Cloud management platform based on cloud rendering technology and authority management method thereof
By building a multi-level permission management model and user data encryption, the shortcomings of cloud platform in permission management and data privacy protection are solved, and a more secure and efficient application management and flow promotion solution is achieved.
Patent Information
- Application Number
- CN202510357448.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-25
AI Technical Summary
The existing cloud platforms have insufficient permission management in the application management and flow process, resulting in insufficient security and operation flexibility. At the same time, user data privacy protection is not perfect enough, which poses security risks.
Build a cloud management platform based on cloud rendering technology, including permission-related databases, user identity authentication modules, user permission authentication modules, user access permission control modules and permission management modules. Through multi-level permission management models and user data encryption, it supports flexible role definition and permission configuration, realizes dynamic permission adjustments, and records and audits user operation behaviors.
It improves the precision and security of permission management, enhances the flexibility and operability of the system, ensures user data privacy, and provides a more secure and efficient application management and streaming experience.
Smart Images

Figure CN120372591A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing and network services, and particularly to a cloud management platform based on cloud rendering technology and its permission management method. Background Art
[0002] In the development and management of modern applications, the rapid development of cloud computing technology has provided users with more efficient solutions. The Parallel Cloud Platform, as an application management and streaming platform integrating the Unreal Engine and Unity Engine, aims to provide developers with convenient application publishing and streaming media services. By transferring computing and rendering tasks to the cloud, this platform significantly reduces the performance requirements for terminal devices, enabling users to smoothly experience high-quality 3D applications on different devices. However, there are still some demand bottlenecks and security risks in the existing cloud platforms during the application management and streaming process.
[0003] Although the Parallel Cloud Platform provides powerful functions, there are still some problems in actual applications. First of all, most existing cloud platforms only provide basic permission setting functions. This single permission management method is difficult to meet the refined management requirements for multi-level permissions in complex business scenarios. Users often face problems such as insufficient or excessive permissions in actual operations, which affect the security of the system and the flexibility of operations, resulting in difficulty in achieving a balance between security and operability of the system. Secondly, the privacy protection measures for user data processing in the existing technology are still not perfect. Traditional methods often lack effective data encryption means, making these key data vulnerable to external attacks and abuse, seriously threatening user privacy and data security. The above problems and disadvantages lead to obvious security risks and low efficiency in the application management and streaming process of the existing technology. Especially when it comes to sensitive data and applications, the security and efficiency of traditional methods are difficult to be satisfactory. Summary of the Invention
[0004] In order to overcome the above defects, the present invention provides a cloud management platform based on cloud rendering technology and its permission management method, which can provide users with a more secure and efficient application management and streaming experience.
[0005] The technical solution adopted by the present invention to solve its technical problems: A cloud management platform based on cloud rendering technology includes a permission-related database, a user identity authentication module, a user permission authentication module, a user access permission control module, and a permission management module, wherein:
[0006] The permission-related database includes a user information table, a role information table, a permission information table, a user-role relationship table, and a role-permission relationship table. The user information table records user IDs, user names, and user passwords. The role information table records role IDs, role names, and role permissions. The permission information table records permission IDs, permission names, and permission identifiers. The user-role relationship table records the association relationship between user IDs and role IDs. The role-permission relationship table records the association relationship between role IDs and permission IDs;
[0007] The user identity authentication module is used to compare the user name and user password received by the system with the user name and user password information stored in the user information table of the permission-related database, and make a conclusion of authentication success or failure based on the comparison result;
[0008] After successful user identity authentication, the user permission authentication module can obtain the user ID when the system processes the user request. The user permission authentication module can also load the role list of the user according to the user ID, and query the permission list owned by the role through the role ID in the user's role list. The user permission authentication module can compare the requested resource URL or function identifier with the user's permission list to confirm whether the user has the permission to access the resource;
[0009] The user access permission control module can perform permission verification and intercept or release the request sent by the user according to the result confirmed by the user permission authentication module;
[0010] The permission management module enables the administrator to modify the data in the permission-related database through the system background management interface, thereby modifying the permissions of users and roles.
[0011] As a further improvement of the present invention, a user login encryption module is also provided. The user login encryption module can encrypt the password input by the user to form a user password.
[0012] As a further improvement of the present invention, the user information table also records user nicknames, user emails, user mobile phone numbers, user genders, user statuses, user creation times, and user modification times; the role information table also records role remarks, role statuses, role creation times, and role modification times; the permission information table also records menu types, parent permission IDs, permission paths, permission statuses, permission creation times, and permission modification times.
[0013] As a further improvement of the present invention, a permission initialization module is also provided. The permission initialization module can initialize the menu types of each permission, the relationships between each user and each role, and the relationships between each role and each permission.
[0014] As a further improvement of the present invention, a dynamic permission update module is also provided. When the data in the permission-related database changes, the dynamic permission update module can reload the permission data by refreshing the cache or by being triggered through the API.
[0015] As a further improvement of the present invention, a user data privacy and confidentiality module is also provided. The user data privacy and confidentiality module can encrypt the sensitive data of the user and display it with the node name.
[0016] As a further improvement of the present invention, an audit module is also provided. The audit module can record and store permission management behaviors, user operation behaviors, and sensitive data access behaviors of users.
[0017] A permission management method for a cloud management platform is as follows:
[0018] Step 1: Create a permission-related database:
[0019] User information table: Save the basic information of all users in the system through the user information table, and store the password field of the user using an encryption algorithm.
[0020] Role information table: Define all available roles in the system through the role information table.
[0021] Permission information table: Record all permissions in the system through the permission information table.
[0022] User-role relationship table: Maintain the many-to-many relationship between users and roles through the user-role relationship table.
[0023] Role-permission relationship table: Maintain the many-to-many relationship between roles and permissions through the role-permission relationship table.
[0024] Step 2: Dynamically associate users with roles and roles with permissions through foreign keys or associated tables, and when a user registers, updates personal information, or modifies the password, when a role is created, deleted, or modified, and when the system function is updated or the permission is adjusted, the system updates the permission-related data in real time.
[0025] Step 3: User identity authentication:
[0026] After the user submits the username and password on the front-end login page of the cloud management platform, the system receives the login request. The user login encryption module encrypts the input password and compares it with the user password stored in the user information table of the permission-related database. If they match, the user identity authentication is successful; otherwise, feedback information indicating that the user identity authentication fails is provided.
[0027] Step 4: User permission authentication:
[0028] After the user identity authentication is successful, when the user requests to access a resource, the system parses the user's basic information from the request header, queries the user-role relationship table through the user ID to load the user's role list, then queries the role-permission relationship table through the role ID to obtain the set of permission identifiers owned by the role. Finally, the system matches the requested resource identifier with the permission identifier. If the match is successful, the user permission authentication is successful and the request is allowed to pass; otherwise, a 403 status code or a "user has no permission" prompt is returned.
[0029] Step Five: User access permission control:
[0030] After the user permission authentication is successful, the user enters the business processing mode. The system implements permission comparison for the access permission of each resource requested by the user through two methods: annotation or interceptor. If the comparison and verification are successful, the request is allowed to pass and the request continues to execute; otherwise, the system will throw an exception and return a 403 status code or a "no permission" prompt.
[0031] As a further improvement of the present invention, in the user permission authentication step, first define the specific URL access policy in the SecurityConfig class, and then implement the permission authentication through Spring Security or AOP. The specific method is as follows:
[0032] The system defines a PermissionInterceptor interceptor. By obtaining the user information in the preHandle method and matching it with the requested resource URL according to the user permission list, if the match is successful, the request continues to execute; otherwise, the request is intercepted and a "no permission" prompt is returned.
[0033] Through the custom annotation @RequirePermission and the AOP aspect, the system performs permission control on specific methods or specific classes to ensure that only users with corresponding permissions can access specific functions.
[0034] As a further improvement of the present invention, in the user access permission control step, the user access permission is verified through two methods: annotation or interceptor. The specific method is as follows:
[0035] Use the @PreAuthorize annotation and call the @ss.hasPermi method to verify the permissions of the current user. If the user does not have the required permissions, the system will throw an exception and return a 403 status code or a "no permission" prompt.
