Access resource control method and system based on directory granularity, electronic equipment and computer program product
By determining the access resource configuration rules and time windows for directories in the distributed file system, calculating resource quotas and generating access credentials, the resource control problem at the directory level is solved, improving the accuracy and stability of directory access and ensuring service quality.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-04-10
AI Technical Summary
The lack of resource control methods at the directory level in existing technologies affects the service quality of directory access in distributed file systems.
By determining the target access resource configuration rules and target time window for the target directory, the access resource quota is calculated, and access credentials are generated to achieve precise authorization and resource control for the client.
It enables precise control over directory access behavior, prevents unauthorized access and resource abuse, avoids directory resource contention and conflicts, and improves the stability and service quality of directory access.
Smart Images

Figure CN121834862A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of computer storage, and particularly relates to a directory-granularity-based access resource control method and system, an electronic device, and a computer program product. BACKGROUND
[0002] A distributed file system can provide safe and reliable, scalable, and sharable mass data storage and access services for large-scale, multi-scenario, cross-node businesses (such as computing, big data analysis, and artificial intelligence training businesses), and solve problems such as mass data, high concurrency, and cross-device access that cannot be handled by traditional local file systems. The distributed file system supports coarse-grained access resource configuration at the pool level / user level, and is prone to directory access conflicts. At present, there is an urgent need for a directory-granularity-based access resource control method to ensure the quality of service when accessing a directory in a distributed file system. SUMMARY
[0003] Embodiments of the application provide a directory-granularity-based access resource control method and system, an electronic device, and a computer program product to solve the problem of lack of resource control methods at the directory granularity in the prior art, which affects the quality of service when accessing a directory in a distributed file system.
[0004] A first aspect of embodiments of the application provides a directory-granularity-based access resource control method, comprising: determining a target access resource configuration rule and a target time window of a target directory; calculating an access resource quota of the target directory within the target time window based on the target access resource configuration rule; in response to an access request of the target directory from at least one client, generating an access credential of each of the clients based on the access resource quota; sending the access credential to the corresponding client.
[0005] A second aspect of embodiments of the application provides a directory-granularity-based access resource control system, comprising: a determination module configured to determine a target access resource configuration rule and a target time window of a target directory; a calculation module configured to calculate an access resource quota of the target directory within the target time window based on the target access resource configuration rule; a generation module configured to, in response to an access request of the target directory from at least one client, generate an access credential of each of the clients based on the access resource quota; a sending module configured to send the access credential to the corresponding client.
[0006] The third aspect of the embodiments of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to the first aspect when executing the computer program.
[0007] The fourth aspect of the embodiments of the present application provides a computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the steps of the method according to the first aspect.
[0008] The fifth aspect of the embodiments of the present application provides a computer readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the steps of the method according to the first aspect.
[0009] As can be seen from the above, the present application calculates the access resource quota of the target directory based on the target access resource configuration rule and the target time window of the target directory, generates and sends the access credential to the client based on the access resource quota of the target directory in response to the access request of the client, and realizes the precise control of the access behavior of the client to the target directory through the credential-based authorization mode, effectively prevents unauthorized access and resource abuse, ensures that the access resource usage of the target directory within the set time window is always within the controllable range, on the one hand, and on the other hand, through the resource quota allocation and credential-based access control at the directory granularity, a clear resource usage boundary is drawn for all clients accessing the target directory, avoiding access conflicts caused by unordered directory resource occupation by multiple clients, and effectively alleviating the directory access competition problem under coarse-grained resource configuration in the distributed file system. The present application not only improves the precision of the access resource control at the directory dimension in the distributed file system, but also guarantees the orderliness and stability of the directory access, thereby comprehensively improving the service quality during the directory access in the distributed file system. BRIEF DESCRIPTION OF DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0011] Figure 1 is a flowchart of an access resource control method based on directory granularity provided by the embodiments of the present application; Figure 2 is an interaction flow diagram of a server and a configured client in a directory migration scenario provided by the embodiments of the present application; Figure 3is a structural diagram of a resource access control system based on a directory granularity provided by an embodiment of the present application; Figure 4 is a structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0012] In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular sequences of steps, techniques, etc., in order to provide a thorough understanding of the present embodiments. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, and circuits are omitted so as not to obscure the description of the present application with unnecessary detail.
[0013] It is to be understood that the terminology “includes”, “has”, “holds”, “contains” and / or “comprising”, “comprised of” and / or “comprising” used in the present specification in relation to a feature or features, integers, steps, operations, elements, and / or components are intended to be interpreted open-ended. For example, the terminology “includes”, “has”, “holds”, “contains” and / or “comprising”, “comprised of” and / or “comprising” can be taken to indicate the inclusion of stated features, integers, steps, operations, elements, and / or components, but not to the exclusion of one or more other features, integers, steps, operations, elements, and / or components that are not recited.
[0014] It is also to be understood that the terminology “includes”, “has”, “holds”, “contains” and / or “comprising”, “comprised of” and / or “comprising” and / or grammatical variants thereof when used in the present specification includes that stated feature but not to the exclusion of one or more other features that are not recited.
[0015] It is further to be understood that the terminology “and / or” when used in the present specification is to be interpreted as both an inclusive “and” and an inclusive “or” unless it is specifically stated otherwise or is understood from the context that the term is used in a different manner.
[0016] As used in the present specification and claims, the term “if’ can be interpreted as meaning “when”, or “once”, or “in response to a determination”, or “in response to a detection” depending on the context. Similarly, the phrase “if determined”, or “if detected” can be interpreted as meaning “once determined”, or “in response to a determination”, or “once detected”, or “in response to a detection”, depending on the context.
[0017] In particular implementations, the terminals described in the embodiments of the present application include, but are not limited to, other portable devices such as mobile telephones, laptop computers, or tablet computers with touch-sensitive surfaces (e.g., touch screen displays and / or touch pads). It will also be appreciated that, in some embodiments, the device is not a portable communication device, but rather a desktop computer with a touch-sensitive surface (e.g., a touch screen display and / or a touch pad).
[0018] In the following discussion, a terminal that includes a display and a touch-sensitive surface is described. It should be understood, however, that a terminal can include one or more other physical user-interface devices, such as a physical keyboard, a mouse, and / or a joystick.
[0019] The terminal supports a variety of applications, such as one or more of the following: a drawing application, a presentation application, a word processing application, a website creation application, a disk authoring application, a spreadsheet application, a game application, a telephone application, a video conferencing application, an e-mail application, an instant messaging application, a workout support application, a photo management application, a digital camera application, a digital camcorder application, a web browsing application, a digital music player application, and / or a digital video player application.
