Database permission control method, device, medium and product
By automatically obtaining authorization requests and based on the binding relationship between business information and database permissions, the inefficiency of database permission control in existing technologies is solved, realizing automated database permission management and improving the efficiency of database permission control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU SHIYINLIAN SOFTWARE TECH CO LTD
- Filing Date
- 2026-04-10
- Publication Date
- 2026-06-02
AI Technical Summary
In existing technologies, database access control is inefficient, especially when the application's IP address changes, requiring manual modification of authorizations, resulting in high processing complexity and low real-time performance.
By automatically obtaining authorization requests and based on the binding relationship between business information and database permissions, automatic authorization operations are achieved, avoiding cumbersome manual approval processes and adapting to IP address changes caused by application restarts, scaling up or down, etc.
It improves the automation level of database access control, simplifies the efficiency of operations, automates applications, reduces the complexity of database access control, and improves the efficiency of authorization operations.
Smart Images

Figure CN122132450A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data control, and in particular to a method, device, medium, and product for controlling database permissions. Background Technology
[0002] Databases serve as persistent storage for structured data. By controlling the scope of access and operational capabilities of users or applications to database resources through permissions, databases provide data read and write services to applications while ensuring the security and isolation of database resources.
[0003] In related technologies, if the manual approval process is successful, the database administrator can manually add the application's corresponding Internet Protocol (IP) address to the database's permission list to authorize the application.
[0004] However, if the IP address corresponding to the application changes, it needs to be approved again and the authorization needs to be manually changed, which is inefficient and complex. Summary of the Invention
[0005] This application provides a database permission control method, device, medium, and product. The technical solution provided by this application includes the following aspects.
[0006] According to one aspect of the embodiments of this application, a database permission control method is provided, the method comprising: Obtain the authorization request corresponding to the first instance. The authorization request includes business information corresponding to the first instance. The business information is used to indicate the business functions to be performed by the first instance. The authorization request is used to request the allocation of database access permissions to the first instance. Based on the authorization request, an authorization binding relationship is obtained, which includes the binding relationship between business information and database permissions; The first database permission corresponding to the first instance is obtained based on the authorization binding relationship, and the first instance is used to access the database based on the first database permission.
[0007] According to one aspect of the embodiments of this application, a database permission control device is provided, the device comprising: The authorization module is configured to obtain an authorization request corresponding to the first instance. The authorization request includes business information corresponding to the first instance. The business information is used to indicate the business functions to be performed by the first instance. The authorization request is used to request the allocation of database access permissions to the first instance. The authorization module is also configured to obtain an authorization binding relationship based on the authorization request, wherein the authorization binding relationship includes the binding relationship between business information and database permissions; The authorization module is further configured to obtain the first database permissions corresponding to the first instance based on the authorization binding relationship, and the first instance is used to access the database based on the first database permissions.
[0008] According to one aspect of the embodiments of this application, a computer device is provided, the computer device including a processor and a memory, the memory storing a computer program, the computer program being loaded and executed by the processor to implement the above-described database permission control method.
[0009] According to one aspect of the embodiments of this application, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, the computer program being loaded and executed by a processor to implement the above-described database permission control method.
[0010] According to one aspect of the embodiments of this application, a computer program product is provided, the computer program product including a computer program stored in a computer-readable storage medium, and a processor reading from the computer-readable storage medium and executing the computer program to implement the above-described database permission control method.
[0011] The technical solutions provided in this application can bring at least the following beneficial effects: By automatically obtaining authorization requests, the system acquires the business information corresponding to the first instance and the binding relationship between the business information and database permissions. This enables authorization operations to be performed on the first instance, automatically binding the first instance to the business information and acquiring the first database permissions corresponding to the first instance. This avoids cumbersome manual approval processes and manual authorization operations. Furthermore, even if the IP address of the first instance changes due to restarting, scaling up or down, the authorization operation can still be quickly performed through the above authorization process, reducing the complexity of database permission control and improving the efficiency of authorization operations. Attached Figure Description
[0012] Figure 1 This is a schematic diagram of a database permission control system provided in an exemplary embodiment of this application; Figure 2 This is a flowchart of a database permission control method provided in an exemplary embodiment of this application; Figure 3 This is a flowchart of a database permission control method provided in another exemplary embodiment of this application; Figure 4This is a schematic diagram of the authorization process provided in an exemplary embodiment of this application; Figure 5 This is a schematic diagram of the access control interface provided in an exemplary embodiment of this application; Figure 6 This is a flowchart of a database permission control method provided in yet another exemplary embodiment of this application; Figure 7 This is a schematic diagram of the process for obtaining the liveness status of a first instance provided in an exemplary embodiment of this application; Figure 8 This is a flowchart illustrating a dual instance reclamation method provided in an exemplary embodiment of this application; Figure 9 This is a flowchart illustrating a dual instance reclamation method provided in another exemplary embodiment of this application; Figure 10 This is a schematic diagram of an interface for visualizing the number of instances to be recycled, provided in an exemplary embodiment of this application. Figure 11 This is a schematic diagram of the interface for a list of instances to be recycled provided in an exemplary embodiment of this application; Figure 12 This is a schematic diagram of a database access control module provided in an exemplary embodiment of this application; Figure 13 This is a schematic diagram of a database access control module provided in another exemplary embodiment of this application; Figure 14 This is a structural block diagram of a database permission control device provided in an exemplary embodiment of this application; Figure 15 This is a structural block diagram of a database permission control device provided in another exemplary embodiment of this application; Figure 16 This is a structural block diagram of a computer device provided in an exemplary embodiment of this application. Detailed Implementation
[0013] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0014] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0015] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0016] It should be understood that although the terms first, second, etc., may be used in this application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, a first parameter may also be referred to as a second parameter, and similarly, a second parameter may also be referred to as a first parameter. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0017] It should be noted that this application may display prompt interfaces, pop-ups, or output voice prompts before and during the collection of user data. These prompt interfaces, pop-ups, or voice prompts are used to inform the user that their data is being collected. This ensures that the application only begins the steps for collecting user data after receiving confirmation from the user regarding the prompt interface or pop-up; otherwise (i.e., without user confirmation), the steps for collecting user data end, meaning no user data is collected. In other words, all user data collected in this application is collected with the user's consent and authorization, and the collection, use, and processing of related user data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0018] Databases serve as persistent storage for structured data. By controlling the scope of access and operational capabilities of users or applications to database resources through permissions, databases provide data read and write services to applications while ensuring the security and isolation of database resources.
[0019] Access control includes authorizing users or applications that are running and need to access the database, and revoking previously granted database permissions for users or applications that are no longer running. Authorized users or applications can access the database and read and write specified data based on their permissions; otherwise, requests to access the database from unauthorized users or applications whose database permissions have been revoked will be rejected, resulting in data read / write failures. Here, "user" refers to the database identity obtained from the database's perspective, uniquely identified by the database username and the source host; "application" is an instance of the business system that obtains the database access capabilities corresponding to the user by acquiring the database identity.
[0020] In related technologies, there is at least one implementation scheme for authorizing applications.
[0021] (1) Send the application to be authorized and the database permissions that the application is expected to request to the work order system corresponding to the database and execute the manual approval process; if the manual approval process is successful, the database administrator (DatabaseAdministrator, DBA) manually adds the IP address corresponding to the application to the permission list corresponding to the database to realize the database authorization of the application.
[0022] (2) In some embodiments, the applications that need to access the database are managed based on the container coding engine (Kubernetes, K8s). The container orchestration unit (Pod) is the carrier of the application instance in the K8s environment and is the atomic scheduling unit in the K8s environment. K8s maps the Pod, that is, the service account (ServiceAccount) of the application, to the database user through role-based access control (RBAC), thereby obtaining the database identity and storing the credential information corresponding to the database user in the sensitive information storage object (Secret) in K8s.
[0023] The authorization methods of RBAC and database permission models differ significantly in terms of the authorized objects, managed resources, and authorization methods. To illustrate, the authorized object of RBAC is a ServiceAccount, while that of the database permission model is a database user. The resources managed by RBAC are Kubernetes resources such as Pods and Secrets, while the resources managed by the database permission model are data content or data storage procedures such as tables, rows, and columns in the database. RBAC's authorization method is based on the Kubernetes Application Programming Interface (API) to perform authorization operations on the authorized objects, while the database permission model's authorization method is implemented through the GRANT statement in Structured Query Language (SQL).
