Communication authority control method and device in conference
By configuring permission matching rules in the conference system, dynamically controlling conference communication permissions, the problem that network device port settings in the existing technology cannot meet the diversified needs of enterprises is solved, and efficient and flexible communication permission management is achieved.
Patent Information
- Application Number
- CN202410178057.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-11
- Filing Date
- 2024-02-08
- Publication Date
- 2025-07-11
AI Technical Summary
The existing technology relies on network device port settings for conference communication permission control, which cannot meet the diverse information security needs of enterprises, and is not flexible and convenient.
By configuring permission matching rules in the conference system, dynamically control communication permissions in the conference based on user permission types and media data types, avoiding transformation and setting of network devices.
It improves the convenience and flexibility of meeting communication permission management, and allows managers to make refined permission settings according to actual needs to meet the diversified information security needs of enterprises.
Smart Images

Figure CN120301719A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202410044042.9 and the invention title "A Method and Device for Controlling Communication Permissions in a Meeting" filed on January 11, 2024, the entire content of which is incorporated herein by reference. Technical Field
[0002] This application relates to the field of meetings, and particularly to a method and device for controlling communication permissions in a meeting. Background Art
[0003] Out of consideration for information security, many enterprises have strict rules for sharing internal enterprise materials. As one of the most commonly used systems in enterprises, the meeting system naturally needs to comply with the rules set by the enterprise. For example, an enterprise may require that content between different departments cannot be shared, or content between different regions cannot be shared. In short, each enterprise will have its own unique requirements.
[0004] Currently, the response to the above requirements is mainly achieved by setting the underlying network devices of the meeting system. Usually, the ports of the network devices responsible for data exchange are set. For example, if audio is not allowed to be sent between Region A and Region B, the ports responsible for transmitting audio data in the network device are set to achieve this purpose.
[0005] However, relying solely on the method of port setting to control communication permissions in a meeting far from meets the diverse needs of enterprises. Summary of the Invention
[0006] This application provides a method and device for controlling communication permissions in a meeting.
[0007] In a first aspect of this application, a method for controlling communication permissions in a meeting is provided. The method includes: obtaining a permission matching rule configured by a management personnel in a meeting system, where the permission matching rule includes communication rules between multiple permission types, and the meeting system is used to hold a target meeting; in response to a request for obtaining by a target user, sending the target permission type corresponding to the target user to the target user, and at least one participant user is also included in the meeting accessed by the target user; obtaining target media data sent by a target terminal corresponding to the target user, and the media data carries the target permission type; determining whether to send the target media data to the at least one participant user according to the target permission type, the permission types corresponding to the at least one participant user, and the permission matching rule, where each participant user corresponds to one permission type.
[0008] This method only requires the administrator to make settings in the conference system, avoiding the need to configure additional network device management systems outside the conference system, greatly improving the convenience of managing communication permissions in meetings. In addition, this method allows the administrator to set the permission types of participants according to actual needs, no longer limiting the unit of permission management to the people corresponding to network device ports, effectively improving the flexibility of communication permission management in meetings.
[0009] In a possible implementation, obtain one or more of the permission types configured by the administrator and the following permission parameters: employee number, region, department, IP address, access network type, terminal device type; record the correspondence between the permission types configured by the administrator and the permission parameters.
[0010] In a possible implementation, the acquisition request of the target user carries the permission parameters of the target user. Based on the permission parameters of the target user and according to the correspondence between the permission types configured by the administrator and the permission parameters, determine the target permission type corresponding to the target user; send the target permission type corresponding to the target user to the target user.
[0011] In a possible implementation, the media data includes one or more of the following: audio data, video data, shared data, message data, where the video data indicates the data collected by the camera of the participating terminal, and the shared data indicates the data of the shared desktop collected by the participating terminal.
[0012] In a possible implementation, the at least one participating user includes a first participating user. When it is determined not to send the target media data to the first participating user, send a first no-permission indication message to the first participating user, and the first no-permission indication message is used to indicate that the first participating user does not have the permission to receive the target media data.
[0013] For participating users who do not have permission to obtain the target media data, the purpose that different permission types of participating users in the same meeting receive different data can be achieved by using the no-permission indication message.
[0014] In a possible implementation, the at least one participating user includes a second participating user. When it is determined not to send part of the target media data to the second participating user, send a second no-permission indication message and another part of the target media data to the second participating user, and the second no-permission indication message is used to indicate that the second participating user does not have the permission to receive the part of the target media data.
[0015] For participating users who do not have permission to obtain the complete target media data, the use of the no-permission indication information can achieve the purpose of implementing refined management of the media data that participating users can receive according to the permission type in the same meeting. That is,
[0016] In a possible implementation manner, the permission matching rule includes multiple communication rules. According to the priority order of the multiple communication rules in the permission matching rule from high to low, based on the permission matching rule, the target permission type, and the permission types corresponding to the at least one participating user, it is determined whether to send the target media data to the at least one participating user.
[0017] In a possible implementation manner, the permission type includes one or more of the following: high-security-level users, ordinary users, external users, where the high-security-level users and the ordinary users belong to the same enterprise, and the external users do not belong to the enterprise.
[0018] In a possible implementation manner, before obtaining the permission matching rule configured by the management personnel, the method further includes: starting the target meeting. In a possible implementation manner, before obtaining the permission matching rule configured by the management personnel, the method further includes: starting the target meeting.
[0019] The setting operation of the permission matching rule can occur before the meeting starts or during the meeting. Since the configuration action is relatively simple, it allows the management personnel to configure it flexibly.
[0020] In a possible implementation manner, the method further includes: obtaining the adjustment of the permission matching rule by the management personnel, and based on the adjusted permission matching rule, the permission types corresponding to the at least one participating user, and the target permission type, determining whether to send the target media data to the at least one participating user.
[0021] During the meeting, the management personnel can dynamically adjust the permission types of the participants or update the communication rules between multiple permission types according to the actual situation of the meeting, so as to achieve real-time adjustment and application of the permission matching rule.
