Visual strategy configuration method and system for multi-level resources

By decoupling parent-child group relationships through tree-structured display and drag-and-drop selection, the complexity of multi-level resource group policy configuration in cloud computing is solved, enabling flexible policy binding and precise control, and improving configuration efficiency and visibility.

CN121579137APending Publication Date: 2026-02-27北京志凌海纳科技股份有限公司

Patent Information

Application Number
CN202511778879.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

In cloud computing and virtualization environments, the policy configuration of multi-level resource groups suffers from problems such as tight coupling between parent and child groups, implicit policy inheritance, complex hierarchical structure, difficulty in flexible management, and high maintenance costs.

Method used

Resource groups are displayed in a tree structure. Parent-child group relationships are decoupled through drag-and-drop and check-out operations. The scope of policy application is updated in real time, and only the paths explicitly selected by the user are recorded. Flexible binding and control of policies are supported.

Benefits of technology

It improves the visibility, flexibility, and accuracy of policy configuration, reduces system maintenance complexity, reduces the risk of misoperation, and improves operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121579137A_ABST
    Figure CN121579137A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing and virtualization, and discloses a visual strategy configuration method and system for multi-level resources, virtual resources construct multi-level resource groups in a tree structure, set membership information among the resource groups is persistently recorded at a rear end, and structure information is updated in real time when resources are newly added or the structure is changed; receiving the resource group structure information and the strategy action range information, responding to the processing adjustment information in real time, and performing unified display at the front end; receiving a change behavior of a user on the resource structure and the strategy binding range; a change behavior is obtained and processed, and a processing result is stored persistently; a data result of resource group inheritance relation processing is received, the rear end only records an explicit resource group path selected by a user, and a strategy action range result is fed back to the front end in real time; according to the method, the policy configuration transparency and the control flexibility under the multi-layer nested resource structure can be improved, the misoperation risk is reduced, and the operation and maintenance efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of cloud computing and virtualization, and particularly relates to a visual policy configuration method and system for multi-level resources. BACKGROUND

[0002] In the cloud computing and virtualization environment, in order to improve the management efficiency, the virtual machine resources usually support the management mode of multi-level nested structure; in the policy configuration process of security policy, alarm rule, access permission and the like, the user can select the resource group as the dynamic policy action object, so as to facilitate the batch management of virtual machines; however, due to the support of arbitrary nesting of the resource group, the current system generally faces the following problems: 1. The parent group and the child group are tightly coupled, the policy has an implicit inheritance relationship, and lacks controllability and feedback mechanism; 2. The hierarchical structure of the resource group is complex, and the user cannot intuitively perceive the policy action range; 3. The policy cannot be flexibly reused, and the resource group cannot be flexibly specified from the perspective of the policy; 4. When the hierarchical structure is changed, the binding relationship between the parent resource group and the child resource group has a high maintenance cost, which affects the system efficiency. SUMMARY

[0003] The purpose of the present application is to solve the above problems, and a visual policy configuration method and system for multi-level resources are designed, the parent-child group logic is decoupled, the control accuracy of the policy configuration is enhanced while effectively simplifying the backend storage. The selection result of the configuration object is visualized and displayed in a tree structure on the interface, and the user can control the inheritance and exclusion state one by one, combined with the quantity feedback and hierarchical structure updating mechanism, the visibility, flexibility and accuracy of the policy configuration process are significantly enhanced.

[0004] The first aspect of the present application provides a visual policy configuration method for multi-level resources, which comprises the following steps: The virtual resources construct the multi-level resource groups in a tree structure, record the parent-child relationship information between the resource groups in the backend, and update the structure information in real time when the resources are added or the structure is changed; Receive the resource group structure information and the policy action range information, and respond to the adjustment information in real time, and perform unified display on the front end; Receive the change behavior of the user to the resource structure and the policy binding range; Get the change behavior and process it, and store the processing result persistently; Receive the data result of the resource group inheritance relationship processing, and only record the explicit resource group path selected by the user in the backend, and feed back the policy action range result to the front end in real time.

[0005] Optionally, in the first implementation manner of the first aspect, the received resource group structure information and policy scope information, and real-time response processing adjustment information are displayed uniformly at the front end, including: The hierarchical structure of the multi-level resource group is displayed in a tree view, and the inheritance state of the resource to the policy is displayed by checking. The number of selected resource groups, the number of selected resources, the name of the selected resource, and the absolute number of resources contained in each resource group are displayed.

[0006] Optionally, in the second implementation manner of the first aspect, the received user behavior of changing the resource structure and the policy binding scope includes: In response to the user's drag interaction behavior on the existing resource group, when the user drags a certain resource group to another resource group, it is considered as the user's adjustment operation on the resource group hierarchical structure. In response to the user's new resource group creation behavior by inputting the resource group name; In response to the user's check operation on the resource group, when the user checks or unchecks a certain resource group, it is considered as the modification of the resource group's inheritance state to the policy.

[0007] Optionally, in the third implementation manner of the first aspect, the multi-level nested resource groups are displayed in a tree structure, and the absolute number of virtual machines contained in each resource group node is marked. The user's operation on the interface is received, and when the user drags a certain resource group to another position, the system automatically updates the hierarchical structure relationship of the resource group and displays the adjustment result in a tree structure; When the user selects a certain resource group and inputs a new group name and clicks the create button, a new resource group is automatically created under the resource group, and the creation result is displayed in a tree structure; When the user clicks and checks a certain resource group, all its descendants are automatically expanded and checked by default, and the user can independently control the inheritance state of the subgroups, and the feedback is provided in the form of total number on the interface.

[0008] Optionally, in the fourth implementation manner of the first aspect, the obtained change behavior is processed, and the processing result is stored persistently, including: The user can rebuild the resource group structure by dragging, and the system will refresh the hierarchical structure relationship of the resource group and the policy binding scope display in real time after the change; New resource groups can be added at any level of the current structure, increasing the flexibility of policy configuration; The user can control the inheritance state of the resource group to the policy by checking.

[0009] Optionally, in the fifth implementation form of the first aspect of the present application, when a user checks a certain resource group, all the descendant groups are automatically expanded and checked by default in the front end, so as to complete the policy inheritance of the child groups to the parent group, and the user controls the policy inheritance range by manually unchecking any child group.

[0010] The second aspect of the present application provides a visual policy configuration system for multi-level resources, which comprises: A multi-level resource group modeling module for supporting virtual resources to construct multi-level resource groups in a tree structure, persistently recording the parent-child relationship information between the resource groups in the back end, and updating the structure information in real time when the resources are added or the structure is changed; An interactive display module for receiving the resource group structure information provided by the multi-level resource group modeling module and the policy action range information fed back by the policy action binding module, and responding to the adjustment information output by the processing module S304 in real time, and performing unified display in the front end: A receiving module for receiving the change behavior of the user on the resource structure and the policy binding range; A processing module for processing the information from the receiving module and persistently storing the result in the multi-level resource group modeling module or the policy action binding module; A policy action binding module for receiving the data result of the resource group inheritance relationship processing, and only recording the explicit resource group path selected by the user in the back end, and feeding back the policy action range result to the front end in real time.

[0011] Optionally, in the first implementation form of the second aspect of the present application, the interactive display module comprises: A tree relationship display module for displaying the hierarchical structure of the multi-level resource groups in a tree view, and displaying the inheritance state of the resources to the policy by checking; A resource quantity feedback module for displaying the number of selected resource groups, the number of selected resources, the name of selected resources, and the absolute number of resources contained in each resource group.

[0012] Optionally, in the second implementation form of the second aspect of the present application, the receiving module comprises: A structure adjustment receiving unit for responding to the drag interaction behavior of the user on the existing resource groups, and considering that the user drags a certain resource group to another resource group as the adjustment operation of the user on the hierarchical structure of the resource groups; A new resource group receiving unit for responding to the new resource group behavior of the user by inputting the resource group name; A resource group inheritance relationship receiving unit for responding to the check operation of the user on the resource groups, and considering that the user checks or unchecks a certain resource group as the modification of the inheritance state of the resource groups to the policy.