[0024] Additionally, the database operator obtains the database cluster specification configuration corresponding to the Custom Resource Definition (CRD), which includes a permission list. The operator then converts the RBAC authorization method into the authorization method corresponding to the database permission model and adds the database user corresponding to the Pod to the permission list based on the credential information in the Secret, thereby authorizing the application.
[0025] Among these methods, the manual whitelist authorization scheme requires a manual approval process and manual modification of authorizations when the application's corresponding IP address changes. This is inefficient and complex. Alternatively, besides adding the application's static IP address to the database's permission list, the above scheme can also use Classless Inter-Domain Routing (CIDR) to add the application's corresponding IP network segment to the database's permission list. This expands the authorization scope to some extent and reduces the probability of authorization changes when the IP address changes. However, expanding the authorization scope reduces security during database read / write operations.
[0026] For authorization schemes based on RBAC and Operator, the process of establishing the mapping relationship between ServiceAccount and database users by RBAC is complex and inflexible. When the mapping relationship changes, such as adding or deleting ServiceAccount or changing the mapping template in RBAC, a custom controller needs to poll the above change events and update the authorization relationship synchronously, which results in a large adjustment delay and low real-time performance.
[0027] Furthermore, the Operator needs to continuously ensure that database user permissions are consistent with the CRD declaration. Updates to the Operator may cause changes to the CRD structure, resulting in the loss of the mapping relationship between Pods and database user permissions. With the CRD declaration indicating a fixed level of database permissions (e.g., granting access to the entire database, tables within the database, etc.), it is impossible to grant applications other levels of database permissions, leading to low authorization flexibility.
[0028] This application provides an automatic authorization method based on business information. Based on the business information corresponding to the application instance, the IP address corresponding to the application is added to the permission list of the database, thereby realizing the authorization processing of the application, avoiding complex approval processes and database user mapping processing, and improving authorization efficiency.
[0029] Please refer to Figure 1 This illustration shows a schematic diagram of a database permission control system provided in one embodiment of this application. The computer system 100 includes: a terminal 120, or a terminal 120 and a server 140.
[0030] The database permission control method provided in this application embodiment can be executed independently by terminal 120, independently by server 140, or jointly by terminal 120 and server 140. This application embodiment does not limit this. In some embodiments, computer system 100 can be implemented as a system architecture for the database permission control method.
[0031] The device type of terminal 120 includes at least one of the following: smartphone, laptop, desktop computer, tablet computer, smart robot, augmented reality (AR) device, virtual reality (VR) device, vehicle terminal, wearable device, etc.
[0032] Terminal 120 is connected to server 140 via a wireless network or a wired network.
[0033] Those skilled in the art will understand that the number of the aforementioned devices can be more or less. For example, there may be only one device, or there may be dozens or hundreds of devices, or even more. This application does not limit the number or type of devices.
[0034] Server 240 includes at least one of one server or multiple servers. In some embodiments, server 240 is implemented as a private server connected to terminal 220, and the model provided by server 240 is a private model deployed on the private server. Optionally, server 240 undertakes the main computing work, and terminal 220 undertakes the secondary computing work; or, server 240 undertakes the secondary computing work, and terminal 220 undertakes the main computing work; or, server 240 and terminal 220 adopt a distributed computing architecture for collaborative computing.
[0035] In one example, database permission control is implemented collaboratively by terminal 120 and server 140. Illustratively, terminal 120 is used to run a first instance, which includes, but is not limited to, personalized business applications such as user centers and order systems; middleware applications such as log collection systems and message consumption services; operation and maintenance applications such as alarm systems and work order systems; testing applications such as automated testing frameworks and development environment repositories; and reporting applications such as data reporting platforms and file export services.
[0036] In the above example, terminal 120 obtains an authorization request corresponding to the first instance. The authorization request includes business information corresponding to the first instance, which is used to instruct the business functions to be performed by the first instance. The authorization request is used to request database access permissions to be granted to the first instance. Server 140 stores a mapping relationship between business information and database permissions. When server 140 receives the authorization request sent by terminal 120, server 140 obtains the authorization binding relationship based on the authorization request. The authorization binding relationship includes the binding relationship between business information and database permissions. Optionally, terminal 120 can generate an authorization request for the first instance based on the business information corresponding to the first instance and send the authorization request to server 140. In response to receiving the authorization request, server 140 obtains the business information in the authorization request and queries the authorization binding relationship based on the business information.
[0037] In the example above, server 140 includes a database master node that the first instance needs to access. This database master node is responsible for managing database permissions. The database master node and the authorization binding relationship are deployed on the same or different servers. Server 140 obtains the first database permissions corresponding to the first instance based on the authorization binding relationship. The first instance uses these first database permissions to access the database. Optionally, the first instance's access to the database based on the first database permissions includes, but is not limited to, accessing the database, database table, or database row / column corresponding to the first database permissions; and implementing data read / write operations such as adding, deleting, modifying, and querying for specific database content.
[0038] It is worth noting that the aforementioned terminal 120 refers to an electronic device with output display capabilities and input control capabilities. The aforementioned server 140 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud security, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0039] Cloud technology refers to a managed technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing.
[0040] In some embodiments, the server 140 described above can also be implemented as a node in a blockchain system.
[0041] Please refer to Figure 2The diagram illustrates a flowchart of a database permission control method provided in an exemplary embodiment of this application. This method can be implemented by a computer device (which may be configured as follows). Figure 1 The method is executed by either the terminal 120 or the server 140 shown, or it is executed jointly by the terminal and the server. In this embodiment, the method is executed by the terminal as an example. Figure 2 As shown, the method includes at least one of the following steps 210 to 230.
[0042] Step 210: Obtain the authorization request corresponding to the first instance.
[0043] The authorization request includes business information corresponding to the first instance. The business information is used to indicate the business functions to be performed by the first instance. The authorization request is used to request the allocation of database access permissions to the first instance.
[0044] The first instance is a specific implementation or use case applied in a real-world scenario. That is, the first instance is a specific copy of the application implemented in the first instance in a specified runtime environment (such as Kubernetes). The first instance can obtain independent computing resources, storage resources, or network resources, and it is used to execute the complete business functions corresponding to the application in a real-world scenario.
[0045] Optionally, the business information corresponding to the first instance can be identified by the Replication Management System (RMS), that is, the RMS identity number (ID).
[0046] The application corresponding to the first instance includes, but is not limited to, at least one of the following: 1. Personalized business applications: These are used to directly provide client users with read and write services for core business data in the database, such as user centers, order systems, and product catalog services.
[0047] 2. Middleware Applications: These applications implement data flow, message processing, and data synchronization, providing read and write services for logs and messages in the database to the data channels corresponding to core business operations. Examples include log collection systems, message consumption services, and Extract-Transform-Load (ETL) tasks. A message is a data unit used for asynchronous communication, time-based notifications, or data exchange between business components or applications. Optionally, a message includes the sender and receiver, message content, and source data (such as timestamps and identifiers).
[0048] 3. Operation and Maintenance Applications: These provide storage services for application data such as metadata and status data to the runtime environment platform of the first instance, thereby maintaining platform operation. Examples include alarm systems and work order systems. Status data refers to temporary information generated by instances on the runtime environment platform during operation and not persistently stored. Storing status data in the database aims to prevent the loss of status data after process restarts, failures, or migrations, which could lead to business failures.
[0049] 4. Testing applications: Continuous Integration (CI) - Continuous Delivery / Continuous Deployment (CD) management platforms used for temporarily creating or operating development environments and automating testing, such as automated testing frameworks and development environment repositories.
[0050] 5. Reporting applications: These provide query services for specified data to meet non-real-time business needs such as data analysis and data archiving, including data reporting platforms and file export services.
[0051] It is worth noting that the above application scenarios are merely illustrative examples, and this application does not limit the application or project scenarios corresponding to the first instance.
[0052] The authorization request is a request generated based on the database permission changes required by the first instance. Based on the authorization request, the first instance is expected to obtain the first database permission corresponding to the first instance, and then access the database based on the first database permission.