[0022] In a possible implementation manner, the permission matching rule further includes the target topic in the meeting, and the target media data is the media data associated with the target topic.
[0023] When configuring the permission matching rule, the identifier of the topic is added, so as to associate the specific topic with the permission matching rule, and finally achieve the purpose of controlling the meeting permissions in units of topics. Based on this, the communication permissions in the meeting can be controlled more accurately and targeted.
[0024] The second aspect of the present application provides a communication permission control device in a meeting. The system includes: a communication module, configured to obtain a permission matching rule configured by a management personnel in a meeting system. The permission matching rule includes communication rules between multiple permission types. The meeting system is used to hold a target meeting; in response to a request for obtaining by a target user, send the target permission type corresponding to the target user to the target user. The meeting accessed by the target user further includes at least one participating user; obtain target media data sent by a target terminal corresponding to the target user, and the media data carries the target permission type; a processing module, configured to determine whether to send the target media data to the at least one participating user according to the target permission type, the permission types corresponding to the at least one participating user, and the permission matching rule, where each participating user corresponds to one permission type.
[0025] In a possible implementation manner, the communication module is further configured to obtain one or more of the permission types configured by the management personnel and the following permission parameters: employee number, region, department, IP address, access network type, terminal device type; the processing module records the corresponding relationship between the permission types configured by the management personnel and the permission parameters.
[0026] In a possible implementation manner, the request for obtaining by the target user carries the permission parameters of the target user. The processing module is further configured to determine the target permission type corresponding to the target user based on the permission parameters of the target user according to the corresponding relationship between the permission types configured by the management personnel and the permission parameters; the communication module is further configured to send the target permission type corresponding to the target user to the target user.
[0027] In a possible implementation manner, the media data includes one or more of the following: audio data, video data, shared data, message data, where the video data indicates data collected by a camera of a participating terminal, and the shared data indicates data of a shared desktop collected by the participating terminal.
[0028] In a possible implementation manner, the at least one participating user includes a first participating user. The processing module is further configured to determine not to send the target media data to the first participating user. The communication module is further configured to send a first no-permission indication message to the first participating user, and the first no-permission indication message is used to indicate that the first participating user has no permission to receive the target media data.
[0029] In a possible implementation manner, the at least one participating user includes a second participating user, and the processing module is further configured to determine not to send a part of the target media data to the second participating user. The communication module is further configured to send second permission indication information and another part of the target media data to the second participating user, where the second permission indication information is used to indicate that the second participating user does not have the permission to receive the part of the target media data.
[0030] In a possible implementation manner, the permission matching rule includes multiple communication rules, and the processing module is further configured to determine whether to send the target media data to the at least one participating user according to the priority of the multiple communication rules in the permission matching rule from high to low, based on the permission matching rule, the target permission type, and the permission type corresponding to the at least one participating user.
[0031] In a possible implementation manner, the permission type includes one or more of the following: high-security-level user, ordinary user, external user, where the high-security-level user and the ordinary user belong to the same enterprise, and the external user does not belong to the enterprise.
[0032] In a possible implementation manner, the processing module is further configured to start the target meeting before obtaining the permission matching rule configured by the administrator.
[0033] In a possible implementation manner, the permission matching rule further includes a target topic in the meeting, and the target media data is media data associated with the target topic.
[0034] A third aspect of the present application provides a computing device cluster, including at least one computing device, and each computing device includes a processor and a memory; the processor of at least one computing device is configured to execute instructions stored in the memory of at least one computing device, so that the computing device executes the method provided in the first aspect or any possible design of the first aspect.
[0035] A fourth aspect of the present application provides a computer program product including instructions, and when the instructions are run on a computer device cluster, the computer device cluster is caused to execute the method provided in the first aspect or any possible design of the first aspect.
[0036] A fifth aspect of the present application provides a computer-readable storage medium, including computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method provided in the first aspect or any possible design of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the accompanying drawings required for the embodiments will be briefly introduced below.
[0038] Figure 1 It is an architecture diagram of an enterprise internal meeting system provided by an embodiment of the present application;
[0039] Figure 2 It is an architecture diagram of a meeting system provided by an embodiment of the present application;
[0040] Figure 3 It is a schematic flowchart of a communication permission control method provided by an embodiment of the present application;
[0041] Figure 4 It is a configuration interface provided by an embodiment of the present application;
[0042] Figure 5 It is another configuration interface provided by an embodiment of the present application;
[0043] Figure 6 It is yet another configuration interface provided by an embodiment of the present application;
[0044] Figure 7 It is a schematic structural diagram of a communication permission control device provided by an embodiment of the present application;
[0045] Figure 8 It is a schematic structural diagram of a computing device provided by an embodiment of the present application;
[0046] Figure 9 It is a schematic structural diagram of a computing device cluster provided by an embodiment of the present application;
[0047] Figure 10 It is another schematic structural diagram of a computing device cluster provided by an embodiment of the present application. Detailed implementation manners
[0048] In order to make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. The terms used in the implementation part of the present application are only for explaining the specific embodiments of the present application and are not intended to limit the present application.
[0049] Instant Messaging (IM): Instant messaging is common in real-time communication systems, which allow two or more people to instantly transmit text messages, files, voice, and video over a network.
[0050] Media data: Media data refers to video data, shared data, audio data, message data, etc. sent by participating terminals during a meeting.
[0051] Video data: Video data refers to the data collected by the camera of the participating terminal, such as the images of the participating end-users, the surrounding environment of the meeting location, etc.
[0052] Shared data: Shared data refers to the data collected from the shared desktops sent by the participating terminals. Specifically, it can be the desktop data of all or part of the area of the participating terminal, or the display content of a certain application running on the participating terminal.
[0053] Audio data: Audio data refers to the sound data sent by the participating terminals, such as the sounds made by the users of the participating terminals themselves or the sounds of the videos they play, etc.
[0054] Message data: Message data refers to the text messages sent by the participating terminals, such as the text communication content in the chat windows of the users of the participating terminals.
