alternative activation codes configured by the main cluster can be obtained based on the address saved in the authorization information.

[0104] According to an embodiment of the present invention, in the case where there is a newly created activation code in the multi-cluster platform, the relevant parameters of the newly created activation code are encrypted to obtain a ciphertext activation code. Through data encryption and corresponding decryption during the permission determination process, the permission authentication based on the activation code can be performed offline, thereby reducing the requirements of the multi-cluster platform for the network status and improving the security of the activation code. After determining that the newly created activation code becomes effective, the maximum number of nodes allowed to simultaneously call the function in the multi-cluster platform and the available hardware address set that can call the function after the update are determined, and the encrypted newly created activation code is added to multiple alternative activation codes. The authentication tokens of users in the multi-cluster platform are updated using the updated multiple alternative activation codes to ensure that when the alternative activation codes are updated, the users can accurately determine the alternative activation codes based on the authentication tokens. Therefore, in the case of cluster scale expansion, cluster deployment, and permission adjustment in the multi-cluster platform, the accuracy of permission determination can be ensured, thereby improving the scalability and adaptability of the multi-cluster platform.

[0105] According to an embodiment of the present invention, the permission determination method further includes: configuring multiple sub-clusters with the multi-cluster status enabled in the multi-cluster platform into the cluster set saved in the master cluster; and configuring the address and port of the master cluster into multiple sub-clusters with the multi-cluster status enabled respectively.

[0106] Determine the multi-cluster switch status of each of the multiple sub-clusters in the multi-cluster platform, determine the sub-clusters with the multi-cluster switch turned on as the sub-clusters with the multi-cluster status enabled, and configure the above-mentioned sub-clusters into the cluster set saved in the master cluster, where the cluster set may save cluster markers such as the numbers, UUIDs, domain names of the sub-clusters, IP addresses, etc. of the above-mentioned sub-clusters.

[0107] By configuring the information of the sub-clusters in the cluster set, the master cluster can obtain the alternative activation codes configured in each sub-cluster from multiple sub-clusters according to the cluster markers in the cluster set, and configure multiple alternative activation codes locally in the master cluster. However, after the user issues a call request, the sub-cluster to which the target central node belongs cannot obtain the alternative activation codes of other sub-clusters in the multi-cluster platform.

[0108] Therefore, the address and port of the master cluster can be configured into multiple sub-clusters with the multi-cluster status enabled respectively, so that in the case where it is determined through calculation that the sub-cluster can call the target function through one of the multiple alternative activation codes, the sub-cluster can obtain the alternative activation code configured in the master cluster from the master cluster through the address and port of the master cluster.

[0109] According to an embodiment of the present invention, by configuring the information of the master cluster and the sub-clusters on each other's clusters respectively, it is ensured that the master cluster can smoothly obtain information such as the configuration files of the sub-clusters to determine multiple alternative activation codes in the multi-cluster platform, and it is also ensured that the sub-clusters can obtain the alternative activation codes configured in the master cluster through information such as the address and port number of the master cluster, and determine the permission information of the sub-clusters according to the alternative activation code, improving the efficiency of permission determination. In addition, by setting the multi-cluster status, the alternative activation codes of multiple sub-clusters in the multi-cluster platform can be aggregated and used by multiple sub-clusters simultaneously, which can improve the utilization rate of alternative activation codes and authorized nodes.

[0110] Based on the above permission determination method, the present invention also provides a permission determination device. The following will be combined with Figure 5 Describe this device in detail.

[0111] Figure 5 The structural block diagram of the permission determination device according to an embodiment of the present invention is shown.

[0112] As Figure 5 shown, the permission determination device 500 of this embodiment includes a node determination module 510, a quantity determination module 520, and a permission determination module 530.

[0113] The node determination module 510 is configured to determine a target central node for providing a target function based on a target address in a call request in response to a call request from a user for the target function. In one embodiment, the node determination module 510 may be configured to perform the operation S210 described above, which will not be elaborated herein.

[0114] The quantity determination module 520 is configured to determine the number of nodes currently invoking the target function in the multi-cluster platform when it is determined that the set of available hardware addresses of multiple alternative activation codes for the target function includes the hardware address of the target central node based on the decryption results of the multiple alternative activation codes for the target function. In one embodiment, the quantity determination module 520 may be configured to perform the operation S220 described above, which will not be elaborated herein.

[0115] The permission determination module 530 is configured to determine that the target central node has the permission to invoke the target function when the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, so that the user can invoke the target function through the target central node. In one embodiment, the permission determination module 530 may be configured to perform the operation S230 described above, which will not be elaborated herein.

[0116] According to an embodiment of the present invention, the permission determination device 500 further includes a sub-cluster determination module, a call determination module, and a permission assignment module.

[0117] The sub-cluster determination module is configured to determine a sub-cluster corresponding to the call request in multiple sub-clusters of the multi-cluster platform based on the target central node.

[0118] The call determination module is configured to determine the call permission of the main cluster for the sub-cluster based on the set of callable clusters for the main cluster.

[0119] The permission assignment module is configured to perform permission determination on the sub-cluster using multiple alternative activation codes configured by the main cluster when the call permission indicates that the main cluster can call the sub-cluster.

[0120] According to an embodiment of the present invention, the node determination module 510 includes an address resolution sub-module and a node determination sub-module.

[0121] The address resolution sub-module is configured to resolve the target address to determine the hardware address corresponding to the target address.

[0122] The node determination sub-module is configured to determine the target central node from multiple central nodes of the multi-cluster platform based on the hardware address.

[0123] According to an embodiment of the present invention, the address resolution sub-module includes an address determination unit.

[0124] An address determination unit, configured to determine a hardware address corresponding to a target address based on a mapping relationship between the target address and the hardware address, wherein, when the hardware address corresponding to the target address changes, the mapping relationship is updated.

[0125] According to an embodiment of the present invention, the quantity determination module 520 includes an activation code determination sub-module, a parallel number determination sub-module, and a quantity determination sub-module.

[0126] The activation code determination sub-module is configured to determine multiple alternative activation codes for invoking a target function in a multi-cluster platform.

[0127] The parallel number determination sub-module is configured to determine the total available parallel number for the multi-cluster platform to invoke the target function based on the first available parallel number of each of the multiple alternative activation codes.

[0128] The quantity determination sub-module is configured to traverse the nodes in the multi-cluster platform and determine the number of nodes for invoking the target function from the multiple nodes in the multi-cluster platform.

[0129] According to an embodiment of the present invention, the permission determination device 500 further includes an activation code decryption module.

[0130] The activation code decryption module is configured to decrypt the multiple alternative activation codes to obtain the available hardware address sets, the available periods, and the first available parallel numbers of the multiple alternative activation codes respectively.

[0131] According to an embodiment of the present invention, the permission determination module 530 includes a period determination sub-module, a parallel number update sub-module, and a permission determination sub-module.

[0132] The period determination sub-module is configured to delete the alternative activation codes that have reached the available period from the multiple alternative activation codes based on the available periods of the multiple alternative activation codes respectively, to obtain multiple available alternative activation codes.

[0133] The parallel number update sub-module is configured to determine a target activation code from the multiple available alternative activation codes when it is determined that the multiple available alternative activation codes and the number of nodes satisfy a first preset relationship.

[0134] The permission determination sub-module is configured to determine that the target central node has the permission to invoke the target function.

[0135] According to an embodiment of the present invention, the permission determination device 500 further includes a parallel number determination module, a failure determination module, and a permission update module.

[0136] A parallel number determination module, configured to determine, based on the current system time, when it is determined that there are expired activation codes among multiple alternative activation codes that have reached the available expiration date, a second available parallel number of the multi-cluster platform based on the total available parallel number and the first available parallel number of the expired activation codes.

[0137] An invalidation determination module, configured to determine that the permissions of multiple nodes that call a target function in the multi-cluster platform are invalid when it is determined that the second available parallel number and the number of nodes do not satisfy a first preset relationship.

[0138] A permission update module, configured to determine the permissions of multiple nodes whose permissions are invalid based on the second available parallel number.

[0139] According to an embodiment of the present invention, the permission determination device 500 further includes an activation code determination module, a parameter determination module, a single cluster number determination module, and a single cluster permission determination module.

[0140] An activation code determination module, configured to determine alternative activation codes of a target cluster in response to the target cluster in the multi-cluster platform closing the multi-cluster state.

[0141] A parameter determination module, configured to determine an available hardware address set of the alternative activation code, an available expiration date of the alternative activation code, and a first available parallel number of the alternative activation code based on the alternative activation code of the target cluster.

[0142] A single cluster number determination module, configured to determine the number of nodes that call the target function in the target cluster when it is determined that the available hardware address set includes the hardware address of the target central node.

[0143] A single cluster permission determination module, configured to determine that the target central node has the permission to call the target function when the first available parallel number and the number of nodes satisfy a second preset relationship, so that a user can call the target function through the target central node.

[0144] According to an embodiment of the present invention, the permission determination device 500 further includes an encryption module, a parameter update module, an activation code addition module, and a token update module.

[0145] An encryption module, configured to encrypt the available expiration date, the first available parallel number, and the available hardware address set of a newly created activation code to obtain a ciphertext activation code when there is a newly created activation code in the multi-cluster platform.

[0146] A parameter update module, configured to update the total available parallel number and the available hardware address set of the function corresponding to the newly created activation code in the multi-cluster platform based on the function corresponding to the newly created activation code and the first available parallel number and the available hardware address set of the newly created activation code, to obtain an updated total available parallel number and an updated total available hardware address set.

[0147] An activation code adding module, configured to add a ciphertext activation code to multiple alternative activation codes to obtain multiple updated alternative activation codes.

[0148] A token updating module, configured to update the authentication tokens of users in a multi-cluster platform by using the multiple updated alternative activation codes.

[0149] According to an embodiment of the present invention, the token updating module includes an authorization updating sub-module.

[0150] The authorization updating sub-module is configured to update the authorization information in the authentication tokens of multiple users respectively based on the updated multiple alternative activation codes.

[0151] According to an embodiment of the present invention, the permission determining device 500 further includes a first cluster configuration module and a second cluster configuration module.

[0152] The first cluster configuration module is configured to configure multiple sub-clusters with the multi-cluster state enabled in the multi-cluster platform into a cluster set saved in the main cluster.

[0153] The second cluster configuration module is configured to configure the address and port of the main cluster into multiple sub-clusters with the multi-cluster state enabled respectively.

[0154] According to an embodiment of the present invention, any multiple modules among the node determining module 510, the quantity determining module 520, and the permission determining module 530 can be combined and implemented in one module, or any one of them can be split into multiple modules. Or, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present invention, at least one of the node determining module 510, the quantity determining module 520, and the permission determining module 530 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging circuits and other hardware or firmware, or can be implemented in any one of the three implementation manners of software, hardware, and firmware or in any appropriate combination of several of them. Or, at least one of the node determining module 510, the quantity determining module 520, and the permission determining module 530 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions can be executed.

[0155] Figure 6 The block diagram of an electronic device suitable for implementing the permission determining method according to an embodiment of the present invention is shown.

[0156] As Figure 6As shown, the electronic device 600 according to an embodiment of the present invention includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 can include, for example, a general-purpose microprocessor (e.g., CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 601 can also include on-board memory for caching purposes. The processor 601 can include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.

[0157] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The processor 601 performs various operations of the method flow according to an embodiment of the present invention by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the program can also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 can also perform various operations of the method flow according to an embodiment of the present invention by executing the programs stored in the one or more memories.

[0158] According to an embodiment of the present invention, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the input / output (I / O) interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage section 608 as needed.

[0159] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiments of the present invention is implemented.

[0160] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present invention, the computer-readable storage medium may include the above-described ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603.

[0161] An embodiment of the present invention further includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product runs on a computer system, the program code is used to cause the computer system to implement the method provided by the embodiments of the present invention.

[0162] When the computer program is executed by the processor 601, the above functions defined in the system / apparatus of the embodiments of the present invention are executed. According to an embodiment of the present invention, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0163] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 609, and / or be installed from the removable medium 611. The program code included in the computer program may be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0164] In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, the above-described functions defined in the system of the embodiments of the present invention are performed. According to the embodiments of the present invention, the systems, devices, apparatuses, modules, units, etc. described above can be implemented by computer program modules.

[0165] According to the embodiments of the present invention, the program code for executing the computer program provided by the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedures and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0166] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0167] Those skilled in the art can understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in the various embodiments of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

[0168] The embodiments of the present invention have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. Without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present invention.

Claims

1. A permission determination method applied to a multi-cluster platform, characterized in that: The method comprises: In response to a call request for a target function from a user, determining a target hub node for providing the target function based on a target address in the call request; Based on the decryption results of the plurality of candidate activation codes for the target function, determining the number of nodes in the multi-cluster platform currently calling the target function when it is determined that the available hardware address set of the plurality of candidate activation codes includes the hardware address of the target hub node; and In the case where the multiple alternative activation codes and the number of nodes satisfy a first preset relationship, it is determined that the target hub node has the authority to call the target function so that the user can call the target function through the target hub node, wherein, in the case where the total available parallel number for the multi-cluster platform to call the target function is greater than the sum of the number of nodes and the number of target hub nodes, it is determined that the multiple alternative activation codes and the number of nodes satisfy the first preset relationship, the total available parallel number represents the maximum number of nodes in the multi-cluster platform that are allowed to use the multiple alternative activation codes to call the target function, the total available parallel number is obtained by summing the first available parallel numbers of the multiple alternative activation codes, and the first available parallel number represents the maximum number of nodes in the multi-cluster platform that are allowed to use the alternative activation codes to call the target function at the same time.

2. The method according to claim 1, characterized in that: The method further comprises: Based on the target hub node, determining a subcluster corresponding to the call request from a plurality of candidate subclusters of the multi-cluster platform; Determining, based on a callable cluster set for a main cluster of the multi-cluster platform, a calling permission of the main cluster to the sub-cluster; and In the case where the calling authority indicates that the main cluster can call the sub-cluster, the authority of the sub-cluster is determined by using the multiple candidate activation codes configured by the main cluster.

3. The method according to claim 1, characterized in that The step of determining a target hub node for providing the target function based on the target address in the call request includes: Parsing the target address to determine a hardware address corresponding to the target address; and Based on the hardware address, the target hub node is determined from a plurality of hub nodes of the multi-cluster platform.

4. The method according to claim 3, characterized in that: The target address includes a virtual address; The step of parsing the target address to determine a hardware address corresponding to the target address includes: Based on the mapping relationship between the target address and the hardware address, a hardware address corresponding to the target address is determined, wherein when the hardware address corresponding to the target address changes, the mapping relationship is updated.

5. The method according to claim 2, characterized in that: The method of determining the number of nodes currently calling the target function in the multi-cluster platform based on the decryption results of the multiple candidate activation codes for the target function and determining that the available hardware address set of the multiple candidate activation codes includes the hardware address of the target hub node comprises: determining a plurality of candidate activation codes for invoking the target function in the multi-cluster platform; Determining the total available parallelism of the multi-cluster platform invoking the target function based on the first available parallelism of each of the multiple candidate activation codes; and The nodes in the multi-cluster platform are traversed, and the number of nodes that call the target function is determined from the multiple nodes in the multi-cluster platform.

6. The method according to claim 5, characterized in that The method further comprises: The multiple candidate activation codes are decrypted by using the main cluster to obtain the available hardware address sets of the multiple candidate activation codes, the available periods of the candidate activation codes, and the first available parallel number of the candidate activation codes.

7. The method according to claim 6, characterized in that The step of determining, when the plurality of candidate activation codes and the number of nodes satisfy a first preset relationship, that the target hub node has the authority to call the target function so that the user can call the target function through the target hub node, includes: Based on the respective available periods of the multiple candidate activation codes, delete the candidate activation codes whose available periods have expired from the multiple candidate activation codes to obtain multiple available candidate activation codes; In the case where it is determined that the multiple available candidate activation codes and the number of nodes satisfy the first preset relationship, determining a target activation code from the multiple available candidate activation codes, wherein the available hardware address set of the target activation code includes the hardware address, and the first preset relationship indicates that the total available parallel number determined according to the multiple available candidate activation codes is greater than the sum of the number of nodes and the number of the target hub nodes; and Determine whether the target hub node has the authority to call the target function.

8. The method according to claim 7, characterized in that The method further comprises: Based on the current system time, when it is determined that there is an expired activation code that has reached the available period among the multiple alternative activation codes, a second available parallel number of the multi-cluster platform is determined based on the total available parallel number and the first available parallel number of the expired activation code, wherein the second available parallel number represents the maximum number of nodes in the multi-cluster platform that are allowed to use the remaining alternative activation codes except the expired activation code to call the target function; In a case where it is determined that the second available parallel number and the number of nodes do not satisfy the first preset relationship, determining that permissions of multiple nodes in the multi-cluster platform that call the target function are invalid; and Based on the second available parallel number, permissions of a plurality of nodes whose permissions have expired are determined.

9. The method according to claim 6, characterized in that The method further comprises: In response to a target cluster in the multi-cluster platform shutting down a multi-cluster state, determining an alternative activation code for the target cluster; Based on the candidate activation code of the target cluster, determining an available hardware address set of the candidate activation code, an available period of the candidate activation code, and a first available parallel number of the candidate activation code; In case it is determined that the available hardware address set includes the hardware address of the target hub node, determining the number of nodes in the target cluster that call the target function; and When the first available parallel number and the number of nodes satisfy a second preset relationship, it is determined that the target hub node has the authority to call the target function so that the user can call the target function through the target hub node, wherein the second preset relationship indicates that the first available parallel number of the alternative activation code of the target cluster is greater than the sum of the number of nodes in the target cluster that call the target function and the number of the target hub nodes.

10. The method according to claim 9, characterized in that The method further comprises: In the case where a newly created activation code exists in the multi-cluster platform, the usable period, the first available parallel number, and the available hardware address set of the newly created activation code are encrypted to obtain a ciphertext activation code; Based on the function corresponding to the newly created activation code and the first available parallel number and available hardware address set of the newly created activation code, the total available parallel number and available hardware address set of the function corresponding to the newly created activation code in the multi-cluster platform are updated to obtain an updated total available parallel number and total available hardware address set; Adding the encrypted activation code to the multiple candidate activation codes to obtain multiple updated candidate activation codes; and The identity authentication tokens of users in the multi-cluster platform are updated using the multiple update candidate activation codes.

11. The method according to claim 10, characterized in that The updating of the identity authentication token of the user in the multi-cluster platform by using the multiple update candidate activation codes includes: Based on the multiple updated candidate activation codes, the authorization information in the identity authentication tokens of the multiple users are updated.

12. The method according to claim 10, characterized in that The method further comprises: configuring the plurality of sub-clusters in the multi-cluster platform, in which the multi-cluster state has been enabled, to the cluster set saved in the main cluster; and The addresses and ports of the main cluster are respectively configured to the multiple sub-clusters in which the multi-cluster state is enabled.

13. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 12.

14. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.

15. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.

Citation Information

Patent Citations

  • Service request response method and service request response system

    CN111131401A

  • Data processing method, device and equipment and computer readable storage medium

    CN118734282A