[0053] The database permission changes required for the first instance include, but are not limited to: changes to the database access identification information (such as IP address) of the first instance due to reasons such as restart, scaling up or down, or node migration, where scaling up or down refers to the first instance automatically adjusting the number of processing nodes or resource configuration due to changes in workload; or, the first database permissions acquired by the first instance in a historical period are revoked or reset due to reasons such as rebuilding or long-term inactivity; or, changes to the business functions corresponding to the first instance, which correspondingly reduce or expand the required data content or data access mode, such as the first instance adding a new business function indicating the addition of query operations on a new data table.
[0054] In some embodiments, in response to receiving a creation event corresponding to the first instance, an authorization request is obtained. The creation event is used to instruct the first instance to start running. By setting explicit acquisition conditions for the authorization request, an immediate response is made when the creation event occurs, avoiding the waiting delay caused by the polling mechanism and reducing the resource consumption corresponding to invalid polling. This forms a clear execution link between the creation event and the start of the authorization process, which is beneficial for tracking and debugging the permission control process and improving authorization efficiency.
[0055] In some embodiments, a permission control module performs permission granting and revoke processing on the first instance. The permission control module includes a management decision-making unit and a processing execution unit. Optionally, the permission control module is a pre-configured control module in the first instance's runtime environment; the permission control module can implement permission configuration scripts. The management decision-making unit establishes a long-lived connection request with the runtime environment platform API corresponding to the first instance. When platform resources change, such as when the first instance is started, the platform API sends a creation event corresponding to the first instance to the management decision-making unit through the aforementioned long-lived connection. The management decision-making unit generates an authorization request corresponding to the first instance. Correspondingly, the processing execution unit receives the authorization request sent by the management decision-making unit, performs authorization processing based on the authorization request, that is, obtains the authorization binding relationship based on the authorization request, and obtains the first database permissions corresponding to the first instance based on the authorization binding relationship.
[0056] Step 220: Obtain the authorization binding relationship based on the authorization request.
[0057] Authorization binding relationships include the binding relationship between business information and database permissions. These relationships are configured on the business side, binding the application's business information with corresponding database permissions to achieve business planning. During access control, the authorization binding relationship will not change due to the acquisition or revocation of database permissions corresponding to the instance.
[0058] Optionally, the authorization binding relationship can be configured before the first instance runs or is created, or when designing or updating the business requirements or processes corresponding to the application. In some embodiments, configuring the authorization binding relationship requires manual approval to ensure the security of database access control.
[0059] In some embodiments, the configuration process for authorization binding relationships includes, but is not limited to: theoretically determining and reviewing the mapping relationship between business information and database permissions; based on the above theoretical mapping relationship, creating an account corresponding to the database user, obtaining the authentication information corresponding to the account, and granting the corresponding database permissions to the database user through the GRANT statement, that is, binding the account and database permissions to realize the configuration of authorization binding relationships.
[0060] When configuring authorization binding relationships, it is necessary to consider authorization principles, authorization granularity, and authorization hierarchy. Based on authorization principles, it is necessary to clearly define which permissions are granted to the database identity and strictly control the scope of authorization to avoid over-authorization and reduce security risks. When configuring authorization binding relationships, it is necessary to refine the authorization granularity to improve the control over database access operations. Based on the authorization hierarchy, it is necessary to improve the efficiency of database permission management.
[0061] Optionally, the authentication information corresponding to the account is used to verify the database identity corresponding to the account. The implementation methods of the authentication information include, but are not limited to: 1. The password corresponding to the account, the database verifies the database identity by pairing; 2. Plugin authentication information, the database verifies the database identity by a pluggable authentication module, decoupling the authentication logic from the database kernel and extending the authentication method; 3. Certificate authentication information, the database identity is verified by Public Key Infrastructure (PKI) through Transport Layer Security (TTL) or Secure Sockets Layer (SSL) certificates; 4. Lightweight Directory Access Protocol (LDAP) information: authentication information is centrally stored and verified through a unified identity authentication system; 5. Cloud service role: cloud-native databases verify the database identity by using Identity and Access Management (IAM) cloud service roles as temporary credentials; 6. Blockchain digital identity information: the database identity is verified through a Decentralized Identifier (DID).
[0062] In some embodiments, the authorization binding relationship and other business configuration information corresponding to the first instance are centrally stored in the configuration storage space. Optionally, the configuration storage space can be implemented as a Configuration Management Database (CMDB). Illustratively, when the processing execution unit in the access control module receives an authorization request, the processing execution unit generates a query request corresponding to the first instance based on the authorization request to query the authorization binding relationship. This query request includes the business information corresponding to the first instance. In response to receiving the query request corresponding to the first instance, the storage control unit of the configuration storage space returns the authorization binding relationship corresponding to the first instance to the processing execution unit.
[0063] Step 230: Obtain the first database permissions corresponding to the first instance based on the authorization binding relationship.
[0064] The first instance is used to access the database based on the first database permissions. With the authorization binding relationship established, the first database permissions are obtained based on the business information of the first instance. The database can then grant these permissions to the first instance through authorization operations.
[0065] In some embodiments, the first database permission can be applied to different database objects, such as tables, views, rows or columns, stored procedures, or the entire database, and to different access operation types, such as SELECT, INSERT, UPDATE, and DELETE operations. Database permissions indicate permission questions such as "who can access the database," "what operations can be performed," and "what the result of the access is."
[0066] Schematic illustration: When the authorization binding relationship corresponding to the first instance is obtained through the processing execution unit in the access control module, the processing execution unit obtains the authentication information in the authorization binding relationship, and based on the authentication information, obtains the first database permissions corresponding to the first instance. Optionally, obtaining the first database permissions corresponding to the first instance based on the authentication information includes, but is not limited to: the processing execution unit generating an authorization task based on the authentication information, sending the authorization task to the database master node, and the database master node being responsible for managing database permissions; the database master node receiving the authorization task sent by the processing execution unit, verifying the database identity of the first instance based on the authentication information in the authorization task, determining the first database permissions corresponding to the first instance, and granting the first database permissions to the first instance.
[0067] In some embodiments, obtaining the first database permissions corresponding to the first instance includes, but is not limited to, binding the identification information of the first instance with the first database option; when the first instance needs to access the database based on the first database permissions, the first instance sends an access request to the database, the access request including the identification information of the first instance and the database content that the first instance needs to access; based on the access request, the database obtains the first database permissions bound to the identification information of the first instance, and performs corresponding access operations on the database content that the first instance needs to access based on the first database permissions.
[0068] The first instance, based on the authorization binding relationship, obtains the first database permission to perform access operations on the database. This can improve the granularity down to specific tables, views, stored procedures, etc., increase access flexibility, protect the security of sensitive data under the restriction of the first database permission, reduce potential security risks, and improve the overall security of the database.
[0069] In some embodiments, obtaining the first database permission corresponding to the first instance requires logging the authorization operation itself in order to track and review the authorized instance corresponding to the database, and to ensure the effectiveness and security of database permission control.
[0070] In summary, the method provided in this application automatically obtains authorization requests, acquires business information corresponding to the first instance, and obtains the binding relationship between the business information and database permissions, thereby enabling authorization operations to the first instance. That is, it automatically binds the first instance to the binding relationship corresponding to the business information and acquires the first database permissions corresponding to the first instance, avoiding cumbersome manual approval processes and manual authorization operations. Furthermore, even if the IP address of the first instance changes due to restarting, scaling up or down, etc., the authorization operation can still be quickly implemented through the above authorization process, reducing the complexity of database permission control and improving the efficiency of authorization operations.
[0071] Please refer to Figure 3 This illustrates a flowchart of a database permission control method provided in another exemplary embodiment of this application. The method can be implemented by a computer device (which may be configured as follows). Figure 1 The method is executed by either the terminal 120 or the server 140 shown, or it is executed jointly by the terminal and the server. In this embodiment, the method is executed by the terminal as an example. Figure 3 As shown, steps 220 to 230 above include at least one of the following steps.
[0072] Step 222: Based on the authorization request, obtain the authorization password corresponding to the database.
[0073] There is a corresponding relationship between the authorization password and the authorization binding relationship. The authorization password is used to authenticate the database management permissions. The database management permissions are the management permissions used to obtain the first database permissions corresponding to the first instance. Schematic, based on the management permissions, the database adds the identification information of the first instance to the permission list corresponding to the first database permissions. When the first instance accesses the database, if the identification information of the first instance is obtained from this permission list, the first instance is allowed to access the database content corresponding to the first database permissions.
