Multi-tenant cloud policy conflict adaptive adjustment method and system
By collecting and converting policy description models in real time in a multi-tenant cloud computing environment, constructing an incremental policy graph, analyzing policy change events in real time, generating conflict event records, and adaptively generating adjustment policies, the problem of not being able to detect policy conflicts in real time in existing technologies is solved. This enables real-time detection and automated correction of policy conflicts in a multi-tenant cloud computing environment, improving the real-time performance, granularity, and traceability of access control.
Patent Information
- Application Number
- CN202511469835.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-15
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-10-15
AI Technical Summary
In multi-tenant cloud computing environments, existing technologies cannot detect policy conflicts in real time when multiple policies change, leading to problems such as permission drift, over-authorization, or denial of service.
By collecting access control policies in a multi-tenant cloud computing environment in real time, converting them into a standardized policy description model, constructing an incremental policy graph, analyzing policy change events in real time, generating conflict event records, and adaptively generating adjustment policies based on risk assessment, the system automatically executes conflict correction.
It enables real-time detection and automated correction of policy conflicts in multi-tenant cloud computing environments, improving the real-time performance, granularity, and traceability of access control, and reducing operation and maintenance costs.
Smart Images

Figure CN120979825A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud computing security technology, and more specifically, to a method and system for adaptive adjustment of multi-tenant cloud policy conflicts. Background Technology
[0002] In multi-tenant cloud computing environments, access control policies are typically maintained and distributed among different tenants, cloud service providers, and third-party security management systems, resulting in significant differences in policy definition formats, authorization semantics, and update mechanisms. To meet the dynamic access authorization needs of multi-tenants, cloud platforms generally require centralized management and real-time monitoring of these heterogeneous policies to ensure secure resource isolation and correct permission allocation. With the continuous expansion of cloud computing scale and frequent business changes, the number of access control policies is growing exponentially, and policy changes can occur at any time. Efficiently identifying conflicts, assessing risks, and resolving them within a massive policy set has become one of the core technical challenges affecting cloud platform security governance capabilities and operational costs.
[0003] A Chinese patent application with publication number CN102387145B proposes a system and method for detecting access control policy conflicts in a collaborative environment. The method is designed for a dual-domain collaborative scenario based on role mapping. First, it performs syntax-semantic parsing on the XACML policy files of the two domains and adds serial numbers. Then, it generates a global role-resource ontology through ontology semantic mapping. Finally, it uses a subgraph isomorphism algorithm to match a predefined conflict graph template in the integrated policy graph, thereby outputting the conflict type, cause, and source policy location. It only prompts the user to handle the conflict manually, that is, the technical activity focuses on "semantic heterogeneity resolution + offline conflict detection".
[0004] Existing technologies typically detect conflicts through periodic full policy scans, followed by manual review or static rule corrections to authorization configurations, which has significant limitations. Specifically, policy conflict detection relies on offline batch processing mechanisms, resulting in low detection frequency and high latency. It cannot trigger real-time analysis immediately upon policy changes, easily leading to permission drift or authorization failures within a short period. For detected conflicts, existing methods generally only provide simple priority stacking or global reordering, lacking the ability to identify the root cause of changes based on a time dimension. They also lack precise dependency maintenance and sandbox verification mechanisms, easily causing large-scale authorization overlays or authorization gaps, severely impacting the consistency and stability of access control in multi-tenant environments.
[0005] Therefore, there is an urgent need for an access permission method and system that can trigger detection immediately upon policy changes, quantitatively assess conflict risks, and implement adaptive corrections based on version differences and overlapping conditions, in order to improve the real-time performance, precision, and traceability of access control policy governance. Summary of the Invention
[0006] To overcome the aforementioned deficiencies of the prior art and achieve the above objectives, the present invention provides the following technical solution: a multi-tenant cloud policy conflict adaptive adjustment method, comprising:
[0007] Collect access control policies at different levels in a multi-tenant cloud computing environment in real time, and convert access control policies of different formats into a standardized policy description model;
[0008] Based on the standardized strategy description model, an incremental strategy graph with dependency and condition overlap is constructed.
[0009] Based on the event listening mechanism, policy change events are obtained to perform real-time analysis on the incremental policy graph, identify potential conflict relationships between access control policies, and generate access conflict event records.
[0010] Based on access conflict event records, quantitative analysis and hierarchical assessment are performed to determine the risk level of access conflict events and generate conflict risk assessment records.
[0011] Based on conflict risk assessment records and predefined access conflict handling rules, an adaptive access conflict regulation strategy is generated and executed automatically.
[0012] Furthermore, the method for adaptively generating and automatically executing access conflict resolution strategies includes:
[0013] Obtain the comprehensive conflict risk score corresponding to the conflict risk assessment record; classify the access conflict risk level based on the comprehensive conflict risk score; the access conflict risk level includes low access conflict risk level, medium access conflict risk level and high access conflict risk level.
