Authority management method and device and electronic equipment

By adding a unified client and data authentication module on the basis of the data server and client, identifying and handling permission management of different data storage types, the problem of inconsistent permissions in the data storage process is solved, a unified permission management solution is realized, and data management costs are reduced.

CN119939548APending Publication Date: 2025-05-06DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411851895.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, there are large differences in the data permission management methods corresponding to different data storage types in the data storage process, resulting in inconsistent permissions and increasing the cost of data management.

Method used

It provides a permission management system, including a unified client, a storage client and a server, and uses the data authentication module to perform identity authentication and storage type identification, unified client receives user data read and write instructions, and forwards operation instructions to the corresponding storage client for processing based on the authentication results and storage type.

Benefits of technology

No matter what type of data storage data is used, it can be distinguished and identified through the unified client and the data authentication module, and distributed to the corresponding storage client for data processing, solving the problem of inconsistent permissions of different storage types and reducing data management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939548A_ABST
    Figure CN119939548A_ABST
Patent Text Reader

Abstract

The invention provides an authority management system and method and electronic device.According to the authority management system, a unified client side and a data authentication module are additionally arranged on the basis of a common data server side and a client side, and when a user needs to operate data of different data storage types stored in the server side, the unified client side and the data authentication module are not needed to operate the data of different data storage types stored in the server side; a unified client receives a data read-write instruction transmitted by a user, the identity of the user is authenticated according to identity information in the data read-write instruction, if the authentication is passed, the specific data storage type is determined according to storage path information requested to be accessed by the user, and after a target data storage type is determined and obtained, the target data is stored. And forwarding the operation instruction information initiated by the user to a corresponding target client, and processing the data stored in the server based on the operation of the user by the target client. Therefore, even if the data storage types are inconsistent, authority management can be carried out according to the same authority management scheme, and the data management cost can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of database technology, and in particular to a permission management method, device and electronic device. Background Art

[0002] In the field of database technology, object storage is a method for solving and processing discrete data units, which can provide data storage services in the form of objects based on distributed data storage systems. However, due to the development of big data, the amount of data has increased dramatically, and the data types have become increasingly complex. Data storage parties will choose appropriate data storage methods for data storage. Common data storage methods include: file storage and object storage. Each data storage method has its own advantages and disadvantages.

[0003] In the actual data storage process, it is found that there are significant differences in the management methods of data permissions corresponding to different data storage types, which can easily lead to inconsistent permissions and increase data management costs. Summary of the invention

[0004] In view of this, embodiments of the present application provide a permission management method, device, and electronic device to solve the problem of high data management costs caused by inconsistent permission management in the existing data storage process.

[0005] In a first aspect, an embodiment of the present application provides a rights management system, the rights management system comprising: a unified client, a storage client, and a server, wherein a data authentication module exists between the unified client and the storage client, the storage client is connected to the server, and the server stores data stored according to various data storage types, wherein:

[0006] The unified client is used to receive data read and write instructions transmitted by a target user, wherein the data read and write instructions carry the identity information of the target user, the storage path information requested to be accessed by the target user, and the operation instruction information of the target user;

[0007] The data authentication module is used to perform identity authentication based on the identity information of the target user. If the authentication is successful, the target data storage type corresponding to the storage path information is obtained, the corresponding target storage client is determined based on the target data storage type, and the operation instruction information of the target user is forwarded to the target storage client;

[0008] The storage client is used to receive the operation instruction information distributed by the data authentication module, and process the target data stored in the server according to the data processing type corresponding to the operation instruction information.

[0009] In some possible embodiments, the data authentication module is further used to:

[0010] If the authentication fails, a warning reminder is sent to the unified client, so that the unified client outputs the warning reminder to the target user.

[0011] In some possible embodiments, the data authentication module is specifically used to:

[0012] Parsing the storage path information to obtain storage type identification information carried in the storage path information;

[0013] The target data storage type is determined according to the storage type identification information.

[0014] In some possible embodiments, the data authentication module is specifically used to:

[0015] If the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client;

[0016] The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information.

[0017] In some possible embodiments, the data authentication module is specifically used to:

[0018] If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client;

[0019] The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction.