[0074] In some embodiments, based on an authorization request, encrypted information in the authorization binding relationship is obtained, where the encrypted information is the encrypted authorization password; the encrypted information is then decrypted to obtain the authorization password. Optionally, the encrypted information is the authentication information corresponding to the account of the database user created based on business information during the configuration process of the authorization binding relationship, and the authorization binding relationship includes the binding relationship between the account and database permissions. The process of decrypting the encrypted information to obtain the authorization password includes, but is not limited to: sending the encrypted information to a dedicated encryption / decryption platform, and obtaining the authorization password corresponding to the encrypted information based on the decryption function module of the encryption / decryption platform.
[0075] By first obtaining the encrypted information stored in ciphertext within the authorization binding relationship, and then obtaining the authorization password in plaintext through an encryption / decryption platform, the security of authentication information in the management authorization binding relationship is improved, and the risk of permission leakage is reduced.
[0076] Step 232: Based on the authorization password, obtain the first database permissions corresponding to the first instance.
[0077] Once the authorized password is verified, the database user account corresponding to the first database permission logs in and obtains the first database permission corresponding to the first instance under the management permissions of that account.
[0078] In some embodiments, based on the authorization binding relationship, the address information of the first instance is bound to the first database permission, and the address information of the first instance is used to uniquely identify the identity information of the first instance. By adding the address information of the first instance as identification information to the permission list corresponding to the first database permission when logging into the database user account corresponding to the first database permission, the binding of the address information of the first instance to the first database permission is achieved; this improves the accuracy of authorization, avoids the security risks caused by permission diffusion between different instances, keeps the authorization method consistent with the database authorization model, and reduces the complexity of the authorization logic. Optionally, the address information of the first instance is an IP address.
[0079] In some embodiments, before obtaining authorization relationship information based on the authorization request, the method further includes: adding a locking identifier to the address information of the first instance, the locking identifier indicating that the address information of the first instance is being authorized; after binding the address information of the first instance with database permissions based on the authorization relationship information, the method further includes: releasing the locking identifier on the address information of the first instance. It is understood that during the process of obtaining the first database permissions corresponding to the first instance, the revocation of database permissions can be performed simultaneously. If the address information of the first instance is the address information corresponding to an instance that was destroyed (i.e., terminated) during a historical time period, and this address information is already bound to the second database permissions, the first database permissions and the second database permissions may be the same or different.
[0080] To illustrate, if the first instance terminates during a historical time period, and the second database permissions acquired during that period are not currently revoked, and the first instance hosts the same or different applications, and then restarts, requiring the acquisition of the first database permissions, the previously acquired second database permissions will be revoked upon restarting. This means the address information of the first instance will be unbound from the second database permissions, potentially leading to authorization errors during the permission acquisition process. Therefore, an authorization flag needs to be added during the authorization process to lock permissions and prevent accidental revocation. By setting the authorization flag during the authorization process, accidental revocation and other abnormal authorization operations can be avoided, improving the efficiency and accuracy of database permission control.
[0081] In some embodiments, the granting of the first database permission corresponding to the first instance is completed asynchronously after obtaining the authorization request corresponding to the first instance through mechanisms such as message queues, event reception, or timed tuning. Optionally, after the management decision unit in the permission control module corresponding to the first instance generates an authorization request and sends it to the processing unit, it receives an "accepted" response returned by the processing execution unit without waiting for the authorization result corresponding to the authorization request. This is suitable for batch authorization scenarios and improves resource utilization during the authorization process. Optionally, during the loop process after obtaining the authorization request, the loop iteration is paused through a blocking mechanism (such as channel waiting, condition variables, timers, etc.) until the authorization result corresponding to the authorization request is obtained, and then execution continues, rather than idling and checking the authorization result in a blocked state.
[0082] In some embodiments, the first instance includes an initialization container and a business container. The initialization container is used during the startup phase after the first instance is created to configure the runtime environment of the first instance, including but not limited to generating configuration files required for executing business functions, initializing and checking database permissions, detecting runtime dependencies, and preloading basic data necessary for starting the first instance. The business container is used to execute the business functions corresponding to the first instance after the initialization container has finished executing, including but not limited to processing application user requests and executing business phases, and will continue to run until the first instance terminates. Optionally, during the startup phase after the first instance is created, a configuration change request, such as a release request, is sent to the initialization container. The configuration change request includes the permission changes required by the first instance.
[0083] In some embodiments, the initialization container of the first instance blocks the authorization process by executing command lines, utilizing a pre-configured authorization script to achieve unified control over the authorization process, intercepting authorization requests with low security such as ALL PRIVILEGES, and providing a basis for authorization records. Optionally, the permission control module includes an initialization container and an authorization component. Part of the functionality of the initialization container constitutes a management decision unit. For example, through the initialization configuration operation of the initialization container, the authorization component in the management decision unit is configured and an authorization request is generated. The authorization component obtains the pre-configured authorization script and executes the authorization process, including but not limited to obtaining the authorization binding relationship and the authorization password corresponding to the database based on the authorization request, and obtaining the first database permissions corresponding to the first instance based on the authorization password. Optionally, the authorization component is an important component of the processing execution unit.
[0084] Schematic illustration: The initialization configuration operation of the container includes initializing the database authorization tool, which involves downloading the database authorization tool to the management decision unit. The management decision unit includes a pre-configured configuration template, which generates a configuration file corresponding to execution permission management. The configuration file describes the authorization intent corresponding to the first instance. Optionally, the configuration file includes, but is not limited to, the database identity, first database permissions, business information, database representation, and authentication information (i.e., encryption information) corresponding to the first instance. The database authorization tool includes a template replacement tool and a database connection tool. The template replacement tool replaces placeholders in the preset configuration template with the actual configuration parameters, and the database connection tool connects to the database master node that the first instance is expected to access. The database master node is responsible for managing database permissions.
[0085] Optionally, the configuration file may also include Internet Data Center (IDC) information. An IDC is the physical infrastructure that centrally stores computing, storage, and network devices, and it forms the basis for the application runtime environment platform corresponding to the first instance. The IDC information is used to identify the application runtime environment platform where the first instance resides, i.e., the application cluster. Optionally, the application cluster can be uniquely identified by a cluster identifier, i.e., Cluster_ID.
[0086] In some embodiments, the processing execution unit includes an authorization component and an orchestration component. The authorization component is used to obtain authorization binding relationships based on authorization requests, generate authorization tasks based on authorization binding relationships, and send the configuration file corresponding to the first instance to the database master node. The orchestration component is used to manage and schedule multiple tasks to be executed, and orchestrate the execution order of the tasks based on the dependencies and retry policies among the multiple tasks to be executed, wherein the multiple tasks to be executed include authorization tasks.
[0087] For illustrative purposes, please refer to the following: Figure 4 This illustrates a schematic diagram of the licensing process provided in an exemplary embodiment of this application. Figure 4 As shown, when the first instance 410 is created or restarted, the first instance 410 executes step 1, sending a configuration change request to the initialization container 420. The configuration change request indicates that the first instance 410 needs to obtain the first database permissions corresponding to the first instance 410. Accordingly, the initialization container 420 executes step 2, initializing the database authorization tool. The database authorization tool is a pre-configured authorization script used to execute the process of obtaining the first database permissions when an authorization request is generated. The database authorization tool includes, but is not limited to, a template replacement tool and a database connection tool.
[0088] like Figure 4 As shown, the initialization container 420 executes step 3, sending an authorization request to the authorization component 430. The authorization component 430 then executes step 4, adding a lock identifier, based on the address information of the first instance 410. This ensures that the first database permissions of the first instance 410 are not mistakenly revoked during the acquisition of first database permissions. The authorization component 430 generates a query request based on the business information corresponding to the first instance 410 in the authorization request and executes step 5, querying the authorization binding relationship, to the CMDB 440. That is, it sends a query request to the CMDB 440. Upon receiving the query request, the CMDB 440 obtains the mapping relationship between the business information corresponding to the first instance 410 and the first database permissions, and obtains the encrypted information of the database user corresponding to the first database permissions. This encrypted information is the authentication information corresponding to the database identity of the first instance 410. The CMDB 440 then executes step 6, sending a decryption request to the encryption / decryption platform 450 based on the encrypted information. This yields the authorization password corresponding to the database, and a corresponding relationship exists between the authorization password and the authorization binding relationship.