[0020] Various applications that can be executed on the terminal can use at least one common physical user-interface device, such as a touch-sensitive surface. One or more functions of the touch-sensitive surface, as well as the corresponding information displayed on the terminal, can be adjusted and / or changed between applications and / or within respective applications. In this way, the common physical architecture (e.g., touch-sensitive surface) of the terminal can support a variety of applications with a user interface that is intuitive and transparent to the user.
[0021] It should be understood that the sequence of the steps in the embodiments does not mean the order of execution, the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0022] The present application provides a directory granularity-based access resource control method and system, electronic equipment and computer program product, which is applied to a distributed file system, such as Ceph File System (CephFS), Lustre File System (Lustre), Bee Global File System (BeeGFS).
[0023] The present application realizes Quality of Service (QoS) control by controlling access resources at the directory granularity, solves the problem of lack of access resource control at the directory granularity in the prior art, and affects the quality of service.
[0024] In order to illustrate the technical solutions described in the present application, the following will be described by specific embodiments.
[0025] Reference Figure 1 , Figure 1This is a flowchart illustrating a directory-level resource access control method provided in an embodiment of this application. Figure 1 As shown, a directory-level resource access control method includes the following steps: Step 101: Determine the target access resource configuration rules and target time window for the target directory.
[0026] In this application, the management end, based on the business plan of the distributed file system, pre-sets access resource configuration rules for multiple directories in the distributed file system to realize personalized configuration of multiple directories, so as to implement independent access resource control for each directory and realize performance isolation at the directory level.
[0027] The management terminal typically consists of a hardware server (or cluster) with management privileges and supporting management software. It is the main body for executing operations such as rule configuration and time window setting. It supports administrators to initiate operations through command line interface and graphical user interface, and can also execute automated configuration logic independently.
[0028] Access resource configuration rules, also known as directory-level Quality of Service (QoS) policies, are rules that constrain the use of access resources within a directory, thereby implementing performance resource constraints. Access resource configuration rules may include resource limit parameters such as the maximum number of access operations per unit time (maximum input / output operations per second, IOPS) and the maximum data transfer bandwidth per unit time (BW). They may also include auxiliary control parameters such as Time To Live (TTL). Access resource configuration rules are the key basis for achieving directory-level resource isolation and fair allocation.
[0029] Business planning is the core basis for management to configure rules. For example, tenant directories are divided according to different business departments and user groups, resource priorities of directories are differentiated according to core business / ordinary business / testing business, and IOPS and bandwidth requirements of each directory are determined according to business scenarios such as big data analysis, artificial intelligence training, and daily office work, to ensure that rule configurations are accurately adapted to actual business scenarios.
[0030] A time window, also known as a metering window, refers to the time period during which access statistics, resource quota calculations, and allocations are performed on directory resources in a distributed file system.
[0031] In some embodiments, the duration of the time window (usually denoted as window_ms) can be flexibly configured within the range of 100–2000ms, with the specific value determined by the management end based on business requirements (such as the smoothness of burst traffic and the accuracy of control).
[0032] In some embodiments, the rule configuration of the management end can adopt an artificial configuration mode with administrator intervention, or an automatic configuration mode of the management end, and the two configuration modes can be used independently or in combination. For example, the administrator configures the access resource configuration rule for the directory through the command line interface (CLI) or the graphical user interface (GUI) of the management end.
[0033] The service end receives the access resource configuration rule of each directory sent by the management end, and writes the access resource configuration rule in the form of an extended attribute (xattr) key-value pair into the index node (inode) structure body corresponding to the unique directory. Through the unique identification of the inode, the binding relationship between the rule and the directory is ensured not to be invalid due to path changes.
[0034] The directory is a logical container for organizing, classifying and managing files and subdirectories in the distributed file system, and is the core logical unit for realizing data hierarchical management and access control in the distributed file system.
[0035] In some embodiments, the service end is deployed with a metadata server (MDS) cluster, and the MDS cluster undertakes the authoritative management responsibility of the directory sub-tree. The MDS cluster includes one or more metadata server ranks (MDS Rank), and each MDS Rank undertakes the authoritative management responsibility of a specific directory sub-tree. Specifically, a plurality of directories in the distributed file system form several independent directory sub-trees in a hierarchical tree structure, and the service end divides the management range of each MDS Rank according to the ownership of the directory sub-tree. One or more MDS Ranks are responsible for the exclusive management of the directory sub-tree, including the metadata maintenance of all directories in the directory sub-tree (including the access resource configuration rule stored in the directory inode), the judgment of the hierarchical relationship between directories (used to guide rule inheritance / override), the authoritative measurement of directory access behavior, access resource quota calculation, access credential distribution and other control related operations, to ensure that the management rights and responsibilities of each directory sub-tree are centralized and unique, and to provide authoritative support for access resource control at the directory granularity.
[0036] In some embodiments, the service end synchronously records the configuration operation such as setting, modifying or deleting corresponding to the access resource configuration rule of each directory into a metadata log (MDLog), forming an unalterable operation trace record. The rule of the directory is finally stored into the underlying distributed storage cluster through the synchronization mechanism of the MDLog. The underlying distributed storage cluster includes the MDLog, a metadata cache (MDCache) (used for saving hot data such as directory items and inodes), a reliable autonomic distributed object store (RADOS) / object storage device (OSD) and the like, and the distributed storage cluster also stores file resources associated with each directory. Through the double protection of log recording and underlying persistence, it is ensured that the access resource configuration rule of all directories will not be lost due to node failure, system restart or network fluctuation, and the stable persistence and data reliability are provided, thereby providing a basis support for the subsequent consistent execution of the access resource control of the directory granularity.
[0037] The target directory is a directory in the distributed file system that can implement access resource control. The corresponding inode thereof is the identity thereof, and the target directory bound access resource configuration rule can be accurately associated based on the inode.
[0038] The target directory can be any attribute directory in the distributed file system, such as the root directory, business exclusive directory, subdirectory, grandchild directory and the like of different levels and different business attributes in the distributed file system, as long as the directory is within the management range of the MDS cluster.
[0039] The target access resource configuration rule is the access resource configuration rule corresponding to the target directory, which is a performance control policy set for the target directory, including but not limited to IOPS upper limit and unit time BW upper limit.
[0040] The target time window is a time window corresponding to the target directory, which is used for segment calculation and resetting of the access resource quota of the target directory, and the window length can be configured within a preset range (such as 100-2000 milliseconds).
[0041] In order to implement the access resource management and control of the target directory, the target access resource configuration rule and the target time window of the target directory need to be determined.
