CN110096854A - Access authorization for resource sharing method, device and readable storage medium storing program for executing - Google Patents

Access authorization for resource sharing method, device and readable storage medium storing program for executing Download PDF

Info

Publication number
CN110096854A
CN110096854A CN201910229079.8A CN201910229079A CN110096854A CN 110096854 A CN110096854 A CN 110096854A CN 201910229079 A CN201910229079 A CN 201910229079A CN 110096854 A CN110096854 A CN 110096854A
Authority
CN
China
Prior art keywords
identity information
resource
user identity
access authorization
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201910229079.8A
Other languages
Chinese (zh)
Other versions
CN110096854B (en
Inventor
刘瑶
李璐
周新海
王艳辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Visionvera Information Technology Co Ltd
Original Assignee
Visionvera Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Visionvera Information Technology Co Ltd filed Critical Visionvera Information Technology Co Ltd
Priority to CN201910229079.8A priority Critical patent/CN110096854B/en
Publication of CN110096854A publication Critical patent/CN110096854A/en
Application granted granted Critical
Publication of CN110096854B publication Critical patent/CN110096854B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Storage Device Security (AREA)

Abstract

The embodiment of the invention provides a kind of access authorization for resource sharing method, device and readable storage medium storing program for executing.Access authorization for resource sharing method of the present invention: including: the first user identity information for receiving the access authorization for resource to be shared selected by access authorization for resource administration interface, it receives and is instructed by the sharing that access authorization for resource administration interface inputs, share instruction instruction to share the corresponding access authorization for resource of the first user identity information depending on networked server, it is instructed according to sharing, show the same level user identity information of the first user identity information, subordinate subscriber identification information and higher level's user identity information, from the same level user identity information, second user identification information is determined in subordinate subscriber identification information and higher level's user identity information, and the corresponding access authorization for resource of the first user identity information is shared with the corresponding second user of second user identification information.To solve the problems, such as to need to be followed successively by single user in the prior art and distribute to expend more time and efforts caused by permission.

