WO2023029322A1 - 一种云平台资源跨项目转让方法、系统及计算机存储介质 - Google Patents

一种云平台资源跨项目转让方法、系统及计算机存储介质 Download PDF

Info

Publication number
WO2023029322A1
WO2023029322A1 PCT/CN2021/142860 CN2021142860W WO2023029322A1 WO 2023029322 A1 WO2023029322 A1 WO 2023029322A1 CN 2021142860 W CN2021142860 W CN 2021142860W WO 2023029322 A1 WO2023029322 A1 WO 2023029322A1
Authority
WO
WIPO (PCT)
Prior art keywords
transfer
resource
transferred
project
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2021/142860
Other languages
English (en)
French (fr)
Inventor
海鑫
轩艳东
马翱宇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Wave Intelligent Technology Co Ltd
Original Assignee
Suzhou Wave Intelligent Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Suzhou Wave Intelligent Technology Co Ltd filed Critical Suzhou Wave Intelligent Technology Co Ltd
Priority to US18/261,029 priority Critical patent/US12212664B2/en
Publication of WO2023029322A1 publication Critical patent/WO2023029322A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/06Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
    • G06Q10/063Operations research, analysis or management
    • G06Q10/0631Resource planning, allocation, distributing or scheduling for enterprises or organisations
    • G06Q10/06313Resource planning in a project environment
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/10Office automation; Time management
    • G06Q10/103Workflow collaboration or project management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H04L9/3239Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD

Definitions

  • the present application relates to the field of cloud platform technology, in particular to a method, system and computer storage medium for cross-project transfer of cloud platform resources.
  • Cloud computing platform also known as cloud platform, refers to services based on hardware resources and software resources, providing computing, network and storage capabilities.
  • cloud platform In the current cloud platform environment, once a cloud platform resource is created, its affiliation cannot be changed. That is to say, the entire life cycle of a cloud platform resource will be completed under one project. Although this can handle most user scenarios, for some special user scenarios, a job needs to be completed by multiple users. In typical pipeline job scenarios, the resource transfer feature is required to meet this requirement.
  • a project on the cloud platform will be assigned to a company department, and users under the project will be assigned to corresponding employees under the department.
  • project A the cloud host or cloud hard disk or file storage instance stored in cloud platform project A
  • project B the cloud platform
  • the traditional method requires the user to copy the data for online down transfer.
  • the cloud platform urgently needs to provide a transfer mechanism that allows users to transfer online resources across projects to other project users on the platform.
  • An aspect of the embodiment of the present application provides a method for cross-project transfer of cloud platform resources, which specifically includes the following steps:
  • Hash the slot and the authentication key to obtain an encrypted hash authentication string
  • the transfer ID, authentication key, transfer description, and resource ID are returned to the transfer user based on the transfer request.
  • the method also includes:
  • the resource to be transferred is transferred to the project quota in response to the transferee user's project having a project quota for accommodating the resource to be transferred.
  • the method also includes:
  • an error message is returned to the transferee user in response to the fact that the project of the transferee user has no project quota for accommodating the resources to be transferred.
  • transferring the resource to be transferred to the project quota further includes:
  • the method also includes:
  • the transfer cancel request includes the transfer ID of the resource to be transferred
  • the transfer record In response to finding the transfer record, the transfer record is deleted and the resource status is set to available.
  • the method also includes:
  • generating the transfer ID of the resource to be transferred includes:
  • a random UIID string is generated, and the string is used as the transfer ID of the resource to be transferred.
  • the transfer request is a transfer rest request
  • the transfer rest request is configured to put the information to be transferred into the request body of the transfer rest request, and after obtaining the return information, put the return information into the return body of the transfer rest request, To return the return information to the transfer user, wherein the information to be transferred includes the transfer description and the resource ID, and the return information includes the transfer ID, the authentication key, the transfer description and the resource ID.
  • Another aspect of the embodiment of the present application also provides a cloud platform resource cross-project transfer system, including:
  • a request receiving module configured to receive a transfer request, and generate a slot of the resource to be transferred and an authentication key based on the transfer request, wherein the transfer request includes a transfer description and a resource ID of the resource to be transferred;
  • a hash operation module configured to perform hash operations on the slot and the authentication key to obtain an encrypted hash authentication string
  • the construction module is configured to generate the transfer ID of the resource to be transferred and obtain the project ID of the resource to be transferred based on the resource ID, and based on the transfer ID, the project ID of the resource to be transferred, the slot, the authentication key and the encrypted hash authentication character String constructs the transfer structure, and writes the transfer structure into the database;
  • the record generation module is configured to generate a transfer record of the transfer structure in the database, and set the resource status of the resource to be transferred as waiting for transfer in the transfer record;
  • a request returning module configured to return the transfer ID, the authentication key, the transfer description, and the resource ID to the transfer user based on the transfer request.
  • the system also includes:
  • a transfer receiving module configured to receive a transfer request of the resource to be transferred, wherein the transfer request includes a transfer ID and an authentication key;
  • An acquisition module configured to acquire the corresponding slot and encrypted hash authentication string in the database based on the transfer ID;
  • the comparison module is configured to perform hash calculation on the corresponding slot and the authentication key in the transfer request to obtain the transfer encrypted hash authentication string, and combine the transfer encrypted hash authentication string with the obtained encrypted Hash authentication strings are compared, and based on the comparison result, it is judged whether the authentication is successful;
  • the transfer module is configured to respond to the success of the authentication, when whether the project of the transferee user has a project quota for the resource to be transferred, in response to the project quota of the resource to be transferred in the project of the transferee user, transfer the resource to be transferred to the project quota.
  • the assignment module is further configured to:
  • an error message is returned to the transferee user in response to the fact that the project of the transferee user has no project quota for accommodating the resources to be transferred.
  • transferring the resource to be transferred to the project quota further includes:
  • the system also includes:
  • the transfer cancel request includes the transfer ID of the resource to be transferred
  • the transfer record In response to finding the transfer record, the transfer record is deleted and the resource status is set to available.
  • the system also includes:
  • generating the transfer ID of the resource to be transferred includes:
  • a random UIID string is generated, and the string is used as the transfer ID of the resource to be transferred.
  • the transfer request is a transfer rest request
  • the transfer rest request is configured to put the information to be transferred into the request body of the transfer rest request, and after obtaining the return information, put the return information into the return body of the transfer rest request, To return the return information to the transfer user, wherein the information to be transferred includes the transfer description and the resource ID, and the return information includes the transfer ID, the authentication key, the transfer description and the resource ID.
  • the embodiment of the present application also provides one or more non-volatile computer-readable storage media storing computer-readable instructions.
  • the computer-readable instructions are executed by one or more processors, the one or more processors execute The steps of any one of the methods for cross-project transfer of cloud platform resources.
  • the embodiment of the present application also provides a computer device, including a memory and one or more processors, where computer-readable instructions are stored in the memory, and when the computer-readable instructions are executed by the one or more processors, one or more The processor executes the steps of any one of the methods for cross-project transfer of cloud platform resources.
  • FIG. 1 is a block diagram of an embodiment of a method for cross-project transfer of cloud platform resources provided by the present application according to one or more embodiments;
  • Fig. 2 is a schematic flowchart of an embodiment of generating assignment information provided by the present application according to one or more embodiments;
  • Fig. 3 is a schematic flow diagram of an embodiment of a transferee user accepting a resource to be transferred according to one or more embodiments of the present application;
  • Fig. 4 is a schematic flowchart of an embodiment for canceling assignment provided by the present application according to one or more embodiments;
  • FIG. 5 is a schematic diagram of an embodiment of a method for cross-project transfer of cloud platform resources provided by the present application according to one or more embodiments;
  • Fig. 6 is a schematic structural diagram of an embodiment of a computer-readable storage medium provided by the present application according to one or more embodiments;
  • Fig. 7 is a schematic structural diagram of a computer device provided by the present application according to one or more embodiments.
  • Cloud platform resources Cloud hosts, cloud hard disks, file storage instances, network instances, etc. created by users in the cloud platform are all platform resources. Any resource belongs to the specified project and user in the cloud platform, and resources under different projects are mutually exclusive. Isolated, resources cannot be accessed across projects.
  • Cross-project transfer of resources It means that the resource owner in the cloud platform (a user under a certain project) transfers his specific resources to the pending transfer state and generates authentication information. Inform the designated user under the designated project to accept the transfer of the authentication information, complete the resource transfer verification process, and finally the specific resource will change its affiliation from the source project and user to the transferred project and user. We call the act of accepting the transfer of resources: transfer.
  • Project quota There are different projects on the cloud platform, and each project has multiple users. Each project has its own project quota, that is, the maximum number of resources under the project, and the maximum capacity of resources that can be allocated. Project users cannot create new resources or transfer resources beyond this quota limit. fail.
  • the first aspect of the embodiments of the present application proposes an embodiment of a method for cross-project transfer of cloud platform resources. As shown in Figure 1, it includes the following steps:
  • S101 Receive a transfer request, and generate a slot of the resource to be transferred and an authentication key based on the transfer request, where the transfer request includes a transfer description and a resource ID of the resource to be transferred;
  • FIG. 2 it is a schematic flow chart of generating transfer information for a user to send a transfer request to a server.
  • the user sends a transfer request to the server, and the request includes the resource ID resource_id of the resource to be transferred and the transfer description display_name; after receiving the transfer request, the server randomly generates 2 strings, one is a slot, and the default length is 8 , one is the authentication secret key auth_token, the default length is 16, the slot and auth_token are passed, the Hash (hash) operation is encrypted, and an encrypted encrypted hash authentication string crypt_hash is obtained; the transfer ID is generated, the length is 32, as this The unique ID of the first transfer, and obtain the project ID source_project_id where the resource to be transferred is currently located, and construct the transfer structure.
  • the transfer structure includes: accepted (whether the transfer is completed, Boolean value, the initial value is False, after the transfer is completed, set True), transfer ID, display_name (transfer description), crypt_hash (encrypted hash authentication string), slot (slot), resource_id (resource ID), source_project_id ((the current project ID of the resource to be transferred), destination_project_id ( After the transfer is completed, this information will be improved, and the initial value is empty); write the above transfer structure into the database, that is, add a transfer record in the database, and set the resource status of the resource to be transferred to "waiting for transfer” .Put the information to be returned—transfer ID, auth_token, resoruce_id, display_name—into the transfer request and return it to the transfer user.
  • the user informs the transferee user of the transfer ID and auth_token.
  • the transferee user sends an acceptance transfer request to the server based on the transfer ID and auth_token, that is, the transfer request, to complete the resource transfer.
  • resource transfer information is generated and returned to the transfer user, so that the transfer user can send the resource transfer information to the transferee user, so that the transferee user can complete the resource transfer based on the server.
  • the transfer realizes the cross-project transfer of resources in the cloud platform environment, with simple, convenient operation and strong security.
  • the method also includes:
  • the resource to be transferred is transferred to the project quota.
  • the server in the cloud platform judges whether the project of the transferee user has a project quota for the resource to be transferred, determines that the project of the transferee user has a project quota for the resource to be transferred, and transfers the resource to be transferred to the project quota based on the judgment result .
  • the method also includes:
  • An error message is returned to the transferee user in response to the fact that the project of the transferee user has no project quota for accommodating the resource to be transferred.
  • the server in the cloud platform judges whether the project of the transferee user has a project quota for the resource to be transferred, determines that the project of the transferee user does not have a project quota for the resource to be transferred, and returns an error message to the transferee user based on the judgment result.
  • transferring the resource to be transferred to the project quota further includes:
  • FIG. 3 it is a schematic flow diagram of the transferee user accepting the resources to be transferred.
  • the server receives the transferee REST request from the transferee user to transfer the resource.
  • the transferee REST request includes the transfer ID and the authentication key auth_token.
  • the server searches the database for the slot corresponding to this ID, and the pre-stored in the database.
  • crypt_hash use the slot slot and the auth_token provided by the transferee rest request to perform a hash operation to obtain a real-time calculated transferee encrypted hash authentication string calculate_crypt_hash; compare whether calculate_crypt_hash and crypt_hash are consistent, if they are not consistent, the authentication will fail, that is, the transfer cannot be accepted.
  • the transferee user sends a transfer request to the server, and the server authenticates the transfer request to complete the resource transfer, realizing the cross-project transfer of resources in the cloud platform environment, with simple, convenient operation and strong security .
  • the method also includes:
  • the transfer cancel request includes the transfer ID of the resource to be transferred
  • the method also includes:
  • the transfer cancellation request includes the transfer ID.
  • the transfer user initiates a transfer cancellation request to the server.
  • the server searches the database for a record corresponding to the transfer ID. If it finds a record corresponding to the transfer ID, it deletes the record from the database and sets the resource status to " Available", if not found, return an error message not found to the transfer user.
  • the corresponding transfer key will become invalid.
  • the user can initiate the transfer again to generate a new transfer ID and a new transfer key to ensure the reliability of the transfer information.
  • generating the transfer ID of the resource to be transferred includes:
  • a random UIID string is generated, and the string is used as the transfer ID of the resource to be transferred.
  • the transfer request is a transfer rest request
  • the transfer rest request is configured to put the information to be transferred into the request body of the transfer rest request, and after obtaining the return information, put the return information into the transfer The return body of the rest request, so as to return the return information to the transfer user, wherein the information to be transferred includes the transfer description and the resource ID, and the return information includes the transfer ID, the An authentication key, the assignment description, and the resource ID.
  • the cross-project transfer of resources in the cloud platform environment is realized, the operation is simple, convenient, and the security is strong, the interaction ability between cloud platform projects is improved, the interaction needs between users are met, and the ease of cloud platform is improved. usability and convenience.
  • the embodiment of the present application also provides a cloud platform resource cross-project transfer system, including:
  • a request receiving module 110 the request receiving module is configured to receive a transfer request, and generate a slot of the resource to be transferred and an authentication key based on the transfer request, wherein the transfer request includes a transfer description and a resource ID of the resource to be transferred;
  • a hash operation module 120 the hash operation module is configured to perform a hash operation on the slot and the authentication key to obtain an encrypted hash authentication string;
  • Construction module 130 the construction module is configured to generate the transfer ID of the resource to be transferred and obtain the project ID of the resource to be transferred based on the resource ID, and obtain the project ID of the resource to be transferred based on the transfer ID, the project ID of the resource to be transferred, the slot bit, the authentication key and the encrypted hash authentication string to construct a transfer structure, and write the transfer structure into a database;
  • a generating record module 140 the generating record module is configured to generate a transfer record of the transfer structure in the database, and set the resource status of the resource to be transferred as awaiting transfer in the transfer record;
  • a request returning module 150 configured to return the transfer ID, the authentication key, the transfer description, and the resource ID to the transfer user based on the transfer request.
  • the system also includes:
  • a transfer receiving module configured to receive a transfer request for resources to be transferred, where the transfer request includes the transfer ID and the authentication key;
  • An acquisition module configured to acquire a corresponding slot and an encrypted hash authentication string in the database based on the transfer ID
  • a comparison module configured to perform hash calculation on the corresponding slot and the authentication key in the transfer request to obtain a transfer encrypted hash authentication string, and authenticate the transfer encrypted hash The string is compared with the acquired encrypted hash authentication string, and based on the comparison result, it is judged whether the authentication is successful;
  • a judging module configured to, in response to successful authentication, judge whether the project of the transferee user has a project quota to accommodate the resource to be transferred;
  • a transfer module configured to transfer the resource to be transferred to the project quota in response to the transferee user's project has a project quota for accommodating the resource to be transferred.
  • the assignment module is further configured to:
  • An error message is returned to the transferee user in response to the fact that the project of the transferee user has no project quota for accommodating the resource to be transferred.
  • transferring the resource to be transferred to the project quota further includes:
  • the system also includes:
  • the transfer cancel request includes the transfer ID of the resource to be transferred
  • the system also includes:
  • generating the transfer ID of the resource to be transferred includes:
  • a random UIID string is generated, and the string is used as the transfer ID of the resource to be transferred.
  • the transfer request is a transfer rest request
  • the transfer rest request is configured to put the information to be transferred into the request body of the transfer rest request, and after obtaining the return information, put the return information into the transfer The return body of the rest request, so as to return the return information to the transfer user, wherein the information to be transferred includes the transfer description and the resource ID, and the return information includes the transfer ID, the An authentication key, the assignment description, and the resource ID.
  • the embodiment of the present application also provides a non-volatile readable storage medium 30.
  • Computer-readable instructions 310 are stored, and when the computer-readable instructions 310 are executed by one or more processors, the steps of a method for cross-project transfer of cloud platform resources in any one of the above-mentioned embodiments can be implemented.
  • a computer device is provided, and the computer device may be a terminal or a server, and an internal structural diagram of the computer device may be as shown in FIG. 7 .
  • the computer device includes a processor, a memory, a network interface and an input device connected by a system bus. Among them, the processor is used to provide calculation and control capabilities.
  • the memory includes a non-volatile storage medium and an internal memory.
  • the non-volatile storage medium stores an operating system and computer readable instructions.
  • the internal memory provides an environment for the execution of the operating system and computer readable instructions in the non-volatile storage medium.
  • the network interface of the computer device is used to communicate with an external terminal or server through a network connection.
  • the input device may be a touch layer covered on the display screen, or a button, a trackball or a touch pad provided on the casing of the computer equipment, or an external keyboard, touch pad or mouse.
  • FIG. 7 is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the equipment to which the solution of this application is applied.
  • the specific equipment may include More or fewer components are shown in the figures, or certain components are combined, or have different component arrangements.
  • the storage medium may be a read-only memory, a magnetic disk or an optical disk, and the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Strategic Management (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Computer Security & Cryptography (AREA)
  • Economics (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Business, Economics & Management (AREA)
  • Tourism & Hospitality (AREA)
  • Marketing (AREA)
  • Operations Research (AREA)
  • Quality & Reliability (AREA)
  • Development Economics (AREA)
  • Game Theory and Decision Science (AREA)
  • Educational Administration (AREA)
  • Biodiversity & Conservation Biology (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Automation & Control Theory (AREA)
  • Data Mining & Analysis (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本申请公开了一种云平台资源跨项目转让方法、系统及计算机存储介质,包括:接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥;对槽位与认证密钥进行哈希运算,以得到加密哈希认证字符串;生成待转让资源的转让ID并且基于资源ID获取待转让资源所在项目ID,并构造转让结构体,并将转让结构体写入数据库;在数据库生成转让结构体的转让记录,并在转让记录中将待转让资源的资源状态置为等待转让中;基于转让请求将转让ID、认证密钥、转让描述以及资源ID返回给转让用户。

Description

一种云平台资源跨项目转让方法、系统及计算机存储介质
相关申请的交叉引用
本申请要求于2021年09月06日提交中国专利局,申请号为202111036126.0,申请名称为“一种云平台资源跨项目转让方法、系统及计算机存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及云平台技术领域,尤其涉及一种云平台资源跨项目转让方法、系统及计算机存储介质。
背景技术
云计算平台也称云平台,是指基于硬件资源和软件资源的服务,提供计算、网络和存储能力。在当前在云平台环境下,一个云平台资源一旦创建完成后,将无法改变它的隶属关系。也就是说,一个云平台资源的整个生命周期将在一个项目下完成。虽然这能够应付大部分的用户场景,但是对于某些特殊的用户场景下,一项工作需要多用户配合完成,典型的流水线作业场景下,则需要资源转让特性来满足此需求。
例如,云平台的一个项目会分配给一个公司部门,项目下的用户会分配给该部门下的对应员工。当遇到部门间合作完成一项工程时,需要将项目A的资料(存放在云平台项目A的云主机或云硬盘或文件存储实例)转交给项目B,传统方式需要用户拷贝数据好进行线下转交。为了提高工作效率,云平台急需提供一种转让机制,可以让用户在线资源跨项目转让给平台内其他项目用户。
发明内容
本申请实施例的一方面提供了一种云平台资源跨项目转让方法,具体包括如下步骤:
接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
对槽位与认证密钥进行哈希运算,以得到加密哈希认证字符串;
生成待转让资源的转让ID并且基于资源ID获取待转让资源所在项目ID,并基于转让ID、待转让资源所在项目ID、槽位、认证密钥以及加密哈希认证字符串构造转让结构体,并将转让结构体写入数据库;
在数据库生成转让结构体的转让记录,并在转让记录中将待转让资源的资源状态置为等待转让中;及
基于转让请求将转让ID、认证密钥、转让描述以及资源ID返回给转让用户。
在一些实施方式中,方法还包括:
接收对待转让资源的受让请求,其中,受让请求包含转让ID与认证密钥;
基于转让ID在数据库中获取对应的插槽以及加密哈希认证字符串;
对对应的插槽以及受让请求中的认证密钥进行哈希计算,得到受让加密哈希认证字符串,并将受让加密哈希认证字符串与获取的加密哈希认证字符串进行比较,并基于比较结果判断是否认证成功;及
响应于认证成功,在受让用户所在项目是否有容纳待转让资源的项目配额时,响应于受让用户所在项目有容纳待转让资源的项目配额,将待转让资源转让到项目配额。
在一些实施方式中,方法还包括:
在受让用户所在项目无容纳待转让资源的项目配额时,响应于受让用户所在项目无容纳待转让资源的项目配额,则返回错误信息给受让用户。
在一些实施方式中,响应于受让用户所在项目有容纳待转让资源的项目配额,将待转让资源转让到项目配额,还包括:
通过数据库将待转让资源所在项目ID以及用户ID变更为受让用户所在项目ID以及用户ID,并将待转让资源的状态置为可用。
在一些实施方式中,方法还包括:
响应于资源状态为等待转让中并且接收到取消转让请求,其中,取消转让请求包含待转让资源的转让ID;
从数据库中查找转让ID对应的转让记录;及
响应于找到转让记录,删除转让记录,并将资源状态置为可用。
在一些实施方式中,方法还包括:
响应于未找到转让记录,则返回报错信息给转让用户。
在一些实施方式中,生成待转让资源的转让ID,包括:
基于UUID4算法,生成随机UIID字符串,将字符串作为待转让资源的转让ID。
在一些实施方式中,转让请求为转让rest请求,转让rest请求配置为将要传递的信息放入转让rest请求的请求体,并在得到返回信息后,将返回信息放入转让rest请求的返回体,以将返回信息返回转让用户,其中,要传递的信息包括转让描述以及资源ID,返回信息包括将转让ID、认证密钥、转让描述以及资源ID。
本申请实施例的另一方面,还提供了一种云平台资源跨项目转让系统,包括:
请求接收模块,请求接收模块配置为接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
哈希运算模块,哈希运算模块配置为对槽位与认证密钥进行哈希运算,以得到加密哈希认证字符串;
构造模块,构造模块配置为生成待转让资源的转让ID并且基于资源ID获取待转让资源所在项目ID,并基于转让ID、待转让资源所在项目ID、槽位、认证密钥以及加密哈希认证字符串构造转让结构体,并将转让结构体写入数据库;
生成记录模块,生成记录模块配置为在数据库生成转让结构体的转让记录,并在转让记录中将待转让资源的资源状态置为等待转让中;及
请求返回模块,请求返回模块配置为基于转让请求将转让ID、认证密钥、转让描述以及资源ID返回给转让用户。
在一些实施方式中,系统还包括:
受让接收模块,受让接收模块配置为接收对待转让资源的受让请求,其中,受让请求包含转让ID与认证密钥;
获取模块,获取模块配置为基于转让ID在数据库中获取对应的插槽以及加密哈希认证字符串;
比较模块,比较模块配置为对对应的插槽以及受让请求中的认证密钥进行哈希计算,得到受让加密哈希认证字符串,并将受让加密哈希认证字符串与获取的加密哈希认 证字符串进行比较,并基于比较结果判断是否认证成功;及
转让模块,转让模块配置为响应于认证成功,在受让用户所在项目是否有容纳待转让资源的项目配额时,响应于受让用户所在项目有容纳待转让资源的项目配额,将待转让资源转让到项目配额。
在一些实施方式中,转让模块还配置为:
在受让用户所在项目无容纳待转让资源的项目配额时,响应于受让用户所在项目无容纳待转让资源的项目配额,则返回错误信息给受让用户。
在一些实施方式中,响应于受让用户所在项目有容纳待转让资源的项目配额,将待转让资源转让到项目配额,还包括:
通过数据库将待转让资源所在项目ID以及用户ID变更为受让用户所在项目ID以及用户ID,并将待转让资源的状态置为可用。
在一些实施方式中,系统还包括:
响应于资源状态为等待转让中并且接收到取消转让请求,其中,取消转让请求包含待转让资源的转让ID;
从数据库中查找转让ID对应的转让记录;及
响应于找到转让记录,删除转让记录,并将资源状态置为可用。
在一些实施方式中,系统还包括:
响应于未找到所述转让记录,则返回报错信息给转让用户。
在一些实施方式中,生成待转让资源的转让ID,包括:
基于UUID4算法,生成随机UIID字符串,将字符串作为待转让资源的转让ID。
在一些实施方式中,转让请求为转让rest请求,转让rest请求配置为将要传递的信息放入转让rest请求的请求体,并在得到返回信息后,将返回信息放入转让rest请求的返回体,以将返回信息返回转让用户,其中,要传递的信息包括转让描述以及资源ID,返回信息包括将转让ID、认证密钥、转让描述以及资源ID。
本申请实施例还提供了一个或多个存储有计算机可读指令的非易失性计算机可读存储介质,计算机可读指令被一个或多个处理器执行时,使得一个或多个处理器执行上述任一项云平台资源跨项目转让方法的步骤。
本申请实施例还提供了一种计算机设备,包括存储器及一个或多个处理器,存储器中储存有计算机可读指令,计算机可读指令被一个或多个处理器执行时,使得一个或多个处理器执行上述任一项云平台资源跨项目转让方法的步骤。
本申请的一个或多个实施例的细节在下面的附图和描述中提出。本申请的其它特征和优点将从说明书、附图以及权利要求书变得明显。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的实施例。
图1为本申请根据一个或多个实施例提供的云平台资源跨项目转让方法的一实施例的框图;
图2为本申请根据一个或多个实施例提供的生成转让信息的一实施例的流程示意图;
图3为本申请根据一个或多个实施例提供的受让用户接受待转让资源的一实施例的流程示意图;
图4为本申请根据一个或多个实施例提供的为取消转让的一实施例的流程示意图;
图5为本申请根据一个或多个实施例提供的云平台资源跨项目转让方法的一实施例的示意图;
图6为本申请根据一个或多个实施例提供的计算机可读存储介质的一实施例的结构示意图;
图7为本申请根据一个或多个实施例提供的一种计算机设备的结构示意图。
具体实施方式
为使本申请的目的、技术方案和优点更加清楚明白,以下结合具体实施例,并参照附图,对本申请实施例进一步详细说明。
需要说明的是,本申请实施例中所有使用“第一”和“第二”的表述均是为了区分两个相同名称非相同的实体或者非相同的参量,可见“第一”“第二”仅为了表述的方便,不应理解 为对本申请实施例的限定,后续实施例对此不再一一说明。
下面对本申请提到的一些专有名词进行解释。
云平台资源:用户在云平台内创建的云主机、云硬盘、文件存储实例、网络实例等都属于平台资源,任何资源都隶属于云平台内指定的项目和用户,且不同项目下的资源相互隔离,无法跨项目访问资源。
资源跨项目转让:是指云平台内资源拥有者(某个项目下的某个用户)将自己的特定资源转设置为待转让状态,并生成认证信息。将认证信息告知要接受转让的指定项目下的指定用户,完成资源转让认证过程,最终该特定资源将改变隶属关系,由源项目和用户更改为接受转让的项目和用户。接受资源转让的行为我们称为:受让。
项目配额:在云平台上有不同的项目,每个项目下又具有多个用户。每个项目都有自己的项目配额,即该项目下最大能具有多少个资源,最大能分配多大容量的资源,项目用户创建新的资源或者受让资源都不能超过此配额限制,超过则会操作失败。
基于上述目的,本申请实施例的第一个方面,提出了一种云平台资源跨项目转让方法的实施例。如图1所示,其包括如下步骤:
S101、接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
S103、对所述槽位与所述认证密钥进行哈希运算,以得到加密哈希认证字符串;
S105、生成待转让资源的转让ID并且基于所述资源ID获取待转让资源所在项目ID,并基于所述转让ID、所述待转让资源所在项目ID、所述槽位、所述认证密钥以及所述加密哈希认证字符串构造转让结构体,并将所述转让结构体写入数据库;
S107、在所述数据库生成所述转让结构体的转让记录,并在所述转让记录中将所述待转让资源的资源状态置为等待转让中;
S109、基于所述转让请求将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID返回给转让用户。
如图2所示,为用户向服务器发送转让请求生成转让信息的流程示意图。
用户(转让用户)向服务器发出转让请求,请求内包含待转让资源的资源ID resource_id以及转让描述display_name;服务器接收到转让请求后,随机生成2个字符串,一个是槽位slot,默认长度为8,一个是认证秘钥auth_token,默认长度为16,将slot和auth_token通过,Hash(哈希)运算加密,得到一个加密后的加密哈希认证字符串crypt_hash;生成转让ID,长度为32,作为本次转让的唯一ID,并获取待转让资源当前所在的项目ID source_project_id,并构造转让结构体,转让结构体包括:accepted(是否 完成受让,布尔值,初始值为False,完成受让后,置为True),转让ID,display_name(转让描述),crypt_hash(加密哈希认证字符串),slot(槽位),resource_id(资源ID),source_project_id((待转让资源当前所在的项目ID),destination_project_id(受让完成后,会完善此信息,初始值为空);将以上转让结构体写入数据库,即在数据库中新增一条转让记录,并将待转让资源的资源状态置为“等待转让中”。将要返回的信息——转让ID,auth_token,resoruce_id,display_name——放入转让请求中,并返回给转让用户。
用户将转让ID和auth_token告知受让用户。受让用户基于转让ID和auth_token向服务器发送接受转让请求,即受让请求,来完成资源受让。
通过上述实施例,基于云平台中服务器与数据库的交互,生成了资源转让信息,并返回给了转让用户,使转让用户可以向受让用户发送资源转让信息,使受让用户可以基于服务器完成资源受让,实现了云平台环境中,资源的跨项目转让,操作简单、方便,安全性强。
在一些实施方式中,方法还包括:
接收对待转让资源的受让请求,其中,受让请求包含所述转让ID与所述认证密钥;
基于所述转让ID在数据库中获取对应的插槽以及加密哈希认证字符串;
对所述对应的插槽以及受让请求中的所述认证密钥进行哈希计算,得到受让加密哈希认证字符串,并将所述受让加密哈希认证字符串与获取的所述加密哈希认证字符串进行比较,并基于比较结果判断是否认证成功;
响应于认证成功,判断所述受让用户所在项目是否有容纳所述待转让资源的项目配额;
响应于受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额。
具体地,云平台中服务器判断受让用户所在项目是否有容纳待转让资源的项目配额,判定受让用户所在项目有容纳待转让资源的项目配额,基于该判定结果将待转让资源转让到项目配额。
在一些实施方式中,方法还包括:
响应于所述受让用户所在项目无容纳所述待转让资源的项目配额,则返回错误信息给所述受让用户。
具体地,云平台中服务器判断受让用户所在项目是否有容纳待转让资源的项目配额,判定受让用户所在项目无容纳待转让资源的项目配额,基于该判定结果返回错误信息给受让用户。
在一些实施方式中,响应于受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额,还包括:
通过数据库将所述待转让资源所在项目ID以及用户ID变更为受让用户所在项目ID以及用户ID,并将所述待转让资源的状态置为可用。
下面通过具体的实施例对本申请的多个实施方式进行说明。
如图3所示,为受让用户接受待转让资源的流程示意图。
服务器接收受让用户对待转让资源的受让rest请求,受让rest请求包含转让ID和认证秘钥auth_token,服务器根据转让ID,去数据库内查找对应此ID的槽位slot,以及预存在数据库中的crypt_hash;使用槽位slot和受让rest请求提供的auth_token进行哈希运算得到一个实时计算的受让加密哈希认证字符串calculate_crypt_hash;对比calculate_crypt_hash和crypt_hash是否一致,不一致则认证失败,即不能接受转让,返回错误信息;一致则继续检查项目配额,即检查接受该资源的用户所在项目是否有足够的项目配额来接受该转让,有则完成转让,并通过数据库将待转让资源所在项目ID和用户ID变更为受让用户所在项目ID和受让用户ID,并将资源状态重置为“可用”;无则返回配额不足的错误信息。
通过上述实施例,受让用户向服务器发送受让请求,服务器对受让请进行认证,来完成资源受让,实现了云平台环境中,资源的跨项目转让,操作简单、方便,安全性强。
在一些实施方式中,方法还包括:
响应于所述资源状态为等待转让中并且接收到取消转让请求,其中,所述取消转让请求包含所述待转让资源的转让ID;
从数据库中查找所述转让ID对应的转让记录;
响应于找到所述转让记录,删除所述转让记录,并将所述资源状态置为可用。
在一些实施方式中,方法还包括:
响应于未找到所述转让记录,则返回报错信息给所述转让用户。
下面通过具体的实施例对本申请的多个实施方式进行说明。
如果转让用户发起转让后,发现认证秘钥泄露或者不想转让了,亦或者其他原因想要取消资源的转让,那么转让用户可以在该资源完成受让之前,即资源仍处于“等待转让中”状态下,发起取消转让请求,如图4所示,为取消转让的流程示意图。取消转让请求包含转让ID,转让用户向服务器发起取消转让请求,服务器在数据库查找对应转让ID的 记录,若是找到对应转让ID的记录,则从数据库中删除该条记录,并将资源状态置为“可用”,若是未找到,则向转让用户返回未找到的报错信息。
取消转让后,对应的转让密钥会随之失效。如需继续转让,用户可再次发起转让,生成新的转让ID和新的转让密钥,来确保转让信息的可靠性。
在一些实施方式中,生成待转让资源的转让ID,包括:
基于UUID4算法,生成随机UIID字符串,将所述字符串作为待转让资源的转让ID。
在一些实施方式中,所述转让请求为转让rest请求,所述转让rest请求配置为将要传递的信息放入转让rest请求的请求体,并在得到返回信息后,将所述返回信息放入转让rest请求的返回体,以将所述返回信息返回所述转让用户,其中,所述要传递的信息包括所述转让描述以及所述资源ID,所述返回信息包括将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID。
通过本申请的实施例,实现了云平台环境中资源的跨项目转让,操作简单、方便,安全性强,提升了云平台项目间交互能力,满足用户间交互的需求,提升了云平台的易用性与便捷性。
基于同一发明构思,根据本申请的另一个方面,如图5所示,本申请的实施例还提供了一种云平台资源跨项目转让系统,包括:
请求接收模块110,所述请求接收模块配置为接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
哈希运算模块120,所述哈希运算模块配置为对所述槽位与所述认证密钥进行哈希运算,以得到加密哈希认证字符串;
构造模块130,所述构造模块配置为生成待转让资源的转让ID并且基于所述资源ID获取待转让资源所在项目ID,并基于所述转让ID、所述待转让资源所在项目ID、所述槽位、所述认证密钥以及所述加密哈希认证字符串构造转让结构体,并将所述转让结构体写入数据库;
生成记录模块140,所述生成记录模块配置为在所述数据库生成所述转让结构体的转让记录,并在所述转让记录中将所述待转让资源的资源状态置为等待转让中;
请求返回模块150,所述请求返回模块配置为基于所述转让请求将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID返回给转让用户。
在一些实施方式中,系统还包括:
受让接收模块,受让接收模块配置为接收对待转让资源的受让请求,其中,受让请 求包含所述转让ID与所述认证密钥;
获取模块,获取模块配置为基于所述转让ID在数据库中获取对应的插槽以及加密哈希认证字符串;
比较模块,比较模块配置为对所述对应的插槽以及受让请求中的所述认证密钥进行哈希计算,得到受让加密哈希认证字符串,并将所述受让加密哈希认证字符串与获取的所述加密哈希认证字符串进行比较,并基于比较结果判断是否认证成功;
判断模块,判断模块配置为响应于认证成功,判断所述受让用户所在项目是否有容纳所述待转让资源的项目配额;
转让模块,转让模块配置为响应于受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额。
在一些实施方式中,转让模块还配置为:
响应于所述受让用户所在项目无容纳所述待转让资源的项目配额,则返回错误信息给所述受让用户。
在一些实施方式中,响应于受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额,还包括:
通过数据库将所述待转让资源所在项目ID以及用户ID变更为受让用户所在项目ID以及用户ID,并将所述待转让资源的状态置为可用。
在一些实施方式中,系统还包括:
响应于所述资源状态为等待转让中并且接收到取消转让请求,其中,所述取消转让请求包含所述待转让资源的转让ID;
从数据库中查找所述转让ID对应的转让记录;
响应于找到所述转让记录,删除所述转让记录,并将所述资源状态置为可用。
在一些实施方式中,系统还包括:
响应于未找到所述转让记录,则返回报错信息给所述转让用户。
在一些实施方式中,生成待转让资源的转让ID,包括:
基于UUID4算法,生成随机UIID字符串,将所述字符串作为待转让资源的转让ID。
在一些实施方式中,所述转让请求为转让rest请求,所述转让rest请求配置为将要传递的信息放入转让rest请求的请求体,并在得到返回信息后,将所述返回信息放入转让rest请求的返回体,以将所述返回信息返回所述转让用户,其中,所述要传递的信息包括所述转让描述以及所述资源ID,所述返回信息包括将所述转让ID、所述认证密钥、所述 转让描述以及所述资源ID。
基于同一发明构思,根据本申请的另一个方面,如图6所示,本申请的实施例还提供了一种非易失性可读存储介质30,该非易失性可读存储介质30中存储有计算机可读指令310,该计算机可读指令310被一个或多个处理器执行时可实现上述任意一个实施例的一种云平台资源跨项目转让方法的步骤。
在一些实施例中,提供了一种计算机设备,该计算机设备可以是终端或者服务器,该计算机设备的内部结构图可以如图7所示。该计算机设备包括通过系统总线连接的处理器、存储器、网络接口和输入装置。其中,该处理器用于提供计算和控制能力。该存储器包括非易失性存储介质、内存储器。该非易失性存储介质存储有操作系统和计算机可读指令。该内存储器为非易失性存储介质中的操作系统和计算机可读指令的运行提供环境。该计算机设备的网络接口用于与外部的终端或者服务器通过网络连接通信。该计算机可读指令被处理器执行时以实现一种云平台资源跨项目转让方法。该输入装置可以是显示屏上覆盖的触摸层,也可以是计算机设备外壳上设置的按键、轨迹球或触控板,还可以是外接的键盘、触控板或鼠标等。
本领域技术人员可以理解,图7中示出的结构,仅仅是与本申请方案相关的部分结构的框图,并不构成对本申请方案所应用于其上的设备的限定,具体的设备可以包括比图中所示更多或更少的部件,或者组合某些部件,或者具有不同的部件布置。
本领域技术人员还将明白的是,结合这里的公开所描述的各种示例性逻辑块、模块、电路和算法步骤可以被实现为电子硬件、计算机软件或两者的组合。为了清楚地说明硬件和软件的这种可互换性,已经就各种示意性组件、方块、模块、电路和步骤的功能对其进行了一般性的描述。这种功能是被实现为软件还是被实现为硬件取决于具体应用以及施加给整个系统的设计约束。本领域技术人员可以针对每种具体应用以各种方式来实现的功能,但是这种实现决定不应被解释为导致脱离本申请实施例公开的范围。
以上是本申请公开的示例性实施例,但是应当注意,在不背离权利要求限定的本申请实施例公开的范围的前提下,可以进行多种改变和修改。根据这里描述的公开实施例的方法权利要求的功能、步骤和/或动作不需以任何特定顺序执行。此外,尽管本申请实施例公开的元素可以以个体形式描述或要求,但除非明确限制为单数,也可以理解为多个。
应当理解的是,在本文中使用的,除非上下文清楚地支持例外情况,单数形式“一个”旨在也包括复数形式。还应当理解的是,在本文中使用的“和/或”是指包括一个或者一 个以上相关联地列出的项目的任意和所有可能组合。
上述本申请实施例公开实施例序号仅仅为了描述,不代表实施例的优劣。
本领域普通技术人员可以理解实现上述实施例的全部或部分步骤可以通过硬件来完成,也可以通过程序来指令相关的硬件完成,程序可以存储于一种计算机可读存储介质中,上述提到的存储介质可以是只读存储器,磁盘或光盘等。
所属领域的普通技术人员应当理解:以上任何实施例的讨论仅为示例性的,并非旨在暗示本申请实施例公开的范围(包括权利要求)被限于这些例子;在本申请实施例的思路下,以上实施例或者不同实施例中的技术特征之间也可以进行组合,并存在如上的本申请实施例的不同方面的许多其它变化,为了简明它们没有在细节中提供。因此,凡在本申请实施例的精神和原则之内,所做的任何省略、修改、等同替换、改进等,均应包含在本申请实施例的保护范围之内。

Claims (11)

  1. 一种云平台资源跨项目转让方法,其特征在于,包括:
    接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
    对所述槽位与所述认证密钥进行哈希运算,以得到加密哈希认证字符串;
    生成待转让资源的转让ID并且基于所述资源ID获取待转让资源所在项目ID,并基于所述转让ID、所述待转让资源所在项目ID、所述槽位、所述认证密钥以及所述加密哈希认证字符串构造转让结构体,并将所述转让结构体写入数据库;
    在所述数据库生成所述转让结构体的转让记录,并在所述转让记录中将所述待转让资源的资源状态置为等待转让中;及
    基于所述转让请求将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID返回给转让用户。
  2. 根据权利要求1所述的方法,其特征在于,还包括:
    接收对待转让资源的受让请求,其中,受让请求包含所述转让ID与所述认证密钥;
    基于所述转让ID在数据库中获取对应的插槽以及加密哈希认证字符串;
    对所述对应的插槽以及受让请求中的所述认证密钥进行哈希计算,得到受让加密哈希认证字符串,并将所述受让加密哈希认证字符串与获取的所述加密哈希认证字符串进行比较,并基于比较结果判断是否认证成功;及
    响应于认证成功,在受让用户所在项目有容纳所述待转让资源的项目配额时,响应于所述受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额。
  3. 根据权利要求2所述的方法,其特征在于,还包括:
    在所述受让用户所在项目无容纳所述待转让资源的项目配额时,响应于所述受让用户所在项目无容纳所述待转让资源的项目配额,则返回错误信息给所述受让用户。
  4. 根据权利要求3所述的方法,其特征在于,所述响应于受让用户所在项目有容纳所述待转让资源的项目配额,将所述待转让资源转让到所述项目配额,还包括:
    通过数据库将所述待转让资源所在项目ID以及用户ID变更为受让用户所在项目ID以及用户ID,并将所述待转让资源的状态置为可用。
  5. 根据权利要求1所述的方法,其特征在于,还包括:
    响应于所述资源状态为等待转让中并且接收到取消转让请求,其中,所述取消转让请求包含所述待转让资源的转让ID;
    从数据库中查找所述转让ID对应的转让记录;及
    响应于找到所述转让记录,删除所述转让记录,并将所述资源状态置为可用。
  6. 根据权利要求5所述的方法,其特征在于,还包括:
    响应于未找到所述转让记录,则返回报错信息给所述转让用户。
  7. 根据权利要求1所述的方法,其特征在于,生成待转让资源的转让ID,包括:
    基于UUID4算法,生成随机UIID字符串,将所述字符串作为待转让资源的转让ID。
  8. 根据权利要求1所述的方法,其特征在于,所述转让请求为转让rest请求,所述转让rest请求配置为将要传递的信息放入转让rest请求的请求体,并在得到返回信息后,将所述返回信息放入转让rest请求的返回体,以将所述返回信息返回所述转让用户,其中,所述要传递的信息包括所述转让描述以及所述资源ID,所述返回信息包括将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID。
  9. 一种云平台资源跨项目转让系统,其特征在于,包括:
    请求接收模块,所述请求接收模块配置为接收转让请求,并基于转让请求生成待转让资源的槽位以及认证密钥,其中转让请求包含待转让资源的转让描述以及资源ID;
    哈希运算模块,所述哈希运算模块配置为对所述槽位与所述认证密钥进行哈希运算,以得到加密哈希认证字符串;
    构造模块,所述构造模块配置为生成待转让资源的转让ID并且基于所述资源ID获取待转让资源所在项目ID,并基于所述转让ID、所述待转让资源所在项目ID、所述槽位、所述认证密钥以及所述加密哈希认证字符串构造转让结构体,并将所述转让结构体写入数据库;
    生成记录模块,所述生成记录模块配置为在所述数据库生成所述转让结构体的转让 记录,并在所述转让记录中将所述待转让资源的资源状态置为等待转让中;及
    请求返回模块,所述请求返回模块配置为基于所述转让请求将所述转让ID、所述认证密钥、所述转让描述以及所述资源ID返回给转让用户。
  10. 一个或多个存储有计算机可读指令的非易失性计算机可读存储介质,其特征在于,所述计算机可读指令被一个或多个处理器执行时,使得所述一个或多个处理器执行如权利要求1-8任意一项所述的方法的步骤。
  11. 一种计算机设备,其特征在于,包括存储器及一个或多个处理器,所述存储器中储存有计算机可读指令,所述计算机可读指令被所述一个或多个处理器执行时,使得所述一个或多个处理器执行如权利要求1-8任意一项所述的方法的步骤。
PCT/CN2021/142860 2021-09-06 2021-12-30 一种云平台资源跨项目转让方法、系统及计算机存储介质 Ceased WO2023029322A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US18/261,029 US12212664B2 (en) 2021-09-06 2021-12-30 Cloud platform resource cross-project transfer method and system, and computer storage medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111036126.0A CN113487245B (zh) 2021-09-06 2021-09-06 一种云平台资源跨项目转让方法、系统及计算机存储介质
CN202111036126.0 2021-09-06

Publications (1)

Publication Number Publication Date
WO2023029322A1 true WO2023029322A1 (zh) 2023-03-09

Family

ID=77947216

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/142860 Ceased WO2023029322A1 (zh) 2021-09-06 2021-12-30 一种云平台资源跨项目转让方法、系统及计算机存储介质

Country Status (3)

Country Link
US (1) US12212664B2 (zh)
CN (1) CN113487245B (zh)
WO (1) WO2023029322A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113487245B (zh) * 2021-09-06 2021-12-07 苏州浪潮智能科技有限公司 一种云平台资源跨项目转让方法、系统及计算机存储介质
CN114595954A (zh) * 2022-03-01 2022-06-07 北京金山云网络技术有限公司 资源转移方法、装置、存储介质以及电子设备

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101604421A (zh) * 2009-03-19 2009-12-16 深圳市青铜器软件系统有限公司 一种基于网络的项目计划管理系统及方法
CN103562942A (zh) * 2011-01-28 2014-02-05 Fmr有限责任公司 用于项目组合中资源分配的方法和系统
US20200067697A1 (en) * 2017-03-22 2020-02-27 NEC Laboratories Europe GmbH Method for operating a blockchain
CN111756743A (zh) * 2020-06-24 2020-10-09 腾讯科技(深圳)有限公司 基于区块链的资源转移方法、装置、计算机设备和存储介质
CN112688934A (zh) * 2020-12-21 2021-04-20 杭州云象网络技术有限公司 一种基于智能网关和合约引擎的合约调用方法及系统
CN113487245A (zh) * 2021-09-06 2021-10-08 苏州浪潮智能科技有限公司 一种云平台资源跨项目转让方法、系统及计算机存储介质

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8635624B2 (en) * 2010-10-21 2014-01-21 HCL America, Inc. Resource management using environments
HK1201093A1 (zh) * 2011-06-01 2015-08-21 安全第一公司 用於安全分布式存儲的系統與方法
WO2013025556A1 (en) * 2011-08-12 2013-02-21 Splunk Inc. Elastic scaling of data volume
US9003037B2 (en) * 2012-07-25 2015-04-07 Vmware, Inc. Dynamic allocation of physical computing resources amongst virtual machines
KR101388452B1 (ko) * 2012-09-17 2014-04-23 주식회사 드림시큐리티 인증서 전송 서버를 이용하는 일회용 공개 정보 기반 이동 단말기로의 인증서 이동 방법 및 이를 이용한 장치
JP2014186707A (ja) * 2013-03-26 2014-10-02 Canon Inc 文書生成システム
CN106411521B (zh) * 2015-07-31 2020-02-18 阿里巴巴集团控股有限公司 用于量子密钥分发过程的身份认证方法、装置及系统
US9769153B1 (en) * 2015-08-07 2017-09-19 Amazon Technologies, Inc. Validation for requests
US9794370B2 (en) * 2015-11-09 2017-10-17 Telefonaktiebolaget Lm Ericsson (Publ) Systems and methods for distributed network-aware service placement
CN110880070B (zh) * 2019-11-15 2023-12-22 腾讯科技(深圳)有限公司 资源分配方法、装置、计算机可读介质及电子设备
EP3837657B1 (en) * 2020-04-22 2022-12-07 Alipay (Hangzhou) Information Technology Co., Ltd. Managing transaction requests in ledger systems
CN112468301B (zh) * 2020-10-23 2022-08-02 苏州浪潮智能科技有限公司 一种基于区块链的云平台认证的方法、系统、设备及介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101604421A (zh) * 2009-03-19 2009-12-16 深圳市青铜器软件系统有限公司 一种基于网络的项目计划管理系统及方法
CN103562942A (zh) * 2011-01-28 2014-02-05 Fmr有限责任公司 用于项目组合中资源分配的方法和系统
US20200067697A1 (en) * 2017-03-22 2020-02-27 NEC Laboratories Europe GmbH Method for operating a blockchain
CN111756743A (zh) * 2020-06-24 2020-10-09 腾讯科技(深圳)有限公司 基于区块链的资源转移方法、装置、计算机设备和存储介质
CN112688934A (zh) * 2020-12-21 2021-04-20 杭州云象网络技术有限公司 一种基于智能网关和合约引擎的合约调用方法及系统
CN113487245A (zh) * 2021-09-06 2021-10-08 苏州浪潮智能科技有限公司 一种云平台资源跨项目转让方法、系统及计算机存储介质

Also Published As

Publication number Publication date
CN113487245B (zh) 2021-12-07
CN113487245A (zh) 2021-10-08
US12212664B2 (en) 2025-01-28
US20230403141A1 (en) 2023-12-14

Similar Documents

Publication Publication Date Title
TWI728418B (zh) 使用智慧型合約執行多方交易的方法和系統
JP6387459B2 (ja) ホストされたディレクトリサービスによるディレクトリへのアプリケーションアクセスの管理
CN114817284A (zh) 多租户环境中具有去中心化分类账的高级智能合约
CN114793243A (zh) 自包含格式的一次性使用授权码
CN110612528A (zh) 安全地验证自动程序用户
JPWO2014199464A1 (ja) 開発環境システム、開発環境装置、開発環境提供方法及びプログラム
CN110494857A (zh) 用于减少数字内容访问权限确定的等待时间的预测性本地预缓存
CN113761552A (zh) 一种访问控制方法、装置、系统、服务器和存储介质
CN110472974A (zh) 基于区块链智能合约的资产转移方法、装置及系统
JP2023538497A (ja) 編集可能なブロックチェーン
WO2023029322A1 (zh) 一种云平台资源跨项目转让方法、系统及计算机存储介质
CN108073823A (zh) 数据处理方法、装置及系统
CN117176415A (zh) 集群访问方法、装置、电子设备及存储介质
US20220239660A1 (en) Information processing device and non-transitory computer readable medium
CN116157796A (zh) 警报账户
CN115552842A (zh) 用于通过区块链高效安全地处理、访问和传输数据的计算机实现的系统和方法
US10242174B2 (en) Secure information flow
CN111932239A (zh) 业务处理方法、装置、节点设备及存储介质
CN109388923A (zh) 一种程序执行方法及装置
US20240356985A1 (en) Impersonating request-based security in connection-based security environment
JP2002083102A (ja) 電子文書承認方式及びその方法
US12524522B2 (en) System and method for generating sandbox environments in a computing network
US12609917B2 (en) System and method for requesting data transfers in a blockchain network
US12169712B2 (en) Secrets framework
US20220309599A1 (en) System and method for authorizing transfer requests of physical locations

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21955850

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21955850

Country of ref document: EP

Kind code of ref document: A1