[0089] like Figure 4 As shown, the encryption / decryption platform 450 executes step 7 to CDMB 440, returning the authorization password. CMDB 440 sends the authorization password and authorization binding relationship together as feedback information for the query request to the authorization component 430, that is, executing step 8, returning the authorization binding relationship. The authorization component 430 then executes step 9, obtaining the authorization password, step 10, obtaining IDC information, and step 11, generating an authorization task. The authorization task is used to send the configuration file corresponding to the first instance 410 to the node responsible for managing permissions in the database. The configuration file includes the authorization password, which is used to authenticate database management permissions.
[0090] like Figure 4As shown, the authorization component 430 executes step 12, sending an orchestration signal to the orchestration component 460. The orchestration signal includes an authorization task. The orchestration component 460 converts the orchestration signal into an authorization intent that the database can obtain. The authorization intent is used to indicate that the first instance 410 is determined as the authorization object, and the first database permission is the permission required for the authorization object. The orchestration component 460 executes step 13, sending the authorization intent to the database master node 470. The initialization container 420 executes step 14, polling the authorization results to the authorization component 430. Optionally, step 14 here is only an illustrative example; after the initialization container 420 sends an authorization request to the authorization component 430, the polling step is performed at a fixed period.
[0091] like Figure 4 As shown, in response to receiving the authorization intent, the database master node 470 executes step 15 to the authorization component 430, returning the first sub-authorization result. The first sub-authorization result indicates that the database master node 470 is aware of the authorization intent. Correspondingly, the authorization component 430 executes step 16 to the orchestration component 460, querying the first sub-authorization result. The authorization component 430 synchronizes the first sub-authorization result, indicating the authorization intent, from the database master node 470 to the orchestration component 460, which then executes step 17 to the database master node 470, sending the authorization task through the cloud platform. In response to receiving the authorization task sent by the cloud platform, the database master node 470, after verifying the authorization password, performs an authorization operation on the first instance 410, such as binding the address information of the first instance 410 with the first database permissions. The cloud platform is used to connect the database master node 470 to actually execute the authorization operation (such as the GRANT statement), improving authorization reliability.
[0092] like Figure 4 As shown, the database master node 470 executes step 18 to the authorization component 430, returning the second sub-authorization result. This second sub-authorization result indicates that the database master node 470 has completed the authorization operation for the first instance 410. Correspondingly, the authorization component 430 executes step 19 to the orchestration component 460, querying the second sub-authorization result. The authorization component 430 synchronizes the second sub-authorization result to the orchestration component 460, and the orchestration component 460 terminates the execution flow corresponding to the authorization task. The authorization component 430 executes step 20 to the initialization container 420, returning the authorization result. The initialization container 420 executes step 21 to the first instance 410, returning the configuration change result. After the above authorization process is completed, the authorization component 430 executes step 22, releasing the lock flag.
[0093] For illustrative purposes, please refer to the following: Figure 5 This illustrates a schematic diagram of the access control interface provided in an exemplary embodiment of this application. Figure 5As shown, the permission management interface 510 displays a table showing the correspondence between application cluster names and database cluster names; optionally, the first application cluster is connected to the first database cluster and the second database cluster respectively, and the second application cluster is connected to the first database cluster and the second database cluster respectively, wherein the connection relationship between the application cluster and the database cluster is used to indicate that there is an authorization relationship between the instance in the application cluster and the database in the database cluster.
[0094] like Figure 5 As shown, access control administrators can intuitively manage the database permissions corresponding to applications through a unified access control interface 510. By triggering management commands such as requesting database permissions, closing database authorization relationships, and requesting logs, they can respectively implement the granting, revocation, or control record review of database permissions. Optionally, access control administrators managing the database permissions corresponding to applications include, but are not limited to, application developers managing the database permissions corresponding to applications; DBAs reviewing database permission control records; operations engineers maintaining the stable operation of application systems and handling faults; and security auditors conducting compliance checks and risk assessments of database access control.
[0095] It is worth noting that the above Figure 5 The implementation of the permission management interface 510 shown is merely an illustrative example. This application embodiment does not limit the authorization configuration information and display method in the permission management interface.
[0096] In summary, the method provided in this application automatically obtains authorization requests, acquires business information corresponding to the first instance, and obtains the binding relationship between the business information and database permissions, thereby enabling authorization operations to the first instance. That is, it automatically binds the first instance to the binding relationship corresponding to the business information and acquires the first database permissions corresponding to the first instance, avoiding cumbersome manual approval processes and manual authorization operations. Furthermore, even if the IP address of the first instance changes due to restarting, scaling up or down, etc., the authorization operation can still be quickly implemented through the above authorization process, reducing the complexity of database permission control and improving the efficiency of authorization operations.
[0097] The method provided in this embodiment obtains the authorization password corresponding to the database through the authorization binding relationship. The authorization password is strongly associated with the first database permissions. When the authorization password is configured with the first database permissions, the authorization flexibility is improved. Furthermore, the management permissions of the database are authenticated based on the authorization password, thereby enabling authorization operations on the first instance and improving authorization efficiency.
[0098] In some embodiments, database access control also includes the revocation of database permissions; if the first instance terminates, the previously assigned first database permissions corresponding to the first instance are revoked. Please refer to [reference needed]. Figure 6This illustrates a flowchart of a database permission control method provided in yet another exemplary embodiment of this application. The method can be implemented by a computer device (which may be configured as follows). Figure 1 The method is executed by either the terminal 120 or the server 140 shown, or it is executed jointly by the terminal and the server. In this embodiment, the method is executed by the terminal as an example. Figure 6 As shown, the method further includes at least one of the following steps 610 and 620.
[0099] Step 610: In response to receiving the destruction event corresponding to the first instance, store the first instance in the queue to be recycled.
[0100] The destroy event is used to indicate that the first instance has terminated, and the queue to be reclaimed includes at least one instance whose database privileges have been revoked. Optionally, the termination of the first instance is used to indicate that the first instance is in a terminating state.
[0101] Step 620: If the first instance is in the queue to be reclaimed, revoke the first database permissions corresponding to the first instance and remove the first instance from the queue to be reclaimed.
[0102] In some embodiments, when the first instance is in the reclaim queue, the address information of the first instance is unbound from the permissions of the first data block, and the first instance is removed from the reclaim queue; when the first instance is in the reclaim queue and a lock flag is present on the address information of the first instance, the address information of the first instance is kept bound to the database permissions. By setting the authorization flag during the authorization process, abnormal authorization operations such as accidental reclaiming are avoided, thereby improving the efficiency and accuracy of database permission control.
[0103] In some embodiments, a delayed reclamation list is obtained, which includes at least one instance in a reclamation queue; if a first instance is in the reclamation queue and not in the delayed reclamation list, the liveness status of the first instance is obtained, whereby the liveness status of the first instance includes a first state and a second state, the first state indicating that the first instance has terminated and the second state indicating that the first instance has not terminated; in response to the first instance's liveness status being the first state, the first database permissions corresponding to the first instance are revoked, and the first instance is removed from the reclamation queue; in response to the first instance's liveness status being the second state, the first instance is re-stored in the reclamation queue.
[0104] By setting a delayed eviction list, recently authorized instances or other instances that need to be temporarily spared from eviction can be hidden during the permission eviction process, thus preventing business function failures caused by accidental eviction of database permissions and improving the accuracy of database permission control. In some embodiments, at least one authorized instance corresponding to the database is obtained, which is used to access the database based on the database permissions corresponding to the authorized instance; the at least one authorized instance is sorted from latest to earliest according to the authorization time; the top K authorized instances after sorting are obtained to obtain the delayed eviction list, where K is a positive integer. Optionally, the delayed eviction list can also determine instances that need to be skipped during the permission eviction process in a customized way, thereby protecting business applications with specific needs and improving the efficiency of database permission control.
[0105] In some embodiments, authorization information corresponding to the database and business information corresponding to the first instance are obtained. The authorization information includes business information corresponding to at least one authorized instance of the database. If the intersection of the business information and the authorization information corresponding to the first instance is empty, the survival status of the first instance is determined to be a first state. If the intersection of the business information and the authorization information corresponding to the first instance is not empty, the survival status of the first instance is determined to be a second state. By clearly defining the survival status determination process of the first instance, the security of the permission revoke operation is improved, and the efficiency of database permission control is enhanced by checking whether the first instance is still running.
