Multi-tenant management method, management platform and storage medium

By building a tenant tree structure based on project resource permissions and binding users and tenants, the problem that the existing multi-tenant management structure needs to be re-planned when the organization changes is implemented is solved, and a more flexible and easy-to-use multi-tenant management method is realized.

CN119946077AActive Publication Date: 2025-05-06CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202311443266.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-05-06
Estimated Expiration
2043-11-01

AI Technical Summary

Technical Problem

The existing multi-tenant management structure is usually based on the enterprise administrative organizational structure, which requires re-planning and setting up the multi-tenant management structure when changes and adjustments are made. The operation is cumbersome and inconvenient.

Method used

By obtaining multi-tenant management requests, including resource permission information for multiple projects and user project information, a tenant tree structure is built and corresponding resource permissions are configured for each tenant. Determine the tenant to which the user belongs based on the user's project information and bind the user to the tenant to which he belongs, so that the user can obtain resource permissions of the tenant to which he belongs.

Benefits of technology

The flexibility and ease of use of multi-tenant management architecture are realized, and the tedious work of re-planning of the multi-tenant management architecture is avoided when the organization changes, and the user's resource permissions can continue to remain unchanged.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946077A_ABST
    Figure CN119946077A_ABST
Patent Text Reader

Abstract

The invention provides a multi-tenant management method, a management platform and a storage medium. The method comprises the following steps: acquiring a multi-tenant management request, wherein the multi-tenant management request comprises resource authority information of a plurality of projects and project information of a plurality of users; constructing a tenant tree structure according to the resource permission information of the plurality of projects, and configuring a corresponding resource permission for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure comprises at least one item; and according to the item information of each user, determining a tenant to which the user belongs, and binding the user with the tenant to which the user belongs, so that the user obtains the resource authority of the tenant to which the user belongs. According to the method provided by the invention, a more flexible and easy-to-operate multi-tenant management method is realized, and the business requirements under the change and adjustment of administrative organizations are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing technology, and in particular to a multi-tenant management method, management platform and storage medium. Background Art

[0002] Multi-tenancy technology is a software architecture technology used to enable multiple users to share the same system or program components and ensure data isolation between users. In cloud computing platforms, tenants usually serve as carriers of data or resources, while users are the actual users of the data or resources under the tenants.

[0003] The existing multi-tenant management architecture is usually based on the corporate administrative organization. Once the organization changes, the corresponding platform tenant system and resource division need to be re-planned, adding a lot of tedious and complicated work; and when the user's tenant changes, the user's corresponding resource permissions will also change. However, in many cases, although the user's position in the organization has changed, based on business needs, they hope to continue the previous resource permissions, which requires special settings for the user, which is complicated and inconvenient.

[0004] There is an urgent need for a more flexible and easy-to-operate multi-tenant management method to meet business needs under changes and adjustments in administrative organizations. Summary of the invention

[0005] The present application provides a multi-tenant management method, management platform and storage medium to solve the technical problem that the existing technology constructs a multi-tenant management architecture based on the enterprise administrative organization, which leads to complex and cumbersome re-planning and setting of the multi-tenant management architecture when the administrative organization changes and adjusts.

[0006] In a first aspect, the present application provides a multi-tenant management method, comprising: obtaining a multi-tenant management request, the multi-tenant management request including resource permission information of multiple projects and project information of multiple users; constructing a tenant tree structure based on the resource permission information of the multiple projects, and configuring corresponding resource permissions for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one of the projects; determining the tenant to which the user belongs based on the project information of each user, and binding the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs.

[0007] Optionally, the method as described above, constructing a tenant tree structure based on the resource permission information of the multiple projects, includes: for each of the projects, determining whether the resource permissions of the project are the same as the resource permissions of other projects; if the resource permissions of the project are different from the resource permissions of other projects, treating the project as a tenant; if the resource permissions of the project are the same as the resource permissions of at least one other project, merging the projects with the same resource permissions to form a tenant; for each tenant, setting the tenant level of the tenant according to the resource permissions of the tenant to construct a tenant tree structure; wherein the resource permissions of each level of tenants in the tenant tree structure are greater than the resource permissions of the tenants at the next level.