[0055] Figure 1 Shows an enterprise internal meeting system architecture. Figure 1 Illustratively, two departments are given - the sales department and the finance department. In a meeting, it includes multiple employees from the sales department and multiple employees from the finance department at the same time. Each employee connects to the Selective Forwarding Unit (SFU) through a terminal (such as a personal computer (PC)), and then establishes a data communication link through the SFUs corresponding to their respective departments, so as to realize the access to the meeting. Specifically, different data communication links are established between the two SFUs according to the data type, and both ends of each communication link are ports in their respective SFUs dedicated to transmitting this type of data. For example, both ends of communication link 1 dedicated to transmitting video data are port SFU-S-1 and port SFU-F-1 respectively, and both ends of communication link 2 dedicated to transmitting shared data are port SFU-S-2 and port SFU-F-2 respectively.
[0056] Generally speaking, most of the information processed on the computer desktops of the employees in the finance department is information that needs to be kept confidential internally, such as salary information, the company's fund usage situation, or accounting information. Therefore, the enterprise can require that the desktop shared data of the finance department cannot be shared with other departments (including the sales department). To achieve this goal, the SFU on the finance department side can be set, that is, it is stipulated that port SFU-F-2 can only receive shared data, but cannot send shared data. In this way, during the meeting, when the employees in the sales department share their desktops, the employees in the participating finance department can see; and when the employees in the finance department share their desktops, the employees in the participating sales department can see. It should be noted that at this time, other employees in the participating finance department can see the shared desktop, because colleagues within the finance department may use other ports for data transmission.
[0057] It should be understood that by setting the ports of the SFU, not only can the unidirectional control of data transmission be achieved, but also the bidirectional control can be carried out as needed. That is, in the above example, the finance department cannot view the shared desktops of the sales department either. In other words, the communication link for transmitting shared data between the SFUs corresponding to the two departments is disabled, but this does not affect the employees of the two departments from participating in the same meeting.
[0058] As can be seen from the above example, by setting the ports of network devices (such as SFUs), the simple information security needs of enterprises can be met to a certain extent. However, this method cannot meet the complex and diverse information security needs. For example, if an enterprise stipulates that ordinary employees in the sales department cannot receive the shared data of the finance department, but senior employees (such as department heads, etc.) in the sales department have the right to receive the shared data of the finance department. Then it may be necessary to expand new ports or even new network devices for senior employees to achieve this requirement. In this way, for enterprises, the transformation cost and difficulty of network devices are significantly increased. In addition, although it is the underlying hardware of the conference system, to transform or set network devices (such as SFUs), it needs to be set outside the conference system, which also brings more workload to the enterprise's information technology (IT) staff. Finally, since the management system of network devices is usually independent of the conference system, when new rules need to be issued, the IT staff needs to be informed first, and then the IT staff uses the network device management system to manage and set the network devices. In other words, this method cannot manage and set network devices flexibly and in a timely manner, and naturally cannot meet the information security needs of enterprises flexibly.
[0059] In view of this, the present application proposes a method for controlling communication permissions in a meeting. Specifically, the conference system can receive the permission matching rules configured by enterprise managers at any time. During the meeting, the conference management server and the media server implement the control of communication permissions among multiple users according to the permission matching rules. Among them, the permission matching rules include the communication permissions between participating roles. This method does not require setting or transforming the ports of network devices, but relies on the conference system to complete the control of communication permissions, greatly improving the efficiency and flexibility of communication permission control.
[0060] Figure 2 Fig. shows a conference system architecture involved in the present application. Generally speaking, the conference system 100 includes a conference management server 101, a media server 102, and terminal devices 104. In some possible cases, the conference system 100 further includes a message server 103.
[0061] The conference management server 101 is used, on the one hand, to receive the permission matching rules configured by enterprise managers, and on the other hand, to send some or all of the permission matching rules to the media server 102 and the message server 103, so that the media server 102 and the message server 105 forward the received media data based on the received permission matching rules. The conference management server 101 can be an independent physical server or a physical server cluster. Of course, virtualization technology can also be used to implement the functions of the conference management server 101 through a virtualization instance (such as a virtual machine or a container, etc.); its functions can also be implemented through a cluster of virtualization instances. In some possible implementation manners, the conference management server 101 also provides a configuration interface for receiving the permission matching rules configured by enterprise managers. The configuration interface will be specifically introduced below.
[0062] In addition to obtaining some or all of the permission matching rules, the media server 102 is also used to establish a media data channel between terminal devices to achieve the forwarding of media data between terminal devices. Among them, the forwarding operation is based on the foregoing permission matching rules. It should be noted that the media server 102 can be an SFU or a multi-control unit (MCU). It should be understood that the implementation manner of the media server 102 is not limited in this application. Corresponding to the existence of the media server 102, the conference management server 101 provides a display window for displaying the video data and / or shared data of terminal users.
[0063] In addition to obtaining some or all of the permission matching rules, the message server 103 is also used to establish a message data channel between terminal devices to achieve the forwarding of message data between terminal devices. Among them, the forwarding operation is based on the foregoing permission matching rules. Corresponding to the existence of the message server 103, the conference management server 101 provides a chat window for displaying the message data of terminal users.
[0064] It should be noted that in some possible scenarios, the media server 102 can be used to process various types of media data, so the message server 103 is optional. However, in some possible scenarios, there is a dedicated message server 103 for processing message data. In this scenario, the media server 102 is used to process media data other than message data, while the message server 103 is dedicated to processing message data. This application does not limit the name or number of servers for processing media data, that is, for media data such as video data, shared data, audio data, and message data, dedicated servers can be used for data transmission respectively. Exemplarily, hereinafter, the media server 102 is used to process the first three types of data, and the message server 103 is used to process message data as an example for elaboration.
[0065] The terminal device 104 is a multimedia device for accessing the conference, such as a mobile phone, a computer, or a tablet computer, etc. In some possible implementation manners, the terminal device 104 can also be a virtual terminal provided based on cloud mobile phone services or cloud desktop services. The end user uses the terminal device 104 and the login credential to access the conference and realizes functions such as viewing, speaking, chatting, video, and sharing. Corresponding to the existence of the terminal device 104, the conference management server 101 provides a login interface for obtaining and verifying the user's login credential.
