CN108989300A - A kind of storage environment IP authority control method and system - Google Patents
A kind of storage environment IP authority control method and system Download PDFInfo
- Publication number
- CN108989300A CN108989300A CN201810716033.4A CN201810716033A CN108989300A CN 108989300 A CN108989300 A CN 108989300A CN 201810716033 A CN201810716033 A CN 201810716033A CN 108989300 A CN108989300 A CN 108989300A
- Authority
- CN
- China
- Prior art keywords
- acl
- permission
- authority
- client
- storage environment
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Storage Device Security (AREA)
Abstract
本发明提供了一种存储环境IP权限控制方法与系统,包括:S1、检查fuse客户端是否开启IP权限校验;S2、检查是否超过500条ACL用户;S3、校验调用该用户是否有权限设置扩展属性xattr;S4、查看是否开启ACL属性;S5、向mds发请求,设置IP权限。本发明实现针对特定的IP进行权限控制,不同于以往以用户、用户组为基础的权限控制,解决了现有技术中以用户、用户组为基础的权限控制不能满足复杂场景的问题,支持多客户端数据同步问题,例如在客户端A设置,在客户端B使用生效,另外保证原有ACL功能的需求仍满足,例如支持最大500条ACL的限制,保证NAS协议的支持,包括CIFS/FUSE客户端,满足用户多元化的要求。
The present invention provides a storage environment IP authority control method and system, comprising: S1, checking whether the fuse client has enabled IP authority verification; S2, checking whether there are more than 500 ACL users; S3, checking whether the calling user has authority Set the extended attribute xattr; S4, check whether the ACL attribute is enabled; S5, send a request to mds, and set the IP permission. The present invention realizes authority control for a specific IP, which is different from the previous authority control based on users and user groups, and solves the problem in the prior art that authority control based on users and user groups cannot meet complex scenarios, and supports multiple Client data synchronization issues, such as setting on client A and taking effect on client B, and ensuring that the original ACL function requirements are still met, such as supporting a maximum of 500 ACLs, and ensuring the support of NAS protocols, including CIFS/FUSE The client side meets the diverse requirements of users.
Description
Claims (8)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201810716033.4A CN108989300B (en) | 2018-07-03 | 2018-07-03 | Storage environment IP authority control method and system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201810716033.4A CN108989300B (en) | 2018-07-03 | 2018-07-03 | Storage environment IP authority control method and system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN108989300A true CN108989300A (en) | 2018-12-11 |
| CN108989300B CN108989300B (en) | 2021-03-09 |
Family
ID=64536505
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201810716033.4A Active CN108989300B (en) | 2018-07-03 | 2018-07-03 | Storage environment IP authority control method and system |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN108989300B (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110399736A (en) * | 2019-06-28 | 2019-11-01 | 苏州浪潮智能科技有限公司 | A kind of distributed file system right management method and associated component |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040054987A1 (en) * | 2002-09-17 | 2004-03-18 | Sonpar Nicki P. | System and method of an incremental file audit in a computer system |
| CN106682186A (en) * | 2016-12-29 | 2017-05-17 | 华为技术有限公司 | File access control list (ACL) management method and related device and system |
| CN107277016A (en) * | 2017-06-22 | 2017-10-20 | 郑州云海信息技术有限公司 | A kind of method and device of authorization check |
| CN107547520A (en) * | 2017-07-31 | 2018-01-05 | 中国科学院信息工程研究所 | Flask security modules, construction method and mobile Web system |
| CN107688753A (en) * | 2017-09-01 | 2018-02-13 | 郑州云海信息技术有限公司 | A kind of method and apparatus of ACL controls of authority |
-
2018
- 2018-07-03 CN CN201810716033.4A patent/CN108989300B/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040054987A1 (en) * | 2002-09-17 | 2004-03-18 | Sonpar Nicki P. | System and method of an incremental file audit in a computer system |
| CN106682186A (en) * | 2016-12-29 | 2017-05-17 | 华为技术有限公司 | File access control list (ACL) management method and related device and system |
| CN107277016A (en) * | 2017-06-22 | 2017-10-20 | 郑州云海信息技术有限公司 | A kind of method and device of authorization check |
| CN107547520A (en) * | 2017-07-31 | 2018-01-05 | 中国科学院信息工程研究所 | Flask security modules, construction method and mobile Web system |
| CN107688753A (en) * | 2017-09-01 | 2018-02-13 | 郑州云海信息技术有限公司 | A kind of method and apparatus of ACL controls of authority |
Non-Patent Citations (4)
| Title |
|---|
| BEYOND_DEVIL: "《xattr-文件系统扩展属性》", 《CSDN》 * |
| LINUX内核之旅: "《Linux自主访问控制机制模块详细分析之文件系统的扩展属性》", 《搜狐》 * |
| SINGLEFOLD: "《Linux ACL 学习笔记》", 《博客园》 * |
| 花火殊途: "《Linux中文件系统的权限管理(普通权限,特殊权限,文件的扩展属性,FACL)》", 《51CTO博客》 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110399736A (en) * | 2019-06-28 | 2019-11-01 | 苏州浪潮智能科技有限公司 | A kind of distributed file system right management method and associated component |
Also Published As
| Publication number | Publication date |
|---|---|
| CN108989300B (en) | 2021-03-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN107277049B (en) | An access method and device for an application system | |
| CN106506521B (en) | Resource access control method and device | |
| WO2022126968A1 (en) | Micro-service access method, apparatus and device, and storage medium | |
| CN100466520C (en) | Method, system and management server for controlling front-end equipment | |
| WO2018095416A1 (en) | Information processing method, device and system | |
| CN109413040B (en) | Message authentication method, device, system, and computer-readable storage medium | |
| WO2021115231A1 (en) | Authentication method and related device | |
| CN106844111B (en) | Access method of cloud storage network file system | |
| WO2017152754A1 (en) | Method and apparatus for secure communication of software defined network (sdn) | |
| CN101952830A (en) | Method and system for user authorization | |
| WO2021061419A1 (en) | Template-based onboarding of internet-connectible devices | |
| CN109922030A (en) | Global network access control system and method based on Android device | |
| CN108881309A (en) | Access method, device, electronic equipment and the readable storage medium storing program for executing of big data platform | |
| CN102377737B (en) | The system and method for the interactive email access protocol server of a kind of many account access | |
| CN110971566A (en) | Account unified management method, system and computer readable storage medium | |
| CN106330836B (en) | Access control method of server to client | |
| CN107018128B (en) | A third-party application authorization authentication method based on multi-domain collaborative architecture | |
| CN101001148A (en) | Method and device for safety management maintenance equipment | |
| CN103561083A (en) | Internet of things data processing method | |
| CN105721560B (en) | Unified member's central user login password safe storage system and method | |
| CN101827110B (en) | Application server access system in intranet | |
| CN108366087A (en) | A kind of ISCSI service implementing methods and device based on distributed file system | |
| CN108989300A (en) | A kind of storage environment IP authority control method and system | |
| CN106790219A (en) | The access control method and system of a kind of SDN controllers | |
| CN111783076A (en) | Multi-scenario normalization processing model for construction, right establishment, authorization and verification of authority resources |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| TA01 | Transfer of patent application right | ||
| TA01 | Transfer of patent application right |
Effective date of registration: 20210204 Address after: Building 9, No.1, guanpu Road, Guoxiang street, Wuzhong Economic Development Zone, Wuzhong District, Suzhou City, Jiangsu Province Applicant after: SUZHOU LANGCHAO INTELLIGENT TECHNOLOGY Co.,Ltd. Address before: Room 1601, floor 16, 278 Xinyi Road, Zhengdong New District, Zhengzhou City, Henan Province Applicant before: ZHENGZHOU YUNHAI INFORMATION TECHNOLOGY Co.,Ltd. |
|
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| CP03 | Change of name, title or address | ||
| CP03 | Change of name, title or address |
Address after: Building 9, No.1, guanpu Road, Guoxiang street, Wuzhong Economic Development Zone, Wuzhong District, Suzhou City, Jiangsu Province Patentee after: Suzhou Yuannao Intelligent Technology Co.,Ltd. Country or region after: China Address before: Building 9, No.1, guanpu Road, Guoxiang street, Wuzhong Economic Development Zone, Wuzhong District, Suzhou City, Jiangsu Province Patentee before: SUZHOU LANGCHAO INTELLIGENT TECHNOLOGY Co.,Ltd. Country or region before: China |