[0020] In some possible embodiments, the storage client is specifically used to:

[0021] Parse the operation instruction information to determine the data processing type corresponding to the operation instruction, where the data processing type includes: view, modify, delete, read, write, and write.

[0022] In a second aspect, the present application provides a rights management method, which is applied to the rights management system as described in the first aspect, and the method includes:

[0023] Receive a data read / write instruction transmitted by a target user, wherein the data read / write instruction carries the identity information of the target user, the storage path information requested to be accessed by the target user, and the operation instruction information of the target user;

[0024] Identity authentication is performed based on the identity information of the target user. If the authentication is successful, the target data storage type corresponding to the storage path information is obtained, the corresponding target storage client is determined based on the target data storage type, and the operation instruction information of the target user is forwarded to the target storage client, so that the target storage client processes the target data stored in the server according to the data processing type corresponding to the operation instruction information.

[0025] In some possible embodiments, the method further includes:

[0026] If the authentication fails, a warning reminder is sent to the unified client, so that the unified client outputs the warning reminder to the target user.

[0027] In some possible embodiments, the method further includes:

[0028] Parsing the storage path information to obtain storage type identification information carried in the storage path information;

[0029] The target data storage type is determined according to the storage type identification information.

[0030] In some possible embodiments, the method further includes:

[0031] If the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client;

[0032] The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information.

[0033] In some possible embodiments, the method further includes:

[0034] If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client;

[0035] The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction.

[0036] In some possible embodiments, the method further includes:

[0037] Parse the operation instruction information to determine the data processing type corresponding to the operation instruction, where the data processing type includes: view, modify, delete, read, write, and write.

[0038] In a third aspect, an embodiment of the present application provides an electronic device, wherein the electronic device includes:

[0039] Processor; and

[0040] Memory for storing programs,

[0041] Wherein, the program includes instructions, and when the instructions are executed by the processor, the processor executes the permission management method described in the second aspect.

[0042] In a fourth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute the permission management method described in the second aspect.

[0043] Beneficial effects of this application:

[0044] The present application provides a rights management system, method and electronic device, wherein the rights management system adds a unified client and a data authentication module on the basis of an ordinary data server and client. When a user needs to operate data of different data storage types stored in the server, the unified client receives the data read and write instructions passed by the user, and authenticates the user identity according to the identity information in the data read and write instructions. If the authentication is passed, the storage path information requested by the user to access is used to determine which data storage type it belongs to. After determining the target data storage type, the operation instruction information initiated by the user is forwarded to the corresponding target client, and the target client processes the data stored in the server based on the user's operation. By selecting the embodiment of the present application, no matter what data storage type is used for storage, the unified client and data authentication module provided by the present application can be used to distinguish and identify the type, and then distributed to the corresponding storage client for data processing. In this way, even if the data storage types are inconsistent, rights management can be performed according to the same rights management scheme, which is conducive to reducing data management costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Further details, features and advantages of the present application are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:

[0046] Figure 1A schematic diagram of a system architecture of a rights management system provided by an embodiment of the present application is shown;

[0047] Figure 2 A schematic diagram of a process flow of a rights management method provided by an embodiment of the present application is shown;

[0048] Figure 3 Another schematic diagram of a process flow of a rights management method provided in an embodiment of the present application is shown;

[0049] Figure 4 A structural block diagram of an exemplary electronic device that can be used to implement an embodiment of the present application is shown. DETAILED DESCRIPTION

[0050] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not intended to limit the scope of protection of the present application.

[0051] It should be understood that the various steps described in the method implementation of the present application can be performed in different orders and / or performed in parallel. In addition, the method implementation may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this respect.

[0052] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments". Relevant definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc. mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0053] It should be noted that the modifications of "one" and "plurality" mentioned in the present application are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0054] Before describing the rights management method, device, and electronic device provided in the embodiments of the present application, the following professional terms will be described:

[0055] Object storage: Object storage service (OSS) is a method to solve and process discrete units, which can provide data storage services in the form of objects based on distributed systems. Object storage is different from the storage forms such as data blocks and files in file systems that are often encountered in the field of data storage technology. Object storage provides RESTful API data reading and writing interfaces and rich SDK interfaces, and often provides data access in the form of network services.

[0056] HDFS: HDFS (Hadoop Distributed File System) is an easily scalable distributed file system that runs on hundreds or thousands of low-cost machines. It is a system tool for storing data and is highly fault-tolerant.

[0057] Ranger security management framework: Ranger is an open source, centralized security management framework that is used to perform fine-grained data access control on various components in the Hadoop ecosystem (such as HDFS, Hive, HBase, Yarn, etc.). Ranger provides a centralized security management interface, and users can configure various policies by operating the Ranger console to achieve security management of Hadoop ecosystem components.

[0058] With the development of big data technology, data is becoming an increasingly important asset for individuals and enterprises. Especially for enterprises, the data involved in daily life is becoming more and more complex. The types of data that enterprises are likely to involve in daily life include: internal data, external data, real-time data, offline batch data, structured data, semi-structured data, and unstructured data. According to the characteristics of different data, enterprises will choose appropriate storage methods for data storage. Among them, the commonly used data storage methods are: file storage and object storage, which are gradually becoming the mainstream data storage types. Each data storage type has its specific advantages and applicable scenarios. Therefore, in the actual application process, enterprises will choose multiple data storage types for data storage at the same time, but the storage types are different, and the corresponding data permissions are also managed differently. Specifically:

[0059] The permission management methods of object storage include: Access Control List (ACL) and Policy. Among them:

[0060] Access control list (ACL) is a permission filtering method based on bucket dimension, which can grant data read and write permissions to other users. ACL rules are composed of multiple AC (Access Control) rules, which contain two structures: grantee authorization object and permission. Among them, grantee authorization objects are divided into two categories: user user and user group group. Among them, when the grantee authorization object is user user, the authorized user is the user registered in the system. When the grantee authorization object is user group group, it means that the authorization object is a group. Currently, only group QS_ALL_USERS is supported, that is, the authorization object is all users. At this time, the user can be a user registered in the system or a user not registered in the system (that is, an anonymous user who skips user identity authentication). In addition, the ACL control granularity is relatively rough and simple. Specifically, access control is performed at the user level, which determines who can use the bucket with what data permissions.

[0061] Policy is a permission filter based on resource dimensions, which can grant read and write permissions to other users. Among them, Policy rules are composed of multiple Statements, and Statement contains two structures: Principal authorization objects and Action permissions. Specifically, Principal authorization objects are divided into two categories: AWS (Amazon Web Services) accounts and IAM (Identity and Access Management) accounts. Compared with the coarse granularity of ACL control, Policy can provide more refined permission control. Specifically, Policy can control access rights to data in a bucket. Among them, Action is a data operation, such as GetObject, PutObject and other data operations. Among them, Policy control has a more detailed granularity, which is to perform access control at the resource level to determine who can use the bucket with what permissions.

[0062] The permission management methods for file storage include: user identity authentication, user group mapping, data authorization, and umask permission management. Among them:

[0063] User identity authentication: HDFS is not responsible for checking the legitimacy of user identities. It relies on related systems to obtain user identities for subsequent authentication.

[0064] User group mapping: HDFS obtains the mapping relationship between users and groups through an external Group Mapping service. You can use the system's own solution or a third-party service such as LDAP (Lightweight Directory Access Protocol).

[0065] Data authorization (data rights management): HDFS file permissions are similar to the UGO (Database and Application Migration) model of Linux / Unix systems. UGO permission management can be used to control access to files and directories.

[0066] Umask permission management: The umask in HDFS is used to set the permission bits of newly created files and directories in HDFS by default.

[0067] It can be seen that different data storage types require different permission management methods. For enterprises or organizations that need to use multiple storage types, if each storage type has a separate permission management method, it is very easy to lead to high data management costs due to inconsistent permissions.

[0068] In view of this, the present application provides a rights management system, method and electronic device, wherein the rights management system can be an integrated data system. In some embodiments, the rights management system 10 can be as follows: Figure 1 As shown, it includes the following parts:

[0069] Unified client 11, data authentication module 12, storage client 13, server 14.