[0013] Optionally, in a third implementation form of the second aspect of the present application, the processing module comprises: The structural adjustment processing unit supports the user to reconstruct the resource group structure in a dragging manner, and the system displays the hierarchical structure relationship and the policy binding range of the resource group after the change in real time; The new resource group processing unit supports adding a resource group at any level of the current structure, thereby increasing the flexibility of policy configuration. The resource group inheritance relationship processing unit supports the user to control the inheritance state of the resource group to the policy through the checking manner.

[0014] In the technical solution provided by the present application, the virtual resources are constructed into a multi-level resource group in a tree structure, the parent-child relationship information between the resource groups is recorded in the back end in a persistent manner, the structural information is updated in real time when the resources are added or the structure is changed, the resource group structural information and the policy action range information are received, and the adjustment information is processed and responded in real time, and the front end is uniformly displayed; the change behavior of the user to the resource structure and the policy binding range is received; the change behavior is obtained and processed, and the processing result is stored persistently; the data result of the resource group inheritance relationship processing is received, the back end only records the explicit resource group path selected by the user, and the policy action range result is fed back to the front end in real time; the present application is different from the traditional mode of binding the policy to the resource group, the applicable resource group is selected reversely from the policy action object, the one-to-many binding relationship between the policy and multiple groups is supported, the policy reuse and the flexible control of the action boundary are realized; the policy inheritance logic of selecting the parent group and then checking all the child groups by default is provided on the front end interaction, but the back end only records the group path selected by the user explicitly, thereby improving the storage and processing efficiency; the parent group and the child group relationship are decoupled, the user can cancel the inheritance of the child resources one by one in the tree structure, and the precision of the policy configuration is improved; the absolute number of the resources of each layer is displayed, which helps the user to understand the binding range and assist in decision-making; when the resource group level is adjusted through dragging, the system automatically refreshes the policy action object and the inheritance relationship, thereby guaranteeing the data consistency; it is not a simple UI improvement, but a policy action control mechanism based on structure perception, and has systematic technical effects; the parent group and the child group relationship are decoupled, the resource group is flexibly selected from the policy configuration, and the inheritance state of the child group can be controlled; the selected resource group is displayed in a visual manner, and the user can accurately control the policy influence range; the level structure of the resource group can be freely adjusted, and the system automatically synchronizes the binding logic of the policy; the scheme can improve the policy configuration transparency and control flexibility under the multi-layer nested resource structure, reduce the risk of misoperation, and improve the operation and maintenance efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0015] Various other advantages and benefits will become apparent to those of ordinary skill in the art, upon reading the following detailed description of the preferred embodiment. The accompanying drawings are included to provide a description of preferred embodiments and are not meant to limit the present application.

[0016] Figure 1 For the application and prior art solutions contrast; Figure 2 For the application of the web page instance; Figure 3 For the system module structure diagram of the application; Figure 4 For the user and the application system interaction flow chart. DETAILED DESCRIPTION

[0017] The terms "first", "second", "third", "fourth" and the like in the description and claims of the present application, and above accompanying drawings, if any, are used for distinguishing between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so construed can interchange, under appropriate circumstances, without changing the meaning of the description by the embodiments described herein. In addition, the term "comprising" or "having" and any variations thereof, is intended to cover not exclusively containing, for example, processes, methods, devices, products or devices containing a series of steps or units, not necessarily limited to those clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0018] Currently mainstream virtualization platforms (such as VMware vSphere, KVM, OpenStack) all support virtual machine grouping, but are mostly single-layer management structures. Some systems use nested management structures, using child inheritance parent configuration mode.

[0019] There are no highly similar technical solutions in the current domestic public patent literature, but there are some practical cases with similar purposes or partial functions, which can be divided into two categories: 1. Label-based policy configuration system: platforms such as Nutanix Prism support policy binding by labeling virtual resources. Although this method is flexible, it does not have a clear hierarchical structure and cannot meet the needs of business architecture management such as organization-department-function. As shown in Figure 1 The relationship between resources, labels and policies is a many-to-many relationship, making it difficult to structure the scope of policy action and lacking inheritance control and visual feedback capabilities.