[0014] If the access conflict risk level is low, continue to monitor the conflict risk assessment records;
[0015] If the access conflict risk level is not the low access conflict risk level, then the policy version consistency check is performed on the conflict policy corresponding to the conflict risk assessment record and the conflict detection timestamp. If the check passes, the adjustment process continues. If the check fails, the adjustment process is stopped and the latest conflict risk assessment record is re-detected.
[0016] For medium-risk access conflicts, an interval adaptive boosting algorithm is used to correct the priority of the low-priority policy.
[0017] For high-risk access conflicts, when the sandbox verification result indicates that a conflict will cause authorization drift or denial of service on the live network, an adaptive blocking or rollback solution will be generated and executed.
[0018] Furthermore, methods for determining access conflict risk levels based on comprehensive conflict risk scoring include:
[0019] Preset comprehensive conflict risk scoring threshold 1 and comprehensive conflict risk scoring threshold 2; comprehensive conflict risk scoring threshold 1 is less than comprehensive conflict risk scoring threshold 2;
[0020] If the overall conflict risk score is less than the overall conflict risk score threshold, then the access conflict risk level of the overall conflict risk score is the low access conflict risk level.
[0021] If the overall conflict risk score is less than the second threshold of the overall conflict risk score but greater than or equal to the first threshold of the overall conflict risk score, then the access conflict risk level of the overall conflict risk score is the medium risk level of access conflict.
[0022] If the overall conflict risk score is greater than or equal to the overall conflict risk score threshold two, then the access conflict risk level of the overall conflict risk score is the high access conflict risk level.
[0023] Furthermore, the method for verifying the consistency of policy versions based on the conflict policy identifier and conflict detection timestamp corresponding to the conflict risk assessment record includes:
[0024] Based on the conflict policy pair identifier, retrieve the latest version number corresponding to the conflict policy pair in the policy version repository;
[0025] If the update time of the latest version number is earlier than the conflict detection time, the verification result of the policy version consistency check is that the verification passes.
[0026] If the update time of the latest version number is not earlier than the conflict detection time, the policy version consistency check result will be a failure.
[0027] Furthermore, methods for correcting the policy priorities corresponding to low-priority policies using interval adaptive boosting algorithms include:
[0028] Obtain the policy priority value corresponding to the conflicting policy pair identifier, and record the policy priority with the larger value as the high priority policy, and the policy priority with the smaller value as the low priority policy.
[0029] Calculate the difference in remaining gaps between the upper priority limit of the calculated policy and the higher priority policy;
[0030] If the remaining gap difference is greater than the preset remaining gap difference threshold, the backoff algorithm is activated. Starting from the policy priority value of the high priority policy, the algorithm searches downwards to find the first unoccupied policy priority value, which is recorded as the gap priority value. The policy priority of the low priority policy is then updated to the gap priority value.
[0031] If the remaining gap difference is not greater than the preset remaining gap difference threshold, the policy priority value difference between the high-priority policy and the low-priority policy is calculated. Based on the preset safety interval constant and the policy priority value difference, the target policy priority value is calculated, and the policy priority of the low-priority policy is updated to the target policy priority value.
[0032] Furthermore, the method for adaptively generating and executing blocking or rollback schemes includes:
[0033] Preset time difference threshold;
[0034] The first time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the low-priority policy.
[0035] The second time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the high-priority policy.
[0036] Determine whether the conditions are met: the first time difference is greater than the time difference threshold and the second time difference is less than the time difference threshold.
[0037] If the conditions are met, the latest change is determined to be the root cause of the conflict, triggering a rollback plan. The high-priority policy is rolled back to the previous version of the current version, and the dependency hash is updated synchronously to replace the online high-priority policy version in an atomic write manner.
[0038] If the conditions are not met, the latest change is determined to be a fixed contradiction, triggering the blocking scheme. The low-priority policy status is marked as disabled, and a new overriding declaration sub-policy with the same subject, object, and action as the low-priority policy and the effect of rejection is created. The overriding declaration sub-policy is assigned a policy priority value no lower than the current highest global priority.
[0039] Furthermore, the method for generating the conflict risk assessment record includes:
[0040] Obtain the conflict policy pair identifier, conflict relationship type set, conflict condition expression, and conflict detection timestamp corresponding to the access conflict event record;
[0041] Based on the predefined conflict type weight table, each conflict relationship in the set of conflict relationship types is mapped to the corresponding conflict risk weight value;
[0042] The subject corresponding to the conflict condition expression is matched with the pre-built subject resource impact level table to obtain the corresponding subject impact score; the object corresponding to the conflict condition expression is matched with the pre-built object resource sensitivity level table to obtain the corresponding object impact score; the action corresponding to the conflict condition expression is matched with the pre-built action operation risk level table to obtain the corresponding action impact score.
[0043] If there is a priority conflict in the set of conflict relationship types, the corresponding priority difference score is obtained based on the pre-built priority difference score table;
[0044] The conflict risk weight, subject impact score, object impact score, action impact score, and priority difference score are input into the comprehensive conflict risk assessment model to obtain the comprehensive conflict risk score.
[0045] The conflict strategy pair identifier, comprehensive conflict risk score, and conflict detection timestamp are encapsulated into a conflict risk assessment record.
[0046] Furthermore, the method for generating the access conflict event record includes:
[0047] Based on the strategy graph node numbers contained in the strategy change event, upstream and downstream strategy graph nodes that have direct dependencies on the strategy graph nodes are determined through local strategy subgraphs, and a set of affected strategy graph nodes is constructed; the set of affected strategy graph nodes only contains strategy graph node pairs that are related to this strategy change event;
[0048] For any two policy graph nodes in the affected policy graph node set, perform condition overlap comparison, effect difference comparison, and priority relationship parsing operations respectively to generate the corresponding comparison result data set;
[0049] The conflict relationship is determined based on the predefined conflict determination rules and the comparison result data set, and an access conflict event record is generated.
[0050] Furthermore, the method for constructing the incremental policy graph includes:
[0051] For each standardized strategy metadata structure contained in the standardized strategy description model, a corresponding strategy graph node entity is constructed based on the subject, object, action, condition expression, effect, and strategy source record index corresponding to the standardized strategy metadata structure; that is, a one-to-one mapping relationship is formed between each standardized strategy metadata structure and the corresponding strategy graph node entity.
[0052] Perform policy condition overlap detection and priority relationship parsing operations on policy graph node entities to construct condition overlap dependency edges between policy graph nodes;
[0053] Construct an incremental strategy graph by combining all strategy graph nodes and conditionally overlapping dependency edges. The incremental strategy graph includes E local strategy subgraphs, which are local dependency subgraphs centered on each strategy graph node and consisting of the strategy graph node itself, all upstream strategy graph nodes that have conditionally overlapping dependencies or priority coverage dependencies with the strategy graph node, and downstream strategy graph nodes.
[0054] Furthermore, the method for obtaining the standardized strategy description model includes:
[0055] The policy monitoring channel is connected to the management plane access interface of the cloud service provider, the policy management access interface of each tenant, and the third-party policy distribution channel. The access control policy retrieval operation is performed through periodic polling or based on an event-driven mechanism to obtain the basic meta-information associated with each access control policy. The basic meta-information includes tenant identifier, policy unique identifier, policy version number, effective timestamp, expiration timestamp, policy priority, and scope of application.
[0056] The basic metadata is encapsulated into a policy source record entity, and a unique policy source record index is assigned to each policy.
[0057] Based on the data format type of the access control policy, the matching policy parsing adapter is invoked to perform format parsing and normalization on the policy content, generate a standardized policy metadata structure, and associate it with the policy source record index.
[0058] All standardized strategy metadata structures are constructed into a standardized strategy description model.
[0059] A multi-tenant cloud policy conflict adaptive adjustment system is used to implement the multi-tenant cloud policy conflict adaptive adjustment method, including:
[0060] The policy standardization module is used to collect access control policies at different levels in a multi-tenant cloud computing environment in real time and convert access control policies of different formats into a standardized policy description model.
[0061] The strategy graph construction module, based on a standardized strategy description model, constructs an incremental strategy graph with dependencies and overlapping conditions.
[0062] The access conflict detection module analyzes the incremental policy graph in real time based on policy change events obtained by the event listening mechanism, identifies potential conflict relationships between access control policies, and generates access conflict event records.
[0063] The conflict risk assessment module performs quantitative analysis and hierarchical assessment based on access conflict event records, determines the risk level of access conflict events, and generates conflict risk assessment records.
[0064] The intelligent conflict resolution module adaptively generates and automatically executes access conflict resolution strategies based on conflict risk assessment records and predefined access conflict handling rules.
[0065] Compared with existing technologies, the technical effects and advantages of the multi-tenant cloud policy conflict adaptive adjustment method and system of the present invention are as follows:
[0066] The cloud computing access licensing method and system provided in this application effectively eliminates the problems of semantic inconsistency and parsing latency in multi-tenant environments by collecting and uniformly transforming multi-source heterogeneous access control policies into a standardized policy description model in real time. Based on the standardized policies, an incremental policy graph is constructed. When policies change, only the dependencies of related local subgraphs are recalculated, significantly reducing the complexity of condition comparison and updates. Compared with traditional full-scale traversal detection mechanisms, this application can reduce latency to the millisecond level. By combining an event listening mechanism with an access conflict detection module, a three-dimensional comparison of overlapping conditions, effect differences, and priority relationships can be triggered in real time at the instant a policy addition, modification, or revocation operation occurs, and access conflict event records are automatically generated, improving the accuracy and timeliness of policy conflict identification.
[0067] In the conflict risk assessment process, this application introduces multi-dimensional quantitative factors such as conflict risk weight, subject impact score, object impact score, action impact score, and priority difference score. A comprehensive conflict risk assessment model is used to quantitatively score and classify conflict events, ensuring the assessment results are highly objective and repeatable. For medium-risk conflicts, an interval adaptive boosting algorithm is used to smoothly correct low-priority strategies, effectively avoiding global priority reordering due to frequent boosting. For high-risk conflicts, version difference determination based on time difference thresholds distinguishes between the latest change root cause and entrenched contradictions, and precise adjustment measures are taken to either roll back high-priority strategies or block low-priority strategies. These measures are then implemented atomically after sandbox verification, ensuring that the corrective actions are implemented quickly without causing uncontrollable impacts on the existing network authorization path.
[0068] This application's solution comprehensively realizes the closed-loop management of access control policies for multi-tenant cloud platforms throughout their entire lifecycle, from standardized modeling, incremental detection, quantitative risk assessment to automated correction. It significantly improves policy consistency and security, effectively prevents security risks such as permission drift, over-authorization, and denial of service, while reducing the complexity and operating costs of policy maintenance. It has significant technological advancements and broad industrial application value. Attached Figure Description
[0069] Figure 1 This is a schematic diagram of the multi-tenant cloud policy conflict adaptive adjustment system of Embodiment 1 of the present invention;
[0070] Figure 2 This is a flowchart of the multi-tenant cloud policy conflict adaptive adjustment method according to Embodiment 2 of the present invention;
[0071] Figure 3 This is a flowchart of the method for adaptively generating and automatically executing access conflict adjustment strategies according to Embodiment 1 of the present invention;
[0072] Figure 4This is a flowchart of the method for correcting the policy priority of a low-priority policy using an interval adaptive boosting algorithm according to Embodiment 1 of the present invention.
[0073] Figure 5 This is a flowchart of the method for adaptively generating and executing blocking or rollback schemes according to Embodiment 1 of the present invention. Detailed Implementation
[0074] The technical solutions of the embodiments of the present invention will be described in detail, clearly, and completely below with reference to the accompanying drawings. It should be particularly noted that the specific embodiments described below are only for better illustrating and explaining the technical solutions of the present invention, and are intended to enable those skilled in the art to better understand and implement the present invention, and should not be construed as limiting the scope of protection of the present invention. Without departing from the spirit and substance of the present invention, those skilled in the art can modify, adjust, or make equivalent substitutions based on the content disclosed in the present invention, and these should all be considered within the scope of protection of the present invention.
[0075] Example 1:
[0076] Please see Figure 1 As shown in the figure, this embodiment discloses a multi-tenant cloud policy conflict adaptive adjustment system, including a policy standardization module, a policy graph construction module, an access conflict detection module, a conflict risk assessment module, and a conflict intelligent adjustment module. Each module realizes data transmission through wired and / or wireless connection.
[0077] To further clarify the technical problem to be solved by this application and its background, before proceeding with specific implementation methods, the relevant reaction mechanism, the limitations of the prior art, and the practical difficulties faced by those skilled in the art in solving the problem will be explained in detail.
[0078] Specifically, in multi-tenant cloud computing environments, access control policies are typically defined in a multi-layered manner, including global security policies at the cloud service provider level and fine-grained policies set by the tenants themselves. In principle, when determining the legitimacy of an access request, the policy engine needs to combine these multi-layered policies to derive the final authorization decision. However, due to the high flexibility and diversity of policies in terms of scope, condition expressions, and priority settings, overlapping rules and condition overrides are easily formed. For example, the same resource may be globally blocked, yet allowed under specific conditions in a tenant's policy, or the condition expressions may logically produce contradictory authorization results. This conflict is becoming increasingly common in cloud environments where the number of resources and tenants is constantly growing.
[0079] Existing technologies largely rely on offline batch detection mechanisms, which work by periodically scanning the policy database, parsing policy conditions, and comparing conflict relationships. These detection methods often operate on a minute- or hour-by-hour basis, failing to detect potential conflicts instantly when policies are created or updated. This results in policies remaining potentially ineffective or incorrectly authorized even after they take effect. Once a conflict condition is actually triggered, it can cause permission drift, over-authorization, or denial of service. Permission drift occurs when an operation that should be denied is mistakenly allowed; over-authorization occurs when a tenant gains access permissions beyond what is expected; and denial of service occurs when a legitimate request is incorrectly rejected. Therefore, the core technical problem this application aims to solve is: how to achieve real-time conflict detection, priority reconciliation, and automated correction of cross-layer access policies in a multi-tenant cloud computing environment, thereby addressing the problem that existing technologies cannot detect and eliminate conflicts in time before policies take effect, leading to permission drift, over-authorization, or denial of service.