[0070] The data authentication module is located between the unified client and the storage client, which is connected to the server, and the server stores data stored in various data storage types.

[0071] The unified client is used to receive data read and write instructions transmitted by a target user, wherein the data read and write instructions carry the identity information of the target user, the storage path information requested to be accessed by the target user, and the operation instruction information of the target user;

[0072] The data authentication module is used to perform identity authentication based on the identity information of the target user. If the authentication is successful, the target data storage type corresponding to the storage path information is obtained, the corresponding target storage client is determined based on the target data storage type, and the operation instruction information of the target user is forwarded to the target storage client;

[0073] The storage client is used to receive the operation instruction information distributed by the data authentication module, and process the target data stored in the server according to the data processing type corresponding to the operation instruction information.

[0074] The rights management system provided by the present application adds a unified client and a data authentication module on the basis of an ordinary data server and client. When a user needs to operate data of different data storage types stored in the server, the unified client receives the data read and write instructions input by the user, and authenticates the user identity according to the identity information in the data read and write instructions. If the authentication is successful, the specific data storage type is determined according to the storage path information requested by the user. After determining the target data storage type, the operation instruction information initiated by the user is forwarded to the corresponding target client, and the target client processes the data stored in the server based on the user's operation.

[0075] By using the embodiment of the present application, no matter what data storage type is used for data storage, the unified client and data authentication module provided by the present application can be used to distinguish and identify the type, and then the corresponding storage client can be distributed for data processing. In this way, even if the data storage types are inconsistent, the same permission management scheme can be used for permission management, which is conducive to reducing data management costs.

[0076] The following will explain in detail the various parts of the above permission management system with specific examples:

[0077] Among them, in the embodiments of the present application, the client, the server, and the data authentication module are all collectively referred to as specific parts of the entire data system. As an example, the functional module used to interact with the user and obtain the information input by the user is the client, and the server is the collective name of the entire back-end database that stores data. The data authentication module is a functional module set by the developer between the unified client and the storage client.

[0078] In the embodiment of the present application, the specific installation location of the unified client and the storage client can be flexibly adjusted according to actual needs, and can be installed in the user device or in the database system. As a preferred implementation, the unified client and the storage client can be installed in the user device, and then interact with the data authentication module located in the database through the specified API data interface. As described above, the server is a general term for the backend database, and interacts with the client and the data authentication module through the specified API interface.

[0079] In an embodiment of the present application, the unified client has a user interaction interface, and the user can input corresponding information according to his own needs on the user interaction interface provided by the unified client. The unified client can summarize the information input by the user to obtain data reading and writing instructions.

[0080] Exemplarily, the user can enter his or her identity information, the target data to be accessed, and the type of data processing operation required for the target data on the user interaction interface of the unified client. The identity information can be a user ID or a user group ID, wherein the user group ID can be used by each user belonging to the user group. In an embodiment of the present application, the unified client can also be used to perform an initial query based on the target data accessed by the user, determine the specific storage path of the target data, and then generate a storage path requested by the user to access based on the specific storage path. The types of data processing operations required for the target data include: viewing, deleting, modifying, reading, and writing. The unified client can generate a corresponding data authentication request according to the specified message format using the acquired identity information, storage path, and data processing operation type, and send the data authentication request to the data authentication module.

[0081] The main function of the data authentication module is to authenticate the user identity to ensure the data security in the back-end database. As an implementation method, the data authentication module performs identity authentication based on the user ID of the user, and determines whether the user ID is a user ID in the white list. If so, the authentication is passed. If not, the authentication is not passed. As another implementation method, the data authentication module performs identity authentication based on the user group ID of the user, so that the workload required for authentication can be reduced. If the user group ID of the user is a user group ID in the white list, the authentication is passed, if not, the authentication is not passed. In an embodiment of the present application, the white list refers to a user list or user group list that has been authorized in advance. As another implementation method, the data authentication module can authenticate the user identity based on the user ID of the user in combination with the user password. If the user ID entered by the user is paired with the password entered by the user, the user authentication is passed, and if not, the user authentication is not passed.

[0082] In an embodiment of the present application, if the data authentication module fails to authenticate the user identity, an early warning reminder may be sent to the unified client, so that the unified client outputs the early warning reminder to the target user so that the target user can check or modify the user information input by himself.

[0083] In some possible embodiments, some functions of the data authentication module can be migrated to the unified client, and the unified client can authenticate the user. If the authentication is successful, the storage path information requested by the target user and the target user's operation instruction information are further forwarded to the data authentication module. If the authentication fails, an early warning reminder is directly output to remind the target user to check or modify the information he / she input. As a possible implementation method, if the unified client authenticates the user, the user ID, user password and short-term verification code can be used for verification to improve the security of the entire back-end data.

[0084] In some embodiments, the data authentication module is specifically used to:

[0085] Parsing the storage path information to obtain storage type identification information carried in the storage path information;

[0086] The target data storage type is determined according to the storage type identification information.

[0087] In an embodiment of the present application, the storage path information can be parsed by taking the slash " / " as the storage path parsing benchmark for the entire storage path, extracting the information between each slash line, and obtaining each field included in the entire storage path information. Among them, each field contained in the storage path information includes storage type identification information, and the core of the storage type identification information is used to identify different storage paths. Exemplarily, in the storage path: hdfs / home / user01 / dir, hdfs is the entire storage type identification information, which is used to identify that the target data is stored in the HDFS storage mode. Based on this, the target data storage type of the target data can be quickly determined according to the storage type identification information carried in the storage path information. As an implementation method, if the storage type of the data is object storage, there will be no storage type identification information in the result obtained by parsing the entire storage path information. At this time, if there is no storage type identification information, it indicates that the storage type of the target data is object storage.

[0088] Based on this, the data authentication module also takes into account the task of distributing user operation instructions. After the data authentication module determines the target data storage type corresponding to the storage path information, it can directly determine the corresponding target storage client based on the target data storage type. At this time, the user's operation instruction information is forwarded to the corresponding target storage client. For the target storage client, the actions performed are no different from those of ordinary storage clients. They all determine the corresponding data processing type based on the received operation instruction information, and process the target data stored in the server according to the data processing type.

[0089] In some possible embodiments, if the data storage type is a file storage type, the data authentication module is specifically used to:

[0090] If the target data storage type is file storage (i.e., HDFS type), the target user's operation instruction information is forwarded to the HDFS client;

[0091] The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information.

[0092] If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client;

[0093] The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction.

[0094] In the embodiment of the present application, the operation instruction information carries the storage path information of the target data and the permission information of the target user. The permission information of the target user specifically refers to the processing permission information for the target data, including: read-only permission, write-only permission, read-write permission, only viewable but not readable permission, etc.

[0095] In some embodiments, the specified field in the operation instruction information is used to indicate the data processing type, and the specific data processing types include: view, modify, delete, read, and write. Based on this, in some embodiments, each storage client is specifically used to:

[0096] Analyze the operation instruction information, determine the data processing type corresponding to the operation instruction, and determine whether the data processing type required by the user is view, modify, delete, read, or write.

[0097] Based on this, Figure 2 As shown, if the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client, and the HDFS client writes the storage path information to the Ranger console. The Ranger console performs a secondary check on the target user's processing permission information and determines whether the user's specific data processing type is to read, write, modify or delete the target data. Then, the data under the storage path in the database is adaptively processed according to the specific data processing type.

[0098] If the target data storage type is object storage, the target user's operation instruction information is forwarded to the object storage client, and the object storage client writes the storage path information and the target user's permission information to the object storage service client, and the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction. Among them, the target user's permission information specifically refers to the processing permission information for the target data, including: read-only permission, write-only permission, readable and writable permission, only viewable but not readable permission, etc. Then, based on the user's permission information, the data under the storage path in the database is adaptively processed according to the specific data processing type.

[0099] As an implementation method, the HDFS storage client or object storage client can perform secondary authentication based on the user data permission information carried in the operation instruction information. If the user data permission information previously assigned to the target user is read-only, if the user data permission information in the operation instruction passed by the target user is write, the user cannot write to the target data, which means that the secondary authentication failed. At this time, an early warning reminder can also be output to the user, and the specific failure type can be carried in the early warning reminder so that the user can modify his or her own user data permission information. As an implementation method, the HDFS storage client or object storage client is not responsible for secondary authentication of user data permission information. The Ranger console or object storage service client can perform secondary authentication. Who is responsible for the secondary authentication can be flexibly set according to the actual hardware resource usage, and this application does not make strict restrictions.

[0100] As an example, take a user's read operation on a file as an example: the user uses the unified client to execute the command to view a certain path; the unified client transmits the user identity information, access path information and file operation instruction information to the data authentication module; if the authentication fails, a prompt message indicating that the permission is not passed is returned to the unified client. If the authentication passes, a request to read a certain path information is sent to the server of the storage system, and the server returns the request result to the client, and the user views the file.

[0101] By selecting the embodiment of the present application, even if the enterprise uses multiple storage types for data storage, the permission management system provided by the present application can be adopted, and a unified client and a unified data authentication module can be used to identify the storage type and distribute the corresponding user operation instructions, thereby solving the problem of inconsistent permissions when multiple types of storage solutions are mixed, and reducing the cost consumption caused by inconsistent permissions.

[0102] Based on the discussion of the first aspect, in the second aspect, the present application provides a rights management method, which is applied to any electronic device with a rights management function, and the types of electronic devices include but are not limited to personal mobile terminals, computers or servers, etc. As a preferred implementation, the rights management method can be applied to the rights management system described in the first aspect. In some embodiments, Figure 3 As shown, the method comprises the following steps:

[0103] S31, receiving a data read / write instruction from a target user, wherein the data read / write instruction carries the identity information of the target user, the storage path information requested by the target user to access, and the operation instruction information of the target user;

[0104] S32, performing identity authentication based on the identity information of the target user, if the authentication is successful, executing step S33; executing step S34;

[0105] S33, obtaining a target data storage type corresponding to the storage path information, determining a corresponding target storage client based on the target data storage type, and forwarding the target user's operation instruction information to the target storage client;

[0106] The target storage client processes the target data stored in the server according to the data processing type corresponding to the operation instruction information.

[0107] S34: Sending a warning reminder to the unified client, so that the unified client outputs the warning reminder to the target user.

[0108] In some possible embodiments, the method further includes:

[0109] Parsing the storage path information to obtain storage type identification information carried in the storage path information;

[0110] The target data storage type is determined according to the storage type identification information.

[0111] In some possible embodiments, the method further includes:

[0112] If the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client;

[0113] The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information.

[0114] In some possible embodiments, the method further includes:

[0115] If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client;

[0116] The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction.

[0117] In some possible embodiments, the method further includes:

[0118] Parse the operation instruction information to determine the data processing type corresponding to the operation instruction, where the data processing type includes: view, modify, delete, read, write, and write.

[0119] Among them, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with the relevant laws and regulations and do not violate public order and good morals.

[0120] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0121] In a third aspect, the exemplary embodiments of the present application further provide an electronic device, comprising: at least one processor; and a memory connected to the at least one processor in communication. The memory stores a computer program that can be executed by the at least one processor, and the computer program is used to enable the electronic device to perform a method according to an embodiment of the present application when executed by the at least one processor.

[0122] The exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to perform a method according to an embodiment of the present application.

[0123] The exemplary embodiments of the present application further provide a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to enable the computer to execute the method according to the embodiment of the present application.

[0124] refer to Figure 4, the structural block diagram of the electronic device 400 that can be used as the server or client of the present application will now be described, which is an example of the hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer equipment, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples, and are not intended to limit the implementation of the present application described and / or required herein.

[0125] like Figure 4 As shown, the electronic device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0126] A plurality of components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, an output unit 407, a storage unit 408, and a communication unit 409. The input unit 406 may be any type of device capable of inputting information to the electronic device 400, and the input unit 406 may receive input digital or character information, and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 407 may be any type of device capable of presenting information, and may include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 408 may include, but is not limited to, a disk, an optical disk. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks, and may include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth™ device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0127] The computing unit 401 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 401 performs the various methods and processes described above. For example, in some embodiments, the aforementioned rights management method may be implemented as a computer software program, which is tangibly included in a machine-readable medium, such as a storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 400 via the ROM 402 and / or the communication unit 409. In some embodiments, the computing unit 401 may be configured to perform the aforementioned rights management method in any other appropriate manner (e.g., by means of firmware).

[0128] The program code for implementing the method of the present application can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, implements the functions / operations specified in the flow chart and / or block diagram. The program code can be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0129] In the context of the present application, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0130] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0131] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0132] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0133] A computer system may include clients and servers. Clients and servers are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship to each other.

Claims

1. A rights management system, characterized in that: The rights management system includes: a unified client, a storage client, and a server, wherein a data authentication module exists between the unified client and the storage client, the storage client is connected to the server, and the server stores data stored according to various data storage types, wherein: The unified client is used to receive data read and write instructions transmitted by a target user, wherein the data read and write instructions carry the identity information of the target user, the storage path information requested to be accessed by the target user, and the operation instruction information of the target user; The data authentication module is used to perform identity authentication based on the identity information of the target user. If the authentication is successful, the target data storage type corresponding to the storage path information is obtained, the corresponding target storage client is determined based on the target data storage type, and the operation instruction information of the target user is forwarded to the target storage client; The storage client is used to receive the operation instruction information distributed by the data authentication module, and process the target data stored in the server according to the data processing type corresponding to the operation instruction information.

2. The system according to claim 1, characterized in that The data authentication module is also used for: If the authentication fails, a warning reminder is sent to the unified client, so that the unified client outputs the warning reminder to the target user.

3. The system according to claim 1, characterized in that The data authentication module is specifically used for: Parsing the storage path information to obtain storage type identification information carried in the storage path information; The target data storage type is determined according to the storage type identification information.

4. The system according to any one of claims 1 or 3, characterized in that: The data authentication module is specifically used for: If the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client; The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information.

5. The system according to any one of claims 1 or 3, characterized in that: The data authentication module is specifically used for: If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client; The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction.

6. The system according to claim 1, characterized in that The storage client is specifically used for: The operation instruction information is parsed to determine the data processing type corresponding to the operation instruction, where the data processing type includes: viewing, modifying, deleting, reading, and writing.

7. A rights management method, characterized in that: The method is applied to the rights management system according to any one of claims 1 to 6, and the method comprises: Receive a data read / write instruction transmitted by a target user, wherein the data read / write instruction carries the identity information of the target user, the storage path information requested to be accessed by the target user, and the operation instruction information of the target user; Identity authentication is performed based on the identity information of the target user. If the authentication is successful, the target data storage type corresponding to the storage path information is obtained, the corresponding target storage client is determined based on the target data storage type, and the operation instruction information of the target user is forwarded to the target storage client, so that the target storage client processes the target data stored in the server according to the data processing type corresponding to the operation instruction information.

8. The method according to claim 7, characterized in that The method further comprises: If the authentication fails, sending a warning reminder to the unified client, so that the unified client outputs the warning reminder to the target user; Parsing the storage path information to obtain storage type identification information carried in the storage path information; Determining the target data storage type according to the storage type identification information; If the target data storage type is file storage, the target user's operation instruction information is forwarded to the HDFS client; The HDFS client is used to write the storage path information and the permission information of the target user to the Ranger console, so that the Ranger console processes the target data stored in the server based on the data processing type corresponding to the operation instruction information; If the target data storage type is object storage, forwarding the target user's operation instruction to the object storage client; The object storage client is used to write the storage path information and the permission information of the target user to the object storage service client, so that the object storage service client processes the target data stored in the object storage service client based on the data processing type corresponding to the operation instruction; The operation instruction information is parsed to determine the data processing type corresponding to the operation instruction, where the data processing type includes: viewing, modifying, deleting, reading, and writing.

9. An electronic device, characterized in that: The electronic device comprises: Processor; and Memory for storing programs, The program comprises instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 7 to 8.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to make a computer execute the method according to any one of claims 7-8.