[0020] 2. Resource organization systems based on resource folders: Such as the virtual machine folder mechanism provided by VMware vSphere, which supports multi-level organization of virtual machines in the resource view. This method has a nested structure, but its policy configuration logic is mainly based on a static inheritance chain. That is, when a policy is applied to a group, its child resources implicitly inherit from it. Users cannot flexibly select resource sets from the perspective of the policy's target. For example... Figure 1 As shown, after configuring policy 1 for virtual machine group 1, child virtual machine groups a and b will implicitly inherit the effect of policy 1. If policy 2 is configured separately for child virtual machine group a, virtual machine group a will actually apply the combined effects of policy 1 and policy 2 simultaneously, making it impossible to precisely control the policy's scope. Furthermore, if you want to reuse policy 1 on virtual machine group 2, you must manually create policy 3 with identical attributes and bind it to virtual machine group 2. The relationship between groups and policies is one-to-one, lacking flexibility and making it difficult to manage policy resources holistically.

[0021] Compared to the above solutions, this invention starts from the policy configuration object and focuses on an interactive system for selecting multi-level resource ranges. The same policy supports the selection of multiple resource groups, and the relationship between resource groups and policies is many-to-one, such as... Figure 1 As shown. Simultaneously, by decoupling the parent-child group relationship, users can precisely control the scope of policy application; that is, if policy 1 is bound to virtual machine group 1, it will only apply to VM1 and VM2. This separate storage method eliminates the need to record the parent-child relationship between resource groups when storing policy object scope information, effectively improving system efficiency. For example... Figure 2 As one application example of the present invention, the front-end interaction process introduces visual operation functions such as automatic expansion of hierarchical structure, user-controllable exclusion, resource quantity prompts, and drag-and-drop structure linkage updates, making the strategy configuration more in line with the user's intention and significantly improving the accuracy and efficiency of strategy configuration.

[0022] To simplify system processing logic and improve configuration efficiency, this invention adopts a design approach of separate storage and merged interfaces: during policy configuration, the backend only records the virtual machine group path explicitly selected by the user, and does not implicitly include descendant groups; while the frontend achieves the inheritance effect on the interface by automatically expanding and defaulting to selecting descendant groups, which is essentially a frontend interaction optimization, avoiding the complexity of backend storage and logical calculations; this approach clearly limits the granularity of policy effect boundary control to the resource groups explicitly selected by the user, realizing the visibility, controllability, and traceability of the policy scope; for example Figure 3 The diagram shown is a system structure diagram of the present invention.

[0023] S301 Multi-level resource group modeling module, used to support virtual resources (such as virtual machines) to build a multi-level resource group in a tree structure, and to persistently record the parent-child relationship information between resource groups in the back end, providing a structural basis for front-end display and policy configuration. When resources are added or the structure is changed, the structural information is updated in real time.

[0024] S302 Interaction display module, used to receive resource group structure information provided by the multi-level resource group modeling module S301 and policy action range information fed back by the policy action binding module S305, and to respond to the adjustment information output by the processing module S304 in real time, and to perform unified display on the front end, such as Figure 2 As shown in the example, it contains two sub-modules: In this embodiment, S3021 Tree relationship display module: the hierarchical structure of the multi-level resource group is displayed in a tree view, and the inheritance state of the resource to the policy is displayed by checking. S3022 Resource quantity feedback module: display the number of selected resource groups, the number of selected resources, the name of selected resources, and the absolute number of resources contained in each resource group, that is, the number of resources not contained in the sub-group, for assisting in judging the policy action range and exclusion boundary.

[0025] S303 receiving module, used to receive user changes to resource structure and policy binding range, containing three sub-modules: In this embodiment, S3031 Structure adjustment receiving unit: in response to the user's drag interaction behavior on the existing resource group, when the user drags a resource group under another resource group, it is considered as the user's adjustment operation on the resource group hierarchical structure. S3032 New resource group receiving unit: in response to the user's new resource group behavior by inputting the resource group name; S3033 Resource group inheritance relationship receiving unit: in response to the user's check operation on the resource group, when the user checks or unchecks a resource group, it is considered as the modification of the resource group's inheritance state to the policy.

[0026] S304 processing module for processing information from receiving module S303, and persistently storing the results in multi-level resource group modeling module S301 or policy action binding module S304, corresponding to S303, containing three sub-modules: In this embodiment, S3041 Structure adjustment processing unit: supports users to rebuild the resource group structure by dragging, and the system will refresh the hierarchical structure relationship of the resource group and the policy binding range display in real time after the change. S3043 New resource group processing unit: supports adding a resource group at any level of the current structure, increasing the flexibility of policy configuration; S3043 Resource group inheritance relationship processing unit: support users to control the inheritance state of the policy of the resource group through the way of checking. At the same time, in order to increase the convenience of policy configuration, when the user checks a certain resource group, the policy inheritance effect of the child group to the parent group is realized in the way of automatically expanding and default checking all descendant groups in the front end, and the user can manually uncheck any child group to accurately control the policy inheritance range.

[0027] S305 Policy action binding module is used for receiving the data result of the resource group inheritance relationship processing unit S3043, and the back end only records the explicit resource group path selected by the user, thereby reducing the system complexity. At the same time, the policy action range result is fed back to the S302 interactive display module in real time.

[0028] Fig. 2 is one of the web page application examples of the system, which shows the operation process of the user selecting a virtual resource group through a graphical interface to configure a policy object in a policy configuration process. As shown in Fig. 4, it is a schematic diagram of the interaction process between the user and the system.

[0029] S401 Display the policy configuration object selection interface. The interface displays the multi-level nested resource groups in a tree structure (such as "department A-test group-business system 1-group1" containing subgroups a, b, and c), and each resource group node is marked with the number of virtual machines it contains (for example, "group1 (12 virtual machines)"). S402 Receive the operation of the user on the interface; S403 When the user drags a certain resource group to another position, the system automatically updates the hierarchical structure relationship of the resource group and displays the adjustment result in a tree structure; S404 When the user selects a certain resource group and inputs a new group name, and clicks the create button, the system automatically creates a new resource group under the resource group and displays the creation result in a tree structure; S405 When the user clicks and checks a certain resource group, the system automatically expands and default checks all descendant groups (for example, checking business system 1 automatically expands all descendant resource groups under business system 1), the user can independently control the inheritance state of the child group (for example, unchecking the resource group a means canceling the inheritance state of the resource group a to the policy configuration), and the interface provides feedback in the form of total number (for example, currently 4 virtual machine groups are selected, containing 47 virtual machines), and on the policy configuration range, the back end only records the absolute path of the group, without the structural relationship between the groups.

[0030] In this embodiment, in addition to the joint control of the front-end state tree and the back-end binding table, an independent inheritance relationship mapping layer can be constructed to structure the explicit binding and inheritance binding in each policy action path into a data table or a graph structure, so that the explicit record, traceability and auditability of the policy propagation relationship are realized. In addition to virtual machine resources, the system can also be applied to other multi-level structure resource configuration policy scenarios, such as virtual volumes, container pods, etc. A pre-computation caching mechanism or dynamic computation when the policy is triggered can be used to adapt to the performance requirements in different scales. In addition to the tree structure, a flat view or a column view can be used for hierarchical display of resources, and the display logic does not affect the core logic of the binding policy. In addition to the drag-and-drop method, the hierarchical adjustment can also be performed by batch setting of parent group attributes or by directive reconstruction of group paths.

[0031] In this embodiment, the hierarchical architecture of the multi-level resource group is intuitively presented through a tree view, and the parent-child nesting relationship between the resource groups is clearly presented in the form of visual nodes. An interactive check box is provided beside each node to visually display and control the inheritance state of the resource to the policy. When the parent node is checked, all child nodes under it are automatically expanded and checked by default, so that the inheritance logic is visually embodied. If a user unchecks a child node, the interface will highlight the difference in the check state of the node and the parent node in real time, clearly mark the exclusion boundary of the policy action, help the user quickly identify the coverage range of the policy in the hierarchical structure, and avoid misjudgment of the policy configuration due to complex hierarchical nesting. In the policy configuration interface, a plurality of key quantity indicators are dynamically displayed in real time, including the total number of resource groups that have been explicitly checked, the total number of specific resources such as virtual machines and containers included in these resource groups, and the name list of each resource. At the same time, the absolute resource quantity of each resource group node is separately marked, that is, the resource quantity directly included in the group itself does not include any resources in the child group. These data are displayed in the form of digital tags or statistical panels in conjunction with the tree view. When the user adjusts the check state, the relevant values are updated in real time, so that the user can accurately grasp the resource scale of the policy action, and quickly judge whether a specific child group needs to be excluded to optimize the policy action range by comparing the absolute resource quantities of the parent group and the child group.

[0032] In this embodiment, the real-time monitoring and response to the user's drag-and-drop interaction behavior of the resource group are performed. When the user drags and drops the target resource group under other resource group nodes through mouse or touch operation, the system instantly captures this operation intention and determines it as a hierarchical structure adjustment request. During the dragging process, the interface will feedback the target placement position in real time through dynamic highlight prompt line or shadow area. If the dragging is performed to a non-resource group area, the operation will be automatically ignored to ensure the accuracy of the adjustment behavior. At the same time, the unit records the change relationship between the original hierarchical path and the target hierarchical path to provide original operation data for the subsequent processing module to update the parent-child relationship of the resource group, supports single drag-and-drop of a single resource group or batch drag-and-drop of multiple resource groups after frame selection, and meets the structure adjustment requirements of different scales. "New" button or right-click menu trigger preset by the interface, dedicated to respond to user's operation behavior of creating a new resource group; when the user triggers the new instruction, the unit will pop up an interactive window containing a name input box and a hierarchical position selector, receive user input of resource group name support Chinese, English, numbers and special symbols combination, and real-time check the uniqueness of the name, while allowing users to select the parent of the new resource group through the drop-down menu or tree node; after the input is completed and confirmed, the unit will pack the name information and parent path information into a creation request and pass it to the processing module to perform resource group instantiation operation. The entire process supports shortcut key triggering and batch naming rules such as inputting "server group- "Automatic serial number naming to improve new efficiency; Focus on capturing user's click operation on the resource group node checkbox, and directly map the toggle of the checked state from "unchecked" to "checked" or vice versa as the modification instruction of the resource group's policy inheritance state; when the user checks the parent resource group, the unit will record this operation and trigger the pre-judgment of the child group inheritance logic; when the user unchecks a child group, the unit will mark the "exception" state of the child group and ignore the default inheritance behavior of all grandchildren groups under it; during the operation, the unit will real-time statistics the number of resource groups whose checked state is changed, and pack the timestamp, resource group ID and changed state of each state switch as detailed data, providing accurate basis for the processing module to update the inheritance relationship chain and policy scope, ensuring the consistency of front-end interaction and back-end data record.

[0033] In this embodiment, after receiving the user's drag operation instruction, the parent-child relationship mapping table between resource groups is dynamically reconstructed by analyzing the original resource group path and the target parent path, and the hierarchical structure data stored in the back-end is updated synchronously; after the adjustment is completed, the unit will trigger the real-time refresh mechanism of the front-end view to smoothly display the position change of the resource group in the tree structure with animation effect, and automatically check whether the original policy binding relationship is affected by the hierarchical adjustment. If the resource group has bound policies before adjustment, it will recalculate its display state in the policy scope according to the new hierarchical structure, ensuring that users can immediately see the impact of structure change on policy configuration, while preserving the history operation record for backtracking to avoid structure confusion caused by mistaken dragging; After receiving the new creation request, the uniqueness and legality of the resource group name are first checked, and then a new node is created in the hierarchy according to the parent path specified by the user, a unique identifier is automatically generated and associated with the parent group ID; the new resource group is in the "no policy bound" state by default, and can directly participate in the subsequent policy configuration process, supporting users to rename, move, or bind policies immediately after creation; the unit also optimizes the batch creation logic, when the user inputs a naming rule containing a wildcard, it can automatically generate multiple resource groups with serial numbers and insert them into the specified hierarchy in order, greatly improving the efficiency of building complex resource structures and enhancing the flexibility of policy configuration in hierarchical expansion scenarios. With the user's check behavior as the core, a hybrid control logic of explicit selection + automatic inheritance is constructed; when the user checks a resource group, the unit triggers the front-end linkage mechanism, automatically expands all the child group nodes under it and checks by default, intuitively reflects the effect of "parent group policy inherited by child group" through interface state consistency, and records the user's core check operation to only keep the parent group path, without redundant storage of child group default check state; if the user manually unchecks a child group, the unit will mark the "exception" state of the child group, block its inheritance of the parent group policy, and simultaneously cancel the default check of all grandchild groups under the child group to avoid confusion in the inheritance chain. Finally, all explicitly checked and unchecked resource group paths are summarized as policy scope data, which simplifies batch configuration operations and ensures precise control of policy inheritance through manual intervention mechanism.

[0034] In this embodiment, after receiving the final check state data transmitted by the resource group inheritance relationship processing unit, the minimum storage principle is adopted, only the absolute paths of the resource groups that are explicitly checked, including the parent group actively checked and the child group manually checked, and the resource groups that are explicitly unchecked are recorded to the backend database, and the default inherited child group information is not redundantly stored, thereby greatly reducing the data storage amount and associated verification logic, and reducing the system maintenance complexity. At the same time, the module synchronizes the sorted policy scope data, including all effective resource group IDs, corresponding resource quantities, and hierarchical relationship snapshots, to the interactive display module in real time, triggering the update of statistical data and the refresh of visual state of the interface, such as highlighting all effective resource group nodes in the tree view, updating the total number of resources in the quantity feedback panel, and distinguishing the states of explicitly selected and automatically inherited nodes by color, so that users can intuitively confirm the actual coverage of the policy, ensuring the consistency of the front-end display and the back-end data.

[0035] The above shows and describes the basic principles, main features and advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above-mentioned embodiments, and the above-mentioned embodiments and descriptions in the specification are only preferred examples of the present application and are not intended to limit the present application. Various changes and improvements can be made to the present application without departing from the spirit and scope of the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.

Claims

1. A visual strategy configuration system for multi-level resources, characterized in that, The method includes the following steps: Virtual resources are constructed into multi-level resource groups in a tree structure. The parent-child relationship information between resource groups is persistently recorded in the backend, and the structure information is updated in real time when resources are added or the structure is changed. Receive resource group structure information and policy scope information, respond and process adjustment information in real time, and display them uniformly on the front end; Receive user changes to resource structure and policy binding scope; Acquire changes and process them, then persist the processing results. The backend receives the data results from the resource group inheritance relationship processing. It only records the explicit resource group path selected by the user and feeds back the policy scope results to the frontend in real time.

2. The visualization strategy configuration method for multi-level resources as described in claim 1, characterized in that, The process of receiving resource group structure information and policy scope information, responding and adjusting information in real time, and displaying it uniformly on the front end includes: Display the hierarchical structure of multi-level resource groups in a tree view, and show the inheritance status of resources to policies by checking boxes; Displays the number of currently selected resource groups, the number of selected resources, the names of the selected resources, and the absolute number of resources contained in each resource group.

3. The visualization strategy configuration method for multi-level resources as described in claim 1, characterized in that, The receiving of user changes to resource structure and policy binding scope includes: Respond to user drag-and-drop interactions with existing resource groups. When a user drags a resource group to another resource group, it is considered an adjustment operation of the resource group hierarchy. Respond to the user's action of creating a new resource group by entering the resource group name; Responding to user selection of resource groups, when a user selects or deselects a resource group, it is considered a modification of the policy inheritance state of the resource group.

4. The visualization strategy configuration method for multi-level resources as described in claim 3, characterized in that, The resource groups are displayed in a tree structure, with the absolute number of virtual machines contained in each resource group node marked after the node. The system receives user actions on the interface. When a user drags a resource group to another location, the system automatically updates the hierarchical structure of the resource group and displays the adjustment results in a tree structure. When a user selects a resource group, enters a name for the new group, and clicks the create button, a new resource group will be automatically created under that resource group, and the creation result will be displayed in a tree structure. When a user clicks and selects a resource group, it automatically expands and selects all its descendant groups by default. Users can control the inheritance status of the subgroups and receive feedback on the interface in the form of a total number.

5. The visualization strategy configuration method for multi-level resources as described in claim 1, characterized in that, The process of acquiring and processing the changed behavior, and persistently storing the processing results, includes: Users can rebuild the resource group structure by dragging and dropping. The system will refresh the hierarchical structure and policy binding scope of the resource group in real time after the change. It supports adding new resource groups at any level of the current structure, increasing the flexibility of strategy configuration; Users can control the inheritance status of resource group policies by checking boxes.

6. The visualization strategy configuration method for multi-level resources as described in claim 5, characterized in that, When a user selects a resource group, the system will automatically expand on the front end and select all descendant groups by default to complete the policy inheritance from the parent group to the child group. Users can control the scope of policy inheritance by manually unchecking any child group.

7. A visual strategy configuration system for multi-level resources, characterized in that, The system includes: The multi-level resource group modeling module is used to support the construction of multi-level resource groups in a tree structure for virtual resources. It persistently records the parent-child relationship information between resource groups in the backend and updates the structure information in real time when resources are added or the structure is changed. The interactive display module receives resource group structure information from the multi-level resource group modeling module and strategy scope information from the strategy action binding module, and responds in real time to the adjustment information output by the processing module S304, displaying it uniformly on the front end. The receiving module is used to receive user changes to the resource structure and policy binding scope; The processing module is used to process the information from the receiving module and persist the results to the multi-level resource group modeling module or the strategy action binding module; The strategy scope binding module is used to receive the data results of resource group inheritance relationship processing. The backend only records the explicit resource group path selected by the user and feeds back the strategy scope results to the frontend in real time.

8. A visual strategy configuration system for multi-level resources as described in claim 7, characterized in that, The interactive display module includes: The tree-view module displays the hierarchical structure of multi-level resource groups in a tree view, and shows the inheritance status of resources to strategies by checking boxes. The resource quantity feedback module displays the number of currently selected resource groups, the number of selected resources, the names of the selected resources, and the absolute number of resources contained in each resource group.

9. A visual strategy configuration system for multi-level resources as described in claim 7, characterized in that, The receiving module includes: The structure adjustment receiving unit responds to the user's drag-and-drop interaction with existing resource groups. When a user drags a resource group to another resource group, it is considered as an adjustment operation of the resource group hierarchy. The new resource group receiving unit responds to the user's action of creating a new resource group by entering the resource group name; The resource group inheritance relationship receiving unit responds to the user's selection operation of resource groups. When the user selects or deselects a resource group, it is regarded as a modification of the policy inheritance status of the resource group.

10. A visual strategy configuration system for multi-level resources as described in claim 7, characterized in that, The processing module includes: The structure adjustment processing unit allows users to rebuild the resource group structure by dragging and dropping. After the change, the system will refresh the hierarchical structure relationship and policy binding scope of the resource group in real time. The new resource group processing unit supports adding new resource groups at any level in the current structure, increasing the flexibility of strategy configuration; The resource group inheritance relationship processing unit allows users to control the inheritance status of policies for resource groups by checking boxes.

Citation Information

Patent Citations

  • Access control policy synchronization for service layer

    CN109845221A

  • Inheritance of controls within a hierarchy of data processing system resources

    US20030188198A1

  • Visibility Control of Resources

    US20100257206A1

Cited By

  • Display control method and device for labels in medical image, equipment and medium

    CN121983254A