Description

Access authorization for resource sharing method, device and readable storage medium storing program for executing
Technical field
The present invention relates to the communications fields, more particularly to access authorization for resource sharing method, device and readable storage medium storing program for executing.
Background technique
It is the important milestone of network Development depending on networking, is the more advanced form of internet, is a real-time network, it can It realizes the whole network HD video real-time Transmission that current internet cannot achieve, pushes numerous Internet applications to HD video, High definition is face-to-face.
Depending on networked monitoring and managing system access resource, when user checks, it is shown according to user right.Each user It needs to distribute corresponding authority, could rationally show catalogue and resource.When user volume is larger, there are the users of repetition permission, need It to be sequentially allocated permission for single user, therefore expends more time and efforts.
Summary of the invention
In view of the above problems, it proposes the embodiment of the present invention and overcomes the above problem or at least partly in order to provide one kind A kind of access authorization for resource sharing method, device and the readable storage medium storing program for executing to solve the above problems.
To solve the above-mentioned problems, the embodiment of the invention discloses a kind of access authorization for resource sharing methods, comprising:
Receive the first user identity information of the access authorization for resource to be shared selected by access authorization for resource administration interface;
It receives and is instructed by the sharing that the access authorization for resource administration interface inputs, the sharing instruction instruction view the Internet services Device shares the corresponding access authorization for resource of first user identity information;
It is instructed according to the sharing, shows the same level user identity information, the subordinate subscriber of first user identity information Identification information and higher level's user identity information;
Second is determined from the same level user identity information, subordinate subscriber identification information and higher level's user identity information User identity information, and the corresponding access authorization for resource of first user identity information is shared with the second user identification information Corresponding second user.
The embodiment of the invention also discloses a kind of access authorization for resource sharing apparatus, described device is applied in view networking, comprising:
Receiving module, the first user for receiving the access authorization for resource to be shared selected by access authorization for resource administration interface mark Know information;
The receiving module is also used to reception and is instructed by the sharing that the access authorization for resource administration interface inputs, and described point Instruction instruction is enjoyed to share the corresponding access authorization for resource of first user identity information depending on networked server;
Display module shows the same level user identifier of first user identity information for instructing according to the sharing Information, subordinate subscriber identification information and higher level's user identity information;
Processing module is used for from the same level user identity information, subordinate subscriber identification information and higher level's user identifier Second user identification information is determined in information, and the corresponding access authorization for resource of first user identity information is shared with described the The corresponding second user of two user identity informations.
The embodiment of the invention also discloses a kind of computer readable storage medium, deposited on the computer readable storage medium Computer program is stored up, the computer program realizes access authorization for resource sharing method described above when being executed by processor.
The embodiment of the invention also discloses a kind of access authorization for resource sharing apparatus, including processor, memory and it is stored in institute The computer program that can be run on memory and on the processor is stated, when the computer program is executed by the processor Realize access authorization for resource sharing method described above.
The embodiment of the present invention includes following advantages:
During the present invention is implemented, used by receive the access authorization for resource to be shared selected by access authorization for resource administration interface first Family identification information is received and is instructed by the sharing that access authorization for resource administration interface inputs, and sharing instruction instruction view networked server will The corresponding access authorization for resource of first user identity information is shared, and instructs according to sharing, and shows the sheet of the first user identity information Grade user identity information, subordinate subscriber identification information and higher level's user identity information are used from the same level user identity information, junior Second user identification information is determined in family identification information and higher level's user identity information, and the first user identity information is corresponding Access authorization for resource be shared with the corresponding second user of second user identification information.To solve to need to be followed successively by list in the prior art A user distributes the problem of expending more time and efforts caused by permission.
The above description is only an overview of the technical scheme of the present invention, in order to better understand the technical means of the present invention, And it can be implemented in accordance with the contents of the specification, and in order to allow above and other objects of the present invention, feature and advantage can It is clearer and more comprehensible, the followings are specific embodiments of the present invention.
Detailed description of the invention
By reading the following detailed description of the preferred embodiment, various other advantages and benefits are common for this field Technical staff will become clear.The drawings are only for the purpose of illustrating a preferred embodiment, and is not considered as to the present invention Limitation.And throughout the drawings, the same reference numbers will be used to refer to the same parts.In the accompanying drawings:
Fig. 1 is a kind of networking schematic diagram of view networking of the invention;
Fig. 2 is a kind of hardware structural diagram of node server of the invention;
Fig. 3 is a kind of hardware structural diagram of access switch of the invention;
Fig. 4 is the hardware structural diagram that a kind of Ethernet association of the invention turns gateway;
Fig. 5 is a kind of step flow chart of access authorization for resource sharing method provided in an embodiment of the present invention;
Fig. 6 is a kind of structural schematic diagram of access authorization for resource sharing apparatus provided in an embodiment of the present invention;
Fig. 7 is the structural schematic diagram of another kind access authorization for resource sharing apparatus provided by the embodiment of the present invention.
Specific embodiment
In order to make the foregoing objectives, features and advantages of the present invention clearer and more comprehensible, with reference to the accompanying drawing and specific real Applying mode, the present invention is described in further detail.
It should be appreciated that described herein, specific examples are only used to explain the present invention, and only present invention a part is real Example is applied, instead of all the embodiments, is not intended to limit the present invention.
It is the important milestone of network Development depending on networking, is a real-time network, can be realized HD video real-time Transmission, Push numerous Internet applications to HD video, high definition is face-to-face.
Real-time high-definition video switching technology is used depending on networking, it can be such as high in a network platform by required service Clear video conference, Intellectualized monitoring analysis, emergency command, digital broadcast television, delay TV, the Web-based instruction, shows video monitoring Field live streaming, VOD program request, TV Mail, individual character records (PVR), Intranet (manages) channel by oneself, intelligent video Broadcast Control, information publication All be incorporated into a system platform etc. services such as tens of kinds of videos, voice, picture, text, communication, data, by TV or Computer realizes that high-definition quality video plays.
Embodiment in order to enable those skilled in the art to better understand the present invention is introduced to depending on networking below:
Depending on networking, applied portion of techniques is as described below:
Network technology (Network Technology)
Traditional ethernet (Ethernet) is improved depending on the network technology innovation networked, with potential huge on network Video flow.(Circuit is exchanged different from simple network packet packet switch (Packet Switching) or lattice network Switching), Streaming demand is met using Packet Switching depending on networking technology.Has grouping depending on networking technology Flexible, the simple and low price of exchange, is provided simultaneously with the quality and safety assurance of circuit switching, it is virtually electric to realize the whole network switch type The seamless connection of road and data format.
Switching technology (Switching Technology)
Two advantages of asynchronous and packet switch that Ethernet is used depending on networking eliminate Ethernet under the premise of complete compatible and lack It falls into, has the end-to-end seamless connection of the whole network, direct user terminal, directly carrying IP data packet.User data is in network-wide basis It is not required to any format conversion.It is the more advanced form of Ethernet depending on networking, is a real-time exchange platform, can be realized at present mutually The whole network large-scale high-definition realtime video transmission that networking cannot achieve pushes numerous network video applications to high Qinghua, unitizes.
Server technology (Server Technology)
It is different from traditional server, its Streaming Media depending on the server technology in networking and unified video platform Transmission be built upon it is connection-oriented on the basis of, data-handling capacity is unrelated with flow, communication time, single network layer energy Enough transmitted comprising signaling and data.For voice and video business, handled depending on networking and unified video platform Streaming Media Complexity many simpler than data processing, efficiency substantially increase hundred times or more than traditional server.
Reservoir technology (Storage Technology)
The ultrahigh speed reservoir technology of unified video platform in order to adapt to the media content of vast capacity and super-flow and Using state-of-the-art real time operating system, the programme information in server instruction is mapped to specific hard drive space, media Content is no longer pass through server, and moment is directly delivered to user terminal, and user waits typical time less than 0.2 second.It optimizes Sector distribution greatly reduces the mechanical movement of hard disc magnetic head tracking, and resource consumption only accounts for the 20% of the internet ad eundem IP, but The concurrent flow greater than 3 times of traditional disk array is generated, overall efficiency promotes 10 times or more.
Network security technology (Network Security Technology)
Depending on the structural design networked by servicing independent licence system, equipment and the modes such as user data is completely isolated every time The network security problem that puzzlement internet has thoroughly been eradicated from structure, does not need antivirus applet, firewall generally, has prevented black The attack of visitor and virus, structural carefree secure network is provided for user.
It services innovative technology (Service Innovation Technology)
Business and transmission are fused together by unified video platform, whether single user, private user or a net The sum total of network is all only primary automatic connection.User terminal, set-top box or PC are attached directly to unified video platform, obtain rich The multimedia video service of rich colorful various forms.Unified video platform is traditional to substitute with table schema using " menu type " Complicated applications programming, considerably less code, which can be used, can be realized complicated application, realize the new business innovation of " endless ".
Networking depending on networking is as described below:
It is a kind of central controlled network structure depending on networking, which can be Tree Network, Star network, ring network etc. class Type, but centralized control node is needed to control whole network in network on this basis.
As shown in Figure 1, being divided into access net and Metropolitan Area Network (MAN) two parts depending on networking.
The equipment of access mesh portions can be mainly divided into 3 classes: node server, access switch, terminal (including various machines Top box, encoding board, memory etc.).Node server is connected with access switch, and access switch can be with multiple terminal phases Even, and it can connect Ethernet.
Wherein, node server is the node that centralized control functions are played in access net, can control access switch and terminal. Node server can directly be connected with access switch, can also directly be connected with terminal.
Similar, the equipment of metropolitan area mesh portions can also be divided into 3 classes: metropolitan area server, node switch, node serve Device.Metropolitan area server is connected with node switch, and node switch can be connected with multiple node servers.
Wherein, node server is the node server for accessing mesh portions, i.e. node server had both belonged to access wet end Point, and belong to metropolitan area mesh portions.
Metropolitan area server is the node that centralized control functions are played in Metropolitan Area Network (MAN), can control node switch and node serve Device.Metropolitan area server can be directly connected to node switch, can also be directly connected to node server.
It can be seen that be entirely a kind of central controlled network structure of layering depending on networking network, and node server and metropolitan area The network controlled under server can be the various structures such as tree-shaped, star-like, cyclic annular.
Visually claim, access mesh portions can form unified video platform (part in virtual coil), and multiple unified videos are flat Platform can form view networking;Each unified video platform can be interconnected by metropolitan area and wide area depending on networking.
Classify depending on networked devices
1.1 embodiment of the present invention can be mainly divided into 3 classes: server depending on the equipment in networking, interchanger (including ether Net gateway), terminal (including various set-top boxes, encoding board, memory etc.).Depending on networking can be divided on the whole Metropolitan Area Network (MAN) (or National net, World Wide Web etc.) and access net.
1.2 equipment for wherein accessing mesh portions can be mainly divided into 3 classes: node server, access switch (including ether Net gateway), terminal (including various set-top boxes, encoding board, memory etc.).
The specific hardware structure of each access network equipment are as follows:
Node server:
As shown in Fig. 2, mainly including Network Interface Module 201, switching engine module 202, CPU module 203, disk array Module 204;
Wherein, Network Interface Module 201, the Bao Jun that CPU module 203, disk array module 204 are come in enter switching engine Module 202;Switching engine module 202 look into the operation of address table 205 to the packet come in, to obtain the navigation information of packet; And the packet is stored according to the navigation information of packet the queue of corresponding pack buffer 206;If the queue of pack buffer 206 is close It is full, then it abandons;All pack buffer queues of 202 poll of switching engine mould, are forwarded: 1) port if meeting the following conditions It is less than to send caching;2) the queue package counting facility is greater than zero.Disk array module 204 mainly realizes the control to hard disk, including The operation such as initialization, read-write to hard disk;CPU module 203 is mainly responsible between access switch, terminal (not shown) Protocol processes, to address table 205 (including descending protocol packet address table, uplink protocol package address table, data packet addressed table) Configuration, and, the configuration to disk array module 204.
Access switch:
As shown in figure 3, mainly including Network Interface Module (downstream network interface module 301, uplink network interface module 302), switching engine module 303 and CPU module 304;
Wherein, the packet (upstream data) that downstream network interface module 301 is come in enters packet detection module 305;Packet detection mould Whether mesh way address (DA), source address (SA), type of data packet and the packet length of the detection packet of block 305 meet the requirements, if met, It then distributes corresponding flow identifier (stream-id), and enters switching engine module 303, otherwise abandon;Uplink network interface mould The packet (downlink data) that block 302 is come in enters switching engine module 303;The data packet that CPU module 204 is come in enters switching engine Module 303;Switching engine module 303 look into the operation of address table 306 to the packet come in, to obtain the navigation information of packet; If the packet into switching engine module 303 is that downstream network interface is gone toward uplink network interface, in conjunction with flow identifier (stream-id) packet is stored in the queue of corresponding pack buffer 307;If the queue of the pack buffer 307 is close full, It abandons;If the packet into switching engine module 303 is not that downstream network interface is gone toward uplink network interface, according to packet Navigation information is stored in the data packet queue of corresponding pack buffer 307;If the queue of the pack buffer 307 is close full, Then abandon.
All pack buffer queues of 303 poll of switching engine module, are divided to two kinds of situations in embodiments of the present invention:
If the queue is that downstream network interface is gone toward uplink network interface, meets the following conditions and be forwarded: 1) It is less than that the port sends caching;2) the queue package counting facility is greater than zero;3) token that rate control module generates is obtained;
If the queue is not that downstream network interface is gone toward uplink network interface, meets the following conditions and is forwarded: 1) it is less than to send caching for the port;2) the queue package counting facility is greater than zero.
Rate control module 208 is configured by CPU module 204, to all downlink networks in programmable interval Interface generates token toward the pack buffer queue that uplink network interface is gone, to control the code rate of forwarded upstream.
CPU module 304 is mainly responsible for the protocol processes between node server, the configuration to address table 306, and, Configuration to rate control module 308.
Ethernet association turns gateway:
As shown in figure 4, mainly including Network Interface Module (downstream network interface module 401, uplink network interface module 402), switching engine module 403, CPU module 404, packet detection module 405, rate control module 408, address table 406, Bao Huan Storage 407 and MAC adding module 409, MAC removing module 410.
