Summary of the invention
The technical problem to be solved in the present invention is that for file uploader in the prior art permission can not be carried out to file
The defect of setting, providing one kind can prevent file from revealing and accidentally modifying, and file uploader can access to file
The authorization method for authenticating of the cloud file-sharing of permission control.
The technical solution adopted by the present invention to solve the technical problems is:
The present invention provides a kind of authorization method for authenticating of cloud file-sharing, includes the following steps:
After S1, primary user use the user name of oneself, password login server, file to be sharing is uploaded;
S2, file upload after the completion of, primary user in the user interface of server end, can add primary user token, from
The user name and token at family, and be arranged from user to the access authority of the shared file of upload;
S3, primary user complete to be informed by the user name of primary user, password and from the token of user after the authorization of user
From user, it will be authenticated from user login services device end, and specifically include following steps:
After S31, the username and password login service device from user using primary user, server request is obtained and is verified
From the token of user;
S32, server find the user name from user according to the slave User Token after verifying, and obtain from server
Get the access authority from user to shared file.
The particular content of step S2 shared file setting is to include:
Server saves setting result into access control list ACL and User Control List UCL;
Access control list ACL includes listed files, and to the user list that listed files is assigned, user list is to file
The list of access rights of file in list, additional conditions list and user founder;
User Control List UCL includes user name and token.
The additional conditions list includes:Spatial geographical locations information, equipment identification information are sky, are indicated not to be empty
It limits.
User interface in step S2 specifically includes:
New user adds interface, and primary user adds the token of primary user in the interface, and addition prepares setting file access
Permission from user, and user name and token from user are set;
User file access authority set interface, primary user can be arranged from user in the interface to the access right of file
Limit, set content includes listed files, user list, list of access rights, additional conditions list and user founder.
It completes in step S2 to after the setting of the access authority of user, primary user can continue the addition of login service device
Other access authority, or the operation that the access authority is modified and deleted.
Prescribing a time limit from permission of the user to file for ownership in step S3 should can be other to specified file from user
User distributes permission again, carries out further extension authorization.
The present invention also provides a kind of authorization right discriminating systems of cloud file-sharing, specifically include:
File uploading unit, for uploading file to be sharing after primary user is using user name login service device;
Primary user's authorization unit, for after the completion of file uploads, primary user to add master in the user interface of server end
The token of user, user name and token from user, and be arranged from user to the access authority of the shared file of upload;
From subscription authentication unit, for completing in primary user to after the authorization of user, by the user name of primary user, password
It informs with from the token of user from user, is authenticated, specifically included from user login services device end:
Token authentication unit, for from user using primary user username and password login service device after, server
It requests, obtain and verify the token from user;
Authority acquiring unit, server find the user name from user according to the slave User Token after verifying, and from clothes
The access authority from user to shared file is got on business device.
Primary user's authorization unit specifically includes:
Accesses control list unit is saved in the access control list ACL of server, the access for result will to be arranged
Controlling list includes listed files, to the user list that listed files is assigned, visit of the user list to file in listed files
Ask permissions list, additional conditions list and user founder;
User Control List unit is saved in the User Control List UCL of server, the user for result will to be arranged
Controlling list includes user name and token.
User interface in primary user's authorization unit specifically includes:
New user adds interface, and primary user adds the token of primary user in the interface, and addition prepares setting file access
Permission from user, and user name and token from user are set;
The visit from user to file can be set in user file access authority set interface, primary user in the interface
Ask that permission, set content include listed files, user list, list of access rights, additional conditions list and user founder.
From prescribing a time limit from permission of the user to file for ownership in subscription authentication unit, being somebody's turn to do can be to specified text from user
Part is that other users distribute permission again, carries out further extension authorization.
The beneficial effect comprise that:The present invention provides a kind of authorization method for authenticating of cloud file-sharing, pass through
Different users is identified using token, makes non-administrative users that can also be directed to different use to the cloud shared file of upload
Access authority is arranged in family, and is identified by server end to from the token of user, and then authenticate to it;This method can
To prevent file from leaking, accidentally modify, and convenient and efficient, calculation amount is small, easy to accomplish.
Specific embodiment
In order to make the objectives, technical solutions, and advantages of the present invention clearer, with reference to the accompanying drawings and embodiments, right
The present invention is further elaborated.It should be appreciated that described herein, specific examples are only used to explain the present invention, not
For limiting the present invention.
As shown in Figure 1, the authorization method for authenticating of cloud file-sharing of the invention includes the following steps:
After S1, primary user are using user name UserName and token Token login service device, file to be sharing is uploaded.
Such as:Primary user utilizes the cloud account number of oneself(It is assumed to be " cug ")And password(It is assumed to be " 123456 ")Log in Cloud Server
(It is assumed to be Kingsoft cloud disk, Baidu's cloud disk, some in Ali's cloud disk)Afterwards, upper transmitting file(Assuming that file entitled F1, F2,
F3);After the completion of file uploads, one can be added automatically in server end and is recorded in access control list ACL, this is recorded as<
FList={ F1, F2, F3 }, UserName=Master, OWN, CList=NULL, ByWhom=NULL>;Then server will continue to
Automatic addition one is recorded in User Control List UCL, this is recorded as<UserName=Master,Token=Master>.
After the completion of S2, file upload, the user interface at primary user's login service device end.It should in one embodiment of the present of invention
User interface specifically may include:
New user adds interface, and primary user can be added with the token of primary user oneself in the interface and be prepared setting
File access permission from user, and user name UserName and token Token from user are set, for example,<UserName1,
Token1>,<UserName2,Token2>;
The visit from user to file can be set in user file access authority set interface, primary user in the interface
Ask that permission, set content include listed files, user list, list of access rights, additional conditions list and file creator.Add
Add the UserName and Token from user, is arranged from user to the access authority of the shared file of upload, for example,<F1,
UserName1,Modify,NULL,Master>,<F2,UserName1,Update,Null,Master>,<F3,
UserName2,Read,NULL,Master>;That is the ByWhom in 3 newly added records is primary user Master,
And CList is sky, i.e., without limitation.It completes in primary user to after the priority assignation of user, primary user can continue at this
The operation modified and deleted to access authority in the priority assignation page.
After accomplishing the setting up, server saves the result being arranged in interface into the ACL table and UCL table of server.Then it leads
User by the cloud account number of oneself, that is, and password, and inform from the corresponding Token of user from user, i.e., " cug ",
" 123456 ", " Token1 " inform that user 1, " cug ", " 123456 ", " Token2 " inform user 2.
Wherein, the listed files FList in ACL includes one or more file name F, and user list UList includes
One or more user's name UserName;List of access rights PList includes one or more access authority title P;It is attached
Adding condition list CList includes one or more additional conditions title C;In addition, the relationship between them is the use in UList
Family is to the cloud file name FList being assigned, in the case where additional conditions CList meets, cloud file access having the same
Authority name PList, file creator ByWhom;User Control List UCL includes user name UserName and token Token.
Additional conditions list CList includes:Spatial geographical locations information, equipment identification information, or be NULL, it indicates not
It limits.Equipment beacon information includes:From the terminal device MAC Address of user, from the IMSI of the terminal device of user, Yi Jicong
The IMEI of the terminal device of user.List of access rights PList is specifically included:Possess permission (OWN), renewal authority
(Update), modification authority (Modify), read right (READ).
S3, primary user complete to be authenticated, specifically included following from user login services device end to after the authorization of user
Step:
S31, after user login services device, server obtains and verifies the token Token from user;For example, user 2 exists
After the cloud account number and password login Cloud Server of primary user, server will inquire its Token;User 2 shows that its Token is
Token2。
S32, server find the user name UserName from user according to the slave User Token Token after verifying, and
The access authority from user to shared file is got from server.
Step S32 can be further specifically, server after learning the Token of currently logged on user, be learnt according to UCL
Its UserName, and ACL is accessed according to UserName and obtains its accessible FList, and is corresponding with FList
PList and CList;Such as in this example, server learns that its UserName is according to UCL after learning that its Token is Token2
Then UserName2 accesses ACL according to UserName2 and obtains<F3, UserName2, Read, NULL, Master>, it can
" reading " file F3.
If the corresponding certain file permissions of user name UserName obtained are OWN permission, the user name
UserName can carry out further extension Authorized operation to these files.
In another embodiment of the authorization method for authenticating of cloud file-sharing of the invention, authorized to from user
During, user file access authority set interface, including filename, user name, permission name, additional conditions name;For example,<
FList={ F1, F2 }, UserName1, OWN, NULL, Master>,<F3,UserName2,Read,NULL,Master>;It is exactly
Say that F1 and F2 are OWN permission for UserName1, UserName1 can continue to distribute the permission of file.
Then during to being authenticated from user, from user such as user 1 using primary user cloud account number and
After password login Cloud Server, server will inquire its Token;User 1 shows that its Token is Token1.Server is being learnt
After its Token is Token1, learns that its UserName is UserName1 according to UCL, ACL is then accessed according to UserName1 and is obtained
It arrives<FList={ F1, F2 }, UserName1, OWN, NULL, Master>, it can file F1 and F2 are continued to distribute permission.
If the corresponding P of certain F in the corresponding FList of the UserName is OWN permission, UserName can be to these F
Further extension Authorized operation is carried out, including:It adds new user UserName_Sub, save new record into ACL(New record
For new user UserName_Sub, to the access authority P of file F, and the ByWhom of new record is the UserName);Addition is new
User's name UserName_Sub and Token to UCL.
In the present embodiment, user 1 can be considered group leader, continue to distribute group member's progress Document Editing, such as UserName1 pairs
Add UserName_Sub1 and UserName_Sub2, to Token be Token_Sub1 and Token_Sub2, will<
UserName_Sub1,Token_Sub1>With<UserName_Sub2,Token_Sub2>Into UCL;The visit of two group members is set
Ask permission, such as:<F1,UserName_Sub1,Modify,NULL,UserName1>,<F2,UserName_Sub2,
Modify,NULL,UserName1>, it is added in ACL, it is seen that the ByWhom of this 2 records is UserName1.The two
Group member can modify respectively to file F1 and F2, but cannot update, and update is responsible for by group leader.
When CList is not sky, such as:<F3, UserName2, Read, CList={ Location=Nanjing }, Master
>, then only geographical location UserName2 at Nanjing could read (" Read ") file F3;<F3,UserName2,Read,
CList={ Location=Nanjing, MAC=AABBCCDD }, Master>, then only geographical location is at Nanjing, and use
When the MAC Address of equipment is " AABBCCDD ", UserName2 could read (" Read ") file F3.
As shown in Fig. 2, the authorization right discriminating system of the cloud file-sharing of the embodiment of the present invention is for realizing above-described embodiment
The authorization method for authenticating of cloud file-sharing, specifically includes:
File uploading unit 201, for uploading file to be sharing after primary user is using user name login service device;
Primary user's authorization unit 202 is used for after the completion of file uploads, the user interface at primary user's login service device end,
The user name and token from user are added, and is arranged from user to the access authority of the shared file of upload;
From subscription authentication unit 203, for completing in primary user to after the authorization of user, by the user name of primary user,
Password and from the token of user inform from user, authenticated, specifically included from user login services device end:
Token authentication unit, for from user using primary user username and password login service device after, server
It requests, obtain and verify the token from user;
Authority acquiring unit, server find the user name from user according to the slave User Token after verifying, and from clothes
The access authority from user to shared file is got on business device.
Primary user's authorization unit specifically includes:
Accesses control list unit is saved in the access control list ACL of server, the access for result will to be arranged
Controlling list includes listed files, to the user list that listed files is assigned, visit of the user list to file in listed files
Ask permissions list, additional conditions list and user founder;
User Control List unit is saved in the User Control List UCL of server, the user for result will to be arranged
Controlling list includes user name and token.
User interface in primary user's authorization unit specifically includes:
New user adds interface, and primary user adds the token of primary user in the interface, and addition prepares setting file access
Permission from user, and user name and token from user are set;
The visit from user to file can be set in user file access authority set interface, primary user in the interface
Ask that permission, set content include listed files, user list, list of access rights, additional conditions list and user founder.
From prescribing a time limit from permission of the user to file for ownership in subscription authentication unit, being somebody's turn to do can be to specified text from user
Part is that other users distribute permission again, carries out further extension authorization.
It should be understood that for those of ordinary skills, it can be modified or changed according to the above description,
And all these modifications and variations should all belong to the protection domain of appended claims of the present invention.