[0066] Next, based on Figure 3 the communication permission control method 200 provided by this application will be introduced:
[0067] S201: Enterprise managers configure permission matching rules in the configuration interface provided by the conference management server 101;
[0068] The permission matching rules indicate the communication rules between different permission types. Before introducing the permission matching rules, the permission types will be introduced first.
[0069] From the mapping relationship, each user corresponds to a permission type, and the corresponding relationship between this user and the permission type can be configured by enterprise managers.
[0070] From the perspective of type classification, permission types can be simply divided into senior users and ordinary users. Correspondingly, the permission matching rules should include the communication rules between senior user permissions and junior user permissions. In one possible implementation, permission types can be divided into high-secrecy-level users, ordinary users, and external users. Correspondingly, the permission matching rules should include the communication rules between high-secrecy-level users, ordinary users, and external users. It should be understood that the present application does not limit the number of hierarchical levels and naming of permission types. In other words, enterprise managers can set permission types with more hierarchical levels according to needs. It should be understood that regardless of the number of permission types, the key lies in different settings for different hierarchical permission types in the communication rules.
[0071] From the perspective of parameter configuration, permission types can be configured according to the needs of the enterprise. For example, configuration can be carried out in units of one or more of the following parameters: users, departments, regions, access network types, Internet Protocol Address (IP Address), terminal device types, etc.
[0072] Exemplarily, Figure 4 A schematic diagram of a configuration interface 300 is provided. The configuration interface 300 includes a parameter selection control 301 and a permission type selection control 302.
[0073] Enterprise managers can, as needed, use the parameter selection control 301 to select one or more parameters for setting. A drop-down menu is provided in the selection box for each parameter for enterprise managers to select. Optionally, enterprise managers can also directly input in the text box to achieve the purpose of searching or direct input. Specifically, the employee number is used to identify the identity of an employee. Generally speaking, the employee number of each employee is unique. Enterprise managers can configure the permission type for specific employees by setting this parameter; the region can include various countries, cities, regions, or administrative divisions where the enterprise's business premises are located. Enterprise managers can configure the permission type for participants in a specific region by setting this parameter; the IP address can include multiple IP addresses and multiple IP address segments. Enterprise managers can configure the permission type for participants whose access points are located at specific IP addresses or IP address segments by setting this parameter; the access network type includes the enterprise intranet and the external network. Enterprise managers can configure the permission type for participants whose access points are located in the enterprise intranet or the external network by setting this parameter; the terminal device type includes mobile phones, PCs, and tablet computers, etc. Enterprise managers can configure the permission type for participants whose access terminal devices are mobile phones, PCs, tablet computers, etc. by setting this parameter. After the above parameters are set, the permission type can be configured for the participants who meet the above parameters. As shown in the permission type selection control 302, by clicking the drop-down menu, enterprise managers can select one from multiple options for configuration.
[0074] As mentioned above, the permission matching rule indicates the communication rules between different permission types. Enterprise managers can set the permission matching rule through the configuration interface, or upload a file or script carrying the permission matching rule to the conference management server 101 to complete the configuration action.
[0075] Exemplarily, Figure 5 A schematic diagram of a configuration interface 400 is provided. The configuration interface 400 includes a permission type configuration control 401, a communication rule configuration control 402, and an addition control 403.
[0076] The permission type configuration control 401 includes a sender and a receiver. Enterprise managers can set the sender and the receiver as needed. Four parameters are exemplarily shown in the communication rule configuration control 402: audio, video, sharing, and message, corresponding to audio data, video data, shared data, and message data respectively. Enterprise managers can select allow (√) or not allow (×) for the above four parameters as needed.
[0077] As shown in the first row of the permission matching rules, when the permission type of the sender is a high-security-level user and the permission type of the receiver is an ordinary user, the ordinary user can receive audio data, video data, and message data from the high-security-level user during the meeting, but cannot receive the shared data of the high-security-level user. This may be because the desktop of the high-security-level user usually displays some confidential or content that is not convenient to show to the participants with the permission type of ordinary user.
[0078] In some possible implementation manners, when an enterprise manager adds a new row of rules by using the addition control 403, the manager can further select from "unidirectional" and "bidirectional" (not shown in the figure). Optionally, "unidirectional" will be used as the default option, and the enterprise manager can check "bidirectional" as needed. Among them, "unidirectional" indicates that the setting of this rule is only for the case where the "sender" sends media data to the "receiver" during the meeting, and "bidirectional" indicates that the setting of this rule is for both the case where the "sender" sends media data to the "receiver" during the meeting and the case where the "receiver" sends media data to the "sender" during the meeting. For example, taking the first row as an example, when the user checks "bidirectional" during the setting, a rule will be synchronously generated: when the permission type of the sender is an ordinary user and the permission type of the receiver is a high-security-level user, the high-security-level user can receive audio data, video data, and message data from the ordinary user during the meeting, but cannot receive the shared data of the ordinary user. This setting can effectively improve the configuration efficiency of enterprise managers.
[0079] Exemplarily, Figure 6There is also provided a schematic diagram of a configuration interface 500. The permission matching rules shown in the configuration interface 500 include priority parameters, sender, receiver, data type, and rules. Among them, the types of the sender and the receiver both include: high-security-level users, ordinary users, general users, and all. Among them, "all" indicates that it includes at least the previous three. Optionally, "all" can also include any permission types, such as newly added permission types. The data type includes audio, video, sharing, and messages, corresponding to audio data, video data, sharing data, and message data respectively. The rules include two options: allow and prohibit. It should be noted that for the priority, the smaller the corresponding number, the higher the priority of this rule. When the server needs to use the permission matching rules to determine whether to allow data communication, it will check one by one in the order from high to low priority. For example, when there are participants with permission types of high-security-level users, ordinary users, and external users in a meeting, and when an ordinary user attempts to send message data to the chat window of the meeting, the server will first compare the rule with a priority of 1. When it is determined that the sender of this rule is not "ordinary user", it is considered that there is no match, and then it will compare the rule with a priority of 2. When it is determined that the second rule is: allow participants with the permission type of ordinary users to send all types of data (such as audio data, video data, sharing data, and message data) to participants with the permission type of high-security-level users, then according to the rule with a priority of 2, the aforementioned message data will be sent to the participants with the permission type of high-security-level users. Next, the rule with a priority of 3 will be compared. According to this rule, it is prohibited for participants with the permission type of ordinary users to send message data to participants with the permission type of external users. Therefore, the server will not send message data to participants with the permission type of external users. When the data transmission rules for all participating permission types have been determined, the server will not perform further comparison.