Wherein, the data packet that downstream network interface module 401 is come in enters packet detection module 405;Packet detection module 405 is examined Ethernet mac DA, ethernet mac SA, Ethernet length or frame type, the view networking mesh way address of measured data packet DA, whether meet the requirements depending on networking source address SA, depending on networking data Packet type and packet length, corresponding stream is distributed if meeting Identifier (stream-id);Then, MAC DA, MAC SA, length or frame type are subtracted by MAC removing module 410 (2byte), and enter corresponding receive and cache, otherwise abandon;
Downstream network interface module 401 detects the transmission caching of the port, according to the view of packet networking mesh if there is Bao Ze Address D A knows the ethernet mac DA of corresponding terminal, adds the ethernet mac DA of terminal, Ethernet assists the MAC for turning gateway SA, Ethernet length or frame type, and send.
The function that Ethernet association turns other modules in gateway is similar with access switch.
Terminal:
It mainly include Network Interface Module, Service Processing Module and CPU module;For example, set-top box mainly connects including network Mouth mold block, video/audio encoding and decoding engine modules, CPU module;Encoding board mainly includes Network Interface Module, video encoding engine Module, CPU module;Memory mainly includes Network Interface Module, CPU module and disk array module.
The equipment of 1.3 metropolitan area mesh portions can be mainly divided into 2 classes: node server, node switch, metropolitan area server. Wherein, node switch mainly includes Network Interface Module, switching engine module and CPU module;Metropolitan area server mainly includes Network Interface Module, switching engine module and CPU module are constituted.
2, networking data package definition is regarded
2.1 access network data package definitions
Access net data packet mainly include following sections: destination address (DA), source address (SA), reserve bytes, payload(PDU)、CRC。
As shown in the table, the data packet for accessing net mainly includes following sections:
DA SA Reserved Payload CRC
Wherein:
Destination address (DA) is made of 8 bytes (byte), and first character section indicates type (such as the various associations of data packet Discuss packet, multicast packet, unicast packet etc.), be up to 256 kinds of possibility, the second byte to the 6th byte is metropolitan area net address, Seven, the 8th bytes are access net address;
Source address (SA) is also to be made of 8 bytes (byte), is defined identical as destination address (DA);
Reserve bytes are made of 2 bytes;
The part payload has different length according to the type of different datagrams, is if it is various protocol packages 64 bytes are 32+1024=1056 bytes if it is single group unicast packets words, are not restricted to above 2 kinds certainly;
CRC is made of 4 bytes, and calculation method follows the Ethernet CRC algorithm of standard.
2.2 Metropolitan Area Network (MAN) packet definitions
The topology of Metropolitan Area Network (MAN) is pattern, may there is 2 kinds, connection even of more than two kinds, i.e. node switching between two equipment It can all can exceed that 2 kinds between machine and node server, node switch and node switch, node switch and node server Connection.But the metropolitan area net address of metropolitan area network equipment is uniquely, to close to accurately describe the connection between metropolitan area network equipment System, introduces parameter in embodiments of the present invention: label, uniquely to describe a metropolitan area network equipment.
(Multi-Protocol Label Switch, multiprotocol label are handed over by the definition of label and MPLS in this specification Change) label definition it is similar, it is assumed that between equipment A and equipment B there are two connection, then data packet from equipment A to equipment B just There are 2 labels, data packet also there are 2 labels from equipment B to equipment A.Label is divided into label, outgoing label, it is assumed that data packet enters The label (entering label) of equipment A is 0x0000, and the label (outgoing label) when this data packet leaves equipment A may reform into 0x0001.The networking process of Metropolitan Area Network (MAN) is to enter network process under centralized control, also means that address distribution, the label of Metropolitan Area Network (MAN) Distribution be all to be dominated by metropolitan area server, node switch, node server be all passively execute, this point with The label distribution of MPLS is different, and the distribution of the label of MPLS is the result that interchanger, server are negotiated mutually.
As shown in the table, the data packet of Metropolitan Area Network (MAN) mainly includes following sections:
DA SA Reserved Label Payload CRC
That is destination address (DA), source address (SA), reserve bytes (Reserved), label, payload (PDU), CRC.Its In, the format of label, which can refer to, such as gives a definition: label is 32bit, wherein high 16bit retains, only with low 16bit, its position Set is between the reserve bytes and payload of data packet.
Based on the above-mentioned characteristic of view networking, one of the core concepts of the embodiments of the present invention is proposed, it then follows regard the association of networking View, receives the first user identity information of the access authorization for resource to be shared selected by access authorization for resource administration interface, and reception passes through institute The sharing instruction for stating the input of access authorization for resource administration interface, instructs according to the sharing, shows first user identity information The same level user identity information, subordinate subscriber identification information and higher level's user identity information, from the same level user identity information, Second user identification information is determined in subordinate subscriber identification information and higher level's user identity information, and first user is marked Know the corresponding access authorization for resource of information and is shared with the corresponding second user of the second user identification information.To solve the prior art It is middle to need to be followed successively by the problem of expending more time and efforts caused by single user's distribution permission.
It is a kind of step flow chart of access authorization for resource sharing method provided in an embodiment of the present invention, this reality referring to Fig. 5, Fig. 5 The access authorization for resource sharing method for applying example is suitable for the case where sharing depending on networked server to access authorization for resource.The present embodiment provides Method can be executed by access authorization for resource sharing apparatus, which can be deployed in view networked server, this The method of embodiment includes the following steps:
First user identity information of the access authorization for resource to be shared that S510, reception are selected by access authorization for resource administration interface.
The user logged in depending on networked monitoring and managing system can select resource to be shared to weigh by access authorization for resource administration interface First user identity information of limit is deployed with the view networked monitoring and managing system after user selects the first user identity information First user identity information will be received depending on networked server.After service receives the first user identity information, it can incite somebody to action The corresponding access authorization for resource of first user identity information is shared with other users.Wherein, the first user identity information can be mark Unique identity (identification, abbreviation ID) of first user identity.
S520, the sharing instruction inputted by access authorization for resource administration interface is received, shares instruction instruction view networked server The corresponding access authorization for resource of first user identity information is shared.
After if user chooses the first user identity information, if it is determined that by the corresponding resource of the first user identity information Permission is shared with other users, then can be believed by clicking the sharing button on access authorization for resource administration interface the first user identifier It ceases corresponding access authorization for resource to be shared, the sharing that user is sent by clicking operation will be received depending on networked server at this time Instruction.
S530, it is instructed according to sharing, shows the same level user identity information, the subordinate subscriber mark of the first user identity information Information and higher level's user identity information.
S540, the is determined from the same level user identity information, subordinate subscriber identification information and higher level's user identity information Two user identity informations, and it is corresponding that the corresponding access authorization for resource of the first user identity information is shared with second user identification information Second user.
In S530 and S540, after receiving sharing instruction depending on networked server, the first use can be shown by display interface The same level user identity information, subordinate subscriber identification information and the higher level's user identity information of family identification information, to make user One is selected from the same level user identity information, subordinate subscriber identification information and higher level's user identity information by display interface Second user identification information, and the corresponding access authorization for resource of the first user identity information is shared with second user identification information and is corresponded to Second user.
It should be noted that determining that the same level user of the first user identity information marks according to regional code depending on networked server Know information, other view the Internet services that the same area coding is belonged to depending on networked server with the first user identity information of storage Device is all the same level view networked server for storing the view networked server of the first user identity information, storage the first user identifier letter Breath is view networked server belonging to the first user identity information depending on networked server, belonging to the first user identity information The same level depending on networked server belongs to the first user identity information depending on all user identity informations stored on networked server The same level user identity information and the first user identity information belonging to depending on being stored on networked server except the first user marks Know the same level user identity information that the other users identification information except information also belongs to the first user identity information.Such as north The regional code in capital is 11, and the first user identity information is stored on the view networked server that regional code is 11, then region All other for being encoded to 11 regard the user identity information stored on networked server all as the sheet of the first user identity information Depending on being stored on networked server except the first user identifier is believed belonging to grade user identity information and the first user identity information Other users identification information except breath is also all the same level user identity information of the first user identity information.It equally can be according to Regional code determines the subordinate subscriber identification information and higher level's user identity information of the first user identity information, and by determining The same level user identity information, subordinate subscriber identification information and the higher level's user identity information of one user identity information.
By S510 to S540, consuming caused by needing to be followed successively by single user's distribution permission in the prior art can solve The problem of more time and efforts, when especially encountering interim demonstration or inspection, needs to use for the demonstration of not access authorization for resource Access authorization for resource is redistributed at family, and is redistributed access authorization for resource at this time and compared the consuming time.
Access authorization for resource sharing method provided in this embodiment, by receive by access authorization for resource administration interface select wait divide The first user identity information of access authorization for resource is enjoyed, receives and is instructed by the sharing that access authorization for resource administration interface inputs, share instruction Instruction shares the corresponding access authorization for resource of the first user identity information depending on networked server, instructs according to sharing, and shows the The same level user identity information, subordinate subscriber identification information and the higher level's user identity information of one user identity information, from the same level Second user identification information is determined in user identity information, subordinate subscriber identification information and higher level's user identity information, and will The corresponding access authorization for resource of first user identity information is shared with the corresponding second user of second user identification information.It is existing to solve There is the problem of expending more time and efforts caused by needing to be followed successively by single user's distribution permission in technology.
Optionally, the corresponding access authorization for resource of the first user identity information is shared with second user identification information corresponding Two users can be achieved by the steps of:
It is the by access authorization for resource administration interface if distributing corresponding access authorization for resource for the first user identity information One user identity information distributes corresponding access authorization for resource and saves as the corresponding access authorization for resource of the first user identity information distribution; The corresponding access authorization for resource distributed for the first user identity information is shared with the corresponding second user of second user identification information.
It should be noted that needing first when the first user identity information does not have corresponding access authorization for resource for the first user Identification information distributes corresponding access authorization for resource, can be by opening access authorization for resource administration interface as the distribution of the first user identity information Corresponding access authorization for resource, user can be by the permission catalogues that select access authorization for resource administration interface to show come for the first user identifier Information distributes access authorization for resource, will be the resource of user's selection after the access authorization for resource that user's selection is received depending on networked server Permission is as the corresponding access authorization for resource of the first user identity information and saves the access authorization for resource, and will be the first user identity information The corresponding access authorization for resource of distribution is shared with the corresponding second user of second user identification information.Wherein, it will be marked for the first user After knowing the corresponding access authorization for resource preservation of information distribution, convenient for needing the corresponding resource power of the first user identity information again later When limit is shared with other users, can directly it be shared, without distributing corresponding resource again for the first user identity information Permission, so as to further increase the sharing efficiency of access authorization for resource.
Optionally, the corresponding access authorization for resource of the first user identity information is shared with second user identification information corresponding Two users can be achieved by the steps of:
If being that the first user identity information distributes corresponding access authorization for resource, will be distributed for the first user identity information Corresponding access authorization for resource be shared with the corresponding second user of second user identification information.
It should be noted that if the first user identity information is corresponding access authorization for resource, when needing the first user identifier When the corresponding access authorization for resource of information is shared, then other users can be directly shared with, solve to distribute again for other users It is wasted time caused by access authorization for resource and the problem of energy.
Optionally, the first user of the access authorization for resource to be shared that S510, reception are selected by access authorization for resource administration interface marks Knowing information can be accomplished in that
Show that the same level for logging in the user identity information of view networked monitoring and managing system is used by access authorization for resource administration interface Family identification information and subordinate subscriber identification information;The user identity information of networked monitoring and managing system is regarded from the login of display The first user identity information is selected in the same level user identity information and subordinate subscriber identification information;Receive providing wait share for selection First user identity information of source permission.
It should be noted that view networked monitoring and managing system deployment logs in view networked monitoring and managing in view networked server The user identity information of system is stored in view networked server, when user logs on to view networking monitoring using the user identity information After management system, the same level user identity information of the user identity information is determined according to regional code depending on networked server, also To say, with store the user identity information view networked server belong to the same area coding other regard networked servers all Networked server is regarded to store the same level of the view networked server of the user identity information, stores the view connection of the user identity information Network server is view networked server belonging to the user identity information, view networked server belonging to the user identity information The same level the same level user identifier of the user identity information is belonged to depending on all user identity informations stored on networked server The use is also belonged to depending on the other users identification information stored on networked server belonging to information and the user identity information The same level user identity information of family identification information.It is also possible to determine that the junior of the user identity information uses according to regional code Family identification information.The same level user identifier so as to the user identity information for showing that user from access authorization for resource administration interface The first user identity information is selected in information and subordinate subscriber identification information, passes through user to make to receive depending on networked server The first user identity information selected from access authorization for resource administration interface.
Fig. 6 is a kind of structural schematic diagram of access authorization for resource sharing apparatus provided in an embodiment of the present invention, the money of the present embodiment Source permission sharing apparatus is suitable for the case where sharing depending on networked server to access authorization for resource.The access authorization for resource sharing apparatus is logical Often realized in a manner of hardware and/or software.The access authorization for resource sharing apparatus 600 includes following module: receiving module 610, Display module 620 and processing module 630.
Receiving module 610 is used to receive the first user of the access authorization for resource to be shared selected by access authorization for resource administration interface Identification information;Receiving module 610 is also used to receive to be instructed by the sharing that access authorization for resource administration interface inputs, and shares instruction instruction The corresponding access authorization for resource of the first user identity information is shared depending on networked server;Display module 620 is used for according to sharing Instruction shows the same level user identity information, subordinate subscriber identification information and the higher level's user identifier of the first user identity information Information;Processing module 630 is used for from the same level user identity information, subordinate subscriber identification information and higher level's user identity information It determines second user identification information, and the corresponding access authorization for resource of the first user identity information is shared with second user identification information Corresponding second user.
Access authorization for resource sharing apparatus provided in this embodiment, by receive by access authorization for resource administration interface select wait divide The first user identity information of access authorization for resource is enjoyed, receives and is instructed by the sharing that access authorization for resource administration interface inputs, share instruction Instruction shares the corresponding access authorization for resource of the first user identity information depending on networked server, instructs according to sharing, and shows the The same level user identity information, subordinate subscriber identification information and the higher level's user identity information of one user identity information, from the same level Second user identification information is determined in user identity information, subordinate subscriber identification information and higher level's user identity information, and will The corresponding access authorization for resource of first user identity information is shared with the corresponding second user of second user identification information.It is existing to solve There is the problem of expending more time and efforts caused by needing to be followed successively by single user's distribution permission in technology.
Optionally, if processing module 630 is specifically used for not distributing corresponding access authorization for resource for the first user identity information, It is then the corresponding access authorization for resource of the first user identity information distribution by access authorization for resource administration interface and saves as the first user mark Know the corresponding access authorization for resource of information distribution;The corresponding access authorization for resource distributed for the first user identity information is shared with second The corresponding second user of user identity information.
Optionally, if processing module 630 is specifically used for being that the first user identity information distributes corresponding access authorization for resource, The corresponding access authorization for resource distributed for the first user identity information is then shared with second user identification information corresponding second to use Family.
Optionally, receiving module 610 is specifically used for logging in view networked monitoring and managing by the display of access authorization for resource administration interface The same level user identity information and subordinate subscriber identification information of the user identity information of system;Networking prison is regarded from the login of display It controls in the same level user identity information and subordinate subscriber identification information of the user identity information of management system and selects the first user Identification information;Receive the first user identity information of the access authorization for resource to be shared of selection.
In addition, the embodiment of the present invention also provides a kind of access authorization for resource sharing apparatus, as shown in fig. 7, Fig. 7 is that the present invention is implemented The structural schematic diagram of another kind access authorization for resource sharing apparatus provided by example.The access authorization for resource sharing apparatus 700 includes processor 710, memory 720 and it is stored in the computer program that can be run on memory 720 and on the processor 710, the computer Program realizes each process of the access authorization for resource sharing method embodiment of above-described embodiment when being executed by processor 710, and can reach To identical technical effect, to avoid repeating, which is not described herein again.
The embodiment of the present invention also provides a kind of computer readable storage medium, and meter is stored on computer readable storage medium Calculation machine program, the computer program realize each mistake of above-mentioned access authorization for resource sharing method embodiment when being executed by processor Journey, and identical technical effect can be reached, to avoid repeating, which is not described herein again.Wherein, computer readable storage medium, It can be read-only memory (Read-Only Memory, abbreviation ROM), random access memory (Random Access Memory, abbreviation RAM), magnetic or disk etc..
For product embodiments, since it applies the technical solution of above-mentioned apparatus embodiment, so description ground ratio Relatively simple, correlation is pointed out to illustrate referring to the part of Installation practice.
All the embodiments in this specification are described in a progressive manner, the highlights of each of the examples are with The difference of other embodiments, the same or similar parts between the embodiments can be referred to each other.
It should be understood by those skilled in the art that, the embodiment of the embodiment of the present invention can provide as method, apparatus or calculate Machine program product.Therefore, the embodiment of the present invention can be used complete hardware embodiment, complete software embodiment or combine software and The form of the embodiment of hardware aspect.Moreover, the embodiment of the present invention can be used one or more wherein include computer can With in the computer-usable storage medium (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.) of program code The form of the computer program product of implementation.
The embodiment of the present invention be referring to according to the method for the embodiment of the present invention, terminal device (system) and computer program The flowchart and/or the block diagram of product describes.It should be understood that flowchart and/or the block diagram can be realized by computer program instructions In each flow and/or block and flowchart and/or the block diagram in process and/or box combination.It can provide these Computer program instructions are set to general purpose computer, special purpose computer, Embedded Processor or other programmable data processing terminals Standby processor is to generate a machine, so that being held by the processor of computer or other programmable data processing terminal devices Capable instruction generates for realizing in one or more flows of the flowchart and/or one or more blocks of the block diagram The device of specified function.
These computer program instructions, which may also be stored in, is able to guide computer or other programmable data processing terminal devices In computer-readable memory operate in a specific manner, so that instruction stored in the computer readable memory generates packet The manufacture of command device is included, which realizes in one side of one or more flows of the flowchart and/or block diagram The function of being specified in frame or multiple boxes.
These computer program instructions can also be loaded into computer or other programmable data processing terminal devices, so that Series of operation steps are executed on computer or other programmable terminal equipments to generate computer implemented processing, thus The instruction executed on computer or other programmable terminal equipments is provided for realizing in one or more flows of the flowchart And/or in one or more blocks of the block diagram specify function the step of.
Although the preferred embodiment of the embodiment of the present invention has been described, once a person skilled in the art knows bases This creative concept, then additional changes and modifications can be made to these embodiments.So the following claims are intended to be interpreted as Including preferred embodiment and fall into all change and modification of range of embodiment of the invention.
Finally, it is to be noted that, herein, relational terms such as first and second and the like be used merely to by One entity or operation are distinguished with another entity or operation, without necessarily requiring or implying these entities or operation Between there are any actual relationship or orders.Moreover, the terms "include", "comprise" or its any other variant meaning Covering non-exclusive inclusion, so that process, method, article or terminal device including a series of elements not only wrap Those elements are included, but also including other elements that are not explicitly listed, or further includes for this process, method, article Or the element that terminal device is intrinsic.In the absence of more restrictions, being wanted by what sentence "including a ..." limited Element, it is not excluded that there is also other identical elements in process, method, article or the terminal device for including element.
Above to a kind of access authorization for resource sharing method provided by the present invention and a kind of access authorization for resource sharing apparatus, carry out It is discussed in detail, used herein a specific example illustrates the principle and implementation of the invention, above embodiments Illustrate to be merely used to help understand method and its core concept of the invention;At the same time, for those skilled in the art, according to According to thought of the invention, there will be changes in the specific implementation manner and application range, and to sum up, the content of the present specification is not answered It is interpreted as limitation of the present invention.

Claims (10)

1. a kind of access authorization for resource sharing method, which is characterized in that the method is applied in view networking, comprising:
Receive the first user identity information of the access authorization for resource to be shared selected by access authorization for resource administration interface;
It receives and is instructed by the sharing that the access authorization for resource administration interface inputs, the sharing instruction instruction view networked server will The corresponding access authorization for resource of first user identity information is shared;
It is instructed according to the sharing, shows the same level user identity information, the subordinate subscriber mark of first user identity information Information and higher level's user identity information;
Second user is determined from the same level user identity information, subordinate subscriber identification information and higher level's user identity information Identification information, and the corresponding access authorization for resource of first user identity information is shared with the second user identification information and is corresponded to Second user.
2. the method according to claim 1, wherein described by the corresponding resource of first user identity information Permission is shared with the corresponding second user of the second user identification information, comprising:
If not distributing corresponding access authorization for resource for first user identity information, pass through the access authorization for resource administration interface Corresponding access authorization for resource is distributed for first user identity information and saves as pair of the first user identity information distribution The access authorization for resource answered;
The corresponding access authorization for resource distributed for first user identity information is shared with the second user identification information pair The second user answered.
3. the method according to claim 1, wherein described by the corresponding resource of first user identity information Permission is shared with the corresponding second user of the second user identification information, comprising:
It will be first user identity information if being that first user identity information distributes corresponding access authorization for resource The corresponding access authorization for resource of distribution is shared with the corresponding second user of the second user identification information.
4. according to the method in any one of claims 1 to 3, which is characterized in that described receive passes through access authorization for resource management First user identity information of the access authorization for resource to be shared of interface selection, comprising:
Show that the same level for logging in the user identity information of view networked monitoring and managing system is used by the access authorization for resource administration interface Family identification information and subordinate subscriber identification information;
From display login it is described view networked monitoring and managing system user identity information the same level user identity information with And first user identity information is selected in subordinate subscriber identification information;
Receive the first user identity information of the access authorization for resource to be shared of selection.
5. a kind of access authorization for resource sharing apparatus, which is characterized in that described device is applied in view networking, comprising:
Receiving module, the first user identifier for receiving the access authorization for resource to be shared selected by access authorization for resource administration interface are believed Breath;
The receiving module, is also used to receive the sharing instruction inputted by the access authorization for resource administration interface, and the sharing refers to Instruction is enabled to share the corresponding access authorization for resource of first user identity information depending on networked server;
Display module, for being instructed according to the sharing, the same level user identity information of display first user identity information, Subordinate subscriber identification information and higher level's user identity information;
Processing module is used for from the same level user identity information, subordinate subscriber identification information and higher level's user identity information Middle determining second user identification information, and the corresponding access authorization for resource of first user identity information is shared with described second and is used The corresponding second user of family identification information.
6. device according to claim 5, which is characterized in that the processing module, if being specifically used for is not described the One user identity information distributes corresponding access authorization for resource, then is first user identifier by the access authorization for resource administration interface Information distributes corresponding access authorization for resource and saves as the corresponding access authorization for resource of the first user identity information distribution;Will for institute The corresponding access authorization for resource for stating the distribution of the first user identity information is shared with the second user identification information corresponding second and uses Family.
7. device according to claim 5, which is characterized in that the processing module, if being specifically used for has been described the One user identity information distributes corresponding access authorization for resource, then weighs the corresponding resource distributed for first user identity information Limit is shared with the corresponding second user of the second user identification information.
8. device according to any one of claims 5 to 7, which is characterized in that the receiving module, specifically for passing through The access authorization for resource administration interface display logs in the same level user identifier letter of the user identity information of view networked monitoring and managing system Breath and subordinate subscriber identification information;Described in user identity information from the login view networked monitoring and managing system of display First user identity information is selected in the same level user identity information and subordinate subscriber identification information;Receive selection to point Enjoy the first user identity information of access authorization for resource.
9. a kind of computer readable storage medium, which is characterized in that store computer journey on the computer readable storage medium Sequence, the computer program realize access authorization for resource sharing side according to any one of claims 1 to 4 when being executed by processor The step of method.
10. a kind of access authorization for resource sharing apparatus, which is characterized in that including processor, memory and be stored on the memory And the computer program that can be run on the processor, such as right is realized when the computer program is executed by the processor It is required that described in any one of 1 to 4 the step of access authorization for resource sharing method.
CN201910229079.8A 2019-03-25 2019-03-25 Resource permission sharing method and device and readable storage medium Active CN110096854B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910229079.8A CN110096854B (en) 2019-03-25 2019-03-25 Resource permission sharing method and device and readable storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910229079.8A CN110096854B (en) 2019-03-25 2019-03-25 Resource permission sharing method and device and readable storage medium

Publications (2)

Publication Number Publication Date
CN110096854A true CN110096854A (en) 2019-08-06
CN110096854B CN110096854B (en) 2022-03-25

Family

ID=67444000

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910229079.8A Active CN110096854B (en) 2019-03-25 2019-03-25 Resource permission sharing method and device and readable storage medium

Country Status (1)

Country Link
CN (1) CN110096854B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111193905A (en) * 2019-12-24 2020-05-22 视联动力信息技术股份有限公司 Monitoring resource allocation method and device and readable storage medium

Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2408434A (en) * 2003-11-19 2005-05-25 Vodafone Plc Personal area network security domains (PSDs)
CN103745298A (en) * 2013-12-16 2014-04-23 远光软件股份有限公司 Statement user permission setting method and statement user permission setting device based on post system
CN104580364A (en) * 2014-12-01 2015-04-29 百度在线网络技术(北京)有限公司 Resource sharing method and device
CN104683410A (en) * 2013-12-02 2015-06-03 深圳市迅雷网络技术有限公司 Resource sharing method and device
CN105610780A (en) * 2015-10-22 2016-05-25 东北师范大学 Interoperation platform among clouds used for education mechanism and method thereof
CN105610949A (en) * 2015-12-30 2016-05-25 腾讯科技(深圳)有限公司 Method, device and system for sharing resource data permission
CN105740392A (en) * 2016-01-27 2016-07-06 浪潮软件股份有限公司 Resource sharing apparatus, system and method
CN106874351A (en) * 2016-12-27 2017-06-20 浙江宇视科技有限公司 A kind of authority control method and equipment
CN107093089A (en) * 2016-10-14 2017-08-25 口碑控股有限公司 The sharing method and device of a kind of user's virtual resource
CN108306973A (en) * 2018-02-07 2018-07-20 尚国庆 House property medium services platform user stage division and its platform
CN108881361A (en) * 2017-12-26 2018-11-23 北京视联动力国际信息技术有限公司 A kind of data push method and device based on view networking
CN108965226A (en) * 2017-12-21 2018-12-07 北京视联动力国际信息技术有限公司 A kind of data capture method and device based on view networking

Patent Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2408434A (en) * 2003-11-19 2005-05-25 Vodafone Plc Personal area network security domains (PSDs)
CN104683410A (en) * 2013-12-02 2015-06-03 深圳市迅雷网络技术有限公司 Resource sharing method and device
CN103745298A (en) * 2013-12-16 2014-04-23 远光软件股份有限公司 Statement user permission setting method and statement user permission setting device based on post system
CN104580364A (en) * 2014-12-01 2015-04-29 百度在线网络技术(北京)有限公司 Resource sharing method and device
CN105610780A (en) * 2015-10-22 2016-05-25 东北师范大学 Interoperation platform among clouds used for education mechanism and method thereof
CN105610949A (en) * 2015-12-30 2016-05-25 腾讯科技(深圳)有限公司 Method, device and system for sharing resource data permission
CN105740392A (en) * 2016-01-27 2016-07-06 浪潮软件股份有限公司 Resource sharing apparatus, system and method
CN107093089A (en) * 2016-10-14 2017-08-25 口碑控股有限公司 The sharing method and device of a kind of user's virtual resource
CN106874351A (en) * 2016-12-27 2017-06-20 浙江宇视科技有限公司 A kind of authority control method and equipment
CN108965226A (en) * 2017-12-21 2018-12-07 北京视联动力国际信息技术有限公司 A kind of data capture method and device based on view networking
CN108881361A (en) * 2017-12-26 2018-11-23 北京视联动力国际信息技术有限公司 A kind of data push method and device based on view networking
CN108306973A (en) * 2018-02-07 2018-07-20 尚国庆 House property medium services platform user stage division and its platform

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
刘静: "工程项目管理信息系统分析", 《人民长江》 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111193905A (en) * 2019-12-24 2020-05-22 视联动力信息技术股份有限公司 Monitoring resource allocation method and device and readable storage medium
CN111193905B (en) * 2019-12-24 2022-11-01 视联动力信息技术股份有限公司 Monitoring resource allocation method and device and readable storage medium

Also Published As

Publication number Publication date
CN110096854B (en) 2022-03-25

Similar Documents

Publication Publication Date Title
CN108881798B (en) It is a kind of to be carried out using bridge service device across view networking conference method and system
CN108965224A (en) A kind of method and apparatus of video on demand
CN108632238A (en) A kind of method and apparatus of permission control
CN109151058A (en) A kind of data transmission method and device
CN109996086A (en) A kind of view networking service method for inquiring status and device
CN109889779A (en) A kind for the treatment of method and apparatus of packet out-ordering
CN109963109A (en) A kind of processing method and system of video conference
CN108965226A (en) A kind of data capture method and device based on view networking
CN109766753A (en) A kind of finger print information acquisition methods and device
CN108307212A (en) A kind of file order method and device
CN109040656A (en) A kind of processing method and system of video conference
CN110266577A (en) A kind of tunnel establishing method and view networked system
CN110113557A (en) It is a kind of multistage meeting implementation method and view networked system
CN109743555A (en) A kind of information processing method and system based on view networking
CN109819198A (en) A kind of meeting measures and procedures for the examination and approval and device based on view networking
CN109768957A (en) A kind of processing method and system of monitoring data
CN109491783A (en) A kind of acquisition methods and system of memory usage
CN109347930A (en) A kind of task processing method and device
CN109005378A (en) A kind of processing method and system of video conference
CN110401848A (en) A kind of video broadcasting method and device
CN110351573A (en) Virtual present presentation method, system and device
CN110493319A (en) Method of data synchronization, system and device
CN110445759A (en) A kind of electronic whiteboard sharing method and device
CN110149497A (en) A kind of view networked data transmission method, apparatus, system and readable storage medium storing program for executing
CN109698859A (en) A kind of date storage method and device based on view networking

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant