Resource access management method and device, computer readable storage medium and electronic equipment
By combining access control lists and role-based access control policies, flexible and refined permission management of resources is achieved, and the security risks and low work efficiency caused by inflexible permission management in the existing technology are solved, and the security and efficiency of resource access are improved.
Patent Information
- Application Number
- CN202510234686.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-13
AI Technical Summary
The existing team functions lack flexible permission management and cannot meet the user's need to restrict resource access according to project needs, resulting in security risks and low work efficiency.
Flexible and granular permission management of resources is achieved by building access control lists (ACLs) and role-based access control (RBAC) policies. The specific method includes creating roles and assigning permissions according to task requirements, configuring role-based permissions at the folder level, and configuring corresponding roles for users to determine access control policies.
It realizes flexible and refined permission management, ensures the security of resources, and improves work efficiency and meets the needs of users' personalized access management resources.
Smart Images

Figure CN120145352A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and particularly to a resource access management method, apparatus, computer-readable storage medium, and electronic device. Background Art
[0002] With the expansion of team size, the traditional folder-based resource management method faces challenges. Currently, most team members are defaulted to have access to all resources, which poses a threat to data security and privacy. Team owners need more stringent permission control to prevent information leakage and meet the high compliance requirements of customers.
[0003] However, the team functions in the existing market generally lack flexible permission management and cannot meet the needs of users to restrict resource access according to project requirements.
[0004] Therefore, the related technologies not only cause security hazards but also reduce work efficiency. Summary of the Invention
[0005] The main objective of the present disclosure is to provide a resource access management method, apparatus, computer-readable storage medium, and electronic device to solve the problem of low work efficiency caused by security hazards in the related technologies.
[0006] To achieve the above objective, the first aspect of the present disclosure provides a resource access management method, including:
[0007] According to task requirements, create at least one role for the resources to be accessed and managed, and assign corresponding permissions to each of the roles; wherein, the resources include folders and their contents, and the permissions include at least one of the following: view permission, edit permission, upload permission, and delete permission;
[0008] Configure role-based permissions at the folder level of the resources, and configure corresponding roles for the first user in the task requirements to determine the role-based access control policy; wherein, one user corresponds to at least one role, and one role corresponds to at least one permission;
[0009] Configure user-based permissions at the folder level to determine an access control list, and the access control list is used to maintain the permissions of each folder;
[0010] Access and manage the resources according to the role-based access control policy and the access control list.
[0011] Optionally, further, the creating at least one role for the resources to be accessed and managed according to task requirements includes:
[0012] Based on the task requirements, determine the resources to be accessed and managed and the teams with access management requirements, where the first user is a user within the team;
[0013] Determine user groups according to the responsibilities, functions, or permission levels of the users within the team; among them, one user group corresponds to one role;
[0014] Create the at least one role for the resource.
[0015] Optionally, further, configure role-based permissions at the folder level of the resource and configure the corresponding role for the first user in the task requirements to determine the role-based access control policy, including:
[0016] Obtain the first folder that needs to set permissions and its content in the resource; the first folder is at least one;
[0017] For any one of the first folders, match the first folder with the first role, and the first role is a role among the at least one role;
[0018] Associate the first folder with the assigned first role and apply the permissions of the first role to the first folder;
[0019] Create a subfolder to inherit the role configuration of the parent folder so that the permissions of the subfolder of the first folder include the permissions of the folder;
[0020] Associate the first role with the first user;
[0021] Determine the role-based access control policy according to the association relationship between the first user and the first role, and the association relationship between the first role and the permissions of the first folder.
[0022] Optionally, further, if there are multiple of the at least one role, the method further includes:
[0023] Configure the role-based permissions at the subfolder level of the first folder to associate the subfolder of the first folder with the assigned second role and apply the permissions of the second role to the subfolder;
[0024] Among them, the second role is a role among the at least one role.
[0025] Optionally, further, configure user-based permissions at the folder level to determine the access control list, including:
[0026] Obtain a second folder and its content in the resource that requires permission setting; there are at least one second folder;
[0027] Associate the second folder with a second user whose permissions need to be set in the task requirement, and apply the permissions matching the second user to the second folder to determine an access control list.
[0028] Optionally, further, the method further includes:
[0029] Add upload permissions for a preset file format to the upload permissions to control the format of files uploaded by a role or a user configured with the upload permissions.
[0030] Optionally, further, the accessing and managing the resource according to the role-based access control policy and the access control list includes:
[0031] In response to an access management request of a target user for a target resource, determine whether the target user has the viewing permission for the target resource according to the access control list, where the target resource is a resource in the resource to be accessed and managed;
[0032] If the target user has the viewing permission for the target resource, control the target user to view the target resource according to the access control list;
[0033] If the target user does not have the permission to view the target resource, determine the target role corresponding to the target user according to the role-based access control policy, and determine whether the target role has the corresponding permission to access and manage the target resource, where there are at least one target role;
[0034] If the target role has the corresponding permission to access and manage the target resource, control the target user to access and manage the target resource according to the fact that the target role has the corresponding permission to access and manage the target resource; where the access management includes at least one of the following: viewing, editing, uploading, deleting.
[0035] A second aspect of the present disclosure provides a resource access management device, and the device includes:
[0036] A first processing unit, configured to create at least one role for a resource to be accessed and managed according to a task requirement, and assign corresponding permissions to each of the roles; where the resource includes a folder and its content, and the permissions include at least one of the following: viewing permission, editing permission, uploading permission, deleting permission;
[0037] A second processing unit, configured to configure role-based permissions at the folder level of the resource and configure corresponding roles for the first user in the task requirements to determine a role-based access control policy; wherein, one user corresponds to at least one role, and one role corresponds to at least one permission.
[0038] A determination unit, configured to configure user-based permissions at the folder level and determine an access control list for maintaining the permissions of each folder.
[0039] An access management unit, configured to manage the access to the resource according to the role-based access control policy and the access control list.
[0040] A third aspect of the present disclosure provides a computer-readable storage medium storing computer instructions for causing a computer to execute the resource access management method provided in any one of the first aspects.
[0041] A fourth aspect of the present disclosure provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to cause the at least one processor to execute the resource access management method provided in any one of the first aspects.
[0042] A fifth aspect of the present disclosure provides a computer program product including a computer program that, when executed by a processor, implements the resource access management method provided in any one of the first aspects.
[0043] In the resource access management method provided by the embodiments of the present disclosure, at least one role to be created is determined for the resources to be accessed and managed based on the task requirements, and corresponding permissions are configured for each role, thereby realizing the association between the role and the permission. Then, role-based permissions are configured at the folder level of the resources, and the corresponding role is configured for the first user in the task requirements, realizing the association between the first user and the role, and further realizing the association between the user, the role, and the permission, so as to constitute a role-based access control policy for the user. The flexibility of the permission configuration based on access management is relatively high, and the occurrence of security hazard problems is avoided, ensuring the security management of the resources. At the same time, efficient access management of the team is realized, thereby improving work efficiency. At the same time, user-based permissions can also be configured at the folder level to realize the direct association between the user and the permissions of the folder, thereby realizing refined permission management. While preventing information leakage, it meets the needs of users for personalized access management of resources, achieving the purpose of flexible and refined permission management, and thus realizing the technical effects of ensuring information security, improving work efficiency, and meeting the personalized needs of users, and further solving the technical problem of low work efficiency caused by the existence of security hazards. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the related art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the related art. Obviously, the following drawings are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 Schematic diagram of the scenario of the resource access management method provided by the embodiments of the present disclosure;
[0046] Figure 2 Schematic diagram of the scenario of the resource access management method provided by another embodiment of the present disclosure;
[0047] Figure 3 Schematic diagram of the process of the resource access management provided by the embodiments of the present disclosure;
[0048] Figure 4 Block diagram of the resource access management device provided by the embodiments of the present disclosure;
[0049] Figure 5 Block diagram of the electronic device provided by the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] To enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.
[0051] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to describe the embodiments of the present disclosure here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0052] In the present disclosure, the orientation or positional relationship indicated by the terms "upper", "lower", "left", "right", "front", "rear", "top", "bottom", "inner", "outer", "middle", "vertical", "horizontal", "lateral", "longitudinal", etc. is based on the orientation or positional relationship shown in the drawings. These terms are mainly used to better describe the present disclosure and its embodiments, and are not used to limit that the indicated devices, elements or components must have a specific orientation or be constructed and operated in a specific orientation.
[0053] Moreover, in addition to being able to represent an orientation or positional relationship, some of the above terms may also be used to represent other meanings. For example, the term "upper" may also be used to represent a certain attachment relationship or connection relationship in some cases. For those of ordinary skill in the art, the specific meanings of these terms in the present disclosure can be understood according to specific circumstances.
[0054] In addition, the terms "install", "set", "be provided with", "connect", "be connected", "be sleeved" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral structure; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, or there can be internal communication between two devices, elements or components. For those of ordinary skill in the art, the specific meanings of the above terms in the present disclosure can be understood according to specific circumstances.
[0055] It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments may be combined with each other. The following will describe the present disclosure in detail with reference to the accompanying drawings and in combination with the embodiments.
[0056] Currently, most team members can access all resources by default, which poses a threat to data security and privacy. Team owners need more stringent permission control to prevent information leakage and at the same time meet the high compliance requirements of customers. However, the team functions in the existing market generally lack flexible permission management and cannot meet the needs of users to restrict resource access according to project requirements. Therefore, the related technologies not only cause security risks but also reduce work efficiency.
[0057] To solve the above problems, the technical concept of the present disclosure is to construct a combination of an access control list (ACL) and a role-based access control (RBAC) policy. Through the ACL, each folder can maintain a permission list separately to adapt to complex and changing requirements; RBAC simplifies permission configuration and management through roles and is applicable to a large number of users and teams. Flexible and refined permission management is achieved, ensuring information security and at the same time improving work efficiency.
[0058] In practical applications, the execution subject of the present disclosure may be a resource access management device, and this resource access management device may be deployed in an electronic device, such as a terminal device, a server, etc. Users can perform permission management based on task requirements (or project requirements) through the electronic device deployed with the resource access management device, realizing flexible permission management and refined permission management, thereby ensuring information security while improving the efficiency of resource access management, further improving the work efficiency of the team (role-based) or users, and meeting the personalized access management needs of users.
[0059] Specifically, refer to Figure 1 as shown Figure 1 is a schematic diagram of the scenario of the resource access management method provided by the embodiment of the present disclosure. This scenario includes a display device 101 (for example, a monitor or a display screen, used to display a user interaction interface or a user interaction page, which is not specifically limited here) and a server 102 deployed with a resource access management device. Among them, the display device 101 is used for users (here the users can be administrators, personnel with access requirements, etc., which is not specifically limited here) to perform visual interaction operations. The server 102 is used to perform permission management based on task requirements (or project requirements); among them, the permission management based on task requirements includes: role-based permission management and user-based permission management.
[0060] For role-based permission management: first determine the resources and teams to be accessed and managed based on task requirements, then group users in the team according to their responsibilities, functions or permission levels to determine the roles corresponding to each user group, and then determine at least one role corresponding to the resource, and create at least one role for the resource, and then generate a role-based access control policy for the resource to implement access management based on role permissions.
[0061] For user-based permission management: first, according to task requirements, determine the resources to be accessed and the users with personalized needs. For the folders of the resources, configure folder-level user permissions. That is, for folders with access management restrictions, associate users with the permissions to access the folders, generate access control lists to maintain permissions for each folder, and implement refined user-based permission management to adapt to complex and changing needs.
[0062] For example, see Figure 2 As shown, Figure 2 A schematic diagram of a scenario of a resource access management method provided by another embodiment of the present disclosure. Figure 2 The leftmost human avatar in the figure represents the user) accesses or operates resources (the resources here include folders and their contents, and resources can be regarded as materials, such as data, etc.) scenarios: When a user (here refers to the target user, that is, a user with access management (including access and / or operation, where operations include but are not limited to editing, uploading, deleting, etc.) requirements) accesses and / or operates a certain resource (here refers to the material), resource access management is implemented through role control and / or access control.
[0063] Specifically, if a user initiates a request to access a material (e.g., to view a material), resource access management may include role control and access control. With respect to access control, access control can be used to determine whether the target user is a department or user with access rights (e.g., viewing rights): by matching the access control list (ACL entry) in order, it is determined whether the target user can access the resource. If the target user is not matched as a department or user with access rights, it indicates that the target user has insufficient rights; if matched, it is determined that the target user can access the resource (material), and then based on the folder's permission inheritance, the target user can access the (parent) folder and its contents in the material. In addition, if the subfolder is not configured with other access rights and only inherits the parent folder's permissions, the target user can also access the subfolders under the parent folder; if the subfolder is configured with new permissions in addition to inheriting the parent folder's permissions, the ACL entries are continued to be matched in order to determine whether the target user has the access rights to the subfolder.
[0064] Regarding role control, through role control, it can be determined whether the target user is a role with access permissions (such as viewing permissions), such as a folder role (i.e., the role corresponding to the folder), a role within the team, etc., to determine whether the target user can access the resource. If the target user fails to match the folder role or does not match a role within the team, it indicates that the target user has insufficient permissions; if the target user matches the folder role or matches a role within the team, it is determined that the target user can access the resource (material), and then based on the permission inheritance of the folder, the (parent) folder and its content in the material can be accessed. Additionally, if the subfolder does not configure other role permissions and only inherits the permissions of the parent folder, the target user can also access the subfolder under the parent folder; if the subfolder configures new role permissions in addition to inheriting the role permissions of the parent folder, then continue to determine whether the target user has access permissions to the subfolder based on role matching.
[0065] If a user initiates a request to operate on a material (such as editing the material, uploading the material, deleting the material, etc.), resource access management can include role control. Through role control, it can be determined whether the user is a role with corresponding operation permissions (including but not limited to editing permissions, uploading permissions, deleting permissions, etc.), such as a folder role (i.e., the role corresponding to the folder), a role within the team, etc., to determine whether the target user can operate the resource. If the target user does not have the corresponding operation permissions, it indicates that the target user has insufficient permissions; if the target user matches the folder role or matches a role within the team, it is determined that the target user can operate the resource (material), and then based on the permission inheritance of the folder, the (parent) folder and its content in the material can be operated. If the subfolder does not configure other role permissions and only inherits the permissions of the parent folder, the target user can also operate the subfolder under the parent folder; if the subfolder configures new role permissions in addition to inheriting the role permissions of the parent folder, then continue to determine whether the target user has operation permissions to the subfolder based on role matching.
[0066] Through the above application scenarios, the present disclosure combines the Access Control List (ACL) and Role-Based Access Control (RBAC) to enable each folder to maintain a permission list separately through ACL, adapting to complex and changing requirements; and simplifies permission configuration and management through roles through RBAC, which is applicable to a large number of users and teams. Furthermore, flexible and refined permission management is achieved, ensuring information security, while improving work efficiency and solving the technical problems that not only pose security risks but also reduce work efficiency.
[0067] It should be noted that in the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of information such as resources comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0068] The technical solution of the present disclosure will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0069] The embodiment of the present disclosure provides a resource access management method, as Figure 3 shown, the method includes the following steps S301 to step S304:
[0070] Step S301: According to the task requirements, create at least one role for the resources to be accessed and managed, and assign corresponding permissions to each of the roles; wherein, the resources include folders and their contents, and the permissions include at least one of the following: viewing permission, editing permission, uploading permission, and deleting permission.
[0071] Step S302: Configure role-based permissions at the folder level of the resources, and configure corresponding roles for the first user in the task requirements to determine the role-based access control policy; wherein, one user corresponds to at least one role, and one role corresponds to at least one permission.
[0072] Step S303: Configure user-based permissions at the folder level to determine an access control list, and the access control list is used to maintain the permissions of each folder.
[0073] Step S304: Access and manage the resources according to the role-based access control policy and the access control list.
[0074] In the disclosed embodiment, based on the task requirements, at least one role to be created is determined for the resource to be accessed and managed, and corresponding permissions are configured for each role, thereby realizing the association between roles and permissions. Then, by configuring role-based permissions at the folder level of the resource, and configuring a corresponding role for the first user in the task requirement, the association between the first user and the role is realized, thereby realizing the association between users, roles and permissions, so as to form a user role-based access control strategy. The permission configuration based on access management has high flexibility, avoids the emergence of potential security risks, ensures the security management of resources, and realizes efficient access management of the team, thereby improving work efficiency. At the same time, user-based permissions can also be configured at the folder level to realize the direct association between users and folder permissions, thereby realizing refined permission management. While preventing information leakage, it meets the user's personalized access management resource needs, and achieves the purpose of flexible and fine-grained permission management, thereby achieving information security while improving work efficiency and meeting user personalized needs.
[0075] Wherein, the role-based permissions are configured at the folder level of the resource: permissions are configured for different roles at the folder level; and the user-based permissions are configured at the folder level: permissions are configured for different users or departments at the folder level.
[0076] Access Control List (ACL): It is a mechanism for managing resource access rights. It defines rules to control which subjects (such as users, processes, devices or network traffic) can access specific objects (such as files, directories, network ports or devices) in what ways (such as reading, writing, executing or communicating). For example, by building an association between users and access management resources (such as folders and their contents), an ACL is formed to provide fine-grained control, flexibly adapt to complex scenarios, and achieve enhanced security and minimize the risk of unauthorized access.
[0077] Each ACL entry in an access control list generally contains the following elements:
[0078] Subject: The entity that initiates the access request (such as user, IP address).
[0079] Object: The resource being accessed (such as a file or network port).
[0080] Operation: The type of operation allowed or denied (such as read, write, delete, etc., here refers to view, edit, upload, delete, etc.).
[0081] Rule priority: ACL entries are matched in order, and the first match usually takes effect.
[0082] Role - based access control policy: It is an access control model that manages user permissions through roles. Its core idea is to assign permissions to roles and then assign roles to users, rather than directly assigning permissions to users, thereby simplifying permission management and enhancing security. The role - based access control policy assigns permissions in batches through roles, reducing duplicate configurations, and reducing internal risks through separation of duties and the principle of least privilege, thereby enhancing security. This policy is suitable for complex scenarios, such as enterprise environments with variable organizational structures, etc.
[0083] Optionally, a resource access management method includes:
[0084] According to the task requirements, create at least one role for the resource to be accessed and managed, and assign corresponding permissions to each of the said roles; wherein, the resource includes a folder and its content, and the permissions include at least one of the following: view permission, edit permission, upload permission, delete permission;
[0085] Configure role - based permissions at the folder level of the resource, and configure corresponding roles for the first user in the task requirements to determine the role - based access control policy; wherein, one user corresponds to at least one role, and one role corresponds to at least one permission;
[0086] Configure user - based permissions at the folder level to determine an access control list, and the access control list is used to maintain the permissions of each folder;
[0087] Wherein, the role - based access control policy and the access control list are used for accessing and managing the resource.
[0088] Optionally, the step of creating at least one role for the resource to be accessed and managed according to the task requirements includes:
[0089] According to the task requirements, determine the resource to be accessed and managed and the team with access management requirements, and the first user is a user within the team;
[0090] According to the responsibilities, functions or permission levels of the users within the team, determine user groups; wherein, one user group corresponds to one role;
[0091] Create the at least one role for the resource.
[0092] In the embodiments of the present disclosure, as shown in combination with Figure 2 Role control provides flexible permission management for users within the team. Among them, a role represents an abstract concept of a set of permissions (such as "administrator", "financial staff", etc.), and roles can be customized based on the responsibilities, functions or permission levels of users within the team.
[0093] Exemplarily, based on any task requirements (the task requirements can be resource access management requirements, etc. For example, opening permissions for certain resources for a certain team, but different users within the team have different permissions, or approval permissions for a certain resource, which are not specifically limited here), the administrator can create roles and assign permissions such as "view", "edit", "upload", "delete", etc. to match the internal responsibilities of the team. A user can correspond to one or more roles. Correspondingly, one role can be assigned to one or more users, and one role corresponds to one or more permissions, that is, one role can correspond to a permission set.
[0094] Therefore, based on the task requirements, creating roles can achieve the flexibility of resource access management and personalized requirements.
[0095] Optionally, configure role-based permissions at the folder level of the resource and configure corresponding roles for the first user in the task requirements to determine the role-based access control policy, including:
[0096] Obtain the first folder and its content in the resource that need to set permissions; the first folder is at least one;
[0097] For any one of the first folders, match a first role to the first folder, and the first role is a role among the at least one role;
[0098] Associate the first folder with the assigned first role and apply the permissions of the first role to the first folder;
[0099] Create sub-folders to inherit the role configuration of the parent folder so that the permissions of the sub-folders of the first folder include the permissions of the folder;
[0100] Associate the first role with the first user;
[0101] Determine the role-based access control policy according to the association relationship between the first user and the first role, and the association relationship between the first role and the permissions of the first folder.
[0102] Among them, the first user here is the user within the team who needs to configure or set permissions in the task requirements. For each file and its content in the resource, access management restrictions can be set in whole or in part. First, determine the folders in the resource for which permissions need to be set and their content (here referring to the first folder and its content, the first folder can be one or more, and no specific limitation is made here), and then configure permissions for different roles at the level of the first folder (here referring to at least one first folder): for any first folder, match at least one first role to the first folder (the first role here is a role among the at least one created role), associate the first folder with the first role assigned to it, form the corresponding relationship between the first folder and the corresponding first role, and then apply the permissions configured for the first role to the first folder to achieve the correspondence between the folder permissions and the role permissions. Then, based on the role corresponding to the first user, associate the first user with the corresponding first role to achieve the association between the user and the role: a user can be assigned multiple roles, and precise permission control is achieved through role combination, and dynamic adjustment of roles is supported. Then, based on the association between the folder permissions and the role permissions, a role-based access control policy is further formed to achieve access control or access management of resources through roles.
[0103] Among them, if the first folder contains sub-folders, sub-folders can be created to inherit the role configuration of the parent folder, that is, the sub-folders of the first folder inherit the permissions of the first folder. Specifically, for folder permission settings: set permissions for different roles at the folder level to control access and operations. Sub-folders can inherit the role configuration of the parent folder to simplify management.
[0104] Optionally, if there are multiple of the at least one role, the method further includes:
[0105] Configure the role-based permissions at the sub-folder level of the first folder to associate the sub-folders of the first folder with the assigned second role and apply the permissions of the second role to the sub-folders;
[0106] Among them, the second role is a role among the at least one role. The first role can be different from the second role.
[0107] In the embodiments of the present disclosure, in addition to inheriting the permissions of the parent folder, a sub-folder can also configure new permissions. The process of configuring new permissions is the same as the method of permission management for the parent folder (such as the first folder, the second folder, etc.): configure permissions for different roles at the sub-folder level (here referring to the sub-folder of the first folder or the second folder): for any sub-folder, match at least one second role (the second role here is a role among the at least one created role) for the sub-folder, associate the sub-folder with the second role assigned to it, form the corresponding relationship between the sub-folder and the corresponding second role, and then apply the permissions configured for the second role to the sub-folder to achieve the correspondence between the permissions of the sub-folder and the permissions of the role. Then, according to the role corresponding to the second user, associate the second user with the corresponding second role to achieve the association between the user and the role: a user can be assigned multiple roles, and precise permission control is achieved through role combination, and dynamic adjustment of roles is supported. Then, based on the association between the permissions of the sub-folder and the permissions of the role, access control or access management of resources is achieved through roles.
[0108] Optionally, configure user-based permissions at the folder level to determine an access control list, including:
[0109] Obtain the second folder and its content in the resource that need to set permissions; the second folder is at least one;
[0110] Associate the second folder with the second user whose permissions need to be set in the task requirement, and apply the permissions matching the second user to the second folder to determine the access control list.
[0111] Among them, the second user can overlap with the first user or not, and no specific limitation is made here.
[0112] The second folder can be the same as or different from the first folder. For example: when the second folder is the same as the first folder, the first folder configures role-based permissions and also configures user-based permissions. The role here may or may not include this user, that is, there may be an overlap or not; when the second folder is different from the first folder, for example, the first folder configures role-based permissions and does not configure user-based permissions, so only when accessed by a role is it allowed to manage the content of the first folder. Similarly, the second folder configures user-based permissions and does not configure role-based permissions, so only when the user permissions match can the content of the second folder be accessed.
[0113] In the embodiments of the present disclosure, first, according to the task requirements, the resources to be accessed and managed and the users with personalized needs are determined. For the folders of the resources, user permissions at the folder level are configured, that is, for the folders restricted by access management, users are associated with the permissions to access and manage the folders, and an access control list is generated to maintain the permissions of each folder, realizing refined permission management based on users and adapting to complex and changeable requirements.
[0114] Through the access control function provided by the access control list, fine-grained permission management can be provided to ensure that the access permissions of various users to resources are clearly controllable. Through personalized settings, access control can ensure the security of resources and improve the operation efficiency of users at the same time.
[0115] Optionally, if there are multiple of the at least one role, the method further includes:
[0116] Configure the user-based permissions at the sub-folder level of the second folder to associate the sub-folders of the second folder with the assigned third user, and apply the permissions of the third user to the sub-folders;
[0117] Among them, the permissions of the third user include the permissions of the second user. The second role may be the same as or different from the third user, and no specific limitation is made here.
[0118] Optionally, the method further includes:
[0119] Add the upload permission for a preset file format to the upload permission to control the format of the files uploaded by the role or user configured with the upload permission.
[0120] In the embodiments of the present disclosure, fine-grained permission settings can be provided, such as: upload restrictions for specific file formats, dynamically adjusting role permissions to adapt to team changes. Specifically, on the basis of the upload permission, add the upload permission for a preset file format to form a corresponding relationship between the role and the upload permission and the upload permission for the preset file format, or form a corresponding relationship between the user and the upload permission and the upload permission for the preset file format, thereby realizing fine-grained permission control or permission management.
[0121] Optionally, the accessing and managing the resources according to the role-based access control policy and the access control list includes:
[0122] In response to an access management request of a target user for a target resource, determine whether the target user has the viewing permission for the target resource according to the access control list, where the target resource is a resource among the resources to be accessed and managed;
[0123] If the target user has viewing authority for the target resource, controlling the target user to view the target resource according to the access control list;
[0124] If the target user does not have the permission to view the target resource, determine the target role corresponding to the target user according to the role-based access control policy, and determine whether the target role has the corresponding permission to access and manage the target resource, and there is at least one target role;
[0125] If the target role has the corresponding authority to access and manage the target resource, then the target user is controlled to access and manage the target resource based on the target role having the corresponding authority to access and manage the target resource; wherein the access management includes at least one of the following: view, edit, upload, and delete.
[0126] The target user here may refer to the user who actually initiates the access or operation request, and the operation here includes but is not limited to editing, uploading, deleting, etc. The target resource here includes the target folder and its content, etc. The target folder here is at least one folder in the resource to be accessed and managed.
[0127] In the embodiments of the present disclosure, the determination of resource access rights is an important step in ensuring data security and operational compliance. Specifically, whether a resource can be operated or viewed requires a comprehensive assessment based on both role control and access control mechanisms. Whether a resource can be viewed can be achieved in at least two ways:
[0128] Method 1: If the target user initiates a viewing request, it can be determined based on the access control list whether the target user has the access permission to view the target resource. If it is determined that the target user does not have sufficient permissions, the role-based access control policy is continued to determine whether the target user has the access permission to view the target resource, that is: first determine the target role corresponding to the target user, and determine whether the target role has the corresponding permission to access the target resource. If it has the corresponding access permission, the target user is provided with the viewing permission for the target resource, and the target user is supported to view the target resource.
[0129] Method 2: If the target user initiates a viewing request, it can be determined based on the access control list and the role-based access control policy at the same time whether the target user has the access permission to view the target resource. If the access permission determined by any of the methods based on the access control list and the role-based access control policy is met, it is determined that the target user has the corresponding access permission; if it is determined that the target user has the corresponding access permission based on any of the methods based on the access control list and the role-based access control policy, the judgment logic process of the other method is stopped.
[0130] Whether a resource can be operated can be achieved in the following way: By adopting a role-based access control policy, it is determined whether the target user has the operation permission for the target resource, that is: First, determine the target role corresponding to the target user, and determine whether the target role has the corresponding permission to operate the target resource. If it has the corresponding operation permission (such as edit permission, upload permission, delete permission, etc.), then provide the target user with the operation permission for the target resource to support the target user to view the target resource.
[0131] From the above description, it can be seen that the present disclosure achieves the following technical effects: The resource access management method based on roles and users optimizes the traditional folder structure and endows the team owner with more efficient and secure permission allocation capabilities. Through this resource access management method, resource usage becomes more efficient and secure, meeting the strict standards of enterprise-level users for resource management, and can provide a more efficient and secure resource management solution for enterprises. Through flexible role control and fine-grained access control, the dual needs of enterprises for data security and operation efficiency are met, realizing flexible and fine-grained permission management, and further meeting the needs of users to restrict resource access according to roles, responsibilities, and project requirements.
[0132] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0133] The embodiment of the present disclosure also provides a resource access management device for implementing the above-mentioned resource access management method embodiment, as Figure 4 shown, the resource access management device 40 includes:
[0134] A first processing unit 401, configured to create at least one role for the resource to be accessed and managed according to the task requirements, and assign corresponding permissions to each of the roles; wherein, the resource includes a folder and its content, and the permissions include at least one of the following: view permission, edit permission, upload permission, delete permission;
[0135] A second processing unit 402, configured to configure role-based permissions at the folder level of the resource, and configure corresponding roles for the first user in the task requirements to determine the role-based access control policy; wherein, one user corresponds to at least one role, and one role corresponds to at least one permission;
[0136] A determination unit 403, configured to configure user-based permissions at the folder level, determine an access control list, and the access control list is used to maintain the permissions of each folder;
[0137] An access management unit 404 for accessing and managing the resource according to the role-based access control policy and the access control list.
[0138] Optionally, when the first processing unit 401 creates at least one role for the resource to be accessed and managed according to the task requirements, it specifically includes:
[0139] Determine the resource to be accessed and managed and the team with access management requirements according to the task requirements, and the first user is a user within the team;
[0140] Determine the user group according to the responsibilities, functions or permission levels of the users within the team; wherein, one user group corresponds to one role;
[0141] Create the at least one role for the resource.
[0142] Optionally, when the second processing unit 402 configures role-based permissions at the folder level of the resource and configures the corresponding role for the first user in the task requirements to determine the role-based access control policy, it specifically includes:
[0143] Obtain the first folder and its content in the resource that need to set permissions; the first folder is at least one;
[0144] For any one of the first folders, match the first role to the first folder, and the first role is a role among the at least one role;
[0145] Associate the first folder with the assigned first role, and apply the permissions of the first role to the first folder;
[0146] Create a subfolder to inherit the role configuration of the parent folder, so that the permissions of the subfolder of the first folder include the permissions of the folder;
[0147] Associate the first role with the first user;
[0148] Determine the role-based access control policy according to the association relationship between the first user and the first role, and the association relationship between the first role and the permissions of the first folder.
[0149] Optionally, the resource access management device is further configured to perform the following operations:
[0150] If there are multiple of the at least one role, configure the role-based permissions at the sub-folder level of the first folder to associate the sub-folders of the first folder with the assigned second role, and apply the permissions of the second role to the sub-folders;
[0151] Wherein, the second role is a role among the at least one role.
[0152] Optionally, when the determining unit 403 executes configuring user-based permissions at the folder level and determining the access control list, it specifically includes:
[0153] Obtain the second folder and its content in the resource that need to set permissions; there is at least one second folder;
[0154] Associate the second folder with the second user whose permissions need to be set in the task requirements, and apply the permissions matching the second user to the second folder to determine the access control list.
[0155] Optionally, the resource access management device is further configured to perform the following operations:
[0156] Add upload permissions for a preset file format to the upload permissions to control the file format uploaded by the role or user configured with the upload permissions.
[0157] Optionally, when the access management unit 404 executes access management of the resource according to the role-based access control policy and the access control list, it specifically includes:
[0158] In response to an access management request of a target user for a target resource, determine whether the target user has the viewing permission for the target resource according to the access control list, wherein the target resource is a resource among the resources to be accessed and managed;
[0159] If the target user has the viewing permission for the target resource, control the target user to view the target resource according to the access control list;
[0160] If the target user does not have the permission to view the target resource, determine the target role corresponding to the target user according to the role-based access control policy, and determine whether the target role has the corresponding permission to access and manage the target resource, and there is at least one target role;
[0161] If the target role has the corresponding permission to access and manage the target resource, then, based on the fact that the target role has the corresponding permission to access and manage the target resource, control the target user to access and manage the target resource; wherein, the access and management includes at least one of the following: viewing, editing, uploading, and deleting.
[0162] The specific manners of the execution operations of each unit in the above device embodiments have been described in detail in the embodiments of the resource access management method, and will not be elaborated here.
[0163] Embodiments of the present disclosure also provide an electronic device, as Figure 5 shown, the electronic device includes one or more processors 51 and a memory 52, Figure 5 Taking one processor 51 as an example.
[0164] The controller may further include: an input device 53 and an output device 54.
[0165] The processor 51, the memory 52, the input device 53, and the output device 54 may be connected through a bus or other means, Figure 5 Taking the connection through a bus as an example.
[0166] The processor 51 may be a central processing unit (CPU for short), and the processor 51 may also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), field-programmable gate arrays (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. chips, or a combination of the above types of chips. The general-purpose processor may be a microprocessor or any conventional processor.
[0167] The memory 52, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the control method in the embodiments of the present disclosure. The processor 51 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions, and modules stored in the memory 52, that is, implements the resource access management method in the above method embodiments.
[0168] The memory 52 may include a program storage area and a data storage area. The program storage area may store an operating system and application programs required for at least one function. The data storage area may store data created according to the use of the processing device of the server, etc. In addition, the memory 52 may include a high-speed random access memory and may also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 52 may optionally include a memory remotely provided with respect to the processor 51, and these remote memories may be connected to the network connection device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0169] The input device 53 may receive input digital or character information and generate key signal inputs related to user settings and function controls of the processing device of the server. The output device 54 may include a display device such as a display screen.
[0170] One or more modules are stored in the memory 52 and, when executed by one or more processors 51, perform the method as shown above.
[0171] Embodiments of the present disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute the resource access management method as described above.
[0172] Embodiments of the present disclosure also provide a computer program product including a computer program which, when executed by a processor, implements the resource access management method as described above.
[0173] Those skilled in the art can understand that to implement all or part of the processes in the above method embodiments, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium, and when the program is executed, it may include the processes in the above method embodiments. Among them, the storage medium may be a magnetic disk, an optical disc, a read-only memory (ROM), a random access memory (RAM), a flash memory (FM), a hard disk drive (HDD), or a solid-state drive (SSD), etc.; the storage medium may also include a combination of the above-mentioned types of memories.
[0174] While embodiments of the present disclosure have been described in connection with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations fall within the scope defined by the appended claims.
Claims
1. A resource access management method, characterized in that: include: According to the task requirements, at least one role is created for the resources to be accessed and managed, and corresponding permissions are assigned to each role; wherein the resources include folders and their contents, and the permissions include at least one of the following: viewing permission, editing permission, uploading permission, and deleting permission; Configuring role-based permissions at the folder level of the resource, and configuring a corresponding role for the first user in the task requirement to determine a role-based access control policy; wherein one user corresponds to at least one role, and one role corresponds to at least one permission; Configuring user-based permissions at the folder level to determine an access control list, wherein the access control list is used to maintain permissions for each folder; Access to the resource is managed according to the role-based access control policy and the access control list.
2. The method according to claim 1, characterized in that The step of creating at least one role for the resource to be accessed and managed according to the task requirements includes: According to the task requirements, determine the resources to be accessed and managed and the team with access management requirements, where the first user is a user in the team; Determine user groups based on the responsibilities, functions or authority levels of users within the team; wherein one user group corresponds to one role; The at least one role is created for the resource.
3. The method according to claim 1, characterized in that The configuring of role-based permissions at the folder level of the resource and configuring a corresponding role for the first user in the task requirement to determine a role-based access control policy includes: Obtain a first folder and its content in the resource for which permission needs to be set; the first folder is at least one; For any of the first folders, matching a first role for the first folder, where the first role is a role in the at least one role; Associating the first folder with the assigned first role, and applying the permission of the first role to the first folder; Create a subfolder to inherit the role configuration of the parent folder, so that the permissions of the subfolder of the first folder include the permissions of the folder; associating the first role with the first user; A role-based access control policy is determined according to an association relationship between the first user and the first role, and an association relationship between the first role and permissions of the first folder.
4. The method according to claim 3, characterized in that If the at least one role is multiple, the method further includes: Configuring the role-based permissions at a subfolder level of the first folder to associate the subfolder of the first folder with an assigned second role and apply the permissions of the second role to the subfolder; The second role is a role among the at least one role.
5. The method according to claim 1, characterized in that The configuration at the folder level is based on the user's permissions, determining the access control list, including: Obtain a second folder and its content in the resource for which permission needs to be set; the number of the second folder is at least one; The second folder is associated with a second user for whom permissions are to be set in the task requirement, and permissions matching the second user are applied to the second folder to determine an access control list.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: An upload permission of a preset file format is added to the upload permission to control the format of files uploaded for a role configured with the upload permission or a user configured with the upload permission.
7. The method according to any one of claims 1 to 5, characterized in that: The access management of the resource according to the role-based access control policy and the access control list includes: In response to a target user's access management request for a target resource, determining, according to the access control list, whether the target user has viewing authority for the target resource, wherein the target resource is a resource in the resources to be accessed and managed; If the target user has viewing authority for the target resource, controlling the target user to view the target resource according to the access control list; If the target user does not have the permission to view the target resource, determine the target role corresponding to the target user according to the role-based access control policy, and determine whether the target role has the corresponding permission to access and manage the target resource, and there is at least one target role; If the target role has the corresponding authority to access and manage the target resource, then the target user is controlled to access and manage the target resource based on the target role having the corresponding authority to access and manage the target resource; wherein the access management includes at least one of the following: view, edit, upload, and delete.
8. A resource access management device, characterized in that: The device comprises: A first processing unit is used to create at least one role for the resource to be accessed and managed according to the task requirements, and assign corresponding permissions to each role; wherein the resource includes a folder and its content, and the permission includes at least one of the following: viewing permission, editing permission, uploading permission, and deleting permission; A second processing unit is used to configure role-based permissions at the folder level of the resource, and configure a corresponding role for the first user in the task requirement to determine a role-based access control policy; wherein one user corresponds to at least one role, and one role corresponds to at least one permission; a determination unit, configured to configure user-based permissions at the folder level and determine an access control list, wherein the access control list is used to maintain permissions for each folder; An access management unit is used to access and manage the resource according to the role-based access control policy and the access control list.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the resource access management method described in any one of claims 1 to 7.
10. An electronic device, characterized in that: The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the resource access management method described in any one of claims 1 to 7.