WO2016070604A1 - 一种资源访问的方法和装置 - Google Patents

一种资源访问的方法和装置 Download PDF

Info

Publication number
WO2016070604A1
WO2016070604A1 PCT/CN2015/078920 CN2015078920W WO2016070604A1 WO 2016070604 A1 WO2016070604 A1 WO 2016070604A1 CN 2015078920 W CN2015078920 W CN 2015078920W WO 2016070604 A1 WO2016070604 A1 WO 2016070604A1
Authority
WO
WIPO (PCT)
Prior art keywords
group
resource
identifier
resource identifier
group resource
Prior art date
Application number
PCT/CN2015/078920
Other languages
English (en)
French (fr)
Inventor
高莹
殷佳欣
张永靖
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2016070604A1 publication Critical patent/WO2016070604A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor

Definitions

  • the present invention relates to the field of information technology, and in particular, to a method and apparatus for resource access.
  • Machine-to-Machine Communications is a networked application and service centered on machine intelligence interaction. It embeds wireless or wired communication modules and application processing logic inside the machine to realize user informationization requirements for monitoring, command and dispatch, data acquisition and measurement.
  • various M2M devices such as various sensors, directly access the M2M service platform through the M2M gateway to implement various M2M services. For example, power meter reading, smart home, etc.
  • M2M service platform Through the service capabilities provided by the M2M service platform, data collected by the M2M device can be acquired, or the M2M device can be controlled and managed.
  • any M2M device, M2M gateway or M2M service platform and the service capabilities they provide can be abstracted into resources and have unique resource identifiers, ie URI (Uniform Resource Identifier).
  • ie URI Uniform Resource Identifier
  • Each accessed resource can be set with corresponding access rights, and the access control function of the accessed resource in the system is implemented by referring to an access control policy resource, such as an accessRight resource or an accessControlPolicy resource.
  • an access control policy resource such as an accessRight resource or an accessControlPolicy resource.
  • the access control policy identifier is accessed according to the access control policy identifier of the accessed resource to obtain the corresponding access control policy resource, and each access control rule in the access control policy resource can be viewed.
  • accessControlOriginator represents the requester resource identifier (possibly a CSE-ID, AE-ID, or serviceProvider domain, or All) with operational privileges; accessControlOperations indicates The permission allowed by this rule (may include one or more of Retrieve, Create, Update, Delete, Discovery, and Notify); accessControlContexts is optional and defines the accessControlOriginator with the permissions specified in accessControlOperations, such as Within a certain time frame, within each geographic area, and so on. As an alternative, the value of accessControlContexts can be It is empty, that is, it does not limit and describe the conditions of the operation authority.
  • the device to which the accessed resource belongs determines whether the originator has access to the accessed resource according to whether the accessControlOriginator attribute in the obtained access control policy resource includes the requester originator identifier, and whether the accessControlOperations attribute includes an originator request for the accessed resource request. access permission. Only when both conditions are met indicates that the originator passed the access control permission check.
  • ⁇ accessControlOriginators> is only set for accessing the requester resource of the accessed resource. Therefore, when multiple requester resources need to access the accessed resource, the multiple requests in the access control policy resource are required.
  • the resources are set to the corresponding permissions. That is to say, if a group member of a group has the same operation authority for the same accessed resource, it is necessary to separately configure the same access control authority for each group member. Therefore, the content included in the access control policy resource is verbose, and the device to which the access control policy resource belongs is very complicated to create and update the access control policy resource.
  • the request device accessing the accessed resource is not a group device, and the permission of the requesting device cannot be confirmed, so that the request cannot be ensured.
  • the device controls the access to the accessed resource.
  • the embodiment of the invention provides a resource access method and device applied to an M2M system, which can fully utilize the group collection function to implement group-based access control on the accessed resource.
  • the present invention provides a method for resource access, which is applied to a machine communication M2M system, and includes:
  • the access request includes an identifier of the accessed resource, a requester resource identifier, and an operation requesting the accessed resource;
  • the requester resource is a group member of the group resource corresponding to the group resource identifier of the access control policy resource having the operation authority of the requested operation;
  • the determining that the requester resource is a group member of a group resource corresponding to the group resource identifier of the operation authority that has the requested operation in the access control policy resource specifically And determining, in the access control policy resource, a group resource identifier that has an operation authority of the requested operation, and determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier.
  • Determining that the group resource identifier exists in the access control policy resource determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier, and the determined group resource identifier corresponds to The operation authority is the operation of the request.
  • the determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier is specifically:
  • the acquiring the group resource identifier list of the requester resource is specifically:
  • the access request further includes a group resource identifier list of the requester resource, and obtain the belonging group resource identifier list in the access request.
  • the method further includes:
  • the present invention provides a method for configuring a group resource identifier list to which a resource belongs, including:
  • the operation request of the added group member includes a group resource identifier and an identifier of the newly joined group member, wherein the group resource identifier indicates the newly joined group member Identify the group resource to which the corresponding group member is to be added;
  • the process of adding the identifier of the newly added group member in the member list of the group resource sending, to the group member corresponding to the identifier of the newly added group member, the list of the group resource identifier to which the group belongs is updated. a first request message, where the first request message includes the group resource identifier and information indicating that the group resource identifier is newly added, and the first request message indicates an identifier of the newly joined group member.
  • the corresponding group member adds the group resource identifier to its own group resource identifier list.
  • the method before the receiving an operation request for adding a group member, the method further includes:
  • the method further includes: receiving an operation request for deleting a group member, where the operation request for deleting the group member includes the group resource identifier and an identifier of a group member to be deleted ;
  • deleting the identifier of the group member to be deleted in the member list of the group resource and sending, to the group member corresponding to the identifier of the group member to be deleted, the group resource identifier list to which the group belongs to be updated.
  • a second request message where the second request message includes the group resource identifier and the information indicating that the group resource identifier is deleted, and the second request message indicates that the identifier of the group member to be deleted corresponds to The group member deletes the group resource identifier from its own group resource identifier list.
  • the method further includes
  • Receiving a notification message that the group resource is referenced, and the notification message that the group resource is referenced includes Determining a group resource identifier and an access control policy resource identifier that references the group resource;
  • the method further includes: receiving an operation request for deleting a group resource, where the operation request for deleting the group resource carries the group resource identifier;
  • deleting in the process of deleting the group resource, a second request message that updates a group resource identifier list to be added to each group member in the member list of the group resource, where the second request message includes the group a group resource identifier and information indicating that the group resource identifier is deleted, where the second request message indicates that each group member in the member list of the group resource identifies the group resource identifier from its own group resource Deleted from the list of identifiers.
  • the method before the deleting the group resource, the method further includes:
  • the present invention provides a method for operating an access control policy resource, including:
  • the operation authority corresponding to the group resource identifier is specifically: The operation authority of the group member of the group resource corresponding to the group resource identifier;
  • the group resource corresponding to the group resource identifier includes a notification group member identifier, where the notification group member identifier indicates that the group member of the group resource has a group resource identifier list that belongs to the group resource identifier;
  • the method further includes:
  • the update request of the access control policy resource includes a group resource identifier to be added in the access control policy resource and an operation authority corresponding to the group resource identifier to be added;
  • Determining that the group resource corresponding to the group resource identifier to be added includes the notification group member identifier
  • the group resource identifier to be added and the operation corresponding to the group resource identifier to be added Authorization is added to the access control policy resource.
  • the method further includes: sending, to the group server, a notification message that the group resource is referenced, where the group resource referenced notification message includes the access control policy resource identifier And a group resource identifier referenced in the access control policy resource.
  • the method further includes: receiving a notification message that the group resource sent by the group server is deleted, where the group resource deleted notification message includes the deleted group a group resource identifier and the access control policy resource identifier;
  • the determining that the group resource corresponding to the group resource identifier includes a notification group member identifier specifically:
  • the group resource corresponding to the resource identifier includes the notification group member identifier; determining, according to the response message, that the group resource corresponding to the group resource identifier includes a notification group member identifier; or in the creation request And carrying the information indicating that the group resource corresponding to the group resource identifier includes the notification group member identifier, and determining, according to the creation request, that the group resource corresponding to the group resource identifier includes a notification group member identifier.
  • the present invention provides a device for accessing a resource, where the device is applied to a machine communication M2M system, and includes: a receiving module, configured to receive an access request of a requester resource to a accessed resource, where the access request includes An identifier of the accessed resource, a requester resource identifier, and an operation requesting the accessed resource;
  • a determining module configured to determine the accessed resource according to the identifier of the accessed resource
  • An obtaining module configured to acquire, by the root, an access control policy resource of the accessed resource
  • the determining module is further configured to determine that the requester resource is a group member of the group resource corresponding to the group resource identifier of the access control policy resource having the operation authority of the requested operation;
  • An execution module configured to perform the requested operation on the accessed resource.
  • the determining module is specifically configured to:
  • Determining that the group resource identifier exists in the access control policy resource determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier, and the determined group resource identifier corresponds to The operation authority is the operation of the request.
  • the determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier includes:
  • the acquiring the group resource identifier list of the requester resource is specifically:
  • the access request further includes a group resource identifier list of the requester resource, and obtain the belonging group resource identifier list in the access request.
  • the present invention provides an apparatus for configuring a group resource identifier list to which a resource belongs, including:
  • a receiving module configured to receive an operation request for adding a group member, where the operation request of the added group member includes a group resource identifier and an identifier of the newly joined group member, where the group resource identifier indicates the new joining The group member of the group member corresponding to the group member to be joined;
  • a determining module configured to determine that the group resource includes a notification group member identifier
  • a sending module configured to send an update group to a group member corresponding to the identifier of the newly added group member in the process of adding the identifier of the newly added group member in the member list of the group resource a first request message of the group resource identifier list, where the first request message includes the group resource identifier and information indicating that the group resource identifier is newly added, and the first request message indicates the newly added message
  • the group member corresponding to the identifier of the group member adds the group resource identifier to its own group resource identifier list.
  • the apparatus further includes:
  • the receiving module is further configured to receive an operation request for creating a group resource, where the operation request for creating a group resource includes the notification group member identifier and a member list of the group resource;
  • a creating module configured to create the group resource according to the operation request for creating a group resource, to generate the group resource identifier, where the group resource includes the notification group member identifier and the group a list of members of the group resource;
  • the sending module sends, to each group member in the member list of the group resource, a first request message for updating a group resource identifier list, where the first request message includes the group resource identifier and Instructing to add information about the group resource identifier, where the first request message indicates that each group member in the member list of the group resource adds the group resource identifier to its own group resource identifier list. in.
  • the device further includes:
  • the receiving module is further configured to receive a notification message that the group resource is referenced, where the notification message of the group resource reference includes the group resource identifier and an access control policy resource identifier that references the group resource;
  • a recording module configured to record the access control policy resource identifier in the group resource.
  • the device further includes:
  • the receiving module is further configured to receive an operation request for deleting a group resource, where the operation request for deleting a group resource carries the group resource identifier;
  • the sending module is further configured to: send, in a process of deleting the group resource, a second request message that updates a group resource identifier list to a group member in the member list of the group resource, where The second request message includes the group resource identifier and the information indicating that the group resource identifier is deleted, and the second request message indicates that each group member in the member list of the group resource uses the group resource The identifier is deleted from its own group resource identifier list.
  • the device before the deleting the group resource, further includes:
  • the determining module is further configured to determine that the group resource includes the access control policy resource identifier
  • the sending module is further configured to send, to the access control policy resource corresponding to the access control policy resource identifier, a notification message that the group resource is deleted, indicating that the group resource has been deleted.
  • the present invention provides an operation apparatus for access control policy resources, including: receiving a module, configured to receive a request for creating an access control policy resource, where the creation request includes a group resource identifier and an operation authority corresponding to the group resource identifier, where the operation authority corresponding to the group resource identifier is specific The operating authority of the group member of the group resource corresponding to the group resource identifier;
  • a determining module configured to determine that the group resource corresponding to the group resource identifier includes a notification group member identifier, where the notification group member identifier indicates that the group member of the group resource has a group resource identifier list that belongs to the group resource identifier;
  • a creating module configured to create an access control policy resource according to the creation request, and generate an access control policy resource identifier, where the access control policy resource includes the group resource identifier and the corresponding to the group resource identifier Operational authority.
  • the apparatus further includes:
  • the receiving module is further configured to receive an update request of an access control policy resource, where the update request of the access control policy resource includes a group resource identifier that needs to be added in the access control policy resource, and the required increase The operation authority corresponding to the group resource identifier;
  • the determining module is further configured to: determine that the group resource corresponding to the group resource identifier to be added includes the notification group member identifier;
  • an adding module configured to add the group resource identifier to be added and the operation authority corresponding to the group resource identifier to be added to the access control policy resource.
  • the device further includes:
  • a sending module configured to send, to the group server, a notification message that the group resource is referenced, where the notification message of the group resource reference includes the access control policy resource identifier and a group referenced in the access control policy resource Group resource ID.
  • the device further includes:
  • the receiving module is further configured to receive a notification message that the group resource that is sent by the group server is deleted, and the notification message that the group resource is deleted includes the deleted group resource identifier and the access control policy.
  • a deleting module configured to delete, according to the access control policy resource identifier, the deleted group resource identifier and the operation authority corresponding to the deleted group resource identifier in the access control policy resource.
  • the method for accessing resources provided by the present invention determines whether the requester resource has operational authority A group member of the group resource, so that group-based access control can be implemented on the resource.
  • FIG. 1 is a flowchart of a method for resource access according to an embodiment of the present invention
  • FIG. 2 is a flowchart of a resource access method for end-to-end group-based access control according to an embodiment of the present invention
  • FIG. 3 is a flowchart of a method for configuring a group resource identifier list of a resource according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a method for creating an access control policy resource according to an embodiment of the present invention
  • FIG. 5 is a schematic structural diagram of a resource access device in a machine communication system according to an embodiment of the present disclosure
  • FIG. 6 is a schematic structural diagram of an apparatus for configuring a group resource identifier list to which a resource belongs in a machine communication system according to an embodiment of the present disclosure
  • FIG. 7 is a schematic structural diagram of an apparatus for operating an access control policy resource in a machine communication system according to an embodiment of the present disclosure
  • FIG. 8 is a schematic structural diagram of another resource access device in a machine communication system according to an embodiment of the present disclosure.
  • FIG. 9 is another schematic structural diagram of an apparatus for configuring a group resource identifier list to which a resource belongs in a machine communication system according to an embodiment of the present disclosure
  • FIG. 10 is a schematic structural diagram of another apparatus for operating an access control policy resource in a machine communication system according to an embodiment of the present invention.
  • the embodiment of the present invention provides a method for resource access, which is applied to a machine communication M2M system.
  • the method embodiment describes a processing flow of a device to which the accessed resource belongs. As shown in Figure 1, the following steps are included:
  • Step 102 Receive an access request of a requestor resource to an accessed resource, where the access request includes an identifier of the accessed resource, a requester resource identifier, and an operation requesting the accessed resource;
  • the device to which the accessed resource belongs receives an access request of the requestor resource to the accessed resource by the device to be accessed, where the access request includes the identifier of the accessed resource, the requester resource identifier, and the resource request for the accessed resource.
  • Operation any M2M device, M2M gateway or M2M service platform and applications registered on them can be abstracted into resources and have a unique resource identifier, ie URI (Uniform Resource Identifier), according to the resource identifier. You can uniquely locate resources.
  • the operations requested on the accessed resource include obtaining Retrieve, creating Create, updating Update, and deleting Delete. It should be noted that a plurality of resources may exist on the device to which the accessed resource belongs, and the device to which the accessed resource belongs may determine the resource that the requester resource wishes to access according to the identifier of the accessed resource.
  • the operation for requesting the accessed resource in the access request is Update
  • Step 104 Determine the accessed resource according to the identifier of the accessed resource.
  • each resource in the M2M system has a unique resource identifier, so the accessed resource can be determined according to the identifier of the accessed resource.
  • Step 106 Acquire an access control policy resource of the accessed resource.
  • the access control function of the accessed resource can be implemented by using an access control policy (accessControlPolicy).
  • accessControlPolicy Each accessed resource has a corresponding access control policy resource identifier accessControlPolicyID (if the accessed resource itself does not have the accessControlPolicyID attribute, the accessControlPolicyID attribute of the parent resource of the resource is automatically inherited or other default accessControlPolicyID attribute is used).
  • the device to which the accessed resource belongs can obtain the corresponding access control policy resource according to the accessControlPolicyID.
  • the access control policy resource may be located on a device to which the accessed resource belongs, or may be located on another device.
  • Step 108 Determine that the requester resource is a group member of the group resource corresponding to the group resource identifier of the access control policy resource having the operation authority of the requested operation;
  • determining, by the requester resource, a group member of the group resource corresponding to the group resource identifier that has the operation authority of the requested operation in the access control policy resource specifically: determining the access control policy resource a group resource identifier having an operation authority of the requested operation, and the requester resource is a group member of the group resource corresponding to the determined group resource identifier; or determining the access control policy resource
  • the group resource identifier is determined, the requester resource is a group member of the group resource corresponding to the determined group resource identifier, and the operation authority corresponding to the determined group resource identifier is the requested operating.
  • the two methods are intrinsically consistent, and both need to determine whether the group resource identifier exists in the access control policy, whether the operation authority corresponding to the group resource identifier is the operation of the request, and whether the requester resource is a group.
  • the group members of the group resource corresponding to the resource identifier are only in the order of judgment. The following is a detailed description of the first method:
  • each access control rule in the access control policy resource includes at least ⁇ accessControlOriginators, accessControlOperations>.
  • accessControlContexs is empty, indicating that the conditions of the operation authority are not restricted and described, and since it is not related to the present invention, it is not emphasized in the following description.
  • the device to which the accessed resource belongs determines the group resource identifier that has the operation authority of the operation of the request in the access control policy resource, specifically: determining whether the access control resource includes the requester resource requesting the accessed resource by the device to which the access control is located After determining that the accessControlOperations contains the requester resource requesting the accessed resource through the device to which it belongs, it is determined whether the accessControlOriginators in the access control rule are a group resource identifier. Assume that Table 1 shows the access control policy resources obtained in step 106.
  • the access controlOperations in the third row of the access control policy resource in Table 1 contains the operation Update of the requester resource requesting the accessed resource through the device to which it belongs, and the accessControlOriginators in this access control rule is a group resource identifier Group1. Therefore, it may be determined that the group resource identifier having the operation authority of the requested operation exists in the access control policy resource.
  • AccessControlOriginators accessControlContexs accessControlOperation AE1 / Retrieve/Create CSE1 / Update/Create/Delete Group1 / Update/Create Group2 / retrieve/Create
  • the device to which the accessed resource belongs is according to the access control.
  • a policy determining that the requestor resource identifier does not exist in the access control policy resource; or determining that the requestor resource identifier exists in the access control policy resource, and determining that the operation authority corresponding to the requester resource identifier does not include The requested operation.
  • the access of the requester resource to the accessed resource will be rejected. After accessing the resource, after introducing the group-based access control, it is necessary to further determine whether the requestor resource is a group member of the group resource having the requested operation.
  • determining whether the requester resource is a group member of the group resource corresponding to the determined group resource identifier has two implementation manners:
  • the first mode is to obtain the group resource identifier list of the requester resource, and if the group resource identifier list includes the group resource identifier, determine that the requester resource is the group corresponding to the group resource identifier. a group member of the group resource; if the group resource identifier list does not include the group resource identifier, determining that the requester resource is not a group member of the group resource corresponding to the group resource identifier, where The group resource identifier list includes the group resource identifier of the group resource to which the requester resource belongs; or
  • Embodiment 2 obtaining a member list of the group resource corresponding to the group resource identifier of the operation authority of the requested operation, and checking whether the requester resource identifier is included in the member list of the group resource, if If the requester resource identifier is included in the member list of the group resource, the requester resource is determined to be a group member of the group resource corresponding to the determined group resource identifier; If the requester resource identifier is not included in the member list of the source, it is determined that the requester resource is not a group member of the group resource corresponding to the determined group resource identifier.
  • the device to which the accessed resource belongs may send the group resource identifier of the acquiring requester resource to the device to which the requester resource belongs according to the requester resource identifier in the access request in step 102.
  • List of request messages may be sent.
  • the destination address of the request message for obtaining the group resource identifier list of the requester resource may be http://m2m.example.com/xxx/ApplicationEntity1, to obtain the entire AE1 resource, and then Further, obtain the group resource identifier list of the AE1 resource; the destination address may also be http://m2m.example.com/xxx/ApplicationEntity1/memberOf, so that only the group resource identifier list of the AE1 belongs to.
  • the memberOf attribute of the resource AE1 stores the list of the group resource identifiers to which the AE1 belongs.
  • the group resource identifier list includes the group resource identifier of the group resource to which the requester resource belongs.
  • the access request in the step 102 further includes a group resource identifier list of the requester resource, and in step 108, the device to which the accessed resource belongs may directly acquire the requester resource according to the access request.
  • Step 110 Perform the requested operation on the accessed resource.
  • the device to which the accessed resource belongs performs an operation on the accessed resource request according to the access request, and optionally returns a success response message to the device to which the requester resource belongs.
  • the device to which the accessed resource belongs may include other checking steps, and may also be accessed for other reasons in these checking steps.
  • the operation of the resource request cannot be successfully executed, and a failure response message is returned, which includes the reason why the request is rejected.
  • Embodiments of the present invention assume that no other inspection steps or other inspection steps are passed.
  • the method for accessing resources provided by the embodiment of the present invention implements group-based access control on resources by determining whether the requester resource is a group member of a group resource having operation authority.
  • FIG. 2 is a flow chart of a resource access method for end-to-end group-based access control applied to a machine communication M2M system according to the present invention. As described in FIG. 2, the method includes the following steps:
  • Step 202 The device to which the requester resource belongs sends a resource access request to the device to which the accessed resource belongs, where the access request carries an identifier of the accessed resource, a requester resource identifier, and an operation for requesting the accessed resource.
  • step 202 is the same as the step 102 in the embodiment shown in FIG. 1.
  • steps 102 are the same as the related content of step 102, and details are not described herein again.
  • Step 204 After receiving the access request, the device to which the accessed resource belongs acquires an access control policy resource identifier of the accessed resource.
  • the access control function in the oneM2M standard is implemented by an access control policy (accessControlPolicy).
  • the accessed resource may include a corresponding access control policy resource identifier accessControlPolicyID. If the resource itself does not contain the accessControlPolicyID property, it automatically inherits the parent resource's accessControlPolicyID property or other default accessControlPolicyID property.
  • the device to which the accessed resource belongs acquires the corresponding access control policy resource according to the accessControlPolicyID of the accessed resource.
  • the access control policy resource may be located on a device to which the accessed resource belongs, or may be located on another device.
  • Step 206 The device to which the accessed resource belongs sends a request for acquiring an access control policy resource to a device to which the access control policy resource belongs according to the access control policy resource identifier.
  • the access control policy resource is not on the same device as the accessed resource.
  • the access control policy resource may also be located on the device to which the accessed resource belongs.
  • the signaling interaction between the device to which the accessed resource belongs and the device to which the access control policy resource belongs will be the signaling interaction inside the device to which the accessed resource belongs.
  • Step 208 The device to which the access control policy resource belongs sends a response message for successfully acquiring the access control policy resource to the device to which the accessed resource belongs according to the request for acquiring the access control policy resource, where the access control policy is successfully obtained.
  • the response message of the resource includes the access control policy resource of the accessed resource;
  • Step 210 Determine, according to the access control policy resource, a device to which the accessed resource belongs, a group resource identifier that has an operation authority of the requested operation in the access control policy resource;
  • Determining, in the access control policy resource, a group resource identifier that has an operation authority of the requested operation specifically: determining whether the accessControlOperations includes an operation of requesting a resource by the device to be accessed by the device to be accessed; After determining that the accessControlOperations contains the requester resource requesting the accessed resource through the device to which it belongs, it is determined whether the accessControlOriginators in the access control rule are a group resource identifier.
  • Step 212 The device to which the accessed resource belongs sends the acquisition to the device to which the requester resource belongs. a request message of the group resource identifier list of the requester resource;
  • the device to which the accessed resource belongs may send a request message to the device to which the requester resource belongs according to the requester resource identifier in the access request in step 202 to obtain a group resource identifier list of the requester resource.
  • Step 214 The device to which the requester resource belongs sends a response message for successfully acquiring the group resource identifier list to the device to which the accessed resource belongs, where the response message for successfully obtaining the group resource identifier list includes the requester. A list of the group resource IDs to which the resource belongs.
  • step 202 further includes the group resource identifier list of the requester resource
  • step 212 and step 214 are not necessary, and the device to which the accessed resource belongs may directly access the device according to the access. Request to obtain a list of the group resource identifiers to which the requester resources belong.
  • Step 216 The device to which the accessed resource belongs determines that the requester resource belongs to the group resource corresponding to the group resource identifier of the operation authority of the requested operation, according to the belonging group resource identifier list.
  • the device to which the accessed resource belongs compares the obtained group resource identifier list with the group resource identifier of the operation authority with the requested operation, and exists in the group resource identifier list.
  • the group resource identifier of the operation authority of the requested operation is determined, determining that the requester resource belongs to the group member of the group resource identifier corresponding group resource of the operation authority having the requested operation . Determining that the requester resource has the request for the accessed resource when it is determined that the requester resource belongs to a group member of the group resource identifier corresponding group resource of the operation authority of the requested operation Operational authority for the operation.
  • Step 218 The device to which the accessed resource belongs performs the requested operation.
  • the device to which the accessed resource belongs performs an operation on the accessed resource request according to the access request, and optionally returns a success response message to the device to which the requester resource belongs.
  • the method for accessing resources provided by the embodiment of the present invention implements group-based access control on resources by determining whether the requester resource is a group member of a group resource having operation authority.
  • FIG. 3 is a flowchart of a method for configuring a group resource identifier list of a resource to be applied in a machine communication M2M system according to the present invention.
  • the embodiment of the method describes the processing procedure of the device to which the group resource belongs, where the device to which the group resource belongs is referred to as a group server.
  • the group server may be a service platform for storing and maintaining group resources, an M2M gateway, M2M equipment, etc.
  • the method includes the following steps:
  • Step 302 Receive an operation request for adding a group member, where the operation request of the added group member includes a group resource identifier and an identifier of the newly joined group member, where the group resource identifier indicates the newly joined group The group resource to which the group member belongs to the group member;
  • the group server receives an operation request for adding a group member, and the operation request for adding the group member includes the group resource identifier and the identifier of the newly joined group member.
  • Step 304 Determine that the group resource includes a notification group member identifier.
  • the notification group member identifier may have multiple representation forms, for example, the group type or group usage of the group resource is access control, the group resource includes a notification group member identifier, or the The name of the group resource contains access control tags and so on.
  • the specific solution of the notification group member identifier is not limited by the solution of the present invention.
  • the group resource includes a notification group member identifier as an example for description.
  • the group resource includes the notification group member identifier, indicating that the group resource needs to update the group resource identifier list of the group member that changes in the group resource when the group member is updated.
  • Step 306 In the process of adding the identifier of the newly added group member in the member list of the group resource, sending, to the group member corresponding to the identifier of the newly added group member, the group resource to be updated. a first request message that identifies the list; wherein the first request message includes the group resource identifier and information indicating that the group resource identifier is newly added, and the first request message indicates the newly added group.
  • the group member corresponding to the member's identifier adds the group resource identifier to its own group resource identifier list.
  • the group resource identifier list of the newly joined group member needs to be updated. That is, the group resource identifier is added to the group resource identifier list of the newly joined group member.
  • the group server after receiving the operation request for adding a group member, determining that the group resource includes the notification group member identifier, the group server is configured to be a member of the group resource according to the operation request of the group member. Adding an identifier of the newly added group member to the list, and sending, to the group member corresponding to the identifier of the newly joined group member, a first request message for updating the group resource identifier list to which the group belongs; wherein, the a request message includes the group resource identifier and an indication to add the group resource And the first request message indicates that the group member corresponding to the identifier of the newly joined group member adds the group resource identifier to its own group resource identifier list. It should be noted that, in the present invention, the group server adds the identifier of the newly added group member and the order of sending the first request message to the member list of the group resource.
  • the group server receives the notification message of the group resource identifier list that is successfully updated by the newly added group member, and the notification message that successfully updates the group resource identifier list belongs to the newly added group member.
  • the group resource identifier has been successfully added to the group resource identifier list to which it belongs.
  • the method further includes: the group server receiving an operation request for creating a group resource, where the operation request for creating the group resource includes the notification group member identifier and the group resource Member list. And the group server creates the group resource, and generates the group resource identifier, where the group resource includes the notification group member identifier and the group resource, according to the operation request for creating a group resource. List of members.
  • the group server sends, to each group member in the member list of the group resource, a first request message that updates the group resource identifier list to be associated, where the first request message includes the group resource identifier and the indication new The information of the group resource identifier is added, and the first request message indicates that each group member in the member list of the group resource adds the group resource identifier to its own group resource identifier list.
  • the group server receives the notification message of the group resource identifier list that is successfully updated by each group member in the member list of the group resource, and successfully updates the notification message of the group resource identifier list.
  • Each group member in the member list of the group resource has successfully added the group resource identifier to the group resource identifier list to which it belongs.
  • the group server receives an operation request for deleting a group member, and the operation request for deleting the group member includes the group resource identifier and an identifier of a group member to be deleted.
  • the group server sends a second request message for updating the group resource identifier list to the group member corresponding to the identifier of the group member to be deleted, where
  • the second request message includes the group resource identifier and the information indicating that the group resource identifier is deleted, and the second request message indicates that the group member corresponding to the identifier of the group member to be deleted is
  • the group resource identifier is deleted from its own group resource identifier list.
  • the group server deletes the identifier of the group member to be deleted in the member list of the group resource. It should be noted that, the present invention deletes the group member to be deleted in the member list of the group resource to the group server.
  • the identity of the identity and the order in which the second request message is sent are not limited.
  • the group server receives the notification message of the group resource identifier list that is successfully updated by the group member to be deleted, and the notification message of the group resource identifier list that is successfully updated indicates the group member to be deleted.
  • the group resource identifier has been successfully deleted from the group resource identifier list to which it belongs.
  • the group server receives a notification message that the group resource that is sent by the device to which the access control policy resource is referenced, and the notification message that the group resource is referenced includes the group resource identifier and references the group The access control policy resource ID of the resource.
  • the group server records the access control policy resource identifier in the group resource, where the specific implementation of recording the access control policy resource identifier may also be to create a subscription of the access control policy resource to the group resource.
  • the group server sends a notification message that the group resource is deleted to the device to which the access control policy resource that references the group resource belongs, indicating that the group resource has been deleted, so that The device to which the access control policy resource belongs deletes the access control rule that references the group resource identifier.
  • the group server receives an operation request for deleting the group resource, where the operation request for deleting the group resource carries the group resource identifier. And the group server deletes the group resource according to the operation request for deleting the group resource, and sends a second request message for updating the group resource identifier list to the group member in the member list of the group resource.
  • the second request message includes the group resource identifier and information indicating that the group resource identifier is deleted, and the second request message indicates that each group member in the member list of the group resource is to be The group resource identifier is deleted from its own group resource identifier list.
  • the group server receives the notification message of the group resource identifier list that is successfully updated by each group member in the member list of the group resource, and the notification message that successfully updates the group resource identifier list belongs to the Each group member in the member list of the group resource has successfully deleted the group resource identifier from the group resource identifier list to which it belongs.
  • the access control rule in the access control policy resource that references the group resource also loses the basis of the reference.
  • the group resource server determines, according to the group resource identifier, that the group resource includes an access control policy resource identifier. And the group server sends a notification message that the group resource is deleted to the device to which the access control policy resource belongs, according to the access control policy resource identifier, indicating that the group resource has been deleted, so that the access control policy resource is used.
  • the associated device deletes the access control rule that references the group resource in the access control policy resource.
  • this embodiment provides a method for creating access in a machine communication M2M system.
  • a flow chart of a method for controlling a policy resource the specific steps are as follows:
  • Step 402 Receive a request for creating an access control policy resource, where the creation request includes a group resource identifier and an operation authority corresponding to the group resource identifier, where the operation authority corresponding to the group resource identifier is specifically : the operation authority of the group member corresponding to the group resource indicated by the group resource identifier;
  • the device to which the access control policy resource belongs receives the request for creating the access control policy resource, where the request for creating the access control policy resource includes the group resource identifier and the operation authority corresponding to the group resource identifier;
  • the operation authority corresponding to the group resource identifier with the operation authority is specifically: the operation authority of the group member corresponding to the group resource indicated by the group resource identifier.
  • the device to which the access control policy resource belongs may be an M2M gateway, an M2M device, or a device to which the M2M platform belongs in the M2M system.
  • the request for creating the access control policy resource indicates that the device to which the access control policy resource belongs establishes an access control policy resource, where the access control policy resource includes a group-based access control rule.
  • Step 404 Determine that the group resource corresponding to the group resource identifier includes a notification group member identifier, where the notification group member identifier indicates that the group member of the group resource has a group resource identifier list.
  • the notification group member identifier may have multiple representation forms, for example, the group type or group usage of the group resource is access control, and the group resource includes an identifier or a location of the notification group member.
  • the name of the group resource includes an access control flag or the like, and the notification group member identifier indicates that the group member of the group resource has a group resource identifier list, and the notification group member identifier is set by the solution of the present invention.
  • the specific form is not limited.
  • the group resource includes a notification group member identifier as an example for description.
  • determining that the group resource corresponding to the group resource identifier includes a notification group member identifier specifically:
  • the device to which the access control policy resource belongs sends a request for acquiring the notification group member identifier of the group resource to the device to which the group resource corresponding to the group resource identifier belongs, and receives the group a response message that is sent by the device to which the group resource indicated by the group resource identifier is obtained, and the group resource corresponding to the group resource identifier is included in the response message of the group member identifier.
  • the device to which the access control policy resource belongs determines that the group resource corresponding to the group resource identifier includes the notification group member identifier; and the device to which the access control policy resource belongs and the group resource belong to When the device to which the access control policy resource belongs and the device to which the group resource belongs are the same device, the information interaction between the two devices is performed inside the device. or,
  • the creation request carries information indicating that the group resource corresponding to the group resource identifier includes the notification group member identifier, and according to the creation request, the device to which the access control policy resource belongs determines the group.
  • the group resource corresponding to the group resource identifier includes the notification group member identifier.
  • Step 406 Create an access control policy resource according to the creation request, and generate an access control policy resource identifier.
  • the access control policy resource includes the group resource identifier and the operation authority corresponding to the group resource identifier. .
  • the device to which the access control policy resource belongs is configured to create an access control policy resource according to the request for creating the access control policy resource, and generate an access control policy resource identifier.
  • the access control policy resource includes the group resource identifier and the operation authority corresponding to the group resource identifier.
  • the device to which the access control policy resource belongs sends a notification message that the group resource is referenced to the device to which the group resource belongs, and the notification message that the group resource is referenced includes the access control policy resource identifier. And a group resource identifier referenced in the access control policy resource.
  • the device to which the access control policy resource belongs receives an update request of the access control policy resource, where the update request of the access control policy resource is included in the access control policy resource
  • the added group resource identifier and the operation authority corresponding to the group resource identifier to be added The device to which the access control policy resource belongs determines that the group resource corresponding to the group resource identifier to be added includes the notification group member identifier, and the group resource identifier to be added and the group to be added
  • the operation authority corresponding to the resource identifier is added to the access control policy resource.
  • the device to which the access control policy resource belongs sends a notification message that the group resource is referenced to the device to which the group resource to be added belongs, and the notification message that the group resource is referenced includes the access control.
  • a policy resource identifier and a group resource identifier referenced in the access control policy resource are collectively referred to as the referenced group resource identifiers.
  • the device to which the access control policy resource belongs receives a notification message that the group resource sent by the device to which the deleted group resource belongs is deleted,
  • the notification message that the group resource is deleted includes the deleted group resource identifier and the access control policy resource identifier.
  • the deleted group resource described herein belongs to the referenced group resource.
  • the request for creating the access control policy resource is requested, and the access control policy resource requested to be created is not for the group.
  • Access control rules Establishing corresponding access control policy resources according to the creation request of the access control policy. Further, when the group resource identifier is included in the request for creating the access control policy resource received in step 402, the request for creating the access control policy resource is requested, and the access control policy resource requested to be created includes one for the group. Access control rules.
  • the device to which the access control policy resource belongs rejects the creation request of the access control policy resource, and sends a failure response message to the requesting device, the failure response.
  • the reason for carrying the rejection request in the message is that the access control policy resource information includes a group resource identifier that does not meet the condition.
  • a method for configuring a group resource identifier list of a resource is provided.
  • the update is performed.
  • FIG. 5 is a schematic diagram of a resource access device in a machine communication system according to an embodiment of the present invention, including:
  • the receiving module 501 is configured to receive an access request of the requester resource to the accessed resource, where the access request includes an identifier of the accessed resource, a requester resource identifier, and an operation requesting the accessed resource;
  • a determining module 502 configured to determine the accessed resource according to the identifier of the accessed resource
  • An obtaining module 503, configured to acquire, by the root, an access control policy resource of the accessed resource
  • the determining module 502 is further configured to determine that the requester resource is a group member of the group resource corresponding to the group resource identifier of the access control policy resource having the operation authority of the requested operation;
  • the executing module 504 is configured to perform the requested operation on the accessed resource.
  • the determining module 502 is specifically configured to: determine, in the access control policy resource, a group resource identifier that has an operation authority of the requested operation, and determine that the requester resource is the determined group resource. Identifying a group member of the corresponding group resource; or determining that the group resource identifier exists in the access control policy resource, and determining that the requester resource is a group member of the group resource corresponding to the determined group resource identifier And the determined operation authority corresponding to the determined group resource identifier is the requested operation.
  • the determining, that the requester resource is a group member of the group resource corresponding to the determined group resource identifier specifically: acquiring a group resource identifier list of the requester resource, and determining the belonging
  • the group resource identifier list includes a group resource identifier of the operation authority having the requested operation; or a member list of the group resource corresponding to the group resource identifier of the operation authority having the requested operation, Determining that the member list includes the requester resource identifier.
  • the obtaining the group resource identifier list of the requester resource is specifically: sending, according to the requester resource identifier, a request message for acquiring a group resource identifier list of the requester resource to the requester resource. And receiving the belonging group resource identifier list returned by the requester resource; or the access request further includes a group resource identifier list of the requester resource, and acquiring the belonging group in the access request A list of resource IDs.
  • the determining module 502 is further configured to: Determining that the requestor resource identifier does not exist in the access control policy resource; or determining that the requestor resource identifier exists in the access control policy resource, and determining that the operation authority corresponding to the requester resource identifier does not include the The requested operation.
  • FIG. 6 is a schematic diagram of an apparatus for configuring a group resource identifier list to which a resource belongs in a machine communication system according to an embodiment of the present invention, including:
  • the receiving module 601 is configured to receive an operation request for adding a group member, where the operation request of the added group member includes a group resource identifier and an identifier of the newly joined group member, where the group resource identifier indicates the new The group resource to which the group member corresponding to the added group member is to be added;
  • a determining module 602 configured to determine that the group resource includes a notification group member identifier
  • the sending module 603 is configured to send an update to the group member corresponding to the identifier of the newly added group member in the process of adding the identifier of the newly added group member in the member list of the group resource. a first request message of the group resource identifier list; wherein the first request message includes the The group resource identifier and the information indicating that the group resource identifier is added, and the first request message indicates that the group member corresponding to the identifier of the newly joined group member adds the group resource identifier to the In the group resource identification list.
  • the receiving module 601 is further configured to receive an operation request for creating a group resource, where the operation request for creating a group resource includes the notification group member identifier and a member list of the group resource;
  • the device further includes a creating module 604, configured to create the group resource according to the operation request for creating a group resource, to generate the group resource identifier, where the group resource includes the notification group a member identifier and a member list of the group resource;
  • the sending module 603 is further configured to send, to each group member in the member list of the group resource, a first request message for updating a group resource identifier list that belongs to the group resource,
  • the first request message includes the group resource identifier and information indicating that the group resource identifier is added, and the first request message indicates that each group member in the member list of the group resource will The group resource identifier is added to its own group resource identifier list.
  • the receiving module 601 is further configured to receive an operation request for deleting a group member, where the operation request for deleting the group member includes the group resource identifier and an identifier of a group member to be deleted;
  • the determining module 602 is further configured to determine that the group resource includes the notification group member identifier, and the sending module 603 is further configured to delete the group member to be deleted in a member list of the group resource And sending, to the group member corresponding to the identifier of the group member to be deleted, a second request message for updating the group resource identifier list to be deleted, where the second request message includes the group resource Identifying and indicating to delete the information of the group resource identifier, where the second request message indicates that the group member corresponding to the identifier of the group member to be deleted identifies the group resource identifier from its own group resource identifier Remove from the list.
  • the receiving module 601 is further configured to receive a notification message that the group resource is referenced, where the group resource referenced notification message includes the group resource identifier and access control that references the group resource.
  • the policy resource identifier the device further includes a recording module 605, configured to record the access control policy resource identifier in the group resource.
  • the receiving module 601 is further configured to receive an operation request for deleting a group resource, where the operation request for deleting a group resource carries the group resource identifier; and the sending module is further configured to delete In the process of the group resource, sending, to each group member in the member list of the group resource, a second request message for updating a group resource identifier list, where the second request message includes the group resource Identifying and indicating to delete information of the group resource identifier, the second request message indicating the group Each group member in the member list of the group resource deletes the group resource identifier from its own group resource identifier list.
  • the determining module 602 is further configured to determine that the group resource includes the access control policy resource identifier; and the sending module 603 is further configured to: Sending a notification message that the group resource is deleted to the access control policy resource corresponding to the access control policy resource identifier, indicating that the group resource has been deleted.
  • FIG. 7 is a schematic diagram of an apparatus for operating an access control policy resource in a machine communication system according to an embodiment of the present invention, including:
  • the receiving module 701 is configured to receive a request for creating an access control policy resource, where the creation request includes a group resource identifier and an operation authority corresponding to the group resource identifier, and the operation corresponding to the group resource identifier
  • the permission is specifically: the operation permission of the group member of the group resource corresponding to the group resource identifier;
  • a determining module 702 configured to determine that the group resource corresponding to the group resource identifier includes a notification group member identifier, where the notification group member identifier indicates that the group member of the group resource has a belonging group resource identifier list;
  • a creating module 703 configured to create an access control policy resource according to the creation request, and generate an access control policy resource identifier, where the access control policy resource includes the group resource identifier and the corresponding to the group resource identifier Operational authority.
  • the receiving module 701 is further configured to receive an update request of an access control policy resource, where the update request of the access control policy resource includes a group resource identifier and a required to be added in the access control policy resource.
  • the determining module 702 is further configured to: determine that the group resource corresponding to the group resource identifier to be added includes the notification group member identifier;
  • the method further includes: an adding module 704, configured to add the group resource identifier to be added and the operation authority corresponding to the group resource identifier to be added to the access control policy resource.
  • the device further includes: a sending module 705, configured to send, to the group server, a notification message that the group resource is referenced, where the group resource referenced notification message includes the access control policy resource identifier and The referenced group resource identifier in the access control policy resource.
  • a sending module 705 configured to send, to the group server, a notification message that the group resource is referenced, where the group resource referenced notification message includes the access control policy resource identifier and The referenced group resource identifier in the access control policy resource.
  • the receiving module 701 is further configured to receive a notification message that the group resource that is sent by the group server is deleted, and the notification message that the group resource is deleted includes the deleted group resource identifier and
  • the device further includes: a deleting module 706, configured to delete the deleted group resource identifier and the location in the access control policy resource according to the access control policy resource identifier The operation authority corresponding to the deleted group resource identifier is described.
  • FIG. 8 is a schematic diagram showing another structure of a resource access device in a machine communication system according to an embodiment of the present invention.
  • the program code for executing the solution of the present invention is stored in a memory by a general computer system structure, and is processed by a processor. To control execution.
  • the resource access device includes a bus, a processor (801), a memory (802), and a communication interface (803).
  • the bus can include a path to transfer information between various components of the computer.
  • the processor 801 can be a general purpose central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • One or more memories included in the computer system which may be read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or Other types of dynamic storage devices that store information and instructions may also be disk storage. These memories are connected to the processor via a bus.
  • the communication interface 803 can use any device such as a transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), and the like.
  • a transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), and the like.
  • RAN Radio Access Network
  • WLAN Wireless Local Area Network
  • a memory 802 such as a RAM, holds an operating system and a program for executing the inventive arrangements.
  • the operating system is a program that controls the running of other programs and manages system resources.
  • the program code for carrying out the inventive arrangement is stored in a memory and controlled by the processor for execution.
  • the program stored in the memory 802 is used by the instruction processor to perform a method of resource access in the machine communication, comprising: receiving an access request of the requestor resource to the accessed resource, wherein the access request includes an identifier of the accessed resource, a requester resource identifier and an operation for requesting the accessed resource; determining the accessed resource according to the identifier of the accessed resource; acquiring an access control policy resource of the accessed resource; determining the requestor resource as the access Controlling, in the policy resource, a group member of the group resource corresponding to the group resource identifier of the operation authority of the requested operation; performing the requested operation on the accessed resource.
  • FIG. 9 is another schematic structural diagram of an apparatus for configuring a resource identifier list of a resource to which a resource belongs in a machine communication system according to an embodiment of the present invention.
  • the program code for executing the solution of the present invention is stored in a general computer system structure. In memory, and executed by the processor.
  • the device for configuring the group resource identifier list to which the resource belongs includes a bus, a processor (901), a memory (902), and a communication interface (903).
  • the bus can include a path to transfer information between various components of the computer.
  • the processor 901 can be a general purpose central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • One or more memories included in the computer system which may be read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or Other types of dynamic storage devices that store information and instructions may also be disk storage. These memories are connected to the processor via a bus.
  • any device such as a transceiver can be used to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
  • RAN Radio Access Network
  • WLAN Wireless Local Area Network
  • a memory 902 such as a RAM, holds an operating system and a program for executing the inventive arrangements.
  • the operating system is a program that controls the running of other programs and manages system resources.
  • the program code for carrying out the inventive arrangement is stored in a memory and controlled by the processor for execution.
  • the method stored in the memory is used by the instruction processor to perform a method for configuring a group resource identifier list to which the resource belongs in a machine communication, including: receiving an operation request for adding a group member, where the operation request of the added group member includes a group a resource identifier and an identifier of the newly added group member, where the group resource identifier indicates a group resource to which the group member corresponding to the identifier of the newly joined group member is to join; determining that the group resource includes a notification a group member identifier; in the process of adding the identifier of the newly joined group member in the member list of the group resource, sending an update group to the group member corresponding to the identifier of the newly joined group member a first request message of the group resource identifier list, where the first request message includes the group resource identifier and information indicating that the group resource identifier is newly added, and the first request message indicates the newly added message
  • the group member corresponding to the identifier of the group member adds the group resource identifie
  • the apparatus for configuring the group resource identifier list to which the resource belongs in the machine communication system of the embodiment can be used to implement all the functions in the method embodiment of FIG. 3, and the specific implementation process can refer to the foregoing method embodiment. The related description is not repeated here.
  • FIG. 10 is a schematic structural diagram of another apparatus for operating an access control policy resource according to an embodiment of the present invention.
  • the program code for executing the solution of the present invention is stored in a memory by a processor. Control execution.
  • the operating device for the access control policy resource includes a bus, a processor (1001), a memory (1002), and a communication interface (1003).
  • the bus can include a path to transfer information between various components of the computer.
  • the processor 1001 can be a general purpose central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • One or more memories included in the computer system which may be read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or Other types of dynamic storage devices that store information and instructions may also be disk storage. These memories are connected to the processor via a bus.
  • the communication interface 1003 can use any device such as a transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), and the like.
  • a transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), and the like.
  • RAN Radio Access Network
  • WLAN Wireless Local Area Network
  • a memory 1002 such as a RAM, holds an operating system and a program for executing the inventive scheme.
  • the operating system is a program that controls the running of other programs and manages system resources.
  • the program code for carrying out the inventive arrangement is stored in a memory and controlled by the processor for execution.
  • the program stored in the memory 1002 is used by the instruction processor to perform a method for operating an access control policy resource in a machine communication, including: receiving a request for creating an access control policy resource, where the creation request includes a group resource identifier and a
  • the operation authority corresponding to the group resource identifier is specifically: the operation authority corresponding to the group resource identifier is: the operation authority of the group member of the group resource corresponding to the group resource identifier; determining the group
  • the group resource corresponding to the resource identifier includes a notification group member identifier, the notification group member identifier indicates that the group member of the group resource has a group resource identifier list, and the access control policy resource is created according to the creation request.
  • Generating an access control policy resource identifier where the access control policy resource includes the group resource identifier and the operation authority corresponding to the group resource identifier.
  • the device can be used to implement all the functions in the method embodiment of FIG. 4, and the specific implementation process can refer to the related description of the foregoing method embodiments, and details are not described herein again.
  • each embodiment focuses on the differences from the other embodiments.
  • the description is relatively simple, and the execution process of each unit specific function can be referred to the partial description of the method embodiment.
  • the device embodiments described above are merely illustrative, wherein the units illustrated as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, ie may be located in one place. Or it can be distributed to multiple network elements. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of the embodiment. Those of ordinary skill in the art can understand and implement without any creative effort.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明涉及通信领域,提供了一种机器通信中资源访问的方法及装置。该机器通信中资源访问的方法包括:接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;根据所述被访问资源的标识确定所述被访问资源;获取所述被访问资源的访问控制策略资源;确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;对所述被访问资源执行所述请求的操作。本发明通过判断请求者资源是否是具有操作权限的群组资源的群组成员,从而对资源实现基于群组的访问控制。

Description

一种资源访问的方法和装置 技术领域
本发明涉及信息技术领域,尤其涉及一种资源访问的方法及装置。
背景技术
机器通信(Machine-to-Machine Communications,M2M)是一种以机器智能交互为核心的、网络化的应用与服务。它通过在机器内部嵌入无线或有线通信模块以及应用处理逻辑,实现用户对监控、指挥调度、数据采集和测量等方面的信息化需求。M2M系统中,各种M2M设备,如各种传感器,直接经过M2M网关接入到M2M业务平台,从而实现各种M2M业务。例如电力抄表、智能家居等。通过M2M业务平台所提供的业务能力,可以获取M2M设备采集的数据,或对M2M设备进行控制和管理。
在现有的M2M规范中,采用RESTful(Representational State Transfer)的架构,任何M2M设备、M2M网关或M2M业务平台以及它们所提供的业务能力,都可以被抽象为资源并且具有唯一的资源标识,即URI(Uniform Resource Identifier)。每个被访问资源都可以设置相应的访问权限,通过引用一个访问控制策略资源,如accessRight资源或accessControlPolicy资源等来实现系统中对被访问资源的访问控制功能。后续以accessControlPolicy资源为例说明进行说明。
被访问资源所属的设备收到originator对资源的请求消息时,根据该被访问资源的访问控制策略标识accessControlPolicyID去获取相应的访问控制策略资源,访问控制策略资源中的每一条访问控制规则都可以看作一个三元组,<accessControlOriginators、accessControlContexts、accessControlOperations>,其中accessControlOriginator表示具有操作权限的请求者资源标识(可能是某个CSE-ID、AE-ID或者是serviceProvider domain,也可能是All);accessControlOperations表示该条规则所允许的操作权限(可能包括Retrieve、Create、Update、Delete、Discovery和Notify中的一个或者多个);accessControlContexts是可选的,定义了accessControlOriginator具有accessControlOperations中规定的操作权限的条件,例如在某个时间范围内,每个地理区域内等等。作为一种可选方式,accessControlContexts的取值可以 为空,即不对操作权限的条件进行限制和描述。被访问资源所属的设备根据获取到的访问控制策略资源中的accessControlOriginator属性中是否包含请求者originator标识,以及accessControlOperations属性中是否包含originator对被访问资源请求的操作来判断originator是否具有对被访问资源的访问权限。只有两个条件都满足时才表示originator通过了访问控制权限检查。
现有技术中,<accessControlOriginators>只针对访问被访问资源的请求者资源而设定,因此,当多个请求者资源都需要访问被访问资源时,需要在访问控制策略资源中为该多个请求者资源分别设置相应的权限。也就是说,如果当一个群组的群组成员对同一个被访问资源具有相同的操作权限时,需要为每个群组成员单独配置相同的访问控制权限。从而使得访问控制策略资源包括的内容冗长,且所述访问控制策略资源所属的设备对所述访问控制策略资源的创建和更新过程非常复杂。此外,直接在所述访问控制策略资源中增加群组资源标识以及相应的权限,则由于访问所述被访问资源的请求设备并不是群组设备而无法确认请求设备具有的权限,从而无法确保请求设备对被访问资源进行访问的权限控制。
发明内容
本发明实施例提供了一种应用于M2M系统中的资源访问方法及装置,能够充分利用群组的集合功能,对被访问资源实现基于群组的访问控制。
第一方面,本发明提供一种资源访问的方法,所述方法应用于机器通信M2M系统中,包括:
接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
根据所述被访问资源的标识确定所述被访问资源;
获取所述被访问资源的访问控制策略资源;
确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
对所述被访问资源执行所述请求的操作。
结合第一方面,所述确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员,具体 为:确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者
确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。
结合第一方面的上述所有可能实现方式,所述确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,具体为:
获取所述请求者资源的所属群组资源标识列表,确定所述所属群组资源标识列表包含所述具有所述请求的操作的操作权限的群组资源标识;或
获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,确定所述成员列表包含所述请求者资源标识。
结合第一方面的上述所有可能实现方式,所述获取所述请求者资源的所属群组资源标识列表,具体为:
根据所述请求者资源标识,向所述请求者资源发送获取请求者资源的所属群组资源标识列表的请求消息,接收所述请求者资源返回的所述所属群组资源标识列表;或者
所述访问请求还包括所述请求者资源的所属群组资源标识列表,获取所述访问请求中的所述所属群组资源标识列表。
结合第一方面的上述所有可能实现方式,在所述确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员之前,所述方法还包括:
确定所述访问控制策略资源中不存在所述请求者资源标识;或者
确定所述访问控制策略资源中存在所述请求者资源标识,以及确定所述请求者资源标识对应的操作权限不包含所述请求的操作。
第二方面,本发明提供一种配置资源所属群组资源标识列表的方法,包括:
接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
确定所述群组资源包含通知群组成员标识;
在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
结合第二方面,在所述接收增加群组成员的操作请求之前,所述方法还包括:
接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表;
根据所述创建群组资源的操作请求,创建所述群组资源,生成所述群组资源标识;其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表;
向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
结合第二方面的上述所有可能实现方式,该方法进一步包括:接收删除群组成员的操作请求,所述删除群组成员的操作请求包含所述群组资源标识和需删除的群组成员的标识;
确定所述群组资源包含所述通知群组成员标识;
在所述群组资源的成员列表中删除所述需删除的群组成员的标识的过程中,向所述需删除的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第二请求消息,其中,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述需删除的群组成员的标识对应的群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
结合第二方面的上述所有可能实现方式,所述方法还包括
接收群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所 述群组资源标识和引用所述群组资源的访问控制策略资源标识;
在所述群组资源中记录所述访问控制策略资源标识。
结合第二方面的上述所有可能实现方式,所述方法还包括:接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识;
在删除所述群组资源的过程中,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
结合第二方面的上述所有可能实现方式,在所述删除所述群组资源之前,所述方法还包括:
确定所述群组资源包含所述访问控制策略资源标识;
向所述访问控制策略资源标识对应的访问控制策略资源发送群组资源被删除的通知消息,指示所述群组资源已经被删除。
第三方面,本发明提供一种对访问控制策略资源的操作方法,包括:
接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;
确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
结合第三方面,在所述创建访问控制策略资源之后,所述方法还包括:
接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限;
确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识;
将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操 作权限增加到所述访问控制策略资源中。
结合第三方面的上述所有可能实现方式,所述方法进一步还包括:向群组服务器发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。
结合第三方面的上述所有可能实现方式,所述方法还包括:接收所述群组服务器发送的群组资源被删除的通知消息,所述群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识;
根据所述访问控制策略资源标识,在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。
结合第三方面的上述所有可能实现方式,所述确定所述群组资源标识对应的群组资源包含通知群组成员标识,具体为:
向所述群组服务器发送携带所述群组资源标识的获取所述群组资源的通知群组成员标识的请求,接收所述群组服务器返回的响应消息,所述响应消息指示所述群组资源标识对应的群组资源包含所述通知群组成员标识;根据所述响应消息,确定所述所述群组资源标识对应的群组资源包含通知群组成员标识;或者在所述创建请求中携带指示所述群组资源标识对应的群组资源包含所述通知群组成员标识的信息,根据所述创建请求,确定所述群组资源标识对应的群组资源包含通知群组成员标识。
第四方面,本发明提供一种资源访问的装置,所述装置应用于机器通信M2M系统中,包括:接收模块,用于接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
确定模块,用于根据所述被访问资源的标识确定所述被访问资源;
获取模块,用于根获取所述被访问资源的访问控制策略资源;
所述确定模块,还用于确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
执行模块,用于对所述被访问资源执行所述请求的操作。
结合第四方面,所述确定模块具体用于:
确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群 组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者
确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。
结合第四方面的上述所有可能实现方式,所述确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,具体包括:
获取所述请求者资源的所属群组资源标识列表,确定所述所属群组资源标识列表包含所述具有所述请求的操作的操作权限的群组资源标识;或者
获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,确定所述成员列表包含所述请求者资源标识。
结合第四方面的上述所有可能实现方式,所述获取所述请求者资源的所属群组资源标识列表,具体为:
根据所述请求者资源标识,向所述请求者资源发送获取请求者资源的所属群组资源标识列表的请求消息,接收所述请求者资源返回的所述所属群组资源标识列表;或者
所述访问请求还包括所述请求者资源的所属群组资源标识列表,获取所述访问请求中的所述所属群组资源标识列表。
第五方面,本发明提供一种配置资源所属群组资源标识列表的装置,包括:
接收模块,用于接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
确定模块,用于确定所述群组资源包含通知群组成员标识;
发送模块,用于在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
结合第五方面,所述装置还包括:
所述接收模块,还用于接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表;
创建模块,用于根据所述创建群组资源的操作请求,创建所述群组资源,生成所述群组资源标识;其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表;
所述发送模块,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
结合第五方面的上述所有可能实现方式,所述装置还包括:
所述接收模块,还用于接收群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述群组资源标识和引用所述群组资源的访问控制策略资源标识;
记录模块,用于在所述群组资源中记录所述访问控制策略资源标识。
结合第五方面的上述所有可能实现方式,所述装置还包括:
所述接收模块,还用于接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识;
所述发送模块,还用于在删除所述群组资源的过程中,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
结合第五方面的上述所有可能实现方式,所述装置在所述删除所述群组资源之前,还包括:
所述确定模块,还用于确定所述群组资源包含所述访问控制策略资源标识;
所述发送模块,还用于向所述访问控制策略资源标识对应的访问控制策略资源发送群组资源被删除的通知消息,指示所述群组资源已经被删除。
第六方面,本发明提供一种对访问控制策略资源的操作装置,包括:接收 模块,用于接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;
确定模块,用于确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
创建模块,用于根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
结合第六方面,所述装置还包括:
所述接收模块,还用于接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限;
所述确定模块,还用于确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识;
增加模块,用于将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操作权限增加到所述访问控制策略资源中。
结合第六方面的上述所有可能实现方式,所述装置还包括:
发送模块,用于向群组服务器发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。
结合第六方面的上述所有可能实现方式,所述装置还包括:
所述接收模块,还用于接收所述群组服务器发送的群组资源被删除的通知消息,所述群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识;
删除模块,用于根据所述访问控制策略资源标识,在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。
本发明提供的资源访问的方法,通过判断请求者资源是否是具有操作权限 的群组资源的群组成员,从而可以对资源实现基于群组的访问控制。
附图说明
为了更清楚地说明本发明实施例的技术方案,下面将对实施例描述所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种资源访问的方法流程图;
图2为本发明实施例提供的一种端到端的基于群组的访问控制的资源访问方法的流程图;
图3为本发明实施例提供的对资源的所属群组资源标识列表进行配置的方法的流程图;
图4为本发明实施例提供的一种创建访问控制策略资源的方法的流程图;
图5为本发明实施例提供的一种机器通信系统中资源访问装置的结构示意图;
图6为本发明实施例提供的一种机器通信系统中配置资源所属群组资源标识列表的装置的结构示意图;
图7为本发明实施例提供的一种机器通信系统中对访问控制策略资源的操作装置的结构示意图;
图8为本发明实施例提供的一种机器通信系统中资源访问装置的另一种结构示意图;
图9为本发明实施例提供的一种机器通信系统中配置资源所属群组资源标识列表的装置的另一种结构示意图;
图10为本发明实施例提供的一种机器通信系统中对访问控制策略资源的操作装置的另一种结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明的一部分实施例,而不是全部实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下获取的所有其他实施例,都属于本发明保护的范围。
本发明实施例提供一种资源访问的方法,所述方法应用于机器通信M2M系统中,本方法实施例描述的是被访问资源所属设备的处理流程。如图1所示,包括下面的步骤:
步骤102、接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
具体的,被访问资源所属的设备接收请求者资源通过所属的设备对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问的资源请求的操作。在现有的M2M规范中,任何M2M设备、M2M网关或M2M业务平台以及注册在它们上面的应用,都可以被抽象为资源并且具有唯一的资源标识,即URI(Uniform Resource Identifier),根据资源标识可以唯一定位资源。对被访问资源请求的操作包括获取Retrieve、创建Create、更新Update和删除Delete等。需要说明的是,被访问资源所属的设备上可能同时存在多个资源,所述被访问资源所属的设备可以根据被访问资源的标识确定请求者资源希望访问的资源。
作为一个例子,本发明实施例中所述访问请求中对被访问资源请求的操作为Update,请求者资源标识为AE1=http://m2m.example.com/xxx/ApplicationEntity1。
步骤104、根据所述被访问资源的标识确定所述被访问资源;
如步骤102所述,M2M系统中每个资源都具有唯一的资源标识,所以根据所述被访问资源的标识可以确定所述被访问资源。
步骤106、获取所述被访问资源的访问控制策略资源;
具体的,在M2M系统中,被访问资源的访问控制功能可以通过访问控制策略(accessControlPolicy)来实现。每个被访问资源都有一个对应的访问控制策略资源标识accessControlPolicyID(如果被访问资源本身没有accessControlPolicyID属性,则自动继承该资源的父资源的accessControlPolicyID属性或者采用其他默认的accessControlPolicyID属性)。被访问资源所属的设备可以根据accessControlPolicyID去获取相应的访问控制策略资源。所述访问控制策略资源可以位于被访问资源所属的设备,也可以位于其它的设备上。
步骤108:确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
其中,确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员,具体为:确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,且所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。这两种方法本质是一致的,都需要判断所述访问控制策略中是否存在群组资源标识、群组资源标识对应的操作权限是否为所述请求的操作以及所述请求者资源是否为群组资源标识对应的群组资源的群组成员,只是判断的先后顺序不一样。下面以第一种方法进行详细的说明:
具体的,访问控制策略资源中的每一条访问控制规则中至少包括<accessControlOriginators、accessControlOperations>。需要说明的是,本发明实施例中accessControlContexs为空,表示不对操作权限的条件进行限制和描述,由于和本发明无关,后续说明中不再强调。
被访问资源所属的设备确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,具体为:确定accessControlOperations中是否包含请求者资源通过所属的设备对被访问资源请求的操作;当确定accessControlOperations中包含请求者资源通过所属的设备对被访问资源请求的操作后,再判断这条访问控制规则中的accessControlOriginators中是否是一个群组资源标识。假设表1所示为步骤106中获取到的访问控制策略资源。表1访问控制策略资源中第三行的访问控制规则中accessControlOperations中包含请求者资源通过所属的设备对被访问资源请求的操作Update,并且这条访问控制规则中的accessControlOriginators是一个群组资源标识Group1,所以可以确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识。
表1 访问控制策略
accessControlOriginators accessControlContexs accessControlOperation
AE1 / Retrieve/Create
CSE1 / Update/Create/Delete
Group1 / Update/Create
Group2 / Retrieve/Create
可选的,在确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识的群组成员之前,被访问资源所属的设备根据所述访问控制策略,确定所述访问控制策略资源中不存在所述请求者资源标识;或者确定所述访问控制策略资源中存在所述请求者资源标识,以及确定所述请求者资源标识对应的操作权限不包含所述请求的操作。这种情况下,依据现有技术,请求者资源对被访问资源的访问将被拒绝。对资源的访问,引入基于群组的访问控制之后,需要进一步确定所述请求者资源是否为具有所述请求的操作的群组资源的群组成员。
从表1所述的访问控制策略资源中,可以看到存在具有Update操作权限的群组标识Group1,如果请求者资源AE1是群组Group1的群组成员的话,那么AE1将也具有Update的操作权限。所以为了判断AE1是否具有对所述被访问资源的Upadate操作权限,需要判断AE1是否为Group1的群组成员。
具体的,确定所述请求者资源是否为所述确定的群组资源标识对应的群组资源的群组成员具体有两种实现方式:
实现方式一:获取所述请求者资源的所属群组资源标识列表,如果所述群组资源标识列表中包含所述群组资源标识,则确定请求者资源是所述群组资源标识对应的群组资源的群组成员;如果所述群组资源标识列表中不包含所述群组资源标识,则确定请求者资源不是所述群组资源标识对应的群组资源的群组成员,其中,所述所属群组资源标识列表中包括所述请求者资源所属的群组资源的群组资源标识;或者,
实现方式二:获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,查看所述群组资源的成员列表中是否包含所述请求者资源标识,如果群组资源的成员列表中包含所述请求者资源标识,则确定请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;如果群组资 源的成员列表中不包含所述请求者资源标识,则确定请求者资源不是所述确定的群组资源标识对应的群组资源的群组成员。
具体的,对于实现方式一,被访问资源所属的设备可以根据步骤102中所述访问请求中的请求者资源标识,向所述请求者资源所属的设备发送获取请求者资源的所属群组资源标识列表的请求消息。在本发明实施例中,所述获取请求者资源的所属群组资源标识列表的请求消息的目的地址可以是http://m2m.example.com/xxx/ApplicationEntity1,以获取整个AE1资源,然后再进一步获取AE1资源的所属群组资源标识列表;目的地址也可以是http://m2m.example.com/xxx/ApplicationEntity1/memberOf,从而只获取AE1的所属群组资源标识列表。其中资源AE1的memberOf属性中存储的就是AE1的所属群组资源标识列表。所述所属群组资源标识列表中包括所述请求者资源所属的群组资源的群组资源标识。
可选的,步骤102中所述访问请求中进一步还包括请求者资源的所属群组资源标识列表,则步骤108中,被访问资源所属的设备可以直接根据所述访问请求获取请求者资源的所属群组资源标识列表。
步骤110:对所述被访问资源执行所述请求的操作。
具体的,被访问资源所属的设备按照所述访问请求,执行对被访问资源请求的操作,并且可选的,向请求者资源所属的设备返回成功响应消息。
需要说明的是,被访问资源所属的设备除了需要对请求者资源的访问权限进行检查外,可能还包括其他检查步骤,在这些检查步骤中也可能会因为其他的一些原因导致对所述被访问资源请求的操作无法成功执行,返回失败响应消息,所述失败响应消息中包括请求被拒绝的原因。本发明实施例假设不存在其他检查步骤或者其他检查步骤都是通过的。
本发明实施例提供的资源访问的方法,通过判断请求者资源是否是具有操作权限的群组资源的群组成员,从而对资源实现基于群组的访问控制。
图2为本发明提供的一种应用于机器通信M2M系统的端到端的基于群组的访问控制的资源访问方法的流程图。如图2所述,该方法包括如下步骤:
步骤202:请求者资源所属的设备向被访问资源所属的设备发送资源访问请求,所述访问请求中携带被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
具体的,步骤202与图1所述的实施例中的步骤102相同,具体内容请参阅步骤102的相关内容,这里不再赘述。
步骤204:所述被访问资源所属的设备接收到所述访问请求后,获取所述被访问资源的访问控制策略资源标识;
具体的,oneM2M标准中的访问控制功能是通过访问控制策略(accessControlPolicy)来实现的。被访问资源可以包含对应的访问控制策略资源标识accessControlPolicyID。如果该资源本身不包含accessControlPolicyID属性,则自动继承父资源的accessControlPolicyID属性或者其他默认的accessControlPolicyID属性。被访问资源所属的设备根据被访问资源的accessControlPolicyID去获取相应的访问控制策略资源。所述访问控制策略资源可以位于被访问资源所属的设备,也可以位于其他设备上。
步骤206:根据所述访问控制策略资源标识,所述被访问资源所属的设备向访问控制策略资源所属的设备发送获取访问控制策略资源的请求;
需要说明的是,本发明实施例中访问控制策略资源与被访问资源不在同一个设备上,实际上该访问控制策略资源也可能位于被访问资源所属的设备上。当该访问控制策略资源位于被访问资源所属的设备上时,被访问资源所属的设备和访问控制策略资源所属的设备之间的信令交互将为被访问资源所属的设备内部的信令交互。
步骤208:所述访问控制策略资源所属的设备根据所述获取访问控制策略资源的请求,向所述被访问资源所属的设备发送成功获取访问控制策略资源的响应消息,所述成功获取访问控制策略资源的响应消息中包含所述被访问资源的访问控制策略资源;
步骤210:根据所述访问控制策略资源,被访问资源所属的设备确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识;
其中,确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,具体为:确定accessControlOperations中是否包含请求者资源通过所属的设备对被访问资源请求的操作;当确定accessControlOperations中包含请求者资源通过所属的设备对被访问资源请求的操作后,再判断这条访问控制规则中的accessControlOriginators中是否是一个群组资源标识。
步骤212:所述被访问资源所属的设备向请求者资源所属的设备发送获取 请求者资源的所属群组资源标识列表的请求消息;
具体的,被访问资源所属设备可以根据步骤202中所述访问请求中的请求者资源标识,向请求者资源所属的设备发送请求消息去获取请求者资源的所属群组资源标识列表。
步骤214:请求者资源所属的设备向所述被访问资源所属的设备发送成功获取所属群组资源标识列表的响应消息,其中,所述成功获取所属群组资源标识列表的响应消息中包含请求者资源的所属群组资源标识列表。
需要说明的是,如果步骤202中的访问请求中进一步还包括请求者资源的所属群组资源标识列表,那么步骤212和步骤214则不是必需的,被访问资源所属的设备可以直接根据所述访问请求获取请求者资源的所属群组资源标识列表。
步骤216:根据所述所属群组资源标识列表,所述被访问资源所属的设备确定所述请求者资源属于所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
具体的,所述被访问资源所属的设备将获取到的所属群组资源标识列表与所述具有所述请求的操作的操作权限的群组资源标识进行对比,当所属群组资源标识列表中存在所述具有所述请求的操作的操作权限的群组资源标识时,则确定所述请求者资源属于所述具有所述请求的操作的操作权限的群组资源标识对应群组资源的群组成员。当确定所述请求者资源属于所述具有所述请求的操作的操作权限的群组资源标识对应群组资源的群组成员时,表明所述请求者资源具有对被访问资源的所述请求的操作的操作权限。
步骤218:所述被访问资源所属的设备执行所述请求的操作;
具体的,所述被访问资源所属的设备按照所述访问请求,执行对被访问资源请求的操作,并且可选的,向请求者资源所属的设备返回成功响应消息。
本发明实施例提供的资源访问的方法,通过判断请求者资源是否是具有操作权限的群组资源的群组成员,从而对资源实现基于群组的访问控制。
图3为本发明提供的一种应用于机器通信M2M系统中,对资源的所属群组资源标识列表进行配置的方法的流程图。本方法实施例描述的是群组资源所属的设备的处理流程,其中群组资源所属的设备简称群组服务器。在M2M系统中,所述群组服务器可以是存储和维护群组资源的业务平台、M2M网关、 M2M设备等。如图3所述,该方法包括如下步骤:
步骤302:接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
具体的,群组服务器接收到增加群组成员的操作请求,所述增加群组成员的操作请求包含所述群组资源标识和新加入的群组成员的标识。
步骤304:确定所述群组资源包含通知群组成员标识;
具体的,所述通知群组成员标识可以有多种表现形式,例如:所述群组资源的群组类型或群组用途为访问控制、所述群组资源包含通知群组成员标识或所述群组资源的名称中包含访问控制标记等等。本发明方案对所述通知群组成员标识的具体形式不作限定。为了便于表述,本发明实施例后续步骤中以所述群组资源包含通知群组成员标识为例进行说明。
当所述群组资源包含通知群组成员标识时,表明所述群组资源的在更新群组成员的时候,需要更新所述群组资源中发生变化的群组成员的所属群组资源标识列表。
步骤306:在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
具体的,当所述新加入的群组成员被加入所述群组资源中作为所述群组资源的群组成员时,需要更新所述新加入的群组成员的所属群组资源标识列表,即在所述新加入的群组成员的所属群组资源标识列表中加入所述群组资源标识。
具体的,群组服务器在接收到增加群组成员的操作请求,确定所述群组资源包含通知群组成员标识后,根据所述增加群组成员的操作请求,在所述群组资源的成员列表中增加所述新加入的群组成员的标识,并且向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源 标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。需要说明的是,本发明对群组服务器在所述群组资源的成员列表中增加所述新加入的群组成员的标识和发送第一请求消息的顺序不做限定。
可选的,群组服务器接收所述新加入的群组成员返回的成功更新所属群组资源标识列表的通知消息,成功更新所属群组资源标识列表的通知消息指示所述新加入的群组成员已经成功将所述群组资源标识加入到自身所属的群组资源标识列表中。
进一步的,在步骤302之前,所述方法还包括群组服务器接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表。根据所述创建群组资源的操作请求,群组服务器创建所述群组资源,生成所述群组资源标识,其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表。群组服务器向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。可选的,群组服务器接收所述所述群组资源的成员列表中的各群组成员返回的成功更新所属群组资源标识列表的通知消息,成功更新所属群组资源标识列表的通知消息指示所述群组资源的成员列表中的各群组成员已经成功将所述群组资源标识加入到自身所属的群组资源标识列表中。
进一步的,所述群组服务器接收删除群组成员的操作请求,所述删除群组成员的操作请求包含所述群组资源标识和需删除的群组成员的标识。群组服务器确定所述群组资源包含所述通知群组成员标识后,向所述需删除的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第二请求消息,其中,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述需删除的群组成员的标识对应的群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。群组服务器在所述群组资源的成员列表中删除所述需删除的群组成员的标识。需要说明的是,本发明对群组服务器在所述群组资源的成员列表中删除所述需删除的群组成员 的标识和发送第二请求消息的顺序不做限定。可选的,群组服务器接收所述需删除的群组成员返回的成功更新所属群组资源标识列表的通知消息,成功更新所属群组资源标识列表的通知消息指示所述需删除的群组成员已经成功将所述群组资源标识从自身所属的群组资源标识列表中删除。
进一步的,所述群组服务器接收访问控制策略资源所属的设备发送的群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述群组资源标识和引用所述群组资源的访问控制策略资源标识。群组服务器在所述群组资源中记录所述访问控制策略资源标识,其中,记录所述访问控制策略资源标识具体实现还可以是创建所述访问控制策略资源对所述群组资源的订阅。当所述群组资源被删除的时候,群组服务器向引用所述群组资源的访问控制策略资源所属的设备发送群组资源被删除的通知消息,指示所述群组资源已经被删除,以便于访问控制策略资源所属的设备将引用了所述群组资源标识的访问控制规则删除。可选的,群组服务器接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识。群组服务器根据所述删除群组资源的操作请求,删除所述群组资源,并且向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。可选的,群组服务器接收所述群组资源的成员列表中的各群组成员返回的成功更新所属群组资源标识列表的通知消息,成功更新所属群组资源标识列表的通知消息指示所述群组资源的成员列表中的各群组成员已经成功将所述群组资源标识从自身所属的群组资源标识列表中删除。
所述群组资源被删除后,引用该群组资源的访问控制策略资源中的访问控制规则也就失去引用的基础。可选的,在删除所述群组资源之前,所述群组资服务器根据所述群组资源标识,确定所述群组资源包含访问控制策略资源标识。根据所述访问控制策略资源标识,群组服务器向所述访问控制策略资源所属的设备发送群组资源被删除的通知消息,指示所述群组资源已经被删除,以便于所述访问控制策略资源所属的设备删除访问控制策略资源中引用了所述群组资源的访问控制规则。
如图4所示,本实施例给出一种置应用于机器通信M2M系统中创建访问 控制策略资源的方法的流程图,具体步骤如下:
步骤402:接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识指示的群组资源对应的群组成员的操作权限;
具体的,访问控制策略资源所属的设备接收访问控制策略资源的创建请求,其中所述访问控制策略资源的创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述具有操作权限的群组资源标识对应的操作权限具体为:所述群组资源标识指示的群组资源对应的群组成员的操作权限。所述访问控制策略资源所属的设备可以是M2M系统中的M2M网关、M2M设备或者是M2M平台所属的设备。
所述访问控制策略资源的创建请求指示所述访问控制策略资源所属的设备建立一个访问控制策略资源,该访问控制策略资源包括一个基于群组的访问控制规则。
步骤404:确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
具体的,所述通知群组成员标识可以有多种表现形式,例如:所述群组资源的群组类型或群组用途为访问控制、所述群组资源包含通知群组成员的标识或所述群组资源的名称中包含访问控制标记等等,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表,本发明方案对所述通知群组成员标识的具体形式不作限定。为了便于表述,本发明实施例后续步骤中以所述群组资源包含通知群组成员标识为例进行说明。
具体的,确定所述群组资源标识对应的群组资源包含通知群组成员标识,具体为:
根据所述群组资源标识,访问控制策略资源所属的设备向所述群组资源标识对应的群组资源所属的设备发送获取所述群组资源的通知群组成员标识的请求,接收所述群组资源标识指示的群组资源所属的设备返回的获取通知群组成员标识的响应消息,所述获取通知群组成员标识的响应消息中指示所述群组资源标识对应的群组资源包含所述通知群组成员标识;根据所述获取通知群组 成员标识的响应消息,访问控制策略资源所属的设备确定所述群组资源标识对应的群组资源包含通知群组成员标识;需要说明的是,访问控制策略资源所属的设备和群组资源所属的设备也相同的设备,当访问控制策略资源所属的设备和群组资源所属的设备是相同的设备时,两者之间的信息交互在设备内部进行。或者,
在步骤402中所述创建请求中携带指示所述群组资源标识对应的群组资源包含所述通知群组成员标识的信息,根据所述创建请求,访问控制策略资源所属的设备确定所述群组资源标识对应的群组资源包含通知群组成员标识。
步骤406:根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
具体的,访问控制策略资源所属的设备根据所述访问控制策略资源的创建请求,创建访问控制策略资源,生成访问控制策略资源标识。所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。可选的,所述访问控制策略资源所属的设备向所述群组资源所属的设备发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。
进一步的,当成功创建所述访问控制策略资源后,访问控制策略资源所属的设备接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限。访问控制策略资源所属的设备确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识后,将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操作权限增加到所述访问控制策略资源中。可选的,所述访问控制策略资源所属的设备向所述需增加的群组资源所属的设备发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。需要说明的是,本发明实施例中将访问控制策略资源中accessControlOriginators中的群组资源标识统称为被引用的群组资源标识。
可选的,当所述被引用的群组资源被删除后,访问控制策略资源所属的设备接收被删除的群组资源所属的设备发送的群组资源被删除的通知消息,所述 群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识。根据所述访问控制策略资源标识,访问控制策略资源所属的设备在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。显然,这里所述的被删除的群组资源属于所述被引用的群组资源。
可选的,当根据步骤402中接收的访问控制策略资源的创建请求中不包括群组资源标识时,则表明所述访问控制策略资源的创建请求,请求创建的访问控制策略资源没有针对群组的访问控制规则。按照所述访问控制策略的创建请求,建立相应的访问控制策略资源。进一步的,当根据步骤402中接收的访问控制策略资源的创建请求中包括群组资源标识时,则表明所述访问控制策略资源的创建请求,请求创建的访问控制策略资源包括一个针对群组的访问控制规则。如果在步骤404中,确定所述群组资源不包含通知群组成员标识,则访问控制策略资源所属的设备拒绝访问控制策略资源的创建请求,并向请求设备发送失败响应消息,所述失败响应消息中携带拒绝请求的原因为所述访问控制策略资源信息中包含不符合条件的群组资源标识。
本发明实施例中,提供了一种对资源的所属群组资源标识列表进行配置的方法,当需要对群组资源进行操作而导致群组资源的群组成员所属的群组发生变化时,更新群组成员的所属群组资源标识列表,从而为基于群组的访问控制提供了可能。
图5所示为本发明实施例提供的一种机器通信系统中资源访问装置的示意图,包括:
接收模块501,用于接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
确定模块502,用于根据所述被访问资源的标识确定所述被访问资源;
获取模块503,用于根获取所述被访问资源的访问控制策略资源;
所述确定模块502,还用于确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
执行模块504,用于对所述被访问资源执行所述请求的操作。
具体的,所述确定模块502具体用于:确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。
其中,所述确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,具体包括:获取所述请求者资源的所属群组资源标识列表,确定所述所属群组资源标识列表包含所述具有所述请求的操作的操作权限的群组资源标识;或者获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,确定所述成员列表包含所述请求者资源标识。
其中,所述获取所述请求者资源的所属群组资源标识列表,具体为:根据所述请求者资源标识,向所述请求者资源发送获取请求者资源的所属群组资源标识列表的请求消息,接收所述请求者资源返回的所述所属群组资源标识列表;或者所述访问请求还包括所述请求者资源的所属群组资源标识列表,获取所述访问请求中的所述所属群组资源标识列表。
可选的,在所述确定所述请求者资源为所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员之前,所述确定模块502,还用于确定所述访问控制策略资源中不存在所述请求者资源标识;或者确定所述访问控制策略资源中存在所述请求者资源标识,以及确定所述请求者资源标识对应的操作权限不包含所述请求的操作。
图6所示为本发明实施例提供的一种机器通信系统中配置资源所属群组资源标识列表的装置的示意图,包括:
接收模块601,用于接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
确定模块602,用于确定所述群组资源包含通知群组成员标识;
发送模块603,用于在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述 群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
可选的,所述接收模块601,还用于接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表;所述装置还包括创建模块604,用于根据所述创建群组资源的操作请求,创建所述群组资源,生成所述群组资源标识;其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表;所述发送模块603,还用于向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
可选的,所述接收模块601,还用于接收删除群组成员的操作请求,所述删除群组成员的操作请求包含所述群组资源标识和需删除的群组成员的标识;所述确定模块602,还用于确定所述群组资源包含所述通知群组成员标识;所述发送模块603,还用于在所述群组资源的成员列表中删除所述需删除的群组成员的标识的过程中,向所述需删除的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第二请求消息,其中,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述需删除的群组成员的标识对应的群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
可选的,所述接收模块601,还用于接收群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述群组资源标识和引用所述群组资源的访问控制策略资源标识;所述装置还包括记录模块605,用于在所述群组资源中记录所述访问控制策略资源标识。
可选的,所述接收模块601,还用于接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识;所述发送模块,还用于在删除所述群组资源的过程中,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群 组资源的成员列表中的各群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
可选的,所述装置在所述删除所述群组资源之前,所述确定模块602,还用于确定所述群组资源包含所述访问控制策略资源标识;所述发送模块603,还用于向所述访问控制策略资源标识对应的访问控制策略资源发送群组资源被删除的通知消息,指示所述群组资源已经被删除。
图7所示为本发明实施例提供的一种机器通信系统中对访问控制策略资源的操作装置的示意图,包括:
接收模块701,用于接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;
确定模块702,用于确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
创建模块703,用于根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
可选的,所述接收模块701,还用于接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限;所述确定模块702,还用于确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识;所述装置进一步还包括:增加模块704,用于将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操作权限增加到所述访问控制策略资源中。
可选的,所述装置还包括:发送模块705,用于向群组服务器发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。需要说明的是,本发明实施例中将访问控制策略资源中accessControlOriginators中的群组资源标识统称为被引用的群组资源标识。
可选的,所述接收模块701,还用于接收所述群组服务器发送的群组资源被删除的通知消息,所述群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识;所述装置进一步还包括:删除模块706,用于根据所述访问控制策略资源标识,在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。
图8所示的是本发明实施例提供的一种机器通信系统中资源访问装置的另一种结构示意图,采用通用计算机系统结构,执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。资源访问装置包括总线,处理器(801),存储器(802),通信接口(803)。
总线可包括一通路,在计算机各个部件之间传送信息。
处理器801可以是一个通用中央处理器(CPU),微处理器,特定应用集成电路application-specific integrated circuit(ASIC),或一个或多个用于控制本发明方案程序执行的集成电路。计算机系统中包括的一个或多个存储器,可以是只读存储器read-only memory(ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器random access memory(RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是磁盘存储器。这些存储器通过总线与处理器相连接。
通信接口803,可以使用任何收发器一类的装置,以便与其他设备或通信网络通信,如以太网、无线接入网(RAN)、无线局域网(WLAN)等.
存储器802,如RAM,保存有操作系统和执行本发明方案的程序。操作系统是用于控制其他程序运行,管理系统资源的程序。执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。
存储器802中存储的程序用于指令处理器执行一种机器通信中资源访问的方法,包括:接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;根据所述被访问资源的标识确定所述被访问资源;获取所述被访问资源的访问控制策略资源;确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;对所述被访问资源执行所述请求的操作。
可以理解的是,本实施例的一种机器通信系统中资源访问装置可用于实现 图1和图2所述方法实施例中的所有功能,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
图9所示的是本发明实施例提供的一种机器通信系统中配置资源所属群组资源标识列表的装置的另一种结构示意图,采用通用计算机系统结构,执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。配置资源所属群组资源标识列表的装置包括总线,处理器(901),存储器(902),通信接口(903)。
总线可包括一通路,在计算机各个部件之间传送信息。
处理器901可以是一个通用中央处理器(CPU),微处理器,特定应用集成电路application-specific integrated circuit(ASIC),或一个或多个用于控制本发明方案程序执行的集成电路。计算机系统中包括的一个或多个存储器,可以是只读存储器read-only memory(ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器random access memory(RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是磁盘存储器。这些存储器通过总线与处理器相连接。
通信接口903,可以使用任何收发器一类的装置,以便与其他设备或通信网络通信,如以太网,无线接入网(RAN),无线局域网(WLAN)等.
存储器902,如RAM,保存有操作系统和执行本发明方案的程序。操作系统是用于控制其他程序运行,管理系统资源的程序。执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。
存储器中存储的程序用于指令处理器执行一种机器通信中配置资源所属群组资源标识列表的方法,包括:接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;确定所述群组资源包含通知群组成员标识;在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
可以理解的是,本实施例的一种机器通信系统中配置资源所属群组资源标识列表的装置可用于实现图3所述方法实施例中的所有功能,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
图10所示的是本发明实施例提供的对访问控制策略资源的操作装置的另一种结构示意图,采用通用计算机系统结构,执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。对访问控制策略资源的操作装置包括总线,处理器(1001),存储器(1002),通信接口(1003)。
总线可包括一通路,在计算机各个部件之间传送信息。
处理器1001可以是一个通用中央处理器(CPU),微处理器,特定应用集成电路application-specific integrated circuit(ASIC),或一个或多个用于控制本发明方案程序执行的集成电路。计算机系统中包括的一个或多个存储器,可以是只读存储器read-only memory(ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器random access memory(RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是磁盘存储器。这些存储器通过总线与处理器相连接。
通信接口1003,可以使用任何收发器一类的装置,以便与其他设备或通信网络通信,如以太网,无线接入网(RAN),无线局域网(WLAN)等.
存储器1002,如RAM,保存有操作系统和执行本发明方案的程序。操作系统是用于控制其他程序运行,管理系统资源的程序。执行本发明方案的程序代码保存在存储器中,并由处理器来控制执行。
存储器1002中存储的程序用于指令处理器执行一种机器通信中对访问控制策略资源的操作方法,包括:接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
可以理解的是,本实施例的一种机器通信系统中对访问控制策略资源的操 作装置可用于实现图4所述方法实施例中的所有功能,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
需要说明的是,本说明书中的各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于装置实施例而言,由于其基本相似于方法实施例,所以描述得比较简单,各单元具体功能的执行过程参见方法实施例的部分说明即可。以上所描述的装置实施例仅仅是示意性的,其中作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。本领域普通技术人员在不付出创造性劳动的情况下,即可以理解并实施。
总之,以上所述仅为本发明技术方案的较佳实施例而已,并非用于限定本发明的保护范围。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (31)

  1. 一种资源访问的方法,所述方法应用于机器通信M2M系统中,其特征在于,包括:
    接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
    根据所述被访问资源的标识确定所述被访问资源;
    获取所述被访问资源的访问控制策略资源;
    确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
    对所述被访问资源执行所述请求的操作。
  2. 如权利要求1所述的方法,其特征在于,所述确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员,具体为:
    确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者
    确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。
  3. 如权利要求2所述的方法,其特征在于,所述确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,具体为:
    获取所述请求者资源的所属群组资源标识列表,确定所述所属群组资源标识列表包含所述具有所述请求的操作的操作权限的群组资源标识;或
    获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,确定所述成员列表包含所述请求者资源标识。
  4. 如权利要求3所述的方法,其特征在于,所述获取所述请求者资源的所属群组资源标识列表,具体为:
    根据所述请求者资源标识,向所述请求者资源发送获取请求者资源的所属群组资源标识列表的请求消息,接收所述请求者资源返回的所述所属群组资源标识列表;或者
    所述访问请求还包括所述请求者资源的所属群组资源标识列表,获取所述访问请求中的所述所属群组资源标识列表。
  5. 如权利要求1-4任一所述的方法,其特征在于,在所述确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员之前,所述方法还包括:
    确定所述访问控制策略资源中不存在所述请求者资源标识;或者
    确定所述访问控制策略资源中存在所述请求者资源标识,以及确定所述请求者资源标识对应的操作权限不包含所述请求的操作。
  6. 一种配置资源所属群组资源标识列表的方法,所述方法应用于机器通信M2M系统中,其特征在于,包括:
    接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
    确定所述群组资源包含通知群组成员标识;
    在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
  7. 如权利要求6所述的方法,其特征在于,在所述接收增加群组成员的操作请求之前,所述方法还包括:
    接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表;
    根据所述创建群组资源的操作请求,创建所述群组资源,生成所述群组资源标识;其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表;
    向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列 表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
  8. 如权利要求6-7任一所述的方法,其特征在于,该方法进一步包括:
    接收删除群组成员的操作请求,所述删除群组成员的操作请求包含所述群组资源标识和需删除的群组成员的标识;
    确定所述群组资源包含所述通知群组成员标识;
    在所述群组资源的成员列表中删除所述需删除的群组成员的标识的过程中,向所述需删除的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第二请求消息,其中,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述需删除的群组成员的标识对应的群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
  9. 如权利要求6-8任一所述的方法,其特征在于,所述方法还包括
    接收群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述群组资源标识和引用所述群组资源的访问控制策略资源标识;
    在所述群组资源中记录所述访问控制策略资源标识。
  10. 如权利要求9所述的方法,其特征在于,所述方法还包括:
    接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识;
    在删除所述群组资源的过程中,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
  11. 如权利要求10所述的方法,其特征在于,在所述删除所述群组资源之前,所述方法还包括:
    确定所述群组资源包含所述访问控制策略资源标识;
    向所述访问控制策略资源标识对应的访问控制策略资源发送群组资源被删除的通知消息,指示所述群组资源已经被删除。
  12. 一种对访问控制策略资源的操作方法,所述方法应用于机器通信M2M 系统中,其特征在于,包括:
    接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;
    确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
    根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
  13. 如权利要求12所述的方法,其特征在于,在所述创建访问控制策略资源之后,所述方法还包括:
    接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限;
    确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识;
    将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操作权限增加到所述访问控制策略资源中。
  14. 如权利要求12或13所述的方法,其特征在于,所述方法进一步还包括:
    向群组服务器发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制策略资源中被引用的群组资源标识。
  15. 如利要求14所述的方法,其特征在于,所述方法还包括:
    接收所述群组服务器发送的群组资源被删除的通知消息,所述群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识;
    根据所述访问控制策略资源标识,在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。
  16. 如权利要求12-15任一所述的方法,其特征在于,所述确定所述群组 资源标识对应的群组资源包含通知群组成员标识,具体为:
    向所述群组服务器发送携带所述群组资源标识的获取所述群组资源的通知群组成员标识的请求,接收所述群组服务器返回的响应消息,所述响应消息指示所述群组资源标识对应的群组资源包含所述通知群组成员标识;根据所述响应消息,确定所述所述群组资源标识对应的群组资源包含通知群组成员标识;或者
    在所述创建请求中携带指示所述群组资源标识对应的群组资源包含所述通知群组成员标识的信息,根据所述创建请求,确定所述群组资源标识对应的群组资源包含通知群组成员标识。
  17. 一种资源访问的装置,所述装置应用于机器通信M2M系统中,其特征在于,包括:
    接收模块,用于接收请求者资源对被访问资源的访问请求,其中所述访问请求包括所述被访问资源的标识、请求者资源标识和对被访问资源请求的操作;
    确定模块,用于根据所述被访问资源的标识确定所述被访问资源;
    获取模块,用于根获取所述被访问资源的访问控制策略资源;
    所述确定模块,还用于确定所述请求者资源为所述访问控制策略资源中具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员;
    执行模块,用于对所述被访问资源执行所述请求的操作。
  18. 如权利要求17所述的装置,其特征在于,所述确定模块具体用于:
    确定所述访问控制策略资源中存在具有所述请求的操作的操作权限的群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员;或者
    确定所述访问控制策略资源中存在群组资源标识,确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,且所述确定的群组资源标识对应的操作权限为所述请求的操作。
  19. 如权利要求18所述的装置,其特征在于,所述确定所述请求者资源为所述确定的群组资源标识对应的群组资源的群组成员,具体包括:
    获取所述请求者资源的所属群组资源标识列表,确定所述所属群组资源标识列表包含所述具有所述请求的操作的操作权限的群组资源标识;或者
    获取所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的成员列表,确定所述成员列表包含所述请求者资源标识。
  20. 如权利要求19所述的装置,其特征在于,所述获取所述请求者资源的所属群组资源标识列表,具体为:
    根据所述请求者资源标识,向所述请求者资源发送获取请求者资源的所属群组资源标识列表的请求消息,接收所述请求者资源返回的所述所属群组资源标识列表;或者
    所述访问请求还包括所述请求者资源的所属群组资源标识列表,获取所述访问请求中的所述所属群组资源标识列表。
  21. 如权利要求17-20任一所述的装置,其特征在于,在所述确定所述请求者资源为所述具有所述请求的操作的操作权限的群组资源标识对应的群组资源的群组成员之前,所述确定模块,还用于
    确定所述访问控制策略资源中不存在所述请求者资源标识;或者
    确定所述访问控制策略资源中存在所述请求者资源标识,以及确定所述请求者资源标识对应的操作权限不包含所述请求的操作。
  22. 一种配置资源所属群组资源标识列表的装置,所述装置应用于机器通信M2M系统中,其特征在于,包括:
    接收模块,用于接收增加群组成员的操作请求,所述增加群组成员的操作请求包含群组资源标识和新加入的群组成员的标识,其中所述群组资源标识指示所述新加入的群组成员的标识对应的群组成员待加入的群组资源;
    确定模块,用于确定所述群组资源包含通知群组成员标识;
    发送模块,用于在所述群组资源的成员列表中增加所述新加入的群组成员的标识的过程中,向所述新加入的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第一请求消息;其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述新加入的群组成员的标识对应的群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
  23. 如权利要求21所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收创建群组资源的操作请求,所述创建群组资源的操作请求中包括所述通知群组成员标识和所述群组资源的成员列表;
    创建模块,用于根据所述创建群组资源的操作请求,创建所述群组资源,生成所述群组资源标识;其中,所述群组资源包含所述通知群组成员标识以及所述群组资源的成员列表;
    所述发送模块,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第一请求消息,其中,所述第一请求消息包括所述群组资源标识和指示新增所述群组资源标识的信息,所述第一请求消息指示所述群组资源的成员列表中的各群组成员将所述群组资源标识增加到自身的所属群组资源标识列表中。
  24. 如权利要求22或23所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收删除群组成员的操作请求,所述删除群组成员的操作请求包含所述群组资源标识和需删除的群组成员的标识;
    所述确定模块,还用于确定所述群组资源包含所述通知群组成员标识;
    所述发送模块,还用于在所述群组资源的成员列表中删除所述需删除的群组成员的标识的过程中,向所述需删除的群组成员的标识对应的群组成员发送更新所属群组资源标识列表的第二请求消息,其中,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述需删除的群组成员的标识对应的群组成员将所述群组资源标识从自身的所属群组资源标识列表中删除。
  25. 如权利要求22-24任一所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述群组资源标识和引用所述群组资源的访问控制策略资源标识;
    记录模块,用于在所述群组资源中记录所述访问控制策略资源标识。
  26. 如权利要求25所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收删除群组资源的操作请求,所述删除群组资源的操作请求中携带所述群组资源标识;
    所述发送模块,还用于在删除所述群组资源的过程中,向所述群组资源的成员列表中的各群组成员发送更新所属群组资源标识列表的第二请求消息,所述第二请求消息包括所述群组资源标识和指示删除所述群组资源标识的信息,所述第二请求消息指示所述群组资源的成员列表中的各群组成员将所述群组 资源标识从自身的所属群组资源标识列表中删除。
  27. 如权利要求26所述的装置,其特征在于,所述装置在所述删除所述群组资源之前,还包括:
    所述确定模块,还用于确定所述群组资源包含所述访问控制策略资源标识;
    所述发送模块,还用于向所述访问控制策略资源标识对应的访问控制策略资源发送群组资源被删除的通知消息,指示所述群组资源已经被删除。
  28. 一种对访问控制策略资源的操作装置,所述装置应用于机器通信M2M系统中,其特征在于,包括:
    接收模块,用于接收访问控制策略资源的创建请求,所述创建请求中包括群组资源标识以及与所述群组资源标识对应的操作权限;所述与所述群组资源标识对应的操作权限具体为:所述群组资源标识对应的群组资源的群组成员的操作权限;
    确定模块,用于确定所述群组资源标识对应的群组资源包含通知群组成员标识,所述通知群组成员标识指示所述群组资源的群组成员具有所属群组资源标识列表;
    创建模块,用于根据所述创建请求创建访问控制策略资源,生成访问控制策略资源标识;其中,所述访问控制策略资源包括所述群组资源标识以及所述与所述群组资源标识对应的操作权限。
  29. 如权利要求28所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收访问控制策略资源的更新请求,所述访问控制策略资源的更新请求中包括在所述访问控制策略资源中需增加的群组资源标识和与所述需增加的群资源标识对应的操作权限;
    所述确定模块,还用于确定所述需增加的群组资源标识对应的群组资源包含所述通知群组成员标识;
    增加模块,用于将所述需增加的群组资源标识以及与所述需增加的群资源标识对应的操作权限增加到所述访问控制策略资源中。
  30. 如权利要求28或29所述的装置,其特征在于,所述装置还包括:
    发送模块,用于向群组服务器发送群组资源被引用的通知消息,所述群组资源被引用的通知消息包括所述访问控制策略资源标识以及在所述访问控制 策略资源中被引用的群组资源标识。
  31. 如权利要求30所述的装置,其特征在于,所述装置还包括:
    所述接收模块,还用于接收所述群组服务器发送的群组资源被删除的通知消息,所述群组资源被删除的通知消息中包含被删除的群组资源标识以及所述访问控制策略资源标识;
    删除模块,用于根据所述访问控制策略资源标识,在所述访问控制策略资源中删除所述被删除的群组资源标识以及所述与所述被删除的群组资源标识对应的操作权限。
PCT/CN2015/078920 2014-11-04 2015-05-14 一种资源访问的方法和装置 WO2016070604A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410614623.8A CN105635931B (zh) 2014-11-04 2014-11-04 一种资源访问的方法和装置
CN201410614623.8 2014-11-04

Publications (1)

Publication Number Publication Date
WO2016070604A1 true WO2016070604A1 (zh) 2016-05-12

Family

ID=55908499

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/078920 WO2016070604A1 (zh) 2014-11-04 2015-05-14 一种资源访问的方法和装置

Country Status (2)

Country Link
CN (2) CN110460978B (zh)
WO (1) WO2016070604A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109218024A (zh) * 2017-07-04 2019-01-15 百度在线网络技术(北京)有限公司 用于控制权限的方法和装置
EP3843353A4 (en) * 2018-08-22 2022-05-25 BOE Technology Group Co., Ltd. METHOD, DEVICE AND SYSTEM FOR CONFIGURING ACCESS CONTROL POLICY AND INFORMATION SUPPORT

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106254528B (zh) * 2016-09-14 2019-12-06 北京佰才邦技术有限公司 一种资源下载方法和缓存设备
CN110691061B (zh) * 2018-07-06 2020-12-08 电信科学技术研究院有限公司 一种资源访问控制方法及装置
CN110879747B (zh) * 2018-09-05 2022-08-05 杭州海康威视系统技术有限公司 资源管理方法及装置
CN114374524A (zh) * 2020-10-14 2022-04-19 北京金山云网络技术有限公司 对象存储的访问控制方法和装置、存储介质和电子装置
CN114218560B (zh) * 2022-02-22 2023-04-25 湖北芯擎科技有限公司 资源访问方法、装置、电子设备及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101321306A (zh) * 2008-06-16 2008-12-10 华为技术有限公司 创建业务、部署业务的方法、装置
CN102075456A (zh) * 2011-02-25 2011-05-25 中国科学院计算技术研究所 分布式域管理系统中的群组建立及成员添加方法
CN103200196A (zh) * 2013-04-01 2013-07-10 天脉聚源(北京)传媒科技有限公司 一种用户设备及访问目标间的接入访问方法、系统及装置
CN103731435A (zh) * 2014-01-22 2014-04-16 南京恒知讯科技有限公司 一种社交网络群组成员身份确认机制的实现方法及系统

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
AU2003239385A1 (en) * 2002-05-10 2003-11-11 Richard R. Reisman Method and apparatus for browsing using multiple coordinated device
CN101127614A (zh) * 2006-08-16 2008-02-20 华为技术有限公司 维护公有群组成员呈现信息的系统及方法
CN101141470B (zh) * 2006-09-05 2011-04-06 腾讯科技(深圳)有限公司 一种共享资源方法及系统
CN101350710B (zh) * 2007-07-16 2011-11-16 华为技术有限公司 一种网络系统、权限颁发服务器、权限颁发及执行的方法
CN101355476B (zh) * 2008-05-23 2011-05-11 林云帆 一种基于服务器群集的数据文件存储、分发和应用的系统和方法
CN101771677B (zh) * 2008-12-31 2013-08-07 华为技术有限公司 一种向访问用户提供资源的方法、服务器和系统
CN102130773B (zh) * 2011-02-25 2012-12-19 华为技术有限公司 群组通信的方法和用于群组通信的装置
CN103138953B (zh) * 2011-11-30 2015-11-25 中国联合网络通信集团有限公司 多媒体消息的群发方法及群发系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101321306A (zh) * 2008-06-16 2008-12-10 华为技术有限公司 创建业务、部署业务的方法、装置
CN102075456A (zh) * 2011-02-25 2011-05-25 中国科学院计算技术研究所 分布式域管理系统中的群组建立及成员添加方法
CN103200196A (zh) * 2013-04-01 2013-07-10 天脉聚源(北京)传媒科技有限公司 一种用户设备及访问目标间的接入访问方法、系统及装置
CN103731435A (zh) * 2014-01-22 2014-04-16 南京恒知讯科技有限公司 一种社交网络群组成员身份确认机制的实现方法及系统

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109218024A (zh) * 2017-07-04 2019-01-15 百度在线网络技术(北京)有限公司 用于控制权限的方法和装置
CN109218024B (zh) * 2017-07-04 2021-07-16 百度在线网络技术(北京)有限公司 用于控制权限的方法和装置
EP3843353A4 (en) * 2018-08-22 2022-05-25 BOE Technology Group Co., Ltd. METHOD, DEVICE AND SYSTEM FOR CONFIGURING ACCESS CONTROL POLICY AND INFORMATION SUPPORT
US11902279B2 (en) 2018-08-22 2024-02-13 Boe Technology Group Co., Ltd. Method, apparatus, system and storage medium for access control policy configuration

Also Published As

Publication number Publication date
CN105635931A (zh) 2016-06-01
CN105635931B (zh) 2019-08-13
CN110460978A (zh) 2019-11-15
CN110460978B (zh) 2021-12-14

Similar Documents

Publication Publication Date Title
WO2016070604A1 (zh) 一种资源访问的方法和装置
KR102615419B1 (ko) 가입 및 통지 서비스
US20230319534A1 (en) Cross-resource subscription for m2m service layer
KR102224379B1 (ko) 일반적 상호연동 및 확장성을 위한 서비스 계층 리소스 관리
US10638496B2 (en) Method and apparatus for group management during machine-to-machine communication
US9930632B2 (en) M2M application remote registration method, device, system and storage medium
CN107404512B (zh) 资源订阅方法、资源订阅装置和资源订阅系統
WO2015080401A1 (ko) 무선 통신 시스템에서 특정 리소스의 관리를 위한 방법 및 장치
KR101881427B1 (ko) M2m에서의 정보 처리 방법 및 장치
US11671514B2 (en) Service layer message templates in a communications network
WO2016003134A1 (ko) 무선 통신 시스템에서 요청 메시지를 처리하기 위한 방법 및 이를 위한 장치
CN105578381A (zh) 一种创建订阅资源的方法和装置
KR102455894B1 (ko) 벌크 구독을 위한 필터
KR101975291B1 (ko) 서비스 레이어에서의 리소스 링크 관리
KR20200135176A (ko) 단말의 이동에 따른 엣지 트랜스퍼를 제공하는 방법 및 장치
KR20220103025A (ko) M2m 시스템에서 보안 키를 교체하기 위한 방법 및 장치
WO2016095472A1 (zh) 资源操作请求的处理方法及装置
JP6545820B2 (ja) ネットワークを介した記憶デバイスへのパーソナル化されたアクセス
KR20210102065A (ko) M2m 시스템에서 개인 데이터를 취급하기 위한 방법 및 장치
KR20210127095A (ko) M2m 시스템에서 로그 정보를 관리하기 위한 방법 및 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15856196

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15856196

Country of ref document: EP

Kind code of ref document: A1