[0042] In some embodiments, the target access resource configuration rule and the target time window of the target directory can be obtained from the underlying distributed storage cluster.
[0043] In some embodiments, the determining the target access resource configuration rule of the target directory comprises: if the target directory is configured with the first access resource configuration rule, determining the first access resource configuration rule as the target access resource configuration rule of the target directory; if the target directory is not configured with the first access resource configuration rule, determining the second access resource configuration rule of the ancestor directory closest to the target directory as the target access resource configuration rule of the target directory.
[0044] The first access resource configuration rule refers to an access resource configuration rule explicitly configured by the management end for the target directory, which is directly bound to the inode of the target directory.
[0045] The second access resource configuration rule refers to an access resource configuration rule configured by the ancestor directory closest to the target directory in the directory hierarchy of the distributed file system (the rule of the ancestor directory is also explicitly configured by the management end), which is the inherited rule when the management end does not explicitly configure the rule for the target directory.
[0046] The ancestor directory refers to the upper directory of the target directory in the directory tree of the distributed file system, such as the parent directory, the grandparent directory, and the directory higher than the target directory. The closest ancestor directory is the first directory found in the upward traversal process based on the target directory, which is pre-configured with an access resource configuration rule by the management end.
[0047] Detecting whether the target directory is pre-configured with an access resource configuration rule by the management end.
[0048] If the first access resource configuration rule is detected, the rule is directly determined as the target access resource configuration rule of the target directory.
[0049] If the first access resource configuration rule is not detected, the rule inheritance mechanism is triggered. Starting from the node of the target directory, the directory tree is traversed upward level by level, and the parent directory, the grandparent directory, and other ancestor directories of the target directory are checked in turn for whether they are configured with an access resource configuration rule, until the first ancestor directory configured with an access resource configuration rule is found. The rule of the ancestor directory is the second access resource configuration rule. The second access resource configuration rule is determined as the target access resource configuration rule of the target directory, and the inheritance relationship is recorded in the MDLog, and the inherited rule is bound to the inode of the target directory, serving as the basis for subsequent resource quota calculation. If the management end subsequently explicitly configures an access resource configuration rule for the target directory, the second access resource configuration rule inherited by the target directory will be automatically overwritten, and the new rule takes effect through inode binding.
[0050] In some embodiments, the following directory hierarchy in the distributed file system: directory A - directory A1 - directory A11, wherein directory A is the top-level directory, directory A1 is a subdirectory of directory A, and directory A11 is a subdirectory of directory A1.
[0051] In some embodiments, the management end only explicitly configures the access resource configuration rule for directory A, and does not explicitly configure any rule for directory A1 and directory A11. When the rule information of directory A11 is specified, since it has no explicit rule itself, it traces back to the ancestor directory with the configured access resource configuration rule according to the hierarchy, and finally matches directory A, so the target access resource configuration rule of directory A11 directly inherits the explicitly configured access resource configuration rule of directory A.
[0052] In some embodiments, if the management end later explicitly configures an access resource configuration rule for directory A11, the target access resource configuration rule of directory A11 changes from the rule inherited from directory A to the new rule explicitly configured by the management end for directory A11, realizing rule coverage.
[0053] In some embodiments, the rule management unit in the MDS Rank of each directory is controlled by the service end to write the access resource configuration rule corresponding to the directory into the inode of the directory and complete the record in the MDLog. When the rule is stored in the underlying distributed storage cluster, the rule takes effect and can be called.
[0054] The present application introduces a rule inheritance mechanism. In the case where the target directory is not explicitly configured with a rule by the management end in advance, the effective control rule can be obtained through rule inheritance, avoiding resource preemption or control failure due to rule loss, and ensuring the global consistency of directory granularity resource control. When facing a large number of directories with deep hierarchy, only the top-level or key directories need to be preconfigured with rules, and the lower-level directories can automatically inherit the rules without the need for individual configuration, reducing the configuration workload and greatly reducing the operation and maintenance complexity. At the same time, the present application also supports an explicit configuration covering inheritance management mechanism, which meets the needs of unified control of the top-level and differentiation of subdirectories in the multi-tenant scenario, and is compatible with the simplified scenario where some directories do not need to be configured separately, balancing uniformity and flexibility.
[0055] Step 102, based on the target access resource configuration rule, calculating the access resource quota of the target directory within the target time window.
[0056] The resource constraint parameter in the target access resource configuration rule per unit time is the basis for directory granularity resource control.
[0057] The access resource quota refers to a quota of access resources that a target directory can legally use within a target time window, and is a quantitative embodiment of a target access resource configuration rule in a time window dimension.
[0058] According to the target access resource configuration rule of the target directory, the access resource quota of the target directory in the target time window is calculated. The resource constraint rule is converted into an executable quantitative quota in the time window, so as to measure and control in the time window, and the core problem of how to implement the rule is solved, which provides a quantitative basis for precise control of the directory granularity. At the same time, the quota is calculated based on the target time window, which avoids resource abuse caused by the lack of time dimension constraints, such as a single client suddenly occupying a large amount of resources in a short time.
[0059] In some embodiments, the server calculates the quota by controlling the MDS Rank of the target directory.
[0060] In some embodiments, the calculation of the access resource quota of the target directory in the target time window based on the target access resource configuration rule includes multiplying the number of access operations per unit time and the data transmission bandwidth per unit time in the target access resource configuration rule by the duration of the target time window to obtain the total quota of access operation times and the total quota of data transmission bandwidth of the target directory in the target time window.
[0061] The number of access operations per unit time, also known as IOPS, refers to the number of input / output (I / O) operations per second that the target access resource configuration rule allows the target directory to perform, and is a core parameter for limiting the access frequency of the directory. The IOPS can be valued from 10 7 ops / s.
[0062] The data transmission bandwidth per unit time, also known as unit time bandwidth (BW), refers to the amount of data per second that the target access resource configuration rule allows the target directory to transmit, and is a core parameter for limiting the data transmission amount of the directory, usually measured in megabytes per second (MB / s) or gigabytes per second (GB / s), and is configured by the management end according to business needs. The unit time bandwidth can be valued from 1 MB / s to 10 GB / s.
[0063] The total quota of access operation times (IOPS total quota) is the maximum number of I / O operations that the target directory can perform in a single target time window, and is a quantitative result of the number of access operations per unit time in the time window dimension, which is an upper limit constraint on the I / O operation frequency of the directory.
[0064] The total data transmission bandwidth (total BW) is the maximum amount of data that a target directory can transmit within a single target time window, and is a quantification of the data transmission bandwidth per unit time in the time window dimension. It is an upper limit constraint on the data transmission amount of the directory.