[0080] The difficulty in solving the core technical problem addressed by this application lies in the need to complete conditional cross-checking, priority determination, and conflict risk assessment of tens of thousands of policies within an extremely short time window, such as a millisecond-level time window, and output correction suggestions or blocking actions without interfering with normal access requests. This requires the system to have a highly optimized incremental update mechanism and event-driven detection logic, while also ensuring policy isolation and consistency in a multi-tenant environment, and placing higher demands on the system's scalability and resource consumption. Therefore, existing technologies are insufficient to solve the core technical problem addressed by this application.
[0081] The policy standardization module is used to collect access control policies at different levels in a multi-tenant cloud computing environment in real time, and convert access control policies of different formats into a standardized policy description model, providing a consistent data foundation for subsequent incremental policy graph construction and conflict detection.
[0082] The method for obtaining the standardized strategy description model includes:
[0083] The policy monitoring channel is connected to the cloud service provider's management plane access interface API, each tenant's policy management access interface API, and a third-party policy distribution channel. Access control policies are retrieved through periodic polling or an event-driven mechanism to obtain basic metadata associated with each access control policy. This basic metadata includes, but is not limited to, tenant identifier, policy unique identifier, policy version number, effective timestamp, expiration timestamp, policy priority, and scope. This basic metadata is used to distinguish policies defined by different tenants in a multi-tenant environment, track policy versions, and determine the applicable boundaries of policies.
[0084] Basic metadata is encapsulated into a policy source record entity, and a unique policy source record index is assigned to each policy. The policy source record entity is used to record the policy source, tenant identifier, version information and scope of application throughout the entire lifecycle of the access control policy, and to provide traceability evidence in subsequent processing and auditing.
[0085] Based on the data format type of the access control policy, the matching policy parsing adapter is invoked to perform format parsing and normalization on the policy content, generating a standardized policy metadata structure, which is then associated with the policy source record index, thereby achieving a one-to-one correspondence between the parsing result and the original policy source record entity.
[0086] All standardized strategy metadata structures are constructed into a standardized strategy description model.
[0087] The method for obtaining the standardized strategy metadata structure includes:
[0088] By indexing the policy identifier or policy source record between the basic metadata and the access control policy business logic, the subject, object, action, condition expression, and effect corresponding to the access control policy are extracted and constructed into an initial policy metadata structure for subsequent format conversion and semantic normalization processing. Subsequently, the corresponding parsing adapter is selected for format conversion operation based on the data format type of the access control policy.
[0089] It should be noted that the effect refers to the effect field, which indicates the authorization decision of the access control policy on the access request when the matching conditions are met. The values include "allow" and "deny", which are binary states.
[0090] Specifically, if the access control policy uses YAML format, the YAML parsing adapter is invoked to expand the policy content node by node, mapping each node to predefined standardized fields and generating a standardized policy metadata structure corresponding to the YAML format. If the access control policy uses JSON format, the JSON parsing adapter is invoked to convert JSON fields to a standardized field structure based on the key-value mapping table, generating a standardized policy metadata structure corresponding to the JSON format. If the access control policy uses script format, the script policy parser is invoked to perform syntax checks on the script content to verify the correctness of the rule definitions, then performs semantic parsing and field extraction on the access control rules in the script, and converts them into a standardized policy metadata structure corresponding to the script format. Through these steps of obtaining the standardized policy metadata structure, access control policies of various formats can be uniformly converted into a consistent data structure, ensuring an accurate and standardized policy input foundation for subsequent incremental policy graph construction and conflict prediction and detection processes.
[0091] It should be noted that the policy standardization module plays a crucial role in data preprocessing and semantic normalization in this application, addressing the issues of policy parsing delays and conflict identification difficulties caused by the diverse sources, heterogeneous formats, and inconsistent semantics of conditional expressions in multi-tenant cloud computing environments. Through the policy standardization module, the system can uniformly collect, parse, and standardize policy data from cloud service provider's global security policies, tenant-defined policies, and third-party policy distribution channels, ensuring that subsequent processing steps are based on a consistent and standardized policy description model.
[0092] Specifically, the policy standardization module establishes a multi-channel monitoring mechanism to receive and acquire access control policies and their basic metadata from different sources in real time. It then parses and semantically normalizes the policy content according to data format type, generating a standardized policy metadata structure. Data format types include YAML, JSON, or script formats. This standardized policy metadata structure contains core elements such as subject, object, action, conditional expression, and effect, and is associated one-to-one with the assigned policy source record index, thereby enabling full traceability of policy source, version, tenant identifier, and scope of application.
[0093] In the technical solution of this application, the strategy standardization module works closely with the subsequent strategy graph construction module. The standardized strategy metadata structure output by the strategy standardization module is directly used as input to the strategy graph construction module. The strategy graph construction module establishes strategy dependencies and conflict pointers based on the standardized subject, object, and condition information, thereby significantly reducing the parsing burden and error risk in the condition comparison and graph construction process. The standardized strategy description model provides accurate and unified semantic expression for subsequent conflict detection, avoiding misjudgment of conflicts caused by inconsistent strategy formats or ambiguous condition expressions. At the same time, the strategy source record index generated by the strategy standardization module is used for strategy version tracing and processing tracking in the conflict detection, risk assessment, and resolution stages, ensuring that the system has complete operational traceability and audit compliance.
[0094] In summary, the policy standardization module not only provides high-performance data standardization support for access control policy processing in a multi-tenant cloud computing environment, but also lays the foundation for high consistency and high reliability in the core functional areas of this application system, such as real-time conflict detection, risk quantification assessment, and automated resolution.
[0095] The policy graph construction module, based on a standardized policy description model, builds an incremental policy graph with dependencies and overlapping conditions to support subsequent real-time conflict detection and risk assessment operations. Through this module, the system maps each standardized access control policy to a graph node and constructs directed edges according to the scope, priority, and overlapping conditions between access control policies. This achieves a graphical representation of policy dependencies, and when policies change, only the affected local subgraphs are parsed and updated. This significantly improves the processing performance of subsequent conflict detection operations, shortens detection response time, and enhances the system's scalability in handling high-concurrency policy change events in large-scale multi-tenant environments.
[0096] The method for constructing the incremental strategy graph includes:
[0097] For each standardized policy metadata structure contained in the standardized policy description model, a corresponding policy graph node entity is constructed based on the subject, object, action, condition expression, effect, and policy source record index corresponding to the standardized policy metadata structure. That is, each standardized policy metadata structure and its corresponding policy graph node entity form a one-to-one mapping relationship, ensuring that all access control policies have a unique and complete node representation in the incremental policy graph.
[0098] Perform policy condition overlap detection and priority relationship parsing operations on policy graph node entities to construct condition overlap dependency edges between policy graph nodes;
[0099] Construct an incremental strategy graph by combining all strategy graph nodes and conditionally overlapping dependency edges. The incremental strategy graph includes E local strategy subgraphs, which are local dependency subgraphs centered on each strategy graph node and consisting of the strategy graph node itself, all upstream strategy graph nodes that have conditionally overlapping dependencies or priority coverage dependencies with the strategy graph node, and downstream strategy graph nodes.
[0100] It should be noted that by establishing local policy subgraphs at the node level of the policy graph, this application can perform incremental updates and dependency recalculation only on the local policy subgraphs directly associated with the changed node when a policy is added, modified, or revoked. This avoids global reconstruction of the entire policy graph, effectively reduces the computational complexity of dependency maintenance, improves the response speed of policy change event handling, and enhances the scalability of the system in high-concurrency access control policy management in a multi-tenant environment.
[0101] The method for constructing the strategy graph node entities includes:
[0102] The standardized strategy metadata structure is read to extract core fields relevant to node construction, including subject identifier, object identifier, action identifier, conditional expression, effect, strategy priority, strategy activation timestamp, strategy deactivation timestamp, and strategy source record index. All core fields have been standardized, possessing unified naming conventions and semantic expressions to ensure accuracy and consistency in subsequent node generation.
[0103] The format of the subject identifier, object identifier, and action identifier is standardized, and the three are combined to form a policy triple identifier. The policy triple identifier is used to uniquely identify the access object and operation type of the policy graph node entity in the policy graph structure.
[0104] The conditional expressions are stored using a logical operation tree data structure. This logical operation tree represents the logical combinations within the conditional expressions through nodes and edges, providing efficient condition comparison capabilities for condition overlap detection. The logical combinations include AND, OR, and NOT.
[0105] Priority labels are assigned to policy graph node entities based on policy priority, which are used to determine the relative priority between nodes during the construction of subsequent priority-covered edges.
[0106] Record the policy effective timestamp and policy expiration timestamp, and encapsulate them as a validity period range attribute to identify the active status of policy graph node entities within the policy effective period.
[0107] The effect is standardized to obtain a standardized binary state, which is stored in the entity attribute of the strategy graph node. This is used to determine the authorization differences of the same subject, object and action combination under overlapping conditions during subsequent conflict detection. The binary state includes allow or deny.
[0108] The policy source record index is associated and the extracted policy source record index is bound to the policy graph node entity so as to realize the traceability and audit of the original policy source in the policy dependency relationship graph. This ensures that the corresponding original policy and version information can be quickly located when policy adjustment or rollback operations occur during subsequent conflict detection and automated resolution processes.
[0109] According to the global node numbering management mechanism, a unique node number is assigned to each strategy graph node entity. This node number is calculated by the node number generator based on the policy triple identifier, validity period attribute, and standardized binary state of the effect, ensuring global uniqueness and distinguishability between different strategy graph nodes in a multi-tenant environment. After the node number assignment is completed, the policy triple identifier, logical operation tree, priority label, validity period attribute, standardized effect binary state, and node number are summarized and encapsulated to form the strategy graph node entity.
[0110] Methods for performing policy condition overlap detection and priority relationship resolution operations on policy graph node entities, and constructing condition overlap dependency edges between policy graph nodes, include:
[0111] All policy graph nodes are grouped into W policy graph node groups based on standardized subject, object, and action fields to reduce the overhead of condition comparison for unrelated nodes. Within each policy graph node group, condition overlap analysis is performed sequentially on the condition expressions of any two access control policies. The comparison operation of the logical operation tree is used to determine whether there is a condition overriding, condition intersection, or condition exclusion relationship. If so, the condition overlap relationship is determined to be valid, and a condition overlap dependency edge is generated between the nodes corresponding to the two policies. The condition overlap dependency edge includes dependency relationship type, condition overlap expression, and dependency relationship weight. The dependency relationship type includes condition overriding, condition intersection, or condition exclusion. The condition overlap expression represents the overlap range.
[0112] It should be noted that by grouping policy graph node entities based on standardized subject, object, and action fields, and performing condition overlap analysis and priority relationship resolution within each group, this application can significantly improve the efficiency and accuracy of condition overlap detection. Specifically, the grouping operation can effectively reduce the computational overhead of condition comparison. In multi-tenant cloud computing environments, the subjects, objects, and actions of different access control policies are typically highly diverse. If pairwise condition comparisons are directly performed on all policy graph nodes, the detection complexity will increase quadratically with the number of policies, resulting in excessive computational resource consumption and a significant increase in detection latency. By first grouping by subject, object, and action, and then performing condition logic comparisons only within the same group, the number of policy pairs requiring condition overlap detection can be limited to a subset with strong correlation, thereby reducing the complexity of the condition overlap detection process and improving detection performance.
[0113] By comparing the logical operation tree form of conditional expressions, accurate identification of conditional coverage, intersection, and mutual exclusion relationships can be achieved while maintaining the semantic integrity of the conditions. The generation of overlapping conditional dependency edges, along with information such as dependency types, overlapping expressions, and dependency weights, provides ample data support for subsequent conflict detection and priority reconciliation. Specifically, the dependency type explicitly indicates the logical overlap between two strategies, the overlapping expression accurately describes the specific scope of the overlapping conditions, and the dependency weight quantifies the impact of overlap on access control decisions during conflict assessment.
[0114] Furthermore, by pre-establishing conditional dependency edges between policy graph nodes, this application can perform incremental updates and conflict analysis only on local policy subgraphs that are dependent on the affected nodes when policies are added, modified, or revoked, without having to rescan all nodes and condition expressions. This significantly improves the response speed of policy change event handling and meets the real-time requirements of high-concurrency policy operations in a multi-tenant environment.
[0115] In summary, through the aforementioned grouping and dependency edge construction mechanism, this application not only reduces the computational complexity of condition overlap detection but also improves the accuracy and scalability of detection, ensuring the real-time performance and sustainability of access control policy conflict detection in a multi-tenant cloud computing environment, which is significantly superior to existing technical solutions.
[0116] The access conflict detection module analyzes the incremental policy graph in real time based on policy change events acquired through an event listening mechanism, identifies potential conflict relationships between access control policies, and generates access conflict event records. Through this module, this application can immediately perform conditional logic comparisons, effect difference judgments, and priority relationship assessments on affected policy graph nodes and their dependencies when policies are added, modified, or revoked, achieving low-latency and high-accuracy conflict detection in high-frequency change scenarios.
[0117] It should be noted that the event listening mechanism is based on an event stream subscription model of the policy management plane and graph structure storage layer. It can automatically generate policy change event notifications when a node's state changes, and then pass these notifications to the access conflict detection module for conflict detection and processing. The event listening mechanism is used to capture node addition events, node modification events, and node deletion events.
[0118] The node addition event, node modification event, and node deletion event all refer to state change events generated when operations such as creation, update, and revocation are performed on access control policies in the policy management plane or storage layer. The node addition event indicates the addition of a new access control policy; the node modification event modifies the content of an existing access control policy, including the subject, object, action, condition, effect, and priority; and the node deletion event indicates the revocation or invalidation of an access control policy.
[0119] The method for generating the access conflict event record includes:
[0120] Based on the strategy graph node numbers included in the strategy change event, upstream and downstream strategy graph nodes with direct dependencies on the policy graph node are identified through local strategy subgraphs, and a set of affected strategy graph nodes is generated. This set of affected strategy graph nodes only includes strategy graph node pairs related to the current strategy change event, thus avoiding a full scan of all strategy graph nodes and improving detection and processing efficiency.
[0121] For any two policy graph nodes in the affected policy graph node set, perform condition overlap comparison, effect difference comparison, and priority relationship parsing operations respectively to generate corresponding comparison result data sets; the comparison result data sets include condition overlap comparison result data, effect comparison result data, and priority relationship determination result data.