[0080] In some possible implementation manners, the server can provide a default fallback rule. When a certain permission type attempts to send a specific type of data to another permission type, if none of the rules set by the enterprise management personnel can match it, the server will use the fallback rule for matching, and the matching result is to prohibit the transmission of this type of data. Optionally, the enterprise management personnel can check, delete, and modify the fallback clause according to needs.
[0081] Similar to Figure 4 and Figure 5 the rules shown in the configuration interface, the enterprise management personnel can perform operations such as adding, deleting, and modifying according to needs.
[0082] It should be noted that, on the one hand, the occurrence time of the configuration operation of the permission type can be earlier than the occurrence time of setting the permission matching rule, or later than the occurrence time of setting the permission matching rule; on the other hand, the occurrence times of these two types of operations can both be set in advance before the meeting starts, or can be set during the meeting.
[0083] S202: The conference management server 101 sends the permission matching rule to the media server 102.
[0084] When the enterprise management personnel have configured the permission matching rule, the conference management server 101 will send the complete or partial permission matching rule to the media server 102.
[0085] Optionally, the partial permission matching rule refers to the rule that is only related to the media server 102. When the media server 102 is only used to process media data other than message data, the media server 102 will receive the permission matching rules with data types of video, sharing, audio, and all.
[0086] S203: The conference management server 101 sends the permission matching rule to the message server 103.
[0087] When the enterprise management personnel have configured the permission matching rule, the conference management server 101 will send the complete or partial permission matching rule to the message server 103.
[0088] Optionally, the partial permission matching rule refers to the rule that is only related to the message server 103. When the message server 103 is only used to process message data, the media server 102 will receive the permission matching rules with data types of message and all.
[0089] S204: Multiple terminals obtain their respective permission types from the conference management server 101.
[0090] Taking the terminal user A as an example, when the terminal user A attempts to participate in the conference using the terminal device, the terminal device needs to first obtain its corresponding permission type from the conference management server 101. Among them, the attempt to participate in the conference using the terminal device can be that the user opens or logs in to the conference application, or the action that the user clicks to confirm after inputting the account number and password.
[0091] In some possible implementations, the terminal device can obtain its corresponding permission type without the user's awareness. Taking terminal user A as an enterprise employee as an example, when this employee attempts to access a meeting, the terminal device corresponding to terminal user A will send one or more of the following parameters to the meeting management server 101: employee number, terminal device type, region to which the employee belongs, department where the employee is located, IP address of the access point, access network type of the terminal device, and terminal device type. Corresponding to the foregoing permission type configuration interface 300, the meeting management server 101 will determine the permission type of terminal user A according to the correspondence between the parameters set by the enterprise management personnel and the permission type, and then return this permission type to the terminal device.
[0092] In some possible implementations, it can also be that when the terminal device attempts to use the terminal device to participate in a meeting, the meeting management server 101 sends a permission matching rule to the terminal device, and the terminal device determines the corresponding permission type according to the permission matching rule.
[0093] In some possible implementations, when terminal user A participated in a meeting last time, the terminal device stored the permission type at the last meeting. Therefore, the terminal device corresponding to terminal user A will send the following parameters to the meeting management server 101, which may also carry the permission type corresponding to the user last time. In this implementation, the terminal device receives from the meeting management server 101 a message that may be the permission type or a response message indicating that the permission type remains unchanged.
[0094] S205: Multiple terminal users use the terminal device 104, login credentials, and permission type to establish a communication channel with the server;
[0095] After obtaining its corresponding permission type in S204, terminal user A can access the meeting using the terminal device 104, login credentials, and permission type. Among them, the login credentials include but are not limited to meeting links, account numbers and passwords, face recognition information, fingerprint recognition information, etc.
[0096] After the conference management server 101 confirms that the terminal device accesses the conference, it will instruct the terminal device to establish a communication connection with the server. For example, the terminal device will establish a communication connection with the media server and the message server. Taking the establishment of a communication connection between the terminal device and the media server as an example: The instruction sent by the conference management server 101 to the terminal device to instruct it to establish a communication connection with the media server carries the address (such as the IP address) of the media server 102. The terminal device then sends a communication channel establishment request carrying its permission type to the media server 102. In response to this communication channel establishment request, the media server 102 will establish a communication channel with the terminal device. Since the establishment of a communication channel between two devices belongs to the prior art, it will not be elaborated in this application. It should be noted that while establishing the communication channel, the media server 102 also marks the terminal device according to the permission type carried in the communication channel establishment request. The establishment of the communication channel between the terminal device and the message server 103 can refer to the above content.
[0097] S206: The end user A sends media data to the media server 102;
[0098] After the terminal device corresponding to the end user A establishes a communication channel with the media server 102, the end user A can participate in the conference, and the terminal device can receive and send data.
[0099] Next, taking the example of three end users A, B, and C in the conference participants: When the end user A attempts to share the documents on its desktop and explain the documents in the conference, the media data sent upstream from the terminal device corresponding to the end user A to the media server 102 may include video data, audio data, and shared data. Among them, the video data is mainly used to display the personal image of the end user A, the audio data includes the data explained by the end user A, and the shared data includes the data corresponding to the documents on its desktop.
[0100] S207: The media server 102 sends media data to other end users according to the permission matching rule;
[0101] After the media server 102 receives the above media data including video data, audio data, and shared data, it determines whether to send some or all of the media data to other end users according to the permission matching rule.