[0065] In some embodiments, the access resource quota is quantified using tokens, which form the total IOPS token quota and the total bandwidth token quota. The total IOPS token quota corresponds to the total access operation quota, with one IOPS token corresponding to one I / O operation. The total bandwidth token quota is determined by the total data transmission bandwidth, with one bandwidth token corresponding to a preset data amount, such as 1 MB / token, which is uniformly set by the system. Both of them serve as global measurement units for directory-level resources, providing standardized basis for subsequent allocation of client access resource quotas and precise control of resource usage.
[0066] In some embodiments, the number of access operations per unit time is denoted as max_iops, the data transmission bandwidth per unit time is denoted as max_bw, and the duration of the target time window is denoted as window_ms.
[0067] In some embodiments, the server controls the directory resource controller within the MDS Rank of the target directory to perform quota calculation. The directory resource controller calculates the two types of access resource quotas according to the logic of unit time parameter × time window duration: total access operation quota (total IOPS quota) = number of access operations per unit time (max_iops) × (duration of target time window window_ms / 1000); total data transmission bandwidth (total BW) = data transmission bandwidth per unit time (max_bw) × (duration of target time window window_ms / 1000); where window_ms / 1000 is a time unit conversion, which is to convert the duration of the time window from milliseconds to seconds to ensure consistency with the unit dimensions of max_iops (ops / s) and max_bw (MB / s or GB / s), making the calculation results accurate and effective.
[0068] The linear calculation method of unit time parameter × time window duration is simple and has no redundant operations, ensuring that the directory resource controller in the MDS Rank can quickly complete the quota calculation, adapting to the high-concurrency directory management needs of the distributed file system, and the calculation results are repeatable and verifiable.
[0069] The calculation result is strongly related to the three configurable parameters max_iops, max_bw and window_ms. An administrator can flexibly adapt to different business requirements (such as core business short window + high IOPS, ordinary business long window + smooth bandwidth) by adjusting the configurable parameters in the access resource configuration rule, thereby improving the scene adaptability of the scheme.
[0070] In some embodiments, after calculating the total IOPS quota and the total BW quota, the total quota can be mapped to the corresponding total token quota to obtain the two-dimensional token of the directory. The total IOPS quota directly corresponds to the total IOPS token quota. For example, if the total IOPS quota is 1000 times, the total IOPS token quota is 1000 tokens. The total BW quota is converted into the total bandwidth token quota according to the preset token-data volume mapping relationship. For example, if 1 bandwidth token corresponds to 1 MB of data, and the total BW quota is 500 MB, then the total bandwidth token quota is 500 tokens.
[0071] For example, if the target directory has max_iops=2000 ops / s, max_bw=1GB / s (1024MB / s) and window_ms=500ms, then the total access operation quota is 2000x(500 / 1000)=1000 times, the total IOPS token quota is 1000 tokens, the total data transmission bandwidth quota is 1024MB / s x(500 / 1000)=512MB, and the total bandwidth token quota is 512 tokens (mapped at 1MB / token). That is, in the 500ms time window, the target directory can consume up to 1000 IOPS tokens (perform 1000 I / O operations) and 512 bandwidth tokens (transmit up to 512MB of data).
[0072] The quantized total IOPS token quota and the total bandwidth token quota serve as the global total quota benchmark of the directory-level resources in the target time window of the target directory. The MDS Rank of the server stores the total quota benchmark, and synchronizes the total quota benchmark to the credential management unit, thereby providing data support for subsequent distribution of access credentials to the client and dynamic adjustment of resource allocation.
[0073] The two types of resource quotas are standardized and quantified in the form of tokens, which converts the number of times and the amount of data into a specific number of tokens, thereby providing a unified measurement standard for subsequent resource allocation, usage statistics and flow control execution, and avoiding control deviation caused by inconsistent measurement dimensions.
[0074] This step specifies the specific generation method of the access resource quota, which converts the target access resource configuration rule from an abstract constraint into a specific quota that is executable, measurable and controllable, thereby solving the core technical problem of rule implementation and laying a foundation for accurate flow control at the directory level.
[0075] Step 103, in response to at least one client's access request to the target directory, generating an access credential for each of the clients based on the access resource quota.
[0076] In some embodiments, the client communicates with the server through a cluster network.
[0077] In this application, the client initiating an access request to the target directory is divided into two categories: lease identification client, which refers to a client with lease analysis, token consumption and renewal capabilities, can directly identify and execute the lease type access credential issued by the server; non-lease identification client, which refers to a client without lease analysis capability, cannot directly process lease type credentials.
[0078] The access request triggering the generation of the access credential in this application includes two forms: implicit access request, which refers to the access intention signal transmitted by the client in the initial mounting phase through the mounting connection with the server, which is not an explicit request initiated by the client, but an access demand recognized by the server based on the mounting state of the client; explicit access request, which refers to an access request actively initiated by the client to the target directory due to actual business operations (such as reading / writing files, accessing metadata), which is a request triggered by the client itself.
[0079] The access credential is a resource permission credential allocated by the server for the client to access the target directory, which is divided into two forms according to the type of the client: long-term access credential for lease identification client, also known as lease, which contains the access resource quota and validity parameters that the client can use, supports lease renewal and dynamic adjustment, and is the core credential form of directory-level resource allocation; temporary access credential for non-lease identification client, which contains a single use of resource quota and validity parameters, which is invalid after single use by the client.
[0080] Generating differentiated credentials adapts to different types of clients, without the need to modify non-lease identification clients to achieve resource management and control, reducing deployment costs and adapting to multi-terminal access scenarios in distributed file systems.
[0081] In some embodiments, the generation of step 103 is performed by the credential management unit in the MDS Rank of the target directory controlled by the server, and the core is to generate access credentials through active distribution and dynamic response for implicit access requests of initial mounting and explicit access requests of clients subsequently.
[0082] In some embodiments, for the scenario of implicit access request (active distribution) mounted by the client, the server triggers active distribution by identifying the mounting state of the client. The MDS cluster of the server listens to the mounting request of the client, and the MDS Rank of the target directory receives and analyzes the mounting information of the corresponding directory, extracts core parameters such as client identifier and client type (lease-identified client / non-lease-identified client); based on the global access resource quota of the target directory, the initial access resource quota is configured for the client in combination with the client type.
[0083] In some embodiments, for the scenario of explicit access request (dynamic response) triggered by the client, the server receives the explicit access request initiated by the client through the MDS Rank, analyzes the request to obtain information such as client identifier, requested resource type, and requested resource quota, and generates access credentials for the client in combination with the total and remaining amount of the global access resource quota of the target directory, the access priority and resource usage information (such as token consumption quantity) of the client.
[0084] The access request of the client generates exclusive access credentials, and the directory-level access resource quota is accurately allocated to the client, which converts global resource constraints into executable access permissions of the client, realizes resource management at the directory granularity, guarantees the allocation fairness when multiple clients share directory resources, and avoids resource preemption by a single client. The resource quota is bound to the access credentials as a carrier to establish a request-quota-permission association mechanism, which avoids resource abuse caused by uncontrolled access of the client from the permission level. At the same time, the present application adapts to the access scenario of multiple clients, provides standardized access credentials for different clients, realizes access resource management of the client and the directory on the server side, avoids inconsistent access resource management, and improves the adaptability and management efficiency of the distributed file system to multiple terminal access.
[0085] In some embodiments, the access credentials of each client are generated based on the access resource quota in response to the access request of at least one client to the target directory, comprising: receiving the access request of at least one client to the target directory; based on the access resource quota and the access request, access priority and resource usage information of each client, configuring a first access resource quota and a first validity parameter containing a credential validity period for each client, obtaining the access credentials of each client containing the first access resource quota and the first validity parameter; wherein the access priority is the resource access level of the client for the target directory, and the resource usage information is the access resource consumption record of the client in the historical time window corresponding to the target directory.
[0086] The access priority is used to distinguish the resource allocation weight of the client for the target directory, for example, the access priority of the client processing core business for the target directory is high, the access priority of the client processing ordinary business for the target directory is medium, and the access priority of the client processing low-priority business for the target directory is low, which is the core basis of directory granularity resource allocation. Through the weighted allocation mechanism of the access priority, the core business client can obtain sufficient resource support when accessing the target directory, while balancing the resource demand difference in different business scenarios, and avoiding the decline of service quality due to insufficient resource preemption of core business.
[0087] When allocating the access resource quota of the target directory for the client, the first access resource quota is preferentially allocated to the client with high access priority, so as to ensure the efficiency of business access.
[0088] The resource usage information specifically includes the token consumption rate and token consumption amount of the client in the historical time window corresponding to the target directory, and other records related to access resources. For example, the token consumption rate and total consumption amount of the client accessing the target directory in each window can be counted in the last 3 consecutive historical time windows. In the initial state (when the client accesses the target directory for the first time), the corresponding resource usage information is empty, and at this time, the first access resource quota can be allocated to the client according to the default rule. By collecting and analyzing the resource usage information, the actual access demand of the client for the target directory can be accurately identified, and then the dynamic allocation of the first access resource quota can be realized, so as to avoid that the client with small access resource demand occupies too much resources of the target directory, ensure that the resource allocation matches the actual demand, and improve the rationality of directory granularity resource management.
[0089] The first access resource quota refers to the access resource quota allocated to a single client, including the number of IOPS tokens and the number of bandwidth tokens that can be used by the client, and is the upper limit of the resources for the client to access the target directory.
[0090] The first validity parameter refers to the time constraint parameter of the access credential, including the credential validity period, i.e., TTL (such as 100 ms, 500 ms), and can also include the Epoch (version number of the lease, used to identify the validity and update iteration of the lease), Rank identifier (identifier of the MDS Rank responsible for managing the target directory), and serial number, etc. parameters, used to control the effective time, legal execution node and usage rules of the credential.
[0091] The TTL, Rank identifier, and Epoch triple constraints in the first validity parameter can prevent the misuse of expired credentials and illegal access across servers, and ensure the consistency of resource management.
[0092] In some embodiments, the validity parameters in the access credentials of different types of clients contain different contents. For example, the validity parameters of a non-lease-identified client contain TTL, but not Epoch, and the like. The validity parameters of a lease-identified client contain TTL, Epoch, Rank identification, sequence number, and the like.
[0093] The MDS Rank of the service end is responsible for receiving the (implicit / explicit) access request of the client accessing the target directory under its control, determining the first access resource quota (IOPS token quantity and bandwidth token quantity) that can be allocated to the client according to the access resource quota (i.e., total token quota and remaining token quota) of the target directory, the access priority of the client, the resource usage information of the client, and the resource demand type and resource demand amount in the access request of the client, and the like.
[0094] In some embodiments, the Weighted Deficit Round Robin (W-DRR) algorithm is used to realize the fair allocation of access resources among clients. This algorithm can effectively suppress the short-term preemption behavior of clients for access resources without changing the resource control mechanism of the directory token-access credential-end-side throttling (described in the related step 104), and make the system access latency converge within a controllable range. The core execution logic is as follows: The directory resource controller of the target directory independently maintains two core state parameters, IOPS deficit value and bandwidth deficit value, for each client under the directory, which are used to record the resource allocation difference of the client. In the subsequent configuration, the deficit value compensation can be used to realize the compensation of the shortage, so as to avoid the long-term shortage of resources of a single client and further strengthen the fairness. The directory resource controller configures a weight coefficient for each client according to the access priority of each client in the target directory, and configures the corresponding IOPS token quota and bandwidth token quota for each client in combination with the round-robin scheduling mechanism of the W-DRR algorithm. After completing the quota configuration once, the directory resource controller synchronously updates the remaining token quantity of the target directory and the IOPS deficit value and bandwidth deficit value of each client.
[0095] By configuring the quota according to the access priority and compensating the difference according to the deficit value, the fair allocation of access resources is realized, the core business gets more, and the ordinary business does not suffer losses, that is, no client preempts too many resources, while meeting the needs of different businesses, so that the resource usage of the entire target directory remains fair, controllable, and stable.
[0096] The use of access credentials cannot be separated from the verification information, so the first validity parameter also needs to be configured for the client.
[0097] The first access resource quota and the first validity parameter corresponding to each client are respectively encapsulated and combined to generate an access credential of each client.
[0098] In some embodiments, the access resource quota of the target directory is 1000 IOPS tokens and 500 bandwidth tokens, the time window is 500 ms, and client A (lease-identified client, high priority) requests large file writing (high estimated bandwidth demand); client B (non-lease-identified client, medium priority) requests metadata query (low IOPS demand). For client A, a first access resource quota containing 600 IOPS tokens and 300 bandwidth tokens can be configured for it, and the first validity parameter contains TTL=500 ms, Rank identification=1, and Epoch=1005. By encapsulating and combining the first access resource quota and the first validity parameter corresponding to client A, the access credential corresponding to client A is generated accordingly. For client B, a first access resource quota containing 2 IOPS tokens and 2 bandwidth tokens can be configured for it, and the first validity parameter contains TTL=100 ms. By encapsulating and combining the first access resource quota and the first validity parameter corresponding to client B, the access credential corresponding to client B is generated accordingly.
[0099] The quota configuration is realized in combination with multi-dimensional information such as access resource quota, client request, access priority, and resource usage information, avoiding "one-size-fits-all" allocation, realizing resource on-demand matching, and improving directory-level resource utilization.
[0100] In step 104, the access credential is sent to the corresponding client.
[0101] The generated access credential of each client is sent to the corresponding client. The client can call the access resource of the target directory by means of the access credential to perform compliant access to the target directory.
[0102] In some embodiments, an end-side throttling unit is deployed at the client side. After receiving the access credential issued by the server side, the end-side throttling unit loads the access resource quota in the credential to a local resource library such as a local token bucket. Based on the token deduction rules of the end-side throttling unit, a corresponding number of IOPS tokens and bandwidth tokens are deducted from the local token bucket each time access is initiated. The client can only perform access within the quota defined in the access credential, and performs the above local throttling operation before access.
[0103] In some embodiments, the end side adopts the deduction order of "IOPS token first, bandwidth token second", which realizes differentiated deduction for small I / O (mainly IOPS consumption) and large I / O (mainly bandwidth consumption) resource demand differences, thereby ensuring the relative fairness of resource allocation for the two types of I / O operations.
[0104] When the token quota of the local token bucket is insufficient, the client directly blocks the directory access or returns an error message of insufficient resource quota to the service layer in the hard throttling mode, or reduces the access rate in the form of exponential backoff or fixed step reduction in the soft throttling mode, while triggering the credential renewal process to wait for quota replenishment.
[0105] The client accesses the target directory by calling the access resource of the target directory under the control of the end-side throttling unit through the access credential, and completes the compliant access to the target directory.
[0106] In some embodiments, after sending the access credential to the corresponding client, it further comprises: monitoring the resource usage information of each client in the target directory; in the case of receiving a resource renewal request of any client, based on the access resource quota of the target directory, the resource renewal request of the client and the resource usage information of each client, determining the second access resource quota of the client and the second validity parameter containing the credential validity period, obtaining the new access credential of the client containing the second access resource quota and the second validity parameter.
[0107] The resource renewal request is a resource quota replenishment and credential update request initiated by the client to the server when the token quota of the access credential is about to be exhausted or the TTL is about to expire, containing client identification, current access credential information (such as Rank identification, Epoch, etc.), applied resource quota, access priority, etc. It is usually triggered automatically by the end-side throttling unit according to the renewal threshold.
[0108] The second access resource quota refers to the access resource quota allocated to a single client, including the number of IOPS tokens and the number of bandwidth tokens that the client can use, which is the upper limit of the client's access to the target directory.
[0109] The second validity parameter refers to the time constraint parameter of the access credential, including the credential validity period, i.e. TTL (such as 100ms, 500ms), and can also include lease epoch (Epoch), Rank identification, serial number, etc. Parameters are used to control the effective time of the credential, the legal execution node and the use rules.
[0110] For the same client, the first and second access resource quotas and the first and second validity parameters in the first and second access resource quotas and the first and second validity parameters are only stage identifiers.
[0111] The resource renewal request initiated by the client essentially belongs to the explicit access request in the foregoing access request, and the server can use the receiving and parsing logic of the access request to process the renewal request without additional design of an independent request processing mechanism.
[0112] In some embodiments, the end-side throttling unit of the client initiates a resource renewal request to the MDS Rank when the token remaining quota or the credential validity period reaches a renewal threshold. The credential management unit in the MDS Rank determines the second access resource quota of the client according to the target directory access resource quota, the resource renewal request of the client, and the resource usage information of each client, and configures a second validity parameter accordingly, encapsulates and combines to obtain a new access credential of the client containing the second access resource quota and the second validity parameter.
[0113] When determining the second access resource quota, if the remaining amount of the target directory access resource quota is sufficient, the request is allocated, otherwise the access priority scheduling is allocated.
[0114] Real-time monitoring of client resource usage information, adaptive adjustment of client access resource quota to be allocated in the renewal stage, realization of on-demand matching of resources, and avoidance of "one-size-fits-all" renewal strategy.
[0115] Determination of the second access resource quota based on the overall usage of each client meets the reasonable renewal needs of the client, prevents a single client from excessively occupying resources, and improves the overall utilization rate of directory-level resources.
[0116] The renewal setting avoids interruption of client access due to expired credentials or exhausted quota, and ensures continuous operation of business.
[0117] Figure 2 is an interaction process schematic diagram of a server and a configured client in a directory migration scenario provided by an embodiment of the present application.
[0118] In some embodiments, in response to a migration request of the target directory, the first server stops generation of an access credential of the target directory, and serializes resource configuration information of the target directory to obtain serialized data; the resource configuration information includes the target access resource configuration rule, the target time window, the current remaining access resource quota, and the configured client having the access credential of the target directory of the target directory; the serialized data is sent to a second server; and the second server deserializes the received serialized data to obtain the resource configuration information.
[0119] The first server is an MDS Rank for managing and controlling the target directory before migration.
[0120] The second server is a new MDS Rank for taking over the target directory.
[0121] The configured client specifically refers to a client having an access credential of the target directory.
[0122] The migration request is an instruction triggering the transfer of the management right of the target directory between MDS Ranks, which can be initiated by the server or the management end according to the needs of load balancing, fault tolerance, etc.
[0123] The migration is usually the migration of a directory subtree containing the target directory.
[0124] The serialization processing refers to the operation of converting resource configuration information into a transmissible data stream (such as a binary data stream).
[0125] The deserialization processing refers to the operation of restoring the resource configuration information to the original format from the data stream (such as a binary data stream).
[0126] The credential update prompt information is an instruction sent by the second server to the configured client, notifying it to update the access credential, containing information such as the identification of the new management node (the second server) and the time limit for updating the credential.
[0127] After the MDS cluster receives the migration request of the target directory, the first server is controlled to perform the following operations: immediately stop the generation of access credentials for the target directory; serialize the resource configuration information of the target directory (such as access resource configuration rules, time windows, remaining resource quotas, lists of configured clients, and serial numbers of the latest access credentials) to generate transmissible serialized data (such as a binary data stream); and send the serialized data to the second server through MDLog.
[0128] The first server stops credential generation to avoid conflicts between the two nodes during migration and ensure the orderliness of the migration process.