[0122] Specifically, condition overlap comparison refers to performing cross-analysis of conditional expressions on the logical operation trees of two policy graph nodes to generate condition overlap comparison result data. This comparison result data includes the condition overlap relationship type and the condition overlap expression. Condition overlap relationship types include condition coverage, condition intersection, and condition exclusion. Effect difference comparison refers to comparing the effect fields corresponding to two policy graph nodes to determine whether the effect fields of the two policy graph nodes represent opposite authorization decisions, generating effect comparison result data. This effect comparison result data includes authorization decision consistency and authorization decision inconsistency. Priority relationship resolution refers to determining that when two access control policies have overlapping scopes, overlapping effective time intervals corresponding to validity period attributes, and different priority fields, a priority coverage relationship exists between the two policies. This is used to characterize whether a priority coverage relationship exists between the policies, generating priority relationship determination result data. This priority relationship determination result data includes whether a priority coverage relationship exists and whether a priority coverage relationship does not exist.
[0123] Conflict relationships are determined based on predefined conflict determination rules and comparison result data sets, and access conflict event records are generated. The access conflict event records include conflict policy pair identifiers, conflict relationship types, conflict condition expressions, and conflict detection timestamps. The conflict relationship types include condition overlap conflicts, effect conflicts, and priority conflicts.
[0124] The methods for determining conflict relationships and generating access conflict event records based on predefined conflict determination rules and comparison result datasets include:
[0125] Obtain the conditional overlap relationship type from the conditional overlap comparison results data;
[0126] If the overlapping condition relationship is a mutually exclusive condition relationship, it is determined to be a non-conflicting relationship and the process ends;
[0127] If the condition overlap relationship type is not conditional exclusion, then the conflict relationship determination result has conditional overlap conflict, and the corresponding conflict relationship value is set; for example, the conflict relationship value corresponding to the conditional overlap conflict is marked as 1;
[0128] If the effect comparison results show inconsistencies in authorization decisions, then the conflict relationship determination results indicate an effect conflict, and a corresponding conflict relationship value is set; for example, the conflict relationship value corresponding to the effect conflict is marked as 2.
[0129] If the priority relationship determination result shows that there is a priority overriding relationship, then the conflict relationship determination result shows a priority conflict, and the corresponding conflict relationship value is set; for example, the conflict relationship value corresponding to the priority conflict is marked as 3.
[0130] The numerical combinations of each conflict relationship are used to construct a set of conflict relationship types; the conflict policy pair identifiers, conflict relationship type sets, conflict condition expressions, and conflict detection timestamps corresponding to the two policy graph nodes are encapsulated into access conflict event records.
[0131] It should be noted that the access conflict detection module plays a crucial role in conflict identification and event generation in this application, addressing the problem of high real-time conflict detection in access control policy changes within multi-tenant cloud computing environments in existing technologies. This application, based on an event listening mechanism, automatically captures policy change events the instant an access control policy is added, modified, or revoked. Using these events as triggers, it performs real-time analysis on local policy subgraphs directly associated with the changed policy node in the incremental policy graph. This accurately identifies potential conflict relationships between policies in dimensions such as conditional logic, authorization decisions, and priority coverage, and generates access conflict event records based on predefined conflict determination rules. Through the access conflict detection module, this application can complete conflict relationship identification and recording within milliseconds, effectively reducing the impact of policy changes on access security consistency. This ensures high real-time performance, traceability, and reliability of access control policy management in multi-tenant environments, providing accurate input data support for subsequent conflict risk assessment and automated resolution.
[0132] The conflict risk assessment module performs quantitative analysis and hierarchical assessment based on access conflict event records, determines the risk level of access conflict events, and generates conflict risk assessment records.
[0133] The method for generating the conflict risk assessment record includes:
[0134] Obtain the conflict policy pair identifier, conflict relationship type set, conflict condition expression, and conflict detection timestamp corresponding to the access conflict event record;
[0135] Based on the predefined conflict type weight table, each conflict relationship in the set of conflict relationship types is mapped to the corresponding conflict risk weight value;
[0136] The subject corresponding to the conflict condition expression is matched with the pre-built subject resource impact level table to obtain the corresponding subject impact score; the object corresponding to the conflict condition expression is matched with the pre-built object resource sensitivity level table to obtain the corresponding object impact score; the action corresponding to the conflict condition expression is matched with the pre-built action operation risk level table to obtain the corresponding action impact score.
[0137] If there is a priority conflict in the set of conflict relationship types, the corresponding priority difference score is obtained based on the pre-built priority difference score table;
[0138] The conflict risk weight, subject impact score, object impact score, action impact score, and priority difference score are input into the comprehensive conflict risk assessment model to obtain the comprehensive conflict risk score.
[0139] The conflict strategy pair identifier, comprehensive conflict risