An information processing method, device, server, storage medium and program product
By receiving operation requests from user devices, verifying user identity, identifying target management groups, and sending target resources to user devices, the problem of excessively long operation times in account permission management is solved, and allocation efficiency is improved.
Patent Information
- Application Number
- CN202411997062.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-12-30
AI Technical Summary
Existing account permission management solutions take too long to operate, resulting in low efficiency in account, permission, and resource allocation.
By receiving operation requests from user devices and verifying user identity, the system determines the target management group based on the user identifier and sends the identifier of the target account group to the second server. It also receives and sends target resources to user devices, enabling users to directly operate resources and simplifying the account permission management process.
It improves the efficiency of account, permission and resource allocation and reduces operation time.
Smart Images

Figure CN119853998B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the information processing technology in the field of communication, and in particular to an information processing method and device, a server, a storage medium and a program product. BACKGROUND
[0002] Cloud computing refers to obtaining required resources in a demand-oriented and scalable manner through a network; in a cloud computing with deployment requirements and account management mode, it refers to obtaining required services in a demand-oriented and scalable manner through a network. Such services can be IT and software, Internet related, or other services. Cloud computing has become a popular way of providing various Internet Technology (IT) concepts as services. In one implementation, users can request the services they need and trade the required services with cloud providers. Usually, the cloud service management nodes provided by the cloud computing platform are deployed in the management area, and when the architecture evolves and needs to be sunk through the management area service, the internal circulation account is used to apply for and release resources to realize unified scheduling of hardware resources. However, in the related art, if the account sharing is prohibited, to realize that multiple personnel need to apply for multiple independent sub-accounts under multiple circulation accounts and assign multiple permissions and multiple resources to the sub-accounts, a long time is needed, resulting in low efficiency of account, permission and resource allocation. SUMMARY
[0003] To solve the above technical problems, the embodiments of the present application provide an information processing method, device, server, storage medium and program product, which solve the problem of long operation time in the entire operation process of the related art account permission management scheme, and improve the efficiency of account, permission and resource allocation.
[0004] To achieve the above object, the technical scheme of the embodiments of the present application is as follows:
[0005] An information processing method, applied to a first server, the method comprising:
[0006] receiving an operation request for operating resources sent by a user equipment; wherein the operation request carries an identifier of a user;
[0007] determining a target management group from a management group based on the identifier of the user after the identity verification of the user is passed;
[0008] determining a target account group corresponding to the user based on the target management group, and sending an identifier of the target account group to a second server;
[0009] receiving a target resource determined by the second server based on the identifier of the target account group;
[0010] send the target resource to the user equipment, so that the user equipment operates the target resource; wherein the first server and the second server have passed communication authentication.
[0011] In the above solution, the target account group corresponding to the user is determined based on the target management group, and the method comprises:
[0012] Based on the operation request information for the target resource, the operation authority of the user on the target resource is detected; wherein the operation request carries the operation request information;
[0013] If it is detected that the user has the operation authority on the target resource, the target account group corresponding to the user is determined based on the target management group.
[0014] In the above solution, the target account group corresponding to the user is determined based on the target management group, and the method comprises:
[0015] A first mapping relationship between the management group and the account group is determined.
[0016] The target account group is determined based on the target management group and the first mapping relationship.
[0017] In the above solution, the method further comprises:
[0018] User operation authority change information for the user is received;
[0019] The management group is updated based on the user operation authority change information.
[0020] An information processing method, the method is applied to a second server, and the method comprises:
[0021] The identification of a target account group sent by a first server is received; wherein the first server and the second server have passed communication authentication;
[0022] Based on the identification of the target account group, a target resource corresponding to a user is determined from a plurality of resource sets;
[0023] The target resource is sent to the first server, so that the user equipment operates the target resource received from the first server.
[0024] In the above solution, the target resource corresponding to the user is determined from a plurality of resource sets based on the identification of the target account group, and the method comprises:
[0025] A second mapping relationship between the account group and the resource set is determined.
[0026] Determine the target resource from the plurality of resource sets based on the identification of the target account group and the second mapping relationship.
[0027] In the above scheme, the method further comprises:
[0028] Determine information of a resource to be executed.
[0029] Divide the resource to be executed based on the information of the resource to be executed to obtain the plurality of resource sets.
[0030] In the above scheme, the determination of the information of the resource to be executed comprises:
[0031] Determine the state of the resource to be executed and attribute information of the resource to be executed.
[0032] Correspondingly, the division of the resource to be executed based on the information of the resource to be executed to obtain the plurality of resource sets comprises:
[0033] Divide the resource to be executed based on the state to obtain a first resource set.
[0034] Divide the resource to be executed based on the attribute information to obtain a second resource set.
[0035] Determine the plurality of resource sets based on the first resource set and the second resource set.
[0036] A first information processing device comprises:
[0037] A first receiving unit configured to receive an operation request for operating a resource sent by a user equipment; wherein the operation request carries an identification of a user.
[0038] A first processing unit configured to determine a target management group from management groups based on the identification of the user after identity verification of the user is passed.
[0039] The first processing unit is further configured to determine a target account group corresponding to the user based on the target management group, and send an identification of the target account group to a second server.
[0040] The first receiving unit is further configured to receive a target resource determined by the second server based on the identification of the target account group.
[0041] A first sending unit configured to send the target resource to the user equipment, so that the user equipment operates the target resource; wherein the second server and the first server have passed communication authentication.
[0042] A second information processing device comprises:
[0043] a second receiving unit, configured to receive an identification of a target account group sent by a first server, wherein the first server and the second server have passed a communication authentication;
[0044] a second processing unit, configured to determine a target resource corresponding to the user from a plurality of resource sets based on the identification of the target account group;
[0045] a second sending unit, configured to send the target resource to the first server, so that the user equipment operates on the target resource received from the first server.
[0046] A first server, comprising a first processor, a first memory and a first communication bus;
[0047] The first communication bus is configured to realize communication connection between the first processor and the first memory;
[0048] The first processor is configured to execute an information processing program in the first memory, so as to realize the steps of the information processing method.
[0049] A second server, comprising a second processor, a second memory and a second communication bus;
[0050] The second communication bus is configured to realize communication connection between the second processor and the second memory;
[0051] The second processor is configured to execute an information processing program in the second memory, so as to realize the steps of the information processing method.
[0052] A computer readable storage medium, which stores one or more programs, the one or more programs being executable by one or more processors to realize the steps of the information processing method.
[0053] A computer program product, comprising a computer program, which realizes the method when executed by a processor.
[0054] The information processing method, device, server, storage medium and program product provided by the embodiments of the present application can receive an operation request for operating a resource sent by a user equipment and carrying an identifier of a user, determine a target management group from the management groups based on the identifier of the user after the identity verification of the user is passed, determine a target account group corresponding to the user based on the target management group, and send an identifier of the target account group to a second server. The target resource determined by the second server based on the identifier of the target account group is received, and the target resource is sent to the user equipment to enable the user equipment to operate the target resource. The first server and the second server have passed communication authentication. In this way, the user can directly access the corresponding account group in the second server through the management group of the first server, and obtain the resource that needs to be operated by the user, and then directly operate the resource through the management group of the first server. The problem of long operation time in the entire operation process in the related art solution for account permission management is solved, and the allocation efficiency of accounts, permissions and resources is improved. BRIEF DESCRIPTION OF DRAWINGS
[0055] Figure 1 A flowchart of an information processing method provided by an embodiment of the present application;
[0056] Figure 2 A mapping relationship diagram between a bastion host group, an internal loop account group and an internal loop account resource corresponding to an information processing method provided by an embodiment of the present application;
[0057] Figure 3 A flowchart of another information processing method provided by an embodiment of the present application;
[0058] Figure 4 A structural diagram of a first information processing device provided by an embodiment of the present application;
[0059] Figure 5 A structural diagram of a second information processing device provided by an embodiment of the present application;
[0060] Figure 6 A structural diagram of a first server provided by an embodiment of the present application;
[0061] Figure 7 A structural diagram of a second server provided by an embodiment of the present application. DETAILED DESCRIPTION
[0062] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application.
[0063] It should be understood that the "embodiments of the present application" or "the foregoing embodiments" mentioned throughout the specification mean that the specific features, structures or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, "in the embodiments of the present application" or "in the foregoing embodiments" appearing throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. In various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The sequence number of the above-mentioned embodiments of the present application is only for description, not representing the advantages and disadvantages of the embodiments.
[0064] Unless otherwise specified, the electronic device performs any step in the embodiments of the present application can be a processor of the electronic device performing the step. It is also worth noting that the embodiments of the present application do not limit the order of the steps performed by the electronic device. In addition, the way data is processed in different embodiments can be the same method or different method. It should be noted that any step in the embodiments of the present application can be independently executed by the electronic device, that is, the electronic device can execute any step in the embodiments described below without depending on the execution of other steps.
[0065] It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0066] The embodiments of the present application provide an information processing method, which can be applied to a first server, referring to Figure 1 As shown, the method can include the following steps:
[0067] Step 101, receiving an operation request for operating a resource sent by a user equipment.
[0068] The operation request carries an identifier of a user.
[0069] In the embodiments of the present application, the operation request can be generated by triggering on the user equipment when the user needs to operate the resource in the cloud platform identity authentication system. It should be noted that the identifier of the user is used to uniquely identify the user.
[0070] Specifically, the first server can refer to a bastion host device, and the second server can refer to a cloud platform identity authentication system.
[0071] Step 102, determining a target management group from the management groups based on the identifier of the user after the identity verification of the user is passed.
[0072] The bastion device can first verify the identity of the user after receiving the operation request of the user to determine whether the user is a legal user. It should be noted that any technology that can achieve user identity verification in the related art is applicable.
[0073] In the embodiments of the present application, the management group can be used to manage the account, and different management groups can be pre-configured according to the responsibilities of the user. In a feasible implementation manner, the management group can refer to a bastion group; as shown in Figure 2 The users with different responsibilities are configured into different bastion groups, and the permissions of the inner loop account groups under the bastion group can be updated. Specifically, the bastion device can determine the responsibility of the user according to the identity of the user, and then determine the target bastion group matched with the user from the plurality of bastion groups, and apply the bastion group corresponding to the user as the target bastion group.
[0074] Step 103, determining a target account group corresponding to the user based on the target management group, and sending the identity of the target account group to the second server.
[0075] In the embodiments of the present application, the bastion device can determine the target account group corresponding to the user according to the target bastion group and the association between the bastion group and the account group. And determine the identity of the target account group and send it to the cloud platform identity authentication system.
[0076] It should be noted that the account group can refer to the account group of the inner loop account, and the target account group can refer to the target inner loop account group.
[0077] Step 104, receiving the target resource determined by the second server based on the identity of the target account group.
[0078] The cloud platform identity authentication system can determine the target resource corresponding to the user from a plurality of resource sets according to the identity of the target account group after receiving the identity of the target account group, and send the determined target resource to the bastion device.
[0079] Step 105, sending the target resource to the user device to enable the user device to operate the target resource.
[0080] The first server and the second server have passed the communication authentication.
[0081] Specifically, the bastion device can send the received target resource to the user device, so that the user can perform corresponding operations on the target resource in the user device.
[0082] It should be noted that the federated authentication between the bastion device and the cloud platform identity authentication system can be established in advance; the cloud platform identity authentication system as a service provider needs to provide federated authentication capability, and the bastion device as an identity provider needs to be responsible for the collection and storage of account passwords. The bastion device and the cloud platform identity authentication system can realize the password-free login of the cloud platform identity authentication system after the user authorization of the bastion device by establishing a trust relationship and configuring identity conversion rules.
[0083] In other embodiments of the present application, the "determining the target account group corresponding to the user based on the target management group" in step 103 can be implemented in the following way:
[0084] A1, detecting the operation permission of the user on the target resource based on the operation request information of the target resource.
[0085] The operation request carries the operation request information.
[0086] It should be noted that the bastion device can detect whether the user has the operation permission of the target resource based on the operation request information. Specifically, the operation request information can refer to the information input by the user related to the operation of the target resource. In a feasible implementation manner, the operation request information can refer to the operation reason and other operation-related information.
[0087] A2, if it is detected that the user has the operation permission of the target resource, determining the target account group corresponding to the user based on the target management group.
[0088] Specifically, after determining that the user has the operation permission of the target resource, the bastion device can determine the target account group corresponding to the user according to the target management group.
[0089] In other embodiments of the present application, the "determining the target account group corresponding to the user based on the target management group" can be implemented in the following way:
[0090] determining a first mapping relationship between the management group and the account group;
[0091] determining the target account group based on the target management group and the first mapping relationship.
[0092] The first mapping relationship can be a corresponding relationship between the bastion group and the account group of the inner loop account pre-configured; specifically, as shown in the following table, the account group of the inner loop account can have a corresponding bastion group; the inner loop account group can include a plurality of inner loop accounts, and the inner loop account is used for cloud platform service sinking resource deployment. It should be noted that the bastion device can manage the life cycle and password of the inner loop account. Figure 2
[0093] In the embodiment of the present application, the bastion host device can determine the target inner loop account group according to the target bastion host group and the first mapping relationship between the bastion host group and the account group of the inner loop account.
[0094] In other embodiments of the present application, the method can further include:
[0095] Receiving user operation permission change information for the user;
[0096] Updating the management group based on the user operation permission change information.
[0097] It should be noted that, if the user's responsibility changes, the responsibility change information (i.e. operation permission change information) can be sent to the bastion host device, and then the bastion host device removes or replaces the corresponding bastion host group according to the responsibility change information, i.e. the user's permission change is completed.
[0098] The information processing method provided by the embodiments of the present application can directly access the corresponding account group in the second server through the management group of the first server, and obtain the resources that the user needs to operate, and then the user can directly operate the resources through the management group of the first server, solving the problem of long operation time in the entire operation process in the related art account permission management scheme, and improving the allocation efficiency of accounts, permissions and resources.
[0099] Based on the foregoing embodiments, the embodiments of the present application provide an information processing method, which can be applied to the second server, referring to Figure 3 The method can include the following steps:
[0100] Step 201, receiving the identification of the target account group sent by the first server.
[0101] Wherein, the first server and the second server have passed the communication authentication.
[0102] Step 202, determining the target resource corresponding to the user from the plurality of resource sets based on the identification of the target account group.
[0103] Wherein, the cloud platform identity authentication system can determine the target resource corresponding to the user according to the identification of the target inner loop account group and the association between the inner loop account group and the inner loop account resource set.
[0104] Step 203, sending the target resource to the first server, so that the user device operates the target resource received from the first server.
[0105] Specifically, after determining the target resource that the user needs to operate, the cloud platform identity authentication system can send the target resource to the bastion host device, and then the bastion host can send the target resource to the user device; then, the user can perform corresponding operations on the target resource in the user device, so as to realize the operation of the user on the resource of the cloud platform identity authentication system through the bastion host device.
[0106] In other embodiments of the present application, the above step 202 can be implemented in the following manner:
[0107] B1, determining a second mapping relationship between the account group and the resource set.
[0108] B2, determining the target resource from the plurality of resource sets based on the identifier of the target account group and the second mapping relationship.
[0109] The second mapping relationship can be a preconfigured corresponding relationship between the account group of the internal loop account and the internal loop account resource set. Specifically, as shown in the following table, the account group of the internal loop account can have a corresponding internal loop account resource set. Figure 2
[0110] In the embodiments of the present application, the cloud platform identity authentication system can determine the target internal loop account resource set according to the identifier of the target internal loop account group and the second mapping relationship between the account group of the internal loop account and the internal loop account resource set, and then determine the target resource from the target internal loop account resource set.
[0111] In other embodiments of the present application, the method can further include:
[0112] determining information of the to-be-executed resource;
[0113] dividing the to-be-executed resource based on the information of the to-be-executed resource to obtain a plurality of resource sets.
[0114] The information of the to-be-executed resource can refer to basic information related to the to-be-executed resource. All resources can be divided into different resource sets according to the information of the to-be-executed resource.
[0115] In other embodiments of the present application, the above "determining information of the to-be-executed resource" includes:
[0116] determining the state of the to-be-executed resource and attribute information of the to-be-executed resource;
[0117] The state of the to-be-executed resource can include a delivery state, an acceptance state, and an in-network state. The attribute information of the to-be-executed resource can refer to the name of the to-be-executed resource and corresponding product information.
[0118] In other embodiments of the present application, the "dividing the to-be-executed resource based on the information of the to-be-executed resource to obtain a plurality of resource sets" includes:
[0119] Dividing the to-be-executed resource based on the state to obtain a first resource set;
[0120] Wherein, the resource can be divided into a delivery state resource set, an acceptance state resource set, and a network state resource set according to the resource state.
[0121] Dividing the to-be-executed resource based on the attribute information to obtain a second resource set;
[0122] Wherein, the resource can be divided into an A product resource set, a B product resource set, and a C product resource set according to the attribute information of the resource.
[0123] Based on the first resource set and the second resource set, a plurality of resource sets are determined.
[0124] In the embodiments of the present application, the first resource set and the second resource set are combined to obtain a plurality of resource sets. Specifically, the plurality of resource sets can include an A product delivery state resource set read-only group, a B product acceptance state resource set management group, and a C product network state resource set operation group.
[0125] It should be noted that the same steps and the same content in this embodiment and other embodiments are described with reference to the description of other embodiments, and will not be described here.
[0126] The information processing method provided by the embodiments of the present application can directly access the corresponding account group in the second server through the management group of the first server, and obtain the resource that needs to be operated by the user, and then directly operate the resource through the management group of the first server, solving the problem of long operation time in the whole operation process in the related art account permission management scheme, and improving the allocation efficiency of accounts, permissions and resources.
[0127] Based on the foregoing embodiments, the embodiments of the present application provide a first information processing device, which can be applied to Figure 1 In the information processing method provided by the corresponding embodiments, referring to Figure 4 The first information processing device 3 can include a first receiving unit 31, a first processing unit 32, and a first sending unit 33, wherein:
[0128] The first receiving unit 31 is configured to receive an operation request for operating a resource sent by a user equipment; wherein the operation request carries an identifier of the user;
[0129] The first processing unit 32 is configured to determine a target management group from the management groups based on the identity of the user after the identity of the user is verified.
[0130] The first processing unit 32 is further configured to determine a target account group corresponding to the user based on the target management group, and send an identity of the target account group to the second server.
[0131] The first receiving unit 31 is further configured to receive a target resource determined by the second server based on the identity of the target account group.
[0132] The first sending unit 33 is configured to send the target resource to the user equipment, so that the user equipment operates the target resource; and the first server and the second server have passed a communication authentication.
[0133] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:
[0134] Detect an operation permission of the user on the target resource based on operation request information of the operation request; wherein the operation request information is carried in the operation request;
[0135] If it is detected that the user has the operation permission on the target resource, determine a target account group corresponding to the user based on the target management group.
[0136] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:
[0137] Determine a first mapping relationship between the management groups and the account groups;
[0138] Determine the target account group based on the target management group and the first mapping relationship.
[0139] In other embodiments of the present application, the first processing unit 32 is further configured to perform the following steps:
[0140] Receive user operation permission change information of the user;
[0141] Update the management groups based on the user operation permission change information.
[0142] It should be noted that the specific implementation process of the steps performed by each unit in the embodiments of the present application can refer to the implementation process in the information processing method provided by the corresponding embodiments, which will not be described here in detail. Figure 1 The specific implementation process of the steps performed by each unit in the embodiments of the present application can refer to the implementation process in the information processing method provided by the corresponding embodiments, which will not be described here in detail.
[0143] The first information processing apparatus provided by the embodiment of the present application can enable a user to directly access a corresponding account group in a second server through a management group of a first server, and obtain resources that need to be operated by the user, and then enable the user to directly operate the resources through the management group of the first server, thereby solving the problem of long operation time in the entire operation process of the account permission management solution in the related art, and improving the allocation efficiency of accounts, permissions and resources.
[0144] Based on the foregoing embodiments, the embodiment of the present application provides a second information processing apparatus which can be applied to Figure 3 The information processing method provided by the corresponding embodiment can refer to Figure 5 As shown in the figure, the second information processing apparatus 4 can include a second receiving unit 41, a second processing unit 42 and a second sending unit 43, wherein:
[0145] The second receiving unit 41 is configured to receive an identifier of a target account group sent by a first server; wherein the first server and the second server have passed a communication authentication;
[0146] The second processing unit 42 is configured to determine a target resource corresponding to the user from a plurality of resource sets based on the identifier of the target account group;
[0147] The second sending unit 43 is configured to send the target resource to the first server, so that the user equipment operates the target resource received by the first server.
[0148] In other embodiments of the present application, the second processing unit 42 is further configured to perform the following steps:
[0149] Determine a second mapping relationship between the account group and the resource set;
[0150] Determine the target resource from the plurality of resource sets based on the identifier of the target account group and the second mapping relationship.
[0151] In other embodiments of the present application, the second processing unit 42 is further configured to perform the following steps:
[0152] Determine information of the resource to be executed;
[0153] Divide the resource to be executed based on the information of the resource to be executed to obtain the plurality of resource sets.
[0154] In other embodiments of the present application, the second processing unit 42 is further configured to determine a state of the resource to be executed and attribute information of the resource to be executed.
[0155] In other embodiments of the present application, the second processing unit 42 is further configured to perform the following steps:
[0156] The to-be-executed resources are divided based on the state, to obtain a first resource set;
[0157] The to-be-executed resources are divided based on the attribute information, to obtain a second resource set;
[0158] The plurality of resource sets are determined based on the first resource set and the second resource set.
[0159] It should be noted that the specific implementation process of the steps performed by each unit in the embodiments of the present application can be referred to Figure 3 the implementation process in the information processing method provided by the corresponding embodiments, which will not be described here.
[0160] The second information processing device provided by the embodiments of the present application can directly access the corresponding account group in the second server through the management group of the first server, and obtain the resources that the user needs to operate, and then the user can directly operate the resources through the management group of the first server, thereby solving the problem of long operation time in the entire operation process of the account permission management scheme in the related art, and improving the allocation efficiency of the account, permission and resource.
[0161] Based on the foregoing embodiments, the embodiments of the present application provide a first server which can be applied to Figure 1 In the information processing method provided by the corresponding embodiments, refer to Figure 6 The first server 5 can include a first processor 51, a first memory 52 and a first communication bus 53, wherein:
[0162] The first communication bus 53 is used to realize the communication connection between the first processor 51 and the first memory 52;
[0163] The first processor 51 is used to execute the information processing program in the first memory 52 to realize the following steps:
[0164] Receive the operation request for operating the resource sent by the user equipment; wherein the operation request carries the identity of the user;
[0165] After the identity verification of the user is passed, the target management group is determined from the management group based on the identity of the user;
[0166] The target account group corresponding to the user is determined based on the target management group, and the identity of the target account group is sent to the second server;
[0167] Receive the target resource determined by the second server based on the identity of the target account group;
[0168] Send the target resource to the user equipment to make the user equipment operate the target resource; wherein the first server and the second server have passed the communication authentication.
[0169] In other embodiments of the present application, the first processor 51 is configured to execute the information processing program in the first memory 52 to determine the target account group corresponding to the user based on the target management group, so as to implement the following steps:
[0170] detect the operation permission of the user on the target resource based on the operation request information of the target resource; wherein the operation request information is carried in the operation request;
[0171] If it is detected that the user has the operation permission on the target resource, determine the target account group corresponding to the user based on the target management group.
[0172] In other embodiments of the present application, the first processor 51 is configured to execute the information processing program in the first memory 52 to determine the target account group corresponding to the user based on the target management group, so as to implement the following steps:
[0173] determine the first mapping relationship between the management group and the account group;
[0174] determine the target account group based on the target management group and the first mapping relationship.
[0175] In other embodiments of the present application, the first processor 51 is configured to execute the information processing program in the first memory 52, and can also execute the following steps:
[0176] receive the user operation permission change information of the user;
[0177] update the management group based on the user operation permission change information.
[0178] It should be noted that the specific description of the steps executed by the first processor can refer to the information processing method provided by the corresponding embodiments, which will not be described here. Figure 1 In the information processing method provided by the corresponding embodiments, the specific description of the steps executed by the first processor can refer to
[0179] The first server provided by the embodiments of the present application can be directly accessed by the user through the management group of the first server to access the corresponding account group in the second server, and the user can obtain the resource to be operated, and then the user can directly operate the resource through the management group of the first server. The problem of long operation time in the entire operation process in the related art account permission management scheme is solved, and the allocation efficiency of the account, the permission and the resource is improved.
[0180] Based on the foregoing embodiments, the embodiments of the present application provide a second server, which can be applied to Figure 3 In the information processing method provided by the corresponding embodiments, the specific description of the steps executed by the first processor can refer to Figure 7As shown, the second server 6 can include a second processor 61, a second memory 62 and a second communication bus 63, wherein:
[0181] The second communication bus 63 is used to realize the communication connection between the second processor 61 and the second memory 62;
[0182] The second processor 61 is used to execute the information processing program in the second memory 62 to realize the following steps:
[0183] Receive the identification of the target account group sent by the first server; wherein the first server and the second server have passed the communication authentication;
[0184] Based on the identification of the target account group, determine the target resource corresponding to the user from the plurality of resource sets;
[0185] Send the target resource to the first server, so that the user equipment operates the target resource received by the first server.
[0186] In other embodiments of the present application, the second processor 61 is used to execute the information processing program in the second memory 62 to determine the target resource corresponding to the user from the plurality of resource sets based on the identification of the target account group, to execute the following steps:
[0187] Determine the second mapping relationship between the account group and the resource set;
[0188] Based on the identification of the target account group and the second mapping relationship, determine the target resource from the plurality of resource sets.
[0189] In other embodiments of the present application, the second processor 61 is used to execute the information processing program in the second memory 62, and can also execute the following steps:
[0190] Determine the information of the to-be-executed resource;
[0191] Based on the information of the to-be-executed resource, divide the to-be-executed resource to obtain a plurality of resource sets.
[0192] In other embodiments of the present application, the second processor 61 is used to execute the information processing program in the second memory 62 to determine the information of the to-be-executed resource, to execute the following steps:
[0193] Determine the state of the to-be-executed resource and the attribute information of the to-be-executed resource.
[0194] In other embodiments of the present application, the second processor 61 is used to execute the information processing program in the second memory 62 to divide the to-be-executed resource to obtain a plurality of resource sets based on the information of the to-be-executed resource, to execute the following steps:
[0195] The to-be-executed resources are divided based on the state, to obtain a first resource set;
[0196] The to-be-executed resources are divided based on the attribute information, to obtain a second resource set;
[0197] The multiple resource sets are determined based on the first resource set and the second resource set.
[0198] It should be noted that the specific description of the steps performed by the second processor can refer to the specific description of the steps performed by the second processor in the information processing method provided by the corresponding embodiment. Figure 3 The information processing method provided by the corresponding embodiment will not be described here again.
[0199] The second server provided by the embodiment of the present application can be directly accessed by the user through the management group of the first server to obtain the corresponding account group in the second server, and the resource that needs to be operated by the user can be obtained, and then the operation of the resource can be directly implemented through the management group of the first server, thereby solving the problem of long operation time in the entire operation process of the account permission management scheme in the related art, and improving the allocation efficiency of the account, the permission and the resource.
[0200] Based on the foregoing embodiment, the embodiment of the present application provides a computer readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement Figure 1 and Figure 3 The steps of the information processing method provided by the corresponding embodiment.
[0201] Based on the foregoing embodiment, the embodiment of the present application provides a computer program product, which includes a computer program that can be executed by the first processor 51 and the second processor 61 to complete Figure 1 and Figure 3 The steps of the information processing method provided by the corresponding embodiment.
[0202] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer usable program code.
[0203] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0204] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0205] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0206] The above description is only specific implementation of the present application, but the protection scope of the present application is not limited to this, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An information processing method characterized by comprising: The method is applied to a first server, and the method comprises: receiving an operation request for operating a resource sent by a user equipment; wherein the operation request carries an identity of a user; after the identity of the user is verified, determining a target management group from management groups based on the identity of the user; determining a target account group corresponding to the user based on the target management group, and sending an identity of the target account group to a second server; receiving a target resource determined by the second server based on the identity of the target account group; wherein the target resource is determined by the second server based on the identity of the target account group and an association relationship between account groups and resource sets; sending the target resource to the user equipment to enable the user equipment to operate the target resource; wherein the first server and the second server have passed communication authentication; wherein the determining of the target account group corresponding to the user based on the target management group comprises: determining the target account group based on the target management group and an association relationship between management groups and account groups.
2. The method of claim 1, wherein, The determining of the target account group corresponding to the user based on the target management group comprises: detecting an operation permission of the user on the target resource based on operation request information of the target resource; wherein the operation request carries the operation request information; if it is detected that the user has the operation permission on the target resource, determining the target account group corresponding to the user based on the target management group.
3. The method according to claim 1 or 2, characterized in that, The determining of the target account group corresponding to the user based on the target management group comprises: determining a first mapping relationship between management groups and account groups; determining the target account group based on the target management group and the first mapping relationship.
4. The method of claim 1, wherein, The method further comprises: receiving user operation permission change information of the user; updating the management groups based on the user operation permission change information.
5. An information processing method characterized by comprising: The method is applied to a second server, and the method comprises: receiving an identity of a target account group sent by a first server; wherein the first server and the second server have passed communication authentication; wherein the target account group is determined by the first server based on a determined target management group and an association relationship between management groups and account groups; determining a target resource corresponding to a user from multiple resource sets based on the identity of the target account group; sending the target resource to the first server to enable a user equipment to operate the target resource received from the first server; wherein the determining of the target resource corresponding to the user from the multiple resource sets based on the identity of the target account group comprises: determining the target resource from the multiple resource sets based on the identity of the target account group and an association relationship between account groups and resource sets.
6. The method of claim 5, wherein, The determining of the target resource corresponding to the user from the multiple resource sets based on the identity of the target account group comprises: determining a second mapping relationship between account groups and resource sets; Determine the target resource from the plurality of resource sets based on the identification of the target account group and the second mapping relationship.
7. The method of claim 5, wherein, The method further comprises: Determining information of a resource to be executed; Dividing the resource to be executed based on the information of the resource to be executed to obtain the plurality of resource sets.
8. The method of claim 7, wherein, The determining information of the resource to be executed comprises: Determining a state of the resource to be executed and attribute information of the resource to be executed; Correspondingly, the dividing the resource to be executed based on the information of the resource to be executed to obtain the plurality of resource sets comprises: Dividing the resource to be executed based on the state to obtain a first resource set; Dividing the resource to be executed based on the attribute information to obtain a second resource set; Determining the plurality of resource sets based on the first resource set and the second resource set.
9. A first information processing apparatus comprising: Comprise: A first receiving unit configured to receive an operation request for operating a resource sent by a user equipment; wherein the operation request carries an identification of a user; A first processing unit configured to determine a target management group from management groups based on the identification of the user after the identity verification of the user is passed; The first processing unit is further configured to determine a target account group corresponding to the user based on the target management group and an association relationship between the management groups and account groups, and send an identification of the target account group to a second server; The first receiving unit is further configured to receive a target resource determined by the second server based on the identification of the target account group; wherein the target resource is determined by the second server based on the identification of the target account group and an association relationship between the account groups and resource sets; A first sending unit configured to send the target resource to the user equipment to enable the user equipment to operate the target resource; wherein the second server and the first server have passed communication authentication.
10. A second information processing apparatus comprising: Comprise: A second receiving unit configured to receive an identification of a target account group sent by a first server; wherein the first server and the second server have passed communication authentication; wherein the target account group is determined by the first server based on a determined target management group and an association relationship between the management groups and account groups; A second processing unit configured to determine a target resource corresponding to a user from a plurality of resource sets based on the identification of the target account group and an association relationship between the account groups and resource sets; A second sending unit configured to send the target resource to the first server to enable a user equipment to operate the target resource received from the first server.
11. A first server, characterized by, Comprise: A first processor, a first memory and a first communication bus; The first communication bus is configured to realize communication connection between the first processor and the first memory; The first processor is configured to execute an information processing program in the first memory to realize the steps of the information processing method according to any one of claims 1-4.
12. A second server, characterized by Comprise: A second processor, a second memory and a second communication bus; The communication bus is configured to realize communication connection between the second processor and the second memory; The second processor is configured to execute an information processing program in the second memory to implement the steps of the information processing method according to any one of claims 5-8.
13. A computer-readable storage medium, characterized in that, The computer readable storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the information processing method according to any one of claims 1-4 or 5-8.
14. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method according to any one of claims 1-4 or 5-8.
Citation Information
Patent Citations
Groupware server, client terminal and program used for them
JP2005284642A
Resource selection method and device
US20230015403A1