[0129] After the second server receives the serialized data, the MDS cluster controls the second server to perform deserialization processing on the serialized data to restore the complete resource configuration information, and establishes a resource management context with a new Rank identification, Epoch, etc., and continues to carry out access credential allocation work, completing the migration takeover of the target directory configuration data.
[0130] During the migration operation, the configured client with the access credential can normally access the target directory, taking into account business continuity.
[0131] The serialization processing and deserialization processing enable reliable transmission of resource configuration information between servers, ensuring the consistency of management rules after the migration of the target directory and ensuring uninterrupted management.
[0132] In some embodiments, after the second server deserializes the received serialized data to obtain the resource configuration information, the method further comprises: controlling the second server to send a credential update prompt information to the configured client; and in response to a credential update request from the configured client, configuring a new access credential for the configured client based on the resource configuration information.
[0133] The credential update prompt information is an instruction sent by the second server to the configured client to notify it to update the access credential, and includes information such as the identifier of the new management node (the second server) and the time limit for updating the credential.
[0134] After the second server completes the deserialization of the resource configuration information, it sends a credential update prompt information to the configured client (a client holding an access credential issued by the first server). The configured client sends a credential update request to the second server in response to the credential update prompt information.
[0135] The credential management unit of the second server receives a credential update request initiated by the configured client, and configures a new access credential for the configured client based on the migrated resource configuration information (which can include an Epoch adapted to the second server, a Rank identifier, and the remaining resource quota of the configured client originally), and issues the new access credential to the configured client to complete the credential update.
[0136] For example, the migration request indicates that the target directory is migrated from MDS Rank 1 (the first server) to MDS Rank 2 (the second server). In response to the migration request, MDS Rank 1 is controlled to stop generating access credentials and serializing configuration rules, 500 IOPS tokens, and other information of the target directory, to obtain serialized data, and to send the serialized data to MDS Rank 2. MDS Rank 2 deserializes the serialized data, and then sends a credential update prompt information to the configured client. After MDS Rank 2 receives a credential update request initiated by the configured client, it configures a new lease containing the Rank identifier of MDS Rank 2 and the Epoch, and issues it.
[0137] When the client is initially not configured with an access credential, it is in a ready state; after obtaining a valid access credential, it is converted to an available state; when the access resource quota or TTL reaches the corresponding threshold, it enters a lease renewal state; if the MDS Rank provides the client with a new access credential, the client returns to the available state, otherwise it enters a throttling state in the soft management mode, and enters a waiting state or a failure state in the hard management mode; when the access credential is invalid or the directory migration causes the Epoch to be mismatched, the state of the client returns to the ready state and triggers a new round of application.
[0138] In the engineering implementation stage, the developer can directly write the state management code of the client according to the state transition rules, and clearly define the trigger condition and execution action of each state. In the system operation and maintenance stage, the operation and maintenance personnel can quickly locate the problem (such as MDS Rank refusing to renew, Epoch mismatch not repaired) through the current state of the client (such as continuously being in the failure state), greatly reducing the complexity of problem troubleshooting.
[0139] In some embodiments, hard links are essentially file references to the same inode, and hard links are often created across different directories. For access resource metering scenarios of hard links, if metering is performed according to the directory where the hard link itself is located, cross-directory over-metering or under-metering problems may occur. Therefore, the present application takes the corresponding directory of the target file of the hard link as the metering reference, clearly defines the metering attribution of the hard link, and avoids metering errors in cross-directory scenarios from the root, thereby ensuring the accuracy of the resource metering result.
[0140] In some embodiments, the present application supports generating snapshots for the target directory, and by default excludes snapshot read operations from the access resource metering range of the directory to ensure the efficiency of snapshot access. If snapshot access occurs frequently in the business scenario, to avoid excessive consumption of directory access resources by snapshot access, the metering function of snapshot read can be enabled according to actual business needs to achieve differentiated resource management and control.
[0141] In some embodiments, for the lost or abnormal client, the MDS cluster continuously monitors its TTL period state, and when the timeout duration exceeds a preset number of TTL periods, the MDS cluster automatically performs resource recovery operations to recover the unused access resource quota of the client, thereby preventing resource waste caused by access resource leakage from the source.
[0142] In the present application, the MDS cluster assumes the responsibilities of index collection and export: collecting and exporting core operation and maintenance indexes at the directory level according to a periodic strategy, including access resource quota generation and consumption, I / O queue latency, flow limiting or request discarding events, and the number of currently active clients. The Manager Daemon (Mgr) is the core component of the cluster management, which receives and aggregates the index data reported by each MDS node. On the one hand, it provides self-defined configuration capabilities for alarm rules, which can trigger abnormal alarms according to index thresholds. On the other hand, it converts index data into intuitive running state charts through a visual interface. In addition, for operations such as setting, modifying, and deleting access resource configuration rules, the operator's identity and operation timestamp are automatically recorded to form an unalterable audit log, which not only facilitates operation personnel to trace operation behavior and locate system problems, but also meets the regulatory requirements of industry compliance checks, thereby realizing the observability, alarmability, and auditability of the whole process of system resource management and control.
[0143] In the embodiment of the present application, the target access resource quota of the target directory is calculated based on the target access resource configuration rule of the target directory and the target time window, the access credential is generated and sent to the client based on the target access resource quota of the target directory in response to the access request of the client, and the access credential is generated and sent to the client based on the target access resource quota of the target directory. Through the credential-based authorization mode, on the one hand, the precise control of the access behavior of the client to the target directory is realized, unauthorized access and resource abuse are effectively prevented, and it is ensured that the access resource usage of the target directory within the set time window is always within a controllable range. On the other hand, through the resource quota allocation and credential-based access control of the directory granularity, a clear resource usage boundary is drawn for all clients accessing the target directory, access conflicts caused by unordered directory resource occupation of multiple clients are avoided, and the directory access competition problem under the coarse-grained resource configuration in the distributed file system is effectively alleviated. The present application not only improves the precision of the access resource control of the directory dimension in the distributed file system, but also guarantees the orderliness and stability of the directory access, thereby comprehensively improving the service quality during the directory access in the distributed file system.
[0144] Referring to Figure 3 , Figure 3 is a structure diagram of an access resource control system based on directory granularity provided by the embodiment of the present application. Only the part related to the embodiment of the present application is shown for the convenience of description.
[0145] The access resource control system based on directory granularity 300 comprises a determination module 301, a calculation module 302, a generation module 303 and a sending module 304.
[0146] The determination module 301 is configured to determine the target access resource configuration rule and the target time window of the target directory.
[0147] The calculation module 302 is configured to calculate the access resource quota of the target directory within the target time window based on the target access resource configuration rule.
[0148] The generation module 303 is configured to generate the access credential of each client based on the access resource quota in response to the access request of the client to the target directory.
[0149] The sending module 304 is configured to send the access credential to the corresponding client.
[0150] In some embodiments, the determination module is specifically configured to: if the target directory is configured with a first access resource configuration rule, the first access resource configuration rule is determined as the target access resource configuration rule of the target directory. If the target directory does not configure the first access resource configuration rule, a second access resource configuration rule of an ancestor directory closest to the target directory is determined as the target access resource configuration rule of the target directory.
[0151] In some embodiments, the computing module is specifically configured to: multiply the number of access operations per unit time and the data transmission bandwidth per unit time in the target access resource configuration rule by the length of the target time window, to obtain the total amount of access operations and the total amount of data transmission bandwidth of the target directory within the target time window.
[0152] In some embodiments, the generating module is specifically configured to: receive the access request of at least one of the clients to the target directory; based on the access resource quota and the access request, access priority and resource usage information of each of the clients, configure a first access resource quota and a first validity parameter including a credential validity period for each of the clients, to obtain the access credential of each of the clients including the first access resource quota and the first validity parameter; wherein the access priority is the resource access level of the client for the target directory, and the resource usage information is the access resource consumption record of the client in the historical time window corresponding to the target directory.
[0153] In some embodiments, the generating module is further configured to: monitor the resource usage information of each of the clients in the target directory; in the case of receiving a resource renewal request of any of the clients, based on the access resource quota of the target directory, the resource renewal request of the client and the resource usage information of each of the clients, determine a second access resource quota and a second validity parameter including the credential validity period of the client, to obtain a new access credential of the client including the second access resource quota and the second validity parameter.
[0154] In some embodiments, the system further comprises a migration management module configured to: in response to a migration request of the target directory, control a first server to stop the generation of access credentials of the target directory, and serialize resource configuration information of the target directory to obtain serialized data; the resource configuration information includes the target access resource configuration rule, the target time window, the current remaining access resource quota and the configured client with the access credential of the target directory of the target directory. send the serialized data to a second server; The second server is controlled to deserialize the received serialized data to obtain the resource configuration information.
[0155] In some embodiments, the migration management module is further configured to: Control the second server to send a credential update notification message to the configured client; In response to the credential update request from the configured client, a new access credential is configured for the configured client based on the resource configuration information.
[0156] The directory-based access resource control system provided in this application can implement all the processes of the above-described directory-based access resource control method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0157] Figure 4 This is a structural diagram of an electronic device provided in an embodiment of this application. As shown in the figure, the electronic device 4 of this embodiment includes: at least one processor 40 ( Figure 4 (Only one is shown in the diagram), memory 41, and computer program 42 stored in said memory 41 and executable on said at least one processor 40, which, when executed, implements the steps in any of the above method embodiments.
[0158] The electronic device 4 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. The electronic device 4 may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that... Figure 4 This is merely an example of electronic device 4 and does not constitute a limitation on electronic device 4. It may include more or fewer components than shown, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.
[0159] The processor 40 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0160] The memory 41 can be an internal storage unit of the electronic device 4, such as a hard disk or a memory of the electronic device 4. The memory 41 can also be an external storage device of the electronic device 4, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the electronic device 4. Further, the memory 41 can also include both the internal storage unit and the external storage device of the electronic device 4. The memory 41 is used to store the computer program and other programs and data required by the electronic device. The memory 41 can also be used to temporarily store data that has been output or will be output.
[0161] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the system is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for easy distinction, and do not limit the protection scope of the present application. The specific working process of the unit and module in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0162] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0163] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0164] In the embodiments of the present application, it should be understood that the disclosed system / electronic device and method can be implemented in other manners. For example, the embodiments of the system / electronic device described above are merely schematic. For example, the division of the modules or units is only a logical function division. There can be another division manner for the actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, can be indirect couplings or communication connections through some interfaces, and electrical, mechanical or other forms.
[0165] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0166] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0167] The integrated module / unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, all or part of the flow of the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. When the processor executes the computer program, the steps of each method embodiment described above can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, executable file or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the computer readable medium can include appropriate contents according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0168] The application can realize all or part of the processes in the above-mentioned embodiment methods, and can also be realized by a computer program product. When the computer program product runs on an electronic device, the electronic device is caused to perform the steps in the above-mentioned various method embodiments.
[0169] The above-mentioned embodiments are only used to illustrate the technical solutions of the present application, rather than limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalents. The modifications or replacements do not change the essence of the corresponding technical solutions, and should be included in the protection scope of the present application.
Claims
1. A directory-level resource access control method, characterized in that, The method comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client.
2. The method of claim 1, wherein, The method further comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; 3. The method of claim 1, wherein, generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client.
4. The method of claim 1, wherein, The method further comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; 5. The method of claim 4, wherein, generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client. The method further comprises:
6. The method of claim 1, wherein, determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client. The method further comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client. The method further comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client. The method further comprises: determining a target access resource configuration rule of a target directory and a target time window; calculating an access resource quota of the target directory in the target time window based on the target access resource configuration rule; generating an access credential of each client based on the access resource quota in response to an access request of the target directory of at least one client; sending the access credential to the corresponding client. In response to a migration request of the target directory, the first server is controlled to stop generation of access credentials of the target directory, and to serialize resource configuration information of the target directory to obtain serialized data; the resource configuration information includes the target access resource configuration rule, the target time window, a current remaining access resource quota, and a configured client with the access credentials of the target directory of the target directory; The serialized data is sent to a second server; The second server is controlled to deserialize the received serialized data to obtain the resource configuration information.
7. The method of claim 6, wherein, After the second server is controlled to deserialize the received serialized data to obtain the resource configuration information, the method further includes: The second server is controlled to send credential update prompt information to the configured client; In response to a credential update request of the configured client, the configured client is configured with new access credentials based on the resource configuration information.
8. A directory-granularity-based access resource control system, characterized by comprising: The method includes: A determination module is configured to determine a target access resource configuration rule and a target time window of a target directory; A calculation module is configured to calculate an access resource quota of the target directory within the target time window based on the target access resource configuration rule; A generation module is configured to generate access credentials of each client based on the access resource quota in response to an access request of the target directory of the at least one client; A sending module is configured to send the access credentials to the corresponding client.
9. An electronic device, comprising: The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the electronic device implements the method of any one of claims 1 to 7.
10. A computer program product, characterised in that, The computer program is executed to cause the method of any one of claims 1 to 7 to be performed.