[0008] Optionally, as described above, configuring corresponding resource permissions for each tenant in the tenant tree structure includes: for each tenant, obtaining a cloud account associated with the resource permissions of the tenant; binding the tenant to the cloud account so that the tenant obtains the corresponding resource permissions.

[0009] Optionally, in the method as described above, determining the tenant to which the user belongs based on the project information of each user includes: for each user, determining the project to which the user belongs based on the project information of the user; and determining the tenant to which the project is located to determine the tenant to which the user belongs.

[0010] Optionally, as described above, the method further includes: obtaining a tenant binding request sent by the user, the tenant binding request including a tenant identifier to be bound; sending a binding confirmation request to the tenant corresponding to the tenant identifier to be bound, and upon obtaining confirmation information fed back by the tenant, binding the user to the tenant corresponding to the tenant identifier to be bound, so that the user obtains resource permissions of the tenant.

[0011] Optionally, the method as described above further includes: for each of the users, obtaining the user's operation permission information, and querying the role corresponding to the operation permission information; binding the user to the role so that the user obtains the operation permission corresponding to the operation permission information.

[0012] Optionally, as described above, the method further includes: obtaining a role binding request sent by a user, the role binding request including an identifier of a role to be bound; unbinding the user from the role to which the user is currently bound, and binding the user to the role corresponding to the identifier of the role to be bound, so that the user obtains the operation authority of the role corresponding to the identifier of the role to be bound.

[0013] In a second aspect, the present application provides a multi-tenant management platform, including: an acquisition module, used to obtain a multi-tenant management request, the multi-tenant management request including resource permission information of multiple projects and project information of multiple users; a processing module, used to construct a tenant tree structure based on the resource permission information of the multiple projects, and configure corresponding resource permissions for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one of the projects; the processing module is also used to determine the tenant to which the user belongs based on the project information of each user, and bind the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs.

[0014] In a third aspect, the present application provides a multi-tenant management platform, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the multi-tenant management method as described in the first aspect.

[0015] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer execution instructions, and when the computer execution instructions are executed by a processor, they are used to implement the multi-tenant management method as described in the first aspect.

[0016] The present application provides a multi-tenant management method, management platform and storage medium, obtains a multi-tenant management request, the multi-tenant management request includes resource permission information of multiple projects, and project information of multiple users; constructs a tenant tree structure according to the resource permission information of multiple projects, and configures corresponding resource permissions for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one project; determines the tenant to which the user belongs according to the project information of each user, and binds the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs. Compared with the prior art that constructs a multi-tenant management architecture based on the administrative organization of the enterprise, the present application constructs a tenant tree structure according to the resource permission information of the project, and binds the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs. In this way, the construction of the multi-tenant management architecture has nothing to do with the organizational structure, so when the organizational structure changes, there is no need to re-plan the multi-tenant management architecture, and the tenant to which the user belongs does not need to change, and the previous resource permissions can be continued, avoiding a lot of tedious and complicated work. A more flexible and easy-to-operate multi-tenant management method is realized, which meets the business needs under the changes and adjustments of administrative organizations. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0018] Figure 1 A schematic diagram of a multi-tenant management architecture in the prior art;

[0019] Figure 2 A flowchart of a multi-tenant management method embodiment 1 provided in an embodiment of the present application;

[0020] Figure 3 A schematic diagram of a multi-tenant management architecture provided for an embodiment of the present application;

[0021] Figure 4 A flowchart of a second embodiment of a multi-tenant management method provided in an embodiment of the present application;

[0022] Figure 5 A flowchart of a third embodiment of a multi-tenant management method provided in an embodiment of the present application;

[0023] Figure 6 A flowchart of a fourth embodiment of a multi-tenant management method provided in an embodiment of the present application;

[0024] Figure 7 A schematic diagram of the structure of a multi-tenant management platform embodiment provided in an embodiment of the present application;

[0025] Figure 8 A schematic diagram of the structure of another multi-tenant management platform embodiment provided in an embodiment of the present application.

[0026] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0027] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0028] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0029] The specific application scenario of this application is a multi-tenant management platform. Multi-tenant technology is a software architecture technology used to achieve the same system or program components in multi-user scenarios and ensure data isolation between users. In a cloud computing platform, tenants usually serve as carriers of data or resources, and users are the actual users of data or resources under the tenant.

[0030] Existing multi-tenant management architectures are usually based on corporate administrative organizations. Figure 1 The figure is a schematic diagram of a multi-tenant management architecture in the prior art. Figure 1 The left diagram in the figure is the administrative organization structure of a certain enterprise, in which the first-level organization is the group company, the second-level organization is subsidiary A and subsidiary B, ..., the fifth-level organization is department a and department b, and there are multiple users under the department. Figure 1 The right diagram in the figure is a multi-tenant management architecture diagram established according to the administrative organization of the enterprise. The group company is regarded as the first-level tenant, subsidiary A and subsidiary B are regarded as second-level tenant A and second-level tenant B, and so on. Department A and department B are regarded as fifth-level tenant A and fifth-level tenant B, respectively. Users under each tenant enjoy the resource permissions of the tenant.

[0031] However, the administrative organization of an enterprise will continue to change with the development of the enterprise. Once the organization changes, the corresponding platform tenant system and resource division need to be re-planned, adding a lot of tedious and complicated work; and when the user's tenant changes, the user's corresponding resource permissions will also change. However, in many cases, although the user's position in the organization has changed, based on business needs, they hope to continue the previous resource permissions. This requires special settings for the user, which is complicated and inconvenient.

[0032] Based on the above technical problems, the technical concept of this application is: how to provide a more flexible and easy-to-operate multi-tenant management method to meet the business needs under the changes and adjustments of administrative organizations.

[0033] The multi-tenant management method provided in this application is intended to solve the above technical problems in the prior art.

[0034] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0035] Figure 2 A flowchart of a multi-tenant management method embodiment 1 provided in the present application is shown in FIG. Figure 2 , the multi-tenant management method comprises the following steps:

[0036] Step S201: obtaining a multi-tenant management request, where the multi-tenant management request includes resource permission information of multiple projects and project information of multiple users.

[0037] In this embodiment, the multi-tenant management platform builds a multi-tenant management architecture based on the resource permissions of the project. For example, the project can be a business project, such as a research and development project; it can also be an organization, such as a research and development department or a research and development team. Each project can include multiple users, and for example, the users can be managers and developers.

[0038] The multi-tenant management platform may obtain a multi-tenant management request, which may include resource permission information of multiple projects and project information of multiple users. The resource permission information indicates the resources that can be used by the project, and specifically, the resources may include computing resources, storage resources, and network resources. The user's project information may indicate the project to which the user belongs.

[0039] Step S202: construct a tenant tree structure according to the resource permission information of the multiple projects, and configure corresponding resource permissions for each tenant in the tenant tree structure.

[0040] Each tenant in the tenant tree structure includes at least one project.

[0041] In this embodiment, the multi-tenant management platform can construct a tenant tree structure based on the resource permission information of multiple projects. Figure 3 Schematic diagram of a multi-tenant management architecture provided for an embodiment of the present application. For example, the resource permission information of multiple projects may indicate that the resources available to "R&D team 1" are "computing resources A", the resources available to "R&D team 2" are "computing resources B", the resources available to "R&D team 3" are "computing resources A", the resources available to "R&D team 4" are "computing resources B", and the resources available to "R&D team 5" are "computing resources C".

[0042] "R&D Team 1" and "R&D Team 3" with the same resource permissions can be merged to form "Tenant A"; "R&D Team 2" and "R&D Team 4" can be merged to form "Tenant B"; "R&D Team 5" has different resource permissions from other projects, so "R&D Team 5" is "Tenant C".

[0043] The "R&D Department" has the right to use all resources, so the "R&D Department" can be regarded as a first-level tenant; the resource permissions of "R&D Project 1" are "Computing Resources A" and "Computing Resources B", so "R&D Project 1" is the parent tenant of "Tenant A" and "Tenant B"; the resource permissions of "R&D Project 2" are "Computing Resources C" and "Computing Resources D", so "R&D Project 2" is the parent tenant of "Tenant C"; "R&D Project 1" and "R&D Project 2" are both second-level tenants; "Tenant A", "Tenant B" and "Tenant C" are all third-level tenants.

[0044] After the tenant tree structure is constructed, corresponding resource permissions can be configured for each tenant in the tenant tree structure. Exemplarily, resource permissions can be configured by binding tenants to cloud accounts. Each resource available to a tenant corresponds to a cloud account. By obtaining a cloud account associated with the tenant's resource permissions and binding the tenant to the cloud account, corresponding resource permissions can be configured for the tenant.

[0045] Step S203: According to the project information of each user, the tenant to which the user belongs is determined, and the user is bound to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs.

[0046] In this embodiment, the user information may indicate the project to which the user belongs. When the project is a business project, the user information may indicate the business project to which the user belongs, such as the aforementioned "R&D Project 1" or "R&D Project 2"; when the project is an organization, the user information may indicate the organization to which the user belongs, such as the aforementioned "R&D Department" or "R&D Team 1".

[0047] After the tenant tree structure is constructed, the tenant to which the user belongs can be determined based on the project information of each user. For example, the project to which the user belongs can be determined based on the user's project information, and after determining the tenant to which the project belongs, the tenant to which the user belongs can be determined. By binding the user to the tenant to which he belongs, each user can obtain the resource permissions of the tenant to which he belongs.

[0048] In this embodiment, the multi-tenant management platform obtains a multi-tenant management request, which includes resource permission information of multiple projects and project information of multiple users; according to the resource permission information of multiple projects, a tenant tree structure is constructed, and corresponding resource permissions are configured for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one project; according to the project information of each user, the tenant to which the user belongs is determined, and the user is bound to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs. Compared with the prior art that constructs a multi-tenant management architecture based on the administrative organization of the enterprise, the present application constructs a tenant tree structure based on the resource permission information of the project, and binds the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs. In this way, the construction of the multi-tenant management architecture has nothing to do with the organizational structure. Therefore, when the organizational structure changes, there is no need to re-plan the multi-tenant management architecture, and the tenant to which the user belongs does not need to be changed. The previous resource permissions can be continued, avoiding a lot of tedious and complicated work. A more flexible and easy-to-operate multi-tenant management method is realized, which meets the business needs under the changes and adjustments of administrative organizations.

[0049] Figure 4 A flowchart of a second embodiment of a multi-tenant management method provided in the present application is shown in FIG. Figure 4 , the above step S202 includes the following steps:

[0050] Step S401: for each project, determine whether the resource permissions of the project are the same as the resource permissions of other projects; if not, execute step S402; if yes, execute step S403.

[0051] Step S402: If the resource permissions of the project are different from those of other projects, the project is regarded as a tenant.

[0052] Step S403: If the resource permissions of the project are the same as the resource permissions of at least one other project, the projects with the same resource permissions are merged to form one tenant.

[0053] In this embodiment, the multi-tenant management platform can construct a tenant tree structure based on the resource permission information of multiple projects. For example, multiple projects can include organizations, such as "R&D Department", "R&D Team 1", "R&D Team 2", "R&D Team 3", "R&D Team 4" and "R&D Team 5", and can also include business projects, such as "R&D Project 1" and "R&D Project 2".

[0054] The resource permission information of each project can indicate the resources it can use. For example, the "R&D Department" has the right to use all resources, the resources available to "R&D Team 1" are "Computing Resources A", the resources available to "R&D Team 2" are "Computing Resources B", the resources available to "R&D Team 3" are "Computing Resources A", the resources available to "R&D Team 4" are "Computing Resources B", and the resources available to "R&D Team 5" are "Computing Resources C", the resource permissions of "R&D Project One" are "Computing Resources A" and "Computing Resources B", and the resource permissions of "R&D Project Two" are "Computing Resources C" and "Computing Resources D".

[0055] For each project, you can determine whether the resource permissions of the project are the same as those of other projects. If the resource permissions of the project are different from those of other projects, the project will be treated as a tenant. If the resource permissions of the project are the same as those of at least one other project, the projects with the same resource permissions will be merged to form a tenant.

[0056] As mentioned in the previous example, the resource permissions of "R&D Team 5" are different from those of other projects. "R&D Team 5" can be treated as an independent tenant "Tenant C"; "R&D Team 1" and "R&D Team 3" have the same resource permissions, so "R&D Team 1" and "R&D Team 3" can be merged to form "Tenant A"; "R&D Team 2" and "R&D Team 4" have the same resource permissions, so "R&D Team 2" and "R&D Team 4" can be merged to form "Tenant B".

[0057] Step S404: For each tenant, the tenant level of the tenant is set according to the resource authority of the tenant to construct a tenant tree structure.

[0058] The resource permissions of each level of tenants in the tenant tree structure are greater than the resource permissions of the next level of tenants.

[0059] In this embodiment, for each tenant, the tenant level of the tenant can be set according to the resource authority of the tenant to construct a tenant tree structure, and the resource authority of each level of tenant is greater than the resource authority of the tenant at the next level.

[0060] As mentioned in the previous example, the "R&D Department" has the right to use all resources, so the "R&D Department" can be regarded as a first-level tenant; the resource permissions of "R&D Project 1" are "Computing Resources A" and "Computing Resources B", so "R&D Project 1" is the parent tenant of "Tenant A" and "Tenant B"; the resource permissions of "R&D Project 2" are "Computing Resources C" and "Computing Resources D", so "R&D Project 2" is the parent tenant of "Tenant C"; "R&D Project 1" and "R&D Project 2" are both second-level tenants; "Tenant A", "Tenant B" and "Tenant C" are all third-level tenants.

[0061] Step S405: For each tenant, obtain the cloud account associated with the resource authority of the tenant.

[0062] Step S406: Bind the tenant to the cloud account so that the tenant obtains corresponding resource permissions.

[0063] After the tenant tree structure is constructed, corresponding resource permissions can be configured for each tenant in the tenant tree structure. Specifically, resource permissions can be configured by binding tenants to cloud accounts. Each resource available to a tenant corresponds to a cloud account. For each tenant, a cloud account associated with the tenant's resource permissions can be obtained, and the tenant can be bound to the cloud account to configure corresponding resource permissions for the tenant.

[0064] In this embodiment, the multi-tenant management platform constructs a tenant tree structure based on the resource permission information of the project, and binds the tenant to the cloud account associated with the resource permission so that the tenant obtains the corresponding resource permission. In this way, the construction of the multi-tenant management architecture is independent of the organizational structure, so when the organizational structure changes, there is no need to re-plan, avoiding a lot of tedious and complicated work. It further realizes a more flexible and easy-to-operate multi-tenant management method to meet the business needs under the changes and adjustments of administrative organizations.

[0065] Figure 5 A flowchart of a multi-tenant management method embodiment 3 provided in the present application is shown in FIG. Figure 5 , the above step S203 specifically includes the following steps:

[0066] Step S501: For each user, determine the project to which the user belongs based on the project information of the user.

[0067] Step S502: Determine the tenant to which the project belongs, so as to determine the tenant to which the user belongs.

[0068] In this embodiment, the project information of the user may indicate the project to which the user belongs. Exemplarily, the project information of the user may indicate that the project to which the user belongs is an organization, such as "R&D Department", "R&D Team 1", "R&D Team 2", "R&D Team 3", "R&D Team 4", and "R&D Team 5", or a business project, such as "R&D Project 1", "R&D Project 2".

[0069] For each user, the multi-tenant management platform can determine the project to which the user belongs based on the project information of the user. For example, based on the project information of the user, it is determined that the project to which the user belongs is "R&D Team 1".

[0070] After determining the project to which the user belongs, determine the tenant to which the project belongs, and determine the tenant to which the user belongs. As described in the previous example, if the tenant to which the project "R&D Team 1" belongs is "Tenant A", then the tenant to which the user belongs can be determined to be "Tenant A". By binding the user to "Tenant A", the user can obtain the resource permissions of "Tenant A".

[0071] The multi-tenant management method of the present application also supports binding a user to multiple tenants. Specifically, the multi-tenant management method further includes the following steps:

[0072] Step S503: Acquire a tenant binding request sent by the user, where the tenant binding request includes an identifier of the tenant to be bound.

[0073] Step S504: Send a binding confirmation request to the tenant corresponding to the tenant identifier to be bound, and upon obtaining confirmation information fed back by the tenant, bind the user to the tenant corresponding to the tenant identifier to be bound, so that the user obtains the resource authority of the tenant.

[0074] In this embodiment, the multi-tenant management platform may obtain a tenant binding request sent by a user, where the tenant binding request includes an identifier of a tenant to be bound.

[0075] The multi-tenant management platform can send a binding confirmation request to the tenant corresponding to the tenant ID to be bound. The management end of the tenant corresponding to the tenant ID to be bound can provide feedback based on the binding confirmation request: if the user is accepted for binding, then feedback confirmation information; if the user is not accepted for binding, then feedback rejection information.

[0076] When the multi-tenant management platform obtains the confirmation information fed back by the tenant, it can bind the user to the tenant corresponding to the tenant identifier to be bound, so that the user obtains the resource authority of the tenant.

[0077] In this embodiment, the multi-tenant management platform can determine the tenant to which each user belongs based on the project information of each user, bind the user to the tenant to which the user belongs, and also support binding the user to multiple tenants so that the user can obtain resource permissions of multiple tenants. Through the flexible binding of users and tenants, a more flexible and easy-to-operate multi-tenant management method is implemented, which meets the business needs under the changes and adjustments of administrative organizations.

[0078] Figure 6 A flowchart of a multi-tenant management method embodiment 4 provided in the present application is shown in FIG. Figure 5 , the multi-tenant management method also includes the following steps:

[0079] Step S601: For each user, obtain the operation authority information of the user, and query the role corresponding to the operation authority information.

[0080] Step S602: Bind the user to the role so that the user obtains the operation authority corresponding to the operation authority information.

[0081] In this embodiment, each user also has operation permission information, and the operation permission information indicates the user's operation permission on resources, such as "read-only", "read-write" and other operation permissions.

[0082] For each user, the multi-tenant management platform can obtain the user's operation permission information and query the role corresponding to the operation permission information. Different operation permissions correspond to different roles. For example, the role "administrator" has the operation permission of "read and write", and the role "member" has the operation permission of "read only". If the multi-tenant management platform obtains the user's operation permission information as "read and write", it can determine that the role corresponding to the operation permission information is "administrator".

[0083] The multi-tenant management platform can bind the user to the role so that the user obtains the operation permission corresponding to the operation permission information. For example, binding the user to the role "administrator" can enable the user to obtain the "read and write" operation permission.

[0084] The multi-tenant management method of the present application also supports unbinding and rebinding of users and roles. Specifically, the multi-tenant management method further includes the following steps:

[0085] Step S603: Obtain a role binding request sent by the user, where the role binding request includes an identifier of a role to be bound.

[0086] Step S604: unbind the user from the role currently bound to the user, and bind the user to the role corresponding to the role identifier to be bound, so that the user obtains the operation authority of the role corresponding to the role identifier to be bound.

[0087] In this embodiment, the multi-tenant management platform may obtain a role binding request sent by a user, where the role binding request includes an identifier of a role to be bound.

[0088] The multi-tenant management platform may first unbind the user from the role to which it is currently bound, and then bind the user to the role corresponding to the role identifier to be bound, so that the user obtains the operation authority of the role corresponding to the role identifier to be bound.

[0089] For example, the multi-tenant management platform obtains a role binding request sent by a user, the role binding request includes a role identifier to be bound, the role corresponding to the role identifier to be bound is "member", and the role currently bound to the user is "administrator". The multi-tenant management platform can first unbind the user from the role of "administrator", and then bind the user to the role of "member" so that the user obtains the operation permissions of the role of "member".

[0090] In this embodiment, the multi-tenant management platform binds the user to the role according to the user's operation permission information, and also supports the unbinding and rebinding of the user and the role, so that the user can obtain the corresponding operation permission. After the user binds with the tenant to obtain the resource permission, the user can further obtain the operation permission for the resource, further realizing a more flexible and easy-to-operate multi-tenant management method, which meets the business needs under the changes and adjustments of administrative organizations.

[0091] Figure 7 A schematic diagram of the structure of a multi-tenant management platform embodiment provided in the present application. Figure 7 As shown, the multi-tenant management platform 70 includes an acquisition module 71 and a processing module 72. The acquisition module 71 is used to obtain a multi-tenant management request, which includes resource permission information of multiple projects and project information of multiple users. The processing module 72 is used to build a tenant tree structure based on the resource permission information of multiple projects, and configure corresponding resource permissions for each tenant in the tenant tree structure; each tenant in the tenant tree structure includes at least one project. The processing module 72 is also used to determine the tenant to which the user belongs based on the project information of each user, and bind the user to the tenant to which the user belongs, so that the user obtains the resource permissions of the tenant to which the user belongs.

[0092] The multi-tenant management platform provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0093] In a possible implementation scheme, the processing module 72 is specifically used to determine, for each project, whether the resource permissions of the project are the same as the resource permissions of other projects; if the resource permissions of the project are different from the resource permissions of other projects, the project is treated as a tenant; if the resource permissions of the project are the same as the resource permissions of at least one other project, the projects with the same resource permissions are merged to form a tenant; for each tenant, the tenant level of the tenant is set according to the resource permissions of the tenant to construct a tenant tree structure; wherein the resource permissions of each level of tenants in the tenant tree structure are greater than the resource permissions of the tenants at the next level.

[0094] In a possible implementation, the processing module 72 is specifically used to obtain, for each tenant, a cloud account associated with the resource permissions of the tenant; and bind the tenant to the cloud account so that the tenant obtains the corresponding resource permissions.

[0095] The multi-tenant management platform provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0096] In a possible implementation, the processing module 72 is specifically configured to determine, for each user, the project to which the user belongs based on the user's project information; and determine the tenant to which the project belongs, so as to determine the tenant to which the user belongs.

[0097] In a possible implementation scheme, the processing module 72 is also used to obtain a tenant binding request sent by the user, which tenant binding request includes the tenant identifier to be bound; send a binding confirmation request to the tenant corresponding to the tenant identifier to be bound, and when the confirmation information fed back by the tenant is obtained, bind the user to the tenant corresponding to the tenant identifier to be bound, so that the user obtains the resource permissions of the tenant.

[0098] The multi-tenant management platform provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0099] In a possible implementation, the processing module 72 is also used to obtain the operation permission information of each user and query the role corresponding to the operation permission information; bind the user to the role so that the user obtains the operation permission corresponding to the operation permission information.

[0100] In a possible implementation scheme, the processing module 72 is also used to obtain a role binding request sent by a user, which role binding request includes an identifier of a role to be bound; unbind the user from the role to which it is currently bound, and bind the user to the role corresponding to the identifier of the role to be bound, so that the user obtains the operation authority of the role corresponding to the identifier of the role to be bound.

[0101] The multi-tenant management platform provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0102] Figure 8 A schematic diagram of the structure of another multi-tenant management platform embodiment provided in the present application. Figure 8As shown, the multi-tenant management platform 80 includes: a processor 81, a memory 82 communicatively connected to the processor 81, and a communication interface 83; wherein the memory 82 stores computer execution instructions; the processor 81 executes the computer execution instructions stored in the memory 82 to implement the technical solution in any of the aforementioned method embodiments.

[0103] Optionally, the memory 82 can be independent or integrated with the processor 81.

[0104] Optionally, when the memory 82 is a device independent of the processor 81, the multi-tenant management platform 80 may further include: a bus 84 for connecting the above devices.

[0105] The multi-tenant management platform is used to execute the technical solution in any of the aforementioned method embodiments, and its implementation principles and technical effects are similar and will not be repeated here.

[0106] The present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, which are used to implement the aforementioned Figures 2 to 6 The technical solution in any method embodiment.

[0107] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.

[0108] It should be further noted that, although the various steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0109] It should be understood that the above-mentioned device embodiments are only illustrative, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.

[0110] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present application may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.

[0111] If the integrated unit / module is implemented in the form of hardware, the hardware may be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. If not specifically stated, the processor may be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, etc. If not specifically stated, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory RRAM (Resistive Random Access Memory), a dynamic random access memory DRAM (Dynamic Random Access Memory), a static random access memory SRAM (Static Random-Access Memory), an enhanced dynamic random access memory EDRAM (Enhanced Dynamic Random Access Memory), a high-bandwidth memory HBM (High-Bandwidth Memory), a hybrid memory cube HMC (Hybrid Memory Cube), etc.

[0112] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or all or part of the technical solution, can be embodied in the form of a software product, which is stored in a memory and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.

[0113] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0114] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0115] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A multi-tenant management method, characterized in that: include: Obtaining a multi-tenant management request, where the multi-tenant management request includes resource permission information of multiple projects and project information of multiple users; According to the resource permission information of the multiple projects, a tenant tree structure is constructed, and corresponding resource permissions are configured for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one of the projects; According to the project information of each user, the tenant to which the user belongs is determined, and the user is bound to the tenant to which the user belongs, so that the user obtains the resource authority of the tenant to which the user belongs.

2. The multi-tenant management method according to claim 1, characterized in that: The step of constructing a tenant tree structure according to the resource permission information of the multiple projects includes: For each of the projects, determining whether the resource permissions of the project are the same as the resource permissions of other projects; If the resource permissions of the project are different from those of other projects, the project is considered as a tenant; If the resource permissions of the project are the same as those of at least one other project, the projects with the same resource permissions are merged to form one tenant; For each tenant, the tenant level of the tenant is set according to the resource authority of the tenant to construct a tenant tree structure; wherein the resource authority of each level of tenants in the tenant tree structure is greater than the resource authority of the tenant at the next level.

3. The multi-tenant management method according to claim 1 or 2, characterized in that: The configuring corresponding resource permissions for each tenant in the tenant tree structure includes: For each tenant, obtain a cloud account associated with the resource permissions of the tenant; The tenant is bound to the cloud account so that the tenant obtains corresponding resource permissions.

4. The multi-tenant management method according to claim 1 or 2, characterized in that: The determining, according to the project information of each user, the tenant to which the user belongs includes: For each user, determining the project to which the user belongs according to the project information of the user; The tenant to which the project belongs is determined to determine the tenant to which the user belongs.

5. The multi-tenant management method according to claim 1 or 2, characterized in that: The method further comprises: Obtaining a tenant binding request sent by the user, wherein the tenant binding request includes an identifier of the tenant to be bound; A binding confirmation request is sent to the tenant corresponding to the tenant identifier to be bound, and upon obtaining confirmation information fed back by the tenant, the user is bound to the tenant corresponding to the tenant identifier to be bound, so that the user obtains the resource authority of the tenant.

6. The multi-tenant management method according to claim 1 or 2, characterized in that: The method further comprises: For each of the users, obtain the user's operation permission information, and query the role corresponding to the operation permission information; The user is bound to the role so that the user obtains the operation authority corresponding to the operation authority information.

7. The multi-tenant management method according to claim 6, characterized in that: The method further comprises: Obtaining a role binding request sent by a user, wherein the role binding request includes an identifier of a role to be bound; The user is unbound from the role currently bound to it, and the user is bound to the role corresponding to the role identifier to be bound, so that the user obtains the operation authority of the role corresponding to the role identifier to be bound.

8. A multi-tenant management platform, characterized in that: include: An acquisition module, used to acquire a multi-tenant management request, wherein the multi-tenant management request includes resource permission information of multiple projects and project information of multiple users; A processing module, configured to construct a tenant tree structure according to the resource permission information of the plurality of projects, and configure corresponding resource permissions for each tenant in the tenant tree structure; wherein each tenant in the tenant tree structure includes at least one of the projects; The processing module is further used to determine the tenant to which each user belongs according to the project information of the user, and bind the user to the tenant to which the user belongs, so that the user obtains the resource authority of the tenant to which the user belongs.

9. A multi-tenant management platform, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the multi-tenant management method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the multi-tenant management method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Role-based multi-tenant organization structure management system and method, device and medium

    CN111950866A

  • Multi-tenant space resource management method, system and device and storage medium

    CN113986528A

  • Multi-level multi-tenant cross authorization management method

    CN114090969A

  • System and method for configuring tenant information under various organizations

    CN115952487A

  • Shared identity management (IDM) integration in a multi-tenant computing environment

    US20160087960A1