[0106] For illustrative purposes, please refer to the following: Figure 7 This illustrates a flowchart of obtaining the liveness status of a first instance according to an exemplary embodiment of this application. Figure 7 As shown, when the business information 710 and authorization information 720 corresponding to the first instance are obtained, the intersection 730 between the business information 710 and authorization information 720 corresponding to the first instance is obtained. When the intersection 730 is empty, the survival status of the first instance is obtained as the first state; when the intersection 730 is not empty, the survival status of the first instance is obtained as the second state.
[0107] In some embodiments, in response to receiving a stock reclamation signal, at least one authorized instance corresponding to the database is obtained. The stock reclamation signal is used to indicate that the number of authorized database permissions in the database has reached a preset threshold. The at least one authorized instance includes a second instance, which is used to access the database based on the second database permissions corresponding to the second instance. If the second instance is not in the delayed reclamation list, the survival status of the second instance is obtained. In response to the survival status of the second instance being a first status, the second database permissions corresponding to the second instance are revoked.
[0108] The database cluster consists of at least one database instance, such as MySQL, Ti Database (TiDB), and Redis.
[0109] The system retrieves the number of database user accounts and authorized database permissions as alarm data. When the alarm data reaches a preset threshold, it generates a stock reclamation signal. If the number of database user accounts and authorized database permissions becomes excessive, accounts are promptly deleted or released, reducing the difficulty of tracing account usage and preventing management chaos. It also revokes long-accumulated redundant database permissions, reducing the risk of data leakage. Furthermore, it prevents the database permission list from becoming too large, thereby improving the connection establishment speed between the database and application instances and enhancing database access performance. Finally, it improves the efficiency of database permission control compliance reviews.
[0110] The `host` directive indicates the network address of clients permitted to access the database. The `host` directive can be implemented using, but is not limited to, IP addresses, CIDRs, or hostnames (e.g., localhost). The database maintains a list of `host` directives, which includes at least one `host` record. In some embodiments, the `host` directive includes the address information corresponding to the application instance. Optionally, during the authorization process within a historical time period, the database records historical authorization implementations, i.e., at least one authorized instance, and stores this record as a summary of the corresponding storage space.
[0111] For illustrative purposes, please refer to the following: Figure 8 This illustrates a flowchart of a dual instance reclamation method provided in an exemplary embodiment of this application. Figure 8 As shown, in response to receiving the destruction event 810 corresponding to the first instance 810, the first database permissions corresponding to the terminated first instance 810 are revoked through a periodic recycling method, including but not limited to at least the following steps: storing the first instance 810 in the recycling queue 830; obtaining the delayed recycling list 840; if the first instance 810 is in the delayed recycling list 840, storing the first instance back into the recycling queue 830; if the first instance 810 is not in the delayed recycling list 840, obtaining the survival status 851 of the first instance; if the survival status 851 of the first instance is the first status, executing the revocation of database permissions 860.
[0112] like Figure 8As shown, in response to receiving the existing resource reclamation signal 871, the database permissions corresponding to at least one authorized embodiment that has terminated operation are revoked in batches through the existing resource reclamation method. The method of obtaining the existing resource reclamation signal 871 includes obtaining alarm data 872; when the alarm data 872 reaches a preset threshold, the existing resource reclamation signal 871 is generated, and the permission administrator 873 initiates the database permission reclamation process corresponding to the existing resource reclamation method. The method involves obtaining the host list 891 corresponding to database 880, and obtaining the historical authorized instances 892 corresponding to database 880, thereby obtaining the intersection between the host list 891 and the historical authorized instances 892, i.e., at least one authorized instance; adding at least one authorized instance to the reclamation queue 830; for a second instance of at least one authorized instance, if the second instance is not in the delayed reclamation list 840, obtaining the survival status 852 of the second instance; if the survival status 852 of the second instance is a first state, executing the revocation of database permissions 860.
[0113] For illustrative purposes, please refer to the following: Figure 9 This illustrates a flowchart of another dual instance reclamation method provided in an exemplary embodiment of this application. Figure 9 As shown, in response to receiving the destruction event 910 corresponding to the first instance 910, the first database permissions corresponding to the terminated first instance 910 are revoked through a periodic recycling method, including but not limited to at least the following steps: storing the first instance 910 in the recycling queue 930; obtaining the delayed recycling list 940; if the first instance 910 is in the delayed recycling list 940, storing the first instance back into the recycling queue 930; if the first instance 910 is not in the delayed recycling list 940, obtaining the survival status 951 of the first instance; if the survival status 951 of the first instance is the first status, executing the revocation of database permissions 960.
[0114] like Figure 9As shown, in response to receiving the existing resource reclamation signal 971, the database permissions corresponding to at least one authorized embodiment that has terminated operation are revoked in batches through another existing resource reclamation method. The method of obtaining the existing resource reclamation signal 971 includes obtaining alarm data 972. When the alarm data 972 reaches a preset threshold, the existing resource reclamation signal 971 is generated, and the permission administrator 973 initiates the database permission reclamation process corresponding to the existing resource reclamation method. The host list 980 corresponding to the database is obtained, and it is determined whether the long connection corresponding to at least one host in the host list 980 is alive 991. If the long connection is not alive, it is determined whether the physical machine corresponding to at least one host in the host list 980 is alive 992. If the physical machine is not alive, and if the host is not in the delayed reclamation list 940, the survival status 952 of the second instance is obtained. If the survival status 952 of the second instance is the first state, the database permission revocation 960 is executed. If the long connection corresponding to the host is alive, the physical machine corresponding to the host is alive, or the survival status of the host is the second state, the host is skipped, and the database permission revocation of the host is not executed.
[0115] For illustrative purposes, please refer to the following: Figure 10 This illustrates a graphical interface diagram showing the number of instances to be recycled, provided in an exemplary embodiment of this application. For example... Figure 10 As shown, the interface 1010 for the number of instances to be reclaimed displays real-time metrics related to database access control for at least one instance. Optionally, these metrics are presented as line graphs showing the data over time. The metrics related to database access control for at least one instance include, but are not limited to, the number of instance user table rows (indicating the number of authorized instances) in different database clusters, the number of instance database table rows (indicating the number of authorized database permissions) in different database clusters, the number of instances to be reclaimed, and the number of reclaimable hosts in the database cluster.
[0116] For illustrative purposes, please refer to the following: Figure 11 This illustrates an interface diagram of a list of instances to be recycled provided in an exemplary embodiment of this application. For example... Figure 11 As shown, the interface 1110 displays the identification information, such as IP addresses, corresponding to N instances to be reclaimed, M reclaimable instances, O hosts to be reclaimed, and P reclaimable hosts in the pending instance list interface; where N, M, O, and P are all positive integers. In some embodiments, pending instance or reclaimable host indicates the instance or host that triggered the database permission revocation process, i.e., the instance or host in the pending revocation queue; reclaimable instance or reclaimable host indicates the instance or host that has terminated its operation. Optionally, Figure 11The numbers N1, N2, N3, M1, M2, M3, O1, O2, O3, P1, P2, and P3 shown are used to indicate the serial numbers of the instance or host identification information.
[0117] It is worth noting that the above Figure 10 The interface showing the number of instances to be recycled is 1010 or... Figure 11 The implementation of the pending instance list interface 1110 shown is merely an illustrative example. This application embodiment does not limit the instance information and display method of pending database permissions in the control interface used for permission management.
[0118] In summary, the method provided in this application automatically obtains authorization requests, acquires business information corresponding to the first instance, and obtains the binding relationship between the business information and database permissions, thereby enabling authorization operations to the first instance. That is, it automatically binds the first instance to the binding relationship corresponding to the business information and acquires the first database permissions corresponding to the first instance, avoiding cumbersome manual approval processes and manual authorization operations. Furthermore, even if the IP address of the first instance changes due to restarting, scaling up or down, etc., the authorization operation can still be quickly implemented through the above authorization process, reducing the complexity of database permission control and improving the efficiency of authorization operations.
[0119] The method provided in this embodiment improves the security and efficiency of database permission control through a complete database permission revoke process. It promptly deletes or releases the database user account corresponding to the first instance, reducing the difficulty of tracing account usage and avoiding management chaos; it revokes redundant database permissions, reducing the risk of data leakage in the database; and it avoids an excessively large database permission list, thereby improving the connection establishment speed between the database and the application instance and improving database access performance.
[0120] For illustrative purposes, please refer to the following: Figure 12 This illustrates a schematic diagram of a database permission control module provided in an exemplary embodiment of this application. Figure 12 As shown, permission control is used to grant and revoke permissions for the first instance. The permission control module includes a management decision unit, which comprises an event acquisition module 1210, an authorization decision module 1220, and a registration module for instances to be revoked 1230. The event acquisition module receives real-time data from the runtime environment platform API 1240, such as the creation event 1251 and the destruction event 1252 corresponding to the first instance sent by the K8s API. In response to receiving the creation event 1251 corresponding to the first instance, the authorization decision module 1220 obtains an authorization request, acquires an authorization binding relationship 1260 based on the authorization request, and executes the authorization process through the processing execution unit 1270 included in the permission control module based on the authorization binding relationship 1260 to acquire the first database permissions corresponding to the first instance.
[0121] like Figure 12 As shown, in response to receiving the destruction event 1252 corresponding to the first instance, the instance registration module stores the first instance in the reclaim queue 1280. While the first instance is in the reclaim queue 1280, the processing execution unit 1270 executes the deauthorization process to revoke the first database permissions corresponding to the first instance. Optionally, the existing hosts corresponding to database 1291 include at least one unreclaimed instance in the reclaim queue 1280.
[0122] For illustrative purposes, please refer to the following: Figure 13 This illustrates a schematic diagram of a database permission control module provided in another exemplary embodiment of this application. Figure 13 As shown, the permission granting process, also known as the authorization process, includes, but is not limited to, the first instance 1310 executing step 1.1, template replacement tool download, to the management decision unit 1320 via the initialization container, and step 1.2, database connection tool download, to the management decision unit 1320. The initialization container sends an authorization request to the processing execution unit 1330 via step 1.3. Based on the authorization request, the processing execution unit 1330 obtains the first database permissions corresponding to the first instance 1310.
[0123] like Figure 13 As shown, the permission revoke process, also known as the deauthorization process, includes, but is not limited to, step 2.1 of the management decision unit 1320 executing: receiving a destruction event. The destruction event corresponding to the first instance is sent by the runtime environment platform API 1340, which can optionally be implemented as a K8s API. Furthermore, the management decision unit 1320 sends a deauthorization request to the processing execution unit 1330 in step 2.2. Based on the deauthorization request, the processing execution unit 1330 revokes the first database permission corresponding to the first instance 1310.
[0124] Figure 14 This is a structural block diagram of a database permission control device provided in an exemplary embodiment of this application, such as... Figure 14 As shown, the device includes: The authorization module 1410 is configured to obtain the authorization request corresponding to the first instance. The authorization request includes business information corresponding to the first instance. The business information is used to indicate the business function to be executed by the first instance. The authorization request is used to request the allocation of database access permissions to the first instance. The authorization module 1410 is also configured to obtain the authorization binding relationship based on the authorization request. The authorization binding relationship includes the binding relationship between business information and database permissions. The authorization module 1410 is also configured to obtain the first database permissions corresponding to the first instance based on the authorization binding relationship, and the first instance is used to access the database based on the first database permissions.
[0125] In an optional embodiment, the authorization module 1410 is further configured to obtain the authorization password corresponding to the database based on the authorization request, wherein there is a corresponding relationship between the authorization password and the authorization binding relationship, and the authorization password is used to authenticate the management permissions of the database; The authorization module 1410 is also configured to obtain the first database permissions corresponding to the first instance based on the authorization password.
[0126] In an optional embodiment, the authorization module 1410 is further configured to obtain encrypted information in the authorization binding relationship based on the authorization request, wherein the encrypted information is an encrypted authorization password; The authorization module 1410 is also configured to decrypt encrypted information to obtain the authorization password.
[0127] In an optional embodiment, the authorization module 1410 is further configured to obtain an authorization request in response to receiving a creation event corresponding to the first instance, the creation event being used to instruct the first instance to start running.
[0128] In an optional embodiment, the authorization module 1410 is further configured to bind the address information of the first instance to the first database permissions based on the authorization binding relationship, wherein the address information of the first instance is used to uniquely identify the identity information of the first instance.
[0129] In an optional embodiment, before the authorization module 1410 obtains the authorization relationship information based on the authorization request, the authorization module 1410 is further configured to add a lock identifier to the address information of the first instance, the lock identifier being used to indicate that the address information of the first instance is being authorized; After the authorization module 1410 binds the address information of the first instance to the database permissions based on the authorization relationship information, the authorization module 1410 is also configured to release the lock flag on the address information of the first instance.
[0130] In an optional embodiment, Figure 15 This is a structural block diagram of a database permission control device provided in another exemplary embodiment of this application, such as... Figure 15 As shown, the database permission control device also includes a permission revocation module 1420. The permission revocation module 1420 is configured to store the first instance in a queue to be revoked in response to receiving a destruction event corresponding to the first instance. The destruction event is used to indicate that the first instance terminates its operation. The queue to be revoked includes at least one instance whose database permissions are to be revoked. The permission revocation module 1420 is also configured to revoke the first database permissions corresponding to the first instance and remove the first instance from the revocation queue when the first instance is in the queue to be revoked.
[0131] In an optional embodiment, the permission revocation module 1420 is further configured to, when the first instance is in the revocation queue, unbind the address information of the first instance from the first data block permission and remove the first instance from the revocation queue. The permission revocation module 1420 is also configured to maintain the binding between the address information of the first instance and the database permissions when the first instance is in the queue to be revoked and the address information of the first instance has a lock flag.
[0132] In an optional embodiment, the permission revocation module 1420 is further configured to obtain a delayed revocation list, which includes at least one instance in the queue to be revoked; The permission revocation module 1420 is also configured to obtain the survival status of the first instance when the first instance is in the queue to be revoked and the first instance is not in the delayed revocation list. The survival status of the first instance includes a first state and a second state. The first state is used to indicate that the first instance has terminated its operation, and the second state is used to indicate that the first instance has not terminated its operation. The permission revocation module 1420 is also configured to revoke the first database permissions corresponding to the first instance in response to the first instance being in the first state of being alive. The permission reclamation module 1420 is also configured to re-store the first instance into the reclamation queue in response to the first instance's liveness status being the second state.
[0133] In an optional embodiment, the permission revocation module 1420 is further configured to obtain at least one authorized instance corresponding to the database, the authorized instance being used to access the database based on the database permissions corresponding to the authorized instance; The permission revocation module 1420 is also configured to sort at least one authorized instance in order of authorization time from latest to earliest; The permission revocation module 1420 is also configured to retrieve the top K sorted authorized instances to obtain a delayed revocation list, where K is a positive integer.
[0134] In an optional embodiment, the permission revocation module 1420 is further configured to obtain authorization information corresponding to the database and business information corresponding to the first instance, wherein the authorization information includes business information corresponding to at least one authorized instance corresponding to the database. The permission revocation module 1420 is also configured to obtain the first instance's survival status as the first state when the intersection of the business information and authorization information corresponding to the first instance is empty. The permission revocation module 1420 is also configured to obtain the survival status of the first instance as the second state when the intersection of the business information and authorization information corresponding to the first instance is not empty.
[0135] In an optional embodiment, after the permission revoke module 1420 obtains the delayed revoke list, the permission revoke module 1420 is further configured to obtain at least one authorized instance corresponding to the database in response to receiving the stock revoke signal. The stock revoke signal is used to indicate that the number of authorized database permissions in the database has reached a preset threshold. The at least one authorized instance includes a second instance, which is used to access the database based on the second database permissions corresponding to the second instance. The permission revocation module 1420 is also configured to obtain the survival status of the second instance if the second instance is not in the delayed revocation list, and revoke the second database permissions corresponding to the second instance if the survival status of the second instance is the first state.
[0136] In summary, the apparatus provided in this application automatically obtains authorization requests, acquires business information corresponding to the first instance, and obtains the binding relationship between the business information and database permissions, thereby enabling authorization operations to the first instance. That is, it automatically binds the first instance to the binding relationship corresponding to the business information and acquires the first database permissions corresponding to the first instance, avoiding cumbersome manual approval processes and manual authorization operations. Furthermore, even if the IP address of the first instance changes due to restarting, scaling up or down, etc., the authorization operation can still be quickly implemented through the above authorization process, reducing the complexity of database permission control and improving the efficiency of authorization operations.
[0137] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the content structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0138] Please refer to Figure 16 This diagram illustrates a structural block diagram of a computer device 1600 provided in one embodiment of this application. The computer device 1600 may be... Figure 1The terminal or server in the computer system shown, in this embodiment of the application, is used to implement the database permission control method provided in the above embodiment, taking the computer device 1600 as an example, as an example. Specifically: Typically, computer device 1600 includes a processor 1601 and a memory 1602.
[0139] Processor 1601 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. Processor 1601 may be implemented using at least one hardware form selected from Digital Signal Processing (DSP), Field Programmable Gate Array (FPGA), and Programmable Logic Array (PLA). Processor 1601 may also include a main processor and a coprocessor. The main processor, also known as the CPU, is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 1601 may integrate a Graphics Processing Unit (GPU), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, processor 1601 may also include an Artificial Intelligence (AI) processor, which is used to handle computational operations related to machine learning.
[0140] The memory 1602 may include one or more computer-readable storage media, which may be non-transitory. The memory 1602 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 1602 are used to store a computer program configured to be executed by one or more processors to implement the aforementioned database permission control method.
[0141] In some embodiments, the computer device 1600 may also optionally include other components 1603: a peripheral device interface and at least one peripheral device. The processor 1601, memory 1602, and peripheral device interface can be connected via a bus or signal lines. Each peripheral device can be connected to the peripheral device interface via a bus, signal lines, or a circuit board. Specifically, the peripheral device includes at least one of: radio frequency circuitry, a display screen, audio circuitry, and a power supply.
[0142] Those skilled in the art will understand that Figure 16The structure shown does not constitute a limitation on the computer device 1600, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.
[0143] In an exemplary embodiment, a computer-readable storage medium is also provided, wherein a computer program is stored in the storage medium, and the computer program, when executed by a processor, implements the aforementioned database permission control method. Optionally, the computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), solid-state drives (SSDs), or optical discs, etc. The random access memory may include resistive random access memory (ReRAM) and dynamic random access memory (DRAM).
[0144] In an exemplary embodiment, a computer program product is also provided, the computer program product including a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, causing the computer device to perform the aforementioned database permission control method.
[0145] It should be noted that the collection and processing of relevant data (such as authorization binding information, business information corresponding to the first instance, etc.) in this application should strictly comply with the requirements of relevant national laws and regulations when applying the instance, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0146] It should be understood that "multiple" as used in this article refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0147] Furthermore, the step numbers described herein are merely illustrative of one possible execution order between steps. In some other embodiments, the steps may not be executed in the order of their numbers, such as two steps with different numbers being executed simultaneously, or two steps with different numbers being executed in the reverse order of the illustration. This application does not limit this.
[0148] The above description is merely an exemplary embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A database permission control method, characterized in that, The method includes: Obtain the authorization request corresponding to the first instance. The authorization request includes business information corresponding to the first instance. The business information is used to indicate the business functions to be performed by the first instance. The authorization request is used to request the allocation of database access permissions to the first instance. Based on the authorization request, an authorization binding relationship is obtained, which includes the binding relationship between business information and database permissions; The first database permission corresponding to the first instance is obtained based on the authorization binding relationship, and the first instance is used to access the database based on the first database permission.
2. The method according to claim 1, characterized in that, The step of obtaining the authorization binding relationship based on the authorization request includes: Based on the authorization request, the authorization password corresponding to the database is obtained. There is a corresponding relationship between the authorization password and the authorization binding relationship. The authorization password is used to authenticate the management authority of the database. The step of obtaining the first database permissions corresponding to the first instance based on the authorization binding relationship includes: Based on the authorization password, obtain the first database permissions corresponding to the first instance.
3. The method according to claim 2, characterized in that, The step of obtaining the authorization password corresponding to the database based on the authorization request includes: Based on the authorization request, the encrypted information in the authorization binding relationship is obtained, and the encrypted information is the encrypted authorization password; The encrypted information is decrypted to obtain the authorization password.
4. The method according to any one of claims 1 to 3, characterized in that, The step of obtaining the authorization request corresponding to the first instance includes: In response to receiving a creation event corresponding to the first instance, the authorization request is obtained, wherein the creation event is used to instruct the first instance to start running.
5. The method according to any one of claims 1 to 3, characterized in that, The step of obtaining the first database permissions corresponding to the first instance based on the authorization binding relationship includes: Based on the authorization binding relationship, the address information of the first instance is bound to the first database permissions, and the address information of the first instance is used to uniquely identify the identity information of the first instance.
6. The method according to claim 5, characterized in that, Before obtaining the authorization binding relationship based on the authorization request, the process also includes: Add a lock identifier to the address information of the first instance, the lock identifier being used to indicate that the address information of the first instance is being authorized; After binding the address information of the first instance with the first database permissions based on the authorization binding relationship, the method further includes: Release the lock identifier on the address information of the first instance.
7. The method according to any one of claims 1 to 3, characterized in that, The method further includes: In response to receiving a destruction event corresponding to the first instance, the first instance is stored in a queue to be reclaimed. The destruction event is used to instruct the first instance to terminate its operation. The queue to be reclaimed includes at least one instance whose database permissions are to be revoked. If the first instance is in the queue to be reclaimed, revoke the first database permissions corresponding to the first instance, and remove the first instance from the queue to be reclaimed.
8. The method according to claim 7, characterized in that, The step of revoking the first database permissions corresponding to the first instance when the first instance is in the queue to be reclaimed includes: If the first instance is in the queue to be reclaimed, the address information of the first instance is unbound from the permissions of the first data block, and the first instance is removed from the queue to be reclaimed. The method further includes: When the first instance is in the queue to be recycled and there is a lock flag on the address information of the first instance, the address information of the first instance is kept bound to the database permissions.
9. The method according to claim 7, characterized in that, The step of revoking the first database permissions corresponding to the first instance when the first instance is in the queue to be reclaimed includes: Obtain a delayed recycling list, which includes at least one instance from the queue to be recycled; When the first instance is in the queue to be recycled and the first instance is not in the delayed recycling list, the survival status of the first instance is obtained. The survival status of the first instance includes a first status and a second status. The first status is used to indicate that the first instance has terminated its operation, and the second status is used to indicate that the first instance has not terminated its operation. In response to the fact that the liveness status of the first instance is the first state, the first database permissions corresponding to the first instance are revoked; The method further includes: In response to the first instance's liveness state being the second state, the first instance is re-stored into the queue to be reclaimed.
10. The method according to claim 9, characterized in that, The process of obtaining the delayed recycling list includes: Obtain at least one authorized instance corresponding to the database, wherein the authorized instance is used to access the database based on the database permissions corresponding to the authorized instance; Sort the at least one authorized instance in order of authorization time from latest to earliest; Obtain the first K authorized instances after sorting to obtain the delayed recycling list, where K is a positive integer.
11. The method according to claim 9, characterized in that, The step of obtaining the liveness status of the first instance when the first instance is in the queue to be reclaimed and not in the delayed reclamation list includes: Obtain the authorization information corresponding to the database, and obtain the business information corresponding to the first instance, wherein the authorization information includes the business information corresponding to at least one authorized instance of the database; If the intersection of the business information corresponding to the first instance and the authorization information is empty, the survival status of the first instance is the first status. If the intersection of the business information corresponding to the first instance and the authorization information is not empty, the survival status of the first instance is the second state.
12. The method according to any one of claims 9 to 11, characterized in that, After obtaining the delayed recycling list, the process also includes: In response to receiving a stock reclamation signal, at least one authorized instance corresponding to the database is obtained. The stock reclamation signal is used to indicate that the number of authorized database permissions in the database has reached a preset threshold. The at least one authorized instance includes a second instance, which is used to access the database based on the second database permissions corresponding to the second instance. If the second instance is not in the delayed recycling list, obtain the liveness status of the second instance. If the liveness status of the second instance is the first status, revoke the second database permissions corresponding to the second instance.
13. A computer device, characterized in that, The computer device includes a processor and a memory, the memory storing a computer program that is loaded and executed by the processor to implement the database permission control method as described in any one of claims 1 to 12.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which is loaded and executed by a processor to implement the database permission control method as described in any one of claims 1 to 12.
15. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, and a processor reads from and executes the computer program to implement the database permission control method as described in any one of claims 1 to 12.