[0036] In the interceptor-based approach, permission verification is implemented through a custom interceptor, PermissionInterceptor. The user information is parsed and obtained through the preHandle method, and the requested URL is compared with the user permission list. If the match is successful, the request is allowed to continue execution; otherwise, the request is intercepted and a permission-denied prompt is returned.
[0037] The beneficial effects of the present invention are as follows: By constructing a multi-level permission management model, the present invention supports flexible role definition, permission configuration and other functions, greatly improving the precision and security of permission management; The dynamic permission adjustment function of the present invention enables the system to quickly adapt to changes in business requirements and maintain the operability and flexibility of the system; The present invention particularly focuses on the protection of user data privacy. By encrypting sensitive information such as the user's IP address and displaying it with the node name, the direct exposure of the user's real data is avoided. Moreover, due to the modular design concept of the present invention, each module of the system can be independently extended and upgraded, enabling the system to be flexibly adjusted according to different business scenarios. The technical solution of the present invention optimizes the user interface and interaction design, making it more intuitive and convenient for users to operate the system. In particular, the visual configuration interface of the permission management module makes permission allocation and management easier to understand and improves the usability of the system. In summary, based on the prior art, the present invention provides a more secure and powerful cloud platform application management and streaming solution, effectively solving many problems in the prior art. Brief Description of the Drawings
[0038] Figure 1 It is the user permission management flowchart of the present invention;
[0039] Figure 2 It is the audit log table in the embodiment of the present invention. Detailed Embodiments
[0040] Embodiment: A cloud management platform based on cloud rendering technology includes a permission-related database, a user identity authentication module, a user permission authentication module, a user access permission control module, and a permission management module, wherein:
[0041] The permission-related database includes a user information table, a role information table, a permission information table, a user-role relationship table, and a role-permission relationship table. The user information table records a user ID (the ID that uniquely identifies a user), a user name (the login name of the user), and a user password. The role information table records a role ID (the ID that uniquely identifies a role), a role name (e.g., administrator, ordinary user), and role permissions (the scope of permissions corresponding to the role, usually represented as a string, e.g., ROLE_ADMIN). The permission information table records a permission ID (the ID that uniquely identifies a permission), a permission name (e.g., view user, add user, etc.), and a permission identifier (the identifier of the permission, such as sys:user:view, through which the system makes permission judgments). The user-role relationship table records the association relationship between the user ID and the role ID, and the role-permission relationship table records the association relationship between the role ID and the permission ID;
[0042] The user identity authentication module is used to compare the user name and user password received by the system with the user name and user password information stored in the user information table in the permission-related database, and make a conclusion of authentication passed or authentication failed based on the comparison result;
[0043] After successful user identity authentication, the user permission authentication module can obtain the user ID when the system processes the user request. The user permission authentication module can also load the role list of the user according to the user ID, and query the permission list owned by the role through the role ID in the role list of the user. The user permission authentication module can compare the requested resource URL or function identifier with the permission list of the user to confirm whether the user has the permission to access the resource;
[0044] The user access permission control module can perform permission verification on the request sent by the user and intercept or release it according to the result confirmed by the user permission authentication module;
[0045] The permission management module enables the administrator to modify the data in the permission-related database through the system background management interface, thereby modifying the permissions of users and roles.
[0046] Through the system background management interface, the administrator can configure permissions for different roles. The system usually displays all permissions in the form of a tree structure or checkboxes, and the administrator can check and assign permissions. After the permission configuration is completed, the system will store the corresponding relationship between the role and the permission in the role-permission relationship table, indicating the permissions owned by the role.
[0047] In the permission-related database of the present invention, through the user-role relationship table and the role-permission relationship table, the system administrator can flexibly configure roles for users according to business requirements, ensuring the accuracy and flexibility of role assignment. Moreover, different roles can have different permissions, ensuring the flexibility and security of system permission control. At the same time, the present invention constructs a multi-level permission management model through the user identity authentication module, the user permission authentication module, and the user access permission control module, supporting flexible role definition, permission configuration and other functions, greatly improving the fineness and security of permission management. Each module of the system can be independently extended and upgraded, enabling the system to be flexibly adjusted according to different business scenarios.
[0048] There is also a user login encryption module, which can encrypt the password entered by the user to form a user password. The password field is stored using an encryption algorithm to prevent leakage and ensure data security.
[0049] The user information table also records the user nickname (the nickname or display name of the user), the user email (the email address of the user), the user mobile phone number, the user gender, the user status (the account status of the user is normal, disabled, etc.), the user creation time, and the user modification time (the last modification time of the user information); the role information table also records the role remarks (the remarks or descriptions of the role), the role status (the status of the role is normal, disabled, etc.), the role creation time, and the role modification time (the last modification time of the role information); the permission information table also records the menu type (this permission is a menu permission, a button permission, a data permission, etc.), the parent permission ID (the ID of the parent permission of this permission, used to form the tree structure of permissions), the permission path (the URL or access path of the permission), the permission status (enabled, disabled, etc.), the permission creation time, and the permission modification time (the last modification time of the permission information).
[0050] There is also a permission initialization module, which can initialize the menu types of each permission, the relationships between each user and each role, and the relationships between each role and each permission.
[0051] The initialized permission data includes:
[0052] Menu permissions: Define each menu item, button, and operation permission in the system. In role management, roles obtain corresponding access and operation permissions by associating with these menu permissions;
[0053] Association between roles and permissions: In role management, roles obtain corresponding access and operation permissions by associating with menu permissions. For example, when creating or editing a role, the menu list of the permissions owned by the role can be set;
[0054] Data Permissions: Control the scope of users' access to data. For example, restrict users to only view data within their own department. In role management, data permission modes for roles can be set, such as all data permissions, customized data permissions, data permissions within the department, etc.
[0055] When the system starts up, after initializing the permission data, the system can configure roles based on these permissions and assign the permissions to the corresponding roles.
[0056] There is also a dynamic permission update module. When the data in the permission-related database changes, the dynamic permission update module can reload the permission data by refreshing the cache or by being triggered through an API.
[0057] During the operation of the system, it may be necessary to dynamically adjust the permission configuration. For example, add new functions or adjust the permission requirements for existing functions. This can be directly operated through the background management interface or update the permission data through SQL scripts. After dynamic update, the system needs to reload the permission data to ensure that the new permission configuration takes effect. Usually, when the permissions change, the permission data is reloaded by refreshing the cache or by being triggered through a specific API. Scenarios of dynamic permission update also include user role changes, role permission adjustments, etc. These operations all require the system to update the permission data in a timely manner to ensure the correctness of access control.
[0058] There is also a user data privacy and confidentiality module. The user data privacy and confidentiality module can encrypt the sensitive data of users and display it with node names.
[0059] This invention pays special attention to the protection of user data privacy. By encrypting sensitive information such as the user's IP address and displaying it with node names, it avoids directly exposing the user's real data. Among them, sensitive data usually refers to those data that may cause serious consequences to users or organizations once leaked or illegally accessed. It includes personal identity information (username, password, ID number, bank card number, mobile phone number, email address, etc. For example, fields such as username, password, mobile phone number, and email in the sys_user table), authentication information (including user passwords, tokens, keys, etc. For example: the password field in the sys_user table is stored in an encrypted form), security information (including access control lists, permission data, audit logs, etc. For example: fields related to user permissions in the sys_role_menu and sys_user_role tables. From the perspective of security risks, if the data leakage will cause serious impacts on individuals, companies, and society, then this data should be regarded as sensitive data.
[0060] There is also an audit module. The audit module can record and store permission management behaviors, user operation behaviors, and access behaviors to users' sensitive data.
[0061] The audit module records, analyzes, and traces operations in the system to ensure system transparency and traceability. The audit module can use database auditing and logging functions to achieve this goal. When implementing auditing, the following main steps are included:
[0062] Audit of permission allocation: Record each operation of role and permission allocation, modification, and revocation.
[0063] For example, when an administrator assigns a new role or permission to a user, the operator, operation time, modified role and permission, and modified data should be recorded;
[0064] Audit of user behavior: Record sensitive operations such as user login, logout, permission access, and data modification.
[0065] For example, when a user logs in to the system, record information such as their IP, login time, success or failure; when a user operates on sensitive data, record the operation time, operation content, operation type (new, delete, update, etc.);
[0066] Audit of sensitive data access: Audit access to sensitive data and record who, when, and which sensitive data was accessed.
[0067] For example, when querying or modifying the password field in the sys_user table, detailed log records should be available, including the visitor, operation time, operation type, etc.
[0068] The implementation method of the audit log is as follows:
[0069] Logging: Logging frameworks (such as Logback, Log4j2, etc.) can be used to record operation logs. The logging framework can also configure the system audit log function to record all key operations of the system.
[0070] Database auditing: In the database, triggers or log tables can be used to record access to and modification of sensitive data.
[0071] For example, when a user's password is modified, a log record event can be triggered to insert the operation record into the sys_audit_log table.
[0072] Log content:
[0073] Operation type: Add, delete, update, query;
[0074] Operation object: Which data table and which field are being operated on;
[0075] Operator: The user ID or username who performed the operation;
[0076] Timestamp: The time when the operation occurred;
[0077] IP address: The source IP of the operation;
[0078] Result status: Whether the operation is successful, failed, etc.
[0079] Log storage and management: Store the audit logs in an independent log table (such as sys_audit_log), and regularly clean and back up the logs to ensure the long-term validity and security of the logs.
[0080] An example of the audit log table (sys_audit_log) of the present invention is as Figure 2 shown.
[0081] Implementing a strict audit mechanism can ensure that the process of permission allocation and revocation is transparent and traceable.
[0082] A method for managing permissions in a cloud management platform, the specific steps are as follows:
[0083] Step 1: Create a database related to permissions:
[0084] User information table (sys_user): Save the basic information of all users in the system through the user information table, and store the password field of the user using an encryption algorithm to prevent leakage and ensure data security;
[0085] Role information table (sys_role): Define all available roles in the system through the role information table. The system administrator can flexibly configure roles according to business needs to ensure the accuracy and flexibility of role allocation;
[0086] Permission information table (sys_permission): Record all permissions in the system through the permission information table;
[0087] User-role relationship table (sys_user_role): Maintain the many-to-many relationship between users and roles through the user-role relationship table. A user can be assigned multiple roles to achieve multiple identity management;
[0088] Role-permission relationship table (sys_role_permission): Maintain the many-to-many relationship between roles and permissions through the role-permission relationship table, support the flexible allocation of roles and permissions. Different roles can have different permissions to ensure the flexibility and security of system permission control;
[0089] Step 2: Dynamically associate users with roles and roles with permissions through foreign keys or association tables. When a user registers, updates personal information, or modifies the password, when a role is created, deleted, or modified, and when the system functions are updated or permissions are adjusted, the system updates the permission-related data in real time. For example, when a user's role is assigned or changed, the system will update the user-role relationship table in real time to ensure the accuracy of the user-role relationship. When the permissions of a role are assigned or adjusted, the data in the role-permission relationship table will be automatically updated;
[0090] Step 3: User identity authentication:
[0091] After the user submits the username and password on the front-end login page of the cloud management platform, the system receives the login request. The user login encryption module encrypts the input password and compares it with the user password stored in the user information table of the permission-related database. If they match, the user identity authentication is successful and returned to the front-end, which usually stores it in the browser for use in subsequent requests. Otherwise, a user identity authentication failure message is feedback;
[0092] Step 4: User permission authentication:
[0093] After the user identity authentication is successful, when the user requests to access a resource, the system parses the user's basic information from the request header and queries the user-role relationship table (sys_user_role) through the user ID to load the user's role list. Then, the system queries the role-permission relationship table (sys_role_permission) through the role ID to obtain the set of permission identifiers owned by the role. Finally, the system matches the requested resource identifier with the permission identifier. If the match is successful, the user permission authentication is successful and the request is allowed. Otherwise, a 403 status code or a user has no permission prompt is feedback. For example, after the user logs in and accesses / system / user / list to obtain the user list, when the system processes the request, it obtains the user's user ID. Then, the system queries the role information corresponding to the user through the user ID and loads the user's role list. The system queries the permission list owned by the role through the role ID. Finally, the system compares the resource URL or function identifier requested to access with the user's permission list to confirm whether the user has the permission to access the resource. If the user has the permission to access the resource, the request is allowed and the subsequent business logic is continued. If there is no permission, the request is rejected and a 403 status code or a custom no permission prompt is returned;
[0094] Step 5: User access permission control:
[0095] After successful authentication of the user's permissions, the user enters the business processing mode. The system implements permission comparison for the access permissions of each resource accessed by the user's request through two methods: annotation or interceptor. If the comparison and verification are successful, the request is released and the request continues to execute. Otherwise, the system will throw an exception and return a 403 status code or a permissionless prompt.
[0096] In the user permission authentication step, first define the specific URL access policy in the SecurityConfig class, and then implement permission authentication through Spring Security or AOP. The specific methods are as follows:
[0097] The system defines a PermissionInterceptor interceptor. By obtaining user information in the preHandle method and matching the user permission list with the requested resource URL, if the match is successful, the request continues to execute; otherwise, the request is intercepted and a permissionless prompt is returned.
[0098] Through the custom annotation @RequirePermission and the AOP aspect, the system performs permission control on specific methods or specific classes to ensure that only users with the corresponding permissions can access specific functions.
[0099] In the user access permission control step, the user access permission is verified through two methods: annotation or interceptor. The specific methods are as follows:
[0100] Use the @PreAuthorize annotation and call the @ss.hasPermi method to verify the permissions of the current user. If the user does not have the required permissions, the system will throw an exception and return a 403 status code or a permissionless prompt.
[0101] Based on the interceptor method, the permission verification is implemented through the custom interceptor PermissionInterceptor. The user information is parsed and obtained through the preHandle method, and the requested URL is compared with the user permission list. If the match is successful, the request is allowed to continue to execute; otherwise, the request is intercepted and a permissionless prompt is returned. The configuration of the interceptor is usually performed in WebMvcConfigurer, and the interceptor is added to a specific path through the addInterceptors method to ensure that the permission verification is completed before the request enters the controller.
Claims
1. A cloud management platform based on cloud rendering technology, characterized in that: It includes a permission-related database, a user identity authentication module, a user permission authentication module, a user access permission control module, and a permission management module, where: The permission-related database includes a user information table, a role information table, a permission information table, a user-role relationship table, and a role-permission relationship table. The user information table records user IDs, user names, and user passwords. The role information table records role IDs, role names, and role permissions. The permission information table records permission IDs, permission names, and permission identifiers. The user-role relationship table records the association relationship between user IDs and role IDs. The role-permission relationship table records the association relationship between role IDs and permission IDs; The user identity authentication module is used to compare the user name and user password received by the system with the user name and user password information stored in the user information table in the permission-related database, and make a conclusion of authentication passed or authentication failed based on the comparison result; After the user identity authentication is successful, the user permission authentication module can obtain the user ID when the system processes the user request. The user permission authentication module can also load the role list of the user according to the user ID, and query the permission list owned by the role through the role ID in the user's role list. The user permission authentication module can compare the requested resource URL or function identifier with the user's permission list to confirm whether the user has the permission to access the resource; The user access permission control module can perform permission verification and intercept or release the request sent by the user according to the result confirmed by the user permission authentication module; The permission management module enables the administrator to modify the data in the permission-related database through the system background management interface, thereby modifying the permissions of users and roles.
2. The cloud management platform based on cloud rendering technology according to claim 1, wherein: There is also a user login encryption module, which can encrypt the password input by the user to form a user password.
3. The cloud management platform based on cloud rendering technology according to claim 1, wherein: The user information table also records the user nickname, user email, user mobile phone number, user gender, user status, user creation time, and user modification time; the role information table also records the role remarks, role status, role creation time, and role modification time; the permission information table also records the menu type, parent permission ID, permission path, permission status, permission creation time, and permission modification time.
4. The cloud management platform based on cloud rendering technology according to claim 3, characterized in that: There is also a permission initialization module, which can initialize the menu type of each permission, the relationship between each user and each role, and the relationship between each role and each permission.
5. The cloud management platform based on cloud rendering technology according to claim 1, characterized in that: There is also a dynamic permission update module. When the data in the permission-related database changes, the dynamic permission update module can reload the permission data by refreshing the cache or by being triggered by an API.
6. The cloud management platform based on cloud rendering technology according to claim 1, characterized in that: There is also a user data privacy protection module, which can encrypt the sensitive data of the user and display it with the node name.
7. The cloud management platform based on cloud rendering technology according to claim 6, characterized in that: There is also an audit module, which can record and store permission management behaviors, user operation behaviors, and sensitive data access behaviors of users.
8. A cloud management platform permission management method for the cloud management platform based on cloud rendering technology according to any one of claims 1-7, characterized in that: The specific steps are as follows: Step 1: Create a permission-related database: User Information Table: The basic information of all users in the system is saved through the User Information Table, and the password field of the user is stored using an encryption algorithm; Role Information Table: All available roles within the system are defined through the Role Information Table; Permission Information Table: All permissions in the system are recorded through the Permission Information Table; User-Role Relationship Table: The many-to-many relationship between users and roles is maintained through the User-Role Relationship Table; Role-Permission Relationship Table: The many-to-many relationship between roles and permissions is maintained through the Role-Permission Relationship Table; Step 2: The users are dynamically associated with roles and roles are associated with permissions through foreign keys or associated tables. When a user registers, updates personal information, or modifies the password, when a role is created, deleted, or modified, and when the system functions are updated or permissions are adjusted, the system updates the permission-related data in real time; Step 3: User Identity Authentication: After the user submits the username and password on the front-end login page of the cloud management platform, the system receives the login request. The user login encryption module encrypts the input password and compares it with the user password stored in the User Information Table of the permission-related database. If they match, the user identity authentication is successful; otherwise, an information indicating the failure of user identity authentication is feedback; Step 4: User Permission Authentication: After the user identity authentication is successful, when the user requests to access a resource, the system parses the basic information of the user from the request header, queries the User-Role Relationship Table through the user ID to load the user's role list, and then queries the Role-Permission Relationship Table through the role ID to obtain the set of permission identifiers owned by the role. Finally, the system matches the requested resource identifier with the permission identifier. If the match is successful, the user permission authentication is successful and the request is allowed to pass; otherwise, a 403 status code or a prompt indicating that the user has no permission is feedback; Step 5: User Access Permission Control: After the user permission authentication is successful, the user enters the business processing mode. The system implements permission comparison for the access permission of each resource requested by the user through two methods: annotation or interceptor. If the comparison and verification are successful, the request is allowed to pass and the request continues to execute; otherwise, the system will throw an exception and return a 403 status code or a prompt indicating no permission; 9. The cloud management platform permission management method according to claim 8, wherein: In the user permission authentication step, first define the specific URL access policy in the SecurityConfig class, and then implement the permission authentication through Spring Security or AOP. The specific method is as follows: The system defines a PermissionInterceptor interceptor. In the preHandle method, the user information is obtained and matched with the requested resource URL according to the user permission list. If the match is successful, the request continues to execute; otherwise, the request is intercepted and a prompt indicating no permission is returned; Through the custom annotation @RequirePermission and the AOP aspect, the system controls the permissions for specific methods or specific classes to ensure that only users with the corresponding permissions can access specific functions; 10. The cloud management platform permission management method according to claim 8, wherein: In the user access permission control step, the user access permission is verified through two methods: annotation or interceptor. The specific method is as follows: Use the @PreAuthorize annotation and call the @ss.hasPermi method to verify the permissions of the current user. If the user does not have the required permissions, the system will throw an exception and return a 403 status code or a no-permissions prompt. In the case of the interceptor-based approach, permission verification is implemented through a custom interceptor PermissionInterceptor. The user information is parsed and obtained through the preHandle method, and the requested URL is compared with the user's permission list. If the match is successful, the request is allowed to continue execution; otherwise, the request is intercepted and a no-permissions prompt is returned.