[0102] Suppose the permission type corresponding to the end user A is an ordinary user, the permission type corresponding to the end user B is a high-security-level user, and the permission type corresponding to the end user C is an external user. Figure 6Taking the shown permission matching rules as an example, first, the matching rule with a priority of 1 is followed. When it is confirmed that the sender in the rule (high-security-level user) is inconsistent with the actual sender (ordinary user), the matching rule with a priority of 2 is sequentially judged. According to this matching rule, the end user A can send any type of media data to the end user B. Therefore, the media server 102 will send all the media data received from the end user A to the end user B. Next, the judgment is made according to the matching rule with a priority of 3. Although the sender and the receiver in the matching rule with a priority of 3 are consistent with the actual situation in this example, since the data type is limited to message data, it cannot be matched. Therefore, next, the judgment will be made according to the matching rule with a priority of 4. According to this matching rule, the end user A can send audio data to the end user C. Therefore, the media server 102 will send the audio data received from the end user A to the end user C. At this time, it is not clear whether the video data and shared data of the end user A can be sent to the end user C. Therefore, finally, the judgment will be made according to the fallback rule with the lowest priority. According to this fallback rule, the video data and shared data of the end user A are prohibited from being sent to the end user C. So far, the media server 102 has sent the media data from the end user A to other end users according to the permission matching rules.
[0103] In a possible implementation manner, for the prohibited audio data, shared data, and video data, a prompt will be given at the receiving end, such as displaying the words "content without permission". Therefore, according to the above example, the words "content without permission" will be displayed on the terminal device corresponding to the end user C to prompt the end user C that it has no permission to receive the audio data, video data, and shared data sent by the end user A.
[0104] S208: The end user A sends message data to the message server 103;
[0105] In a possible implementation manner, in addition to sharing the documents on its desktop and explaining the documents at the meeting, the end user A also sends text messages in the chat window, such as the storage address of the shared documents, so that the participants can view the documents by themselves. That is, the end user A further sends message data to the message server 103.
[0106] S209: The message server 103 sends the message data to other end users according to the permission matching rules;
[0107] After the message server 103 receives the above message data, it determines whether to send the message data to other end users according to the permission matching rules.
[0108] Still taking Figure 6Taking the shown permission matching rule as an example, according to a matching method similar to that in S207, it can be determined that: the end user B can see the message sent by the end user A, while the end user C cannot see the message sent by the end user A.
[0109] In a possible implementation, for the message data that is prohibited from being transmitted, a prompt will be given at the receiving end, such as displaying the words "content without permission". Therefore, according to the above example, the terminal device corresponding to the end user C will display "content without permission" to prompt the end user C that it has no permission to receive the message data sent by the end user A.
[0110] As mentioned above, the message server 103, as a server dedicated to processing message data, is not necessary. Therefore, the above steps S203, S208, and S209 are also optional.
[0111] It should be noted that the above method flow can not only be applied to the entire meeting, but also to one or several specific topics in the meeting. Specifically, when configuring the permission matching rule, the identifier of the topic can be added, so as to associate the specific topic with the permission matching rule, and finally achieve the purpose of controlling the meeting permissions in units of topics. Based on this, the communication permission control in the meeting can be realized more accurately and targeted.
[0112] In summary, the present application proposes a method for controlling communication permissions in a meeting. After the meeting management server 101 obtains the permission matching rule configured by the enterprise manager, it distributes the rule to the media server 102 and the message server 103. At the same time, before the terminal device enters the meeting, the permission type corresponding to the terminal device is sent to the terminal device, so that the terminal device can establish a communication connection with the media server 102 and the message server 103 based on the permission type. After the media server 102 and the message server 103 receive the media data sent by a terminal device, they can determine whether to forward the media data to other terminal devices according to the permission matching rule, so as to achieve the control of communication permissions in the meeting.
[0113] This method only requires the enterprise manager to set it in the meeting system, avoiding the need to configure the network device management system outside the meeting system, greatly improving the convenience of managing communication permissions in the meeting; in addition, this method allows the enterprise manager to set it according to needs, no longer limiting the unit of permission management to the people corresponding to the network device ports, effectively improving the flexibility of managing communication permissions in the meeting.
[0114] The present application also provides a communication permission control device 600, as Figure 7 shown, including:
[0115] The communication module 601 is configured to obtain, in step S201, the permission matching rules configured by enterprise managers in the configuration interface provided by the conference management server 101, and is further configured to obtain, in step S204, the acquisition requests sent by at least one terminal, and based on the acquisition requests, send a response message carrying the permission type to the at least one terminal. In step S205, the communication module 601 is configured to receive the login credentials and permission type of the terminal user. Further, the communication module 601 is further configured to obtain, in step S206, the media data sent by the terminal user, where the media data includes one or more of the following: audio data, video data, shared data, and message data. After receiving the media data sent by the terminal user, the communication module 601 is further configured to send the media data to other terminal users in S207.
[0116] The processing module 602 is configured to establish a communication channel with the terminal device according to the login credentials and permission type of the terminal user in step S205. After obtaining the media data sent by the terminal device in step S206, the processing module 602 is configured to determine, according to the permission matching rules, which users to send the media data to and which users to send the no-permission indication information to. Optionally, for the users to whom the media data is to be sent, it is also necessary to determine whether to send the complete media data or partial media data to this part of the users, which is determined according to the permission matching rules.
[0117] The storage module 603 is configured to store the permission matching rules configured by enterprise managers in step S201. Specifically, the permission matching rules further include the corresponding relationship between the permission types configured by the managers and the permission parameters. In a possible implementation manner, in order to implement the function of sending the no-permission indication message to the user in step S307, the storage module 603 is further configured to store the no-permission indication message.
[0118] Among them, the communication module 601, the processing module 602, and the storage module 603 can all be implemented by software or by hardware. Exemplarily, next, taking the communication module 601 as an example, the implementation manner of the communication module 601 will be introduced. Similarly, the implementation manners of the processing module 602 and the storage module 603 can refer to the implementation manner of the communication module 601.
[0119] As an example of a software functional unit, the communication module 601 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance may be one or more. For example, the communication module 601 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Usually, one region may include multiple AZs.
[0120] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, one VPC is set up within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0121] As an example of a hardware functional unit, the communication module 601 may include at least one computing device, such as a server. Alternatively, the communication module 601 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0122] The multiple computing devices included in the communication module 601 may be distributed in the same region or in different regions. The multiple computing devices included in the communication module 601 may be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the communication module 601 may be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0123] It should be noted that in other embodiments, the communication module 601 may be used to execute any step in the communication permission control method 200, the processing module 602 may be used to execute any step in the communication permission control method 200, and the storage module 603 may be used to execute any step in the communication permission control method 200. The steps to be implemented by the communication module 601, the processing module 602, and the storage module 603 can be specified as needed. The entire function of the communication permission control device 600 is realized by separately implementing different steps in the communication permission control method 200 through the communication module 601, the processing module 602, and the storage module 603.
[0124] In summary, the communication permission control device 600 may be a software functional unit, a hardware functional unit, or a combination of a software functional unit and a hardware functional unit. Exemplarily, the communication permission control device 600 may be a cloud management platform.
[0125] Next, the cloud management platform will be introduced:
[0126] The cloud management platform is used to provide access interfaces (such as interfaces or application programming interfaces (APIs)). Tenants can operate the client to remotely access the access interface to register cloud accounts and passwords on the cloud management platform and log in to the cloud management platform. After the cloud management platform successfully authenticates the cloud accounts and passwords, the tenants can further pay on the cloud management platform to select and purchase virtual machines with specific specifications (processors, memory, disks). After the successful payment purchase, the cloud management platform provides the remote login account password of the purchased virtual machine, and the client can remotely log in to the virtual machine and install and run the tenant's applications in the virtual machine.
[0127] Logical function division of the cloud management platform: user console, computing management service, network management service, storage management service, authentication service, and image management service. The user console provides an interface or API to interact with tenants. The computing management service is used to manage servers running virtual machines and containers, as well as bare metal servers. The network management service is used to manage network services (such as gateways, firewalls, etc.). The storage management service is used to manage storage services (such as data bucket services). The authentication service is used to manage tenant account passwords. The image management service is used to manage virtual machine images.
[0128] The cloud management platform also provides a cloud management platform client, which is used to receive control plane commands sent by the cloud management platform and create and perform full life cycle management on virtual machines on the server according to the control plane control commands.
[0129] Therefore, tenants can create, manage, log in to, and operate instances such as virtual machines, containers, and bare metal servers in the cloud data center through the cloud management platform.
[0130] This application also provides a computing device 700. As Figure 8 shown, the computing device 700 includes: a bus 702, a processor 704, a memory 706, and a communication interface 708. The processor 704, the memory 706, and the communication interface 708 communicate with each other through the bus 702. The computing device 700 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 700.
[0131] The bus 702 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 8 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus. The bus 704 can include a path for transmitting information between various components of the computing device 700 (for example, the memory 706, the processor 704, and the communication interface 708).
[0132] The processor 704 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a micro processor (MP), or a digital signal processor (DSP), etc.
[0133] The memory 706 may include volatile memory, such as random access memory (RAM). The processor 704 may also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0134] The memory 706 stores executable program code, and the processor 704 executes the executable program code to implement the functions of the foregoing communication module 601, processing module 602, and storage module 603 respectively, thereby implementing the communication permission control method 200. That is, instructions for executing the communication permission control method 200 are stored on the memory 706.
[0135] The communication interface 703 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 700 and other devices or a communication network.
[0136] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0137] As Figure 9 shown, the computing device cluster includes at least one computing device 700. Instructions for executing the communication permission control method 200 that are the same may be stored in the memory 706 of one or more of the computing devices 700 in the computing device cluster.
[0138] In some possible implementation manners, the memory 706 of one or more of the computing devices 700 in the computing device cluster may also store partial instructions for executing the communication permission control method 200 respectively. In other words, a combination of one or more computing devices 700 may jointly execute the instructions for executing the communication permission control method 200.
[0139] It should be noted that the memories 706 in different computing devices 700 in the computing device cluster may store different instructions, which are respectively used to execute partial functions of the communication permission control device 600. That is, the instructions stored in the memories 706 of different computing devices 700 may implement the functions of one or more of the communication module 601, processing module 602, and storage module 603.
[0140] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. Among them, the network may be a wide area network or a local area network, etc. Figure 10 A possible implementation is shown. As Figure 10 shown, two computing devices 700A and 700B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the memory 706 in the computing device 700A stores instructions for executing the functions of the communication module 601. At the same time, the memory 706 in the computing device 700B stores instructions for executing the functions of the processing module 602 and the storage module 603.
[0141] Figure 10 The connection method between the computing device clusters shown can be considered that since the communication permission control method 200 provided in this application needs to interact frequently with enterprise managers and end users, it is therefore considered to hand over the functions implemented by the processing module 602 and the storage module 603 to the computing device 700B for execution.
[0142] It should be understood that Figure 10 the functions of the computing device 700A shown in can also be completed by multiple computing devices 700. Similarly, the functions of the computing device 700B can also be completed by multiple computing devices 700.
[0143] The embodiments of this application also provide a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the communication permission control method 200.
[0144] The embodiments of this application also provide a computer-readable storage medium. The computer-readable storage medium may be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute the communication permission control method 200.
[0145] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, such modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for controlling communication permissions in a meeting, characterized in that, The method includes: Obtaining a permission matching rule configured by a management staff in a conference system, where the permission matching rule includes communication rules between multiple permission types, and the conference system is used to hold a target conference; In response to a request for acquisition from a target user, sending the target permission type corresponding to the target user to the target user, and at least one participant user is also included in the target conference accessed by the target user; Obtaining target media data sent by a target terminal corresponding to the target user, where the media data carries the target permission type; Determining whether to send the target media data to the at least one participant user according to the target permission type, the permission types corresponding to the at least one participant user, and the permission matching rule, where each participant user corresponds to one permission type.
2. The method according to claim 1, characterized in that, The obtaining the permission matching rule configured by the management staff includes: Obtaining one or more of the permission types configured by the management staff and the following permission parameters: Employee number, region, department, IP address, access network type, terminal device type; Recording the corresponding relationship between the permission types configured by the management staff and the permission parameters.
3. The method according to claim 2, wherein The request for acquisition from the target user carries the permission parameters of the target user, and the sending the target permission type corresponding to the user to the user in response to the request for acquisition from the target user includes: Based on the permission parameters of the target user, determining the target permission type corresponding to the target user according to the corresponding relationship between the permission types configured by the management staff and the permission parameters; Sending the target permission type corresponding to the target user to the target user.
4. The method according to any one of claims 1 to 3, characterized in that, The media data includes one or more of the following: Audio data, video data, shared data, message data, where the video data indicates data collected by a camera of a participant terminal, and the shared data indicates data of a shared desktop collected by the participant terminal.
5. The method according to any one of claims 1 to 4, characterized in that, The at least one participant user includes a first participant user, and the method further includes: When it is determined not to send the target media data to the first participant user, sending a first no-permission indication message to the first participant user, where the first no-permission indication message is used to indicate that the first participant user does not have the permission to receive the target media data.
6. The method according to claim 5, characterized in that, The at least one participant user includes a second participant user, and the method further includes: When it is determined not to send a part of the target media data to the second participant user, sending a second no-permission indication message and another part of the target media data to the second participant user, where the second no-permission indication message is used to indicate that the second participant user does not have the permission to receive the part of the target media data.
7. The method according to any one of claims 1 to 6, characterized in that The permission matching rule includes multiple communication rules, and the determining whether to send the target media data to the at least one participant user according to the target permission type, the permission types corresponding to the at least one participant user, and the permission matching rule includes: Determine whether to send the target media data to the at least one participating user according to the order of the priorities of multiple communication rules in the permission matching rule from high to low, based on the permission matching rule, the target permission type, and the permission types corresponding to the at least one participating user.
8. The method according to any one of claims 1 to 7, characterized in that, The permission types include one or more of the following: High-security-level users, ordinary users, external users. Among them, the high-security-level users and the ordinary users belong to the same enterprise, and the external users do not belong to the enterprise.
9. The method according to any one of claims 1 to 8, characterized in that, Before obtaining the permission matching rule configured by the administrator, the method further includes: Start the target meeting.
10. The method according to any one of claims 1 to 9, characterized in that The permission matching rule further includes the target topic in the meeting, and the target media data is the media data associated with the target topic.
11. A communication permission control device in a conference, characterized in that, It includes: A communication module, configured to obtain the permission matching rule configured by the administrator in the meeting system. The permission matching rule includes communication rules between multiple permission types, and the meeting system is used to hold a target meeting; In response to a request for acquisition by a target user, send the target permission type corresponding to the target user to the target user. The meeting accessed by the target user further includes at least one participating user; obtain the target media data sent by the target terminal corresponding to the target user, and the media data carries the target permission type; A processing module, configured to determine whether to send the target media data to the at least one participating user according to the target permission type, the permission types corresponding to the at least one participating user, and the permission matching rule, where each participating user corresponds to one permission type.
12. The device according to claim 11, characterized in that, The communication module is further configured to obtain one or more of the permission types configured by the administrator and the following permission parameters: employee number, region, department, IP address, access network type, terminal device type; the processing module records the correspondence between the permission types configured by the administrator and the permission parameters.
13. The device according to claim 12, wherein The acquisition request of the target user carries the permission parameters of the target user, and the processing module is further configured to determine the target permission type corresponding to the target user based on the permission parameters of the target user according to the correspondence between the permission types configured by the administrator and the permission parameters. The communication module is further configured to send the target permission type corresponding to the target user to the target user.
14. The device according to any one of claims 11 to 13, characterized in that The media data includes one or more of the following: audio data, video data, shared data, message data. Among them, the video data indicates the data collected by the camera of the participating terminal, and the shared data indicates the data of the shared desktop collected by the participating terminal.
15. The device according to any one of claims 11 to 14, characterized in that The at least one participating user includes a first participating user, and the processing module is further configured to determine not to send the target media data to the first participating user. The communication module is further configured to send a first no-permission indication message to the first participating user, and the first no-permission indication message is used to indicate that the first participating user does not have the permission to receive the target media data.
16. The device according to claim 15, characterized in that, The at least one participating user includes a second participating user. The processing module is further configured to determine not to send a part of the target media data to the second participating user. The communication module is further configured to send second unauthorized indication information and another part of the target media data to the second participating user. The second unauthorized indication information is used to indicate that the second participating user does not have the permission to receive the part of the target media data.
17. The device according to any one of claims 11 to 16, characterized in that, The permission matching rule includes multiple communication rules. The processing module is further configured to determine whether to send the target media data to the at least one participating user according to the priority of the multiple communication rules in the permission matching rule from high to low, based on the permission matching rule, the target permission type, and the permission type corresponding to the at least one participating user.
18. The device according to any one of claims 11 to 17, characterized in that The permission type includes one or more of the following: high-security-level user, ordinary user, external user. Among them, the high-security-level user and the ordinary user belong to the same enterprise, and the external user does not belong to the enterprise.
19. The device according to any one of claims 11 to 18, characterized in that The processing module is further configured to start the target meeting before obtaining the permission matching rule configured by the administrator.
20. The device according to any one of claims 11 to 19, characterized in that The permission matching rule further includes the target topic in the meeting, and the target media data is the media data associated with the target topic.
21. A cluster of computing devices, characterized in that, It includes at least one computing device, and each computing device includes a processor and a memory; The processor of the at least one computing device is configured to execute the instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 9.
22. A computer program product comprising instructions, characterized in that, When the instructions are run by the computer device cluster, the computer device cluster executes the method according to any one of claims 1 to 9.
23. A computer-readable storage medium, characterized in that It includes computer program instructions. When the computer program instructions are executed by the computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 9.
Citation Information
Cited By
Method and apparatus for controlling communication permission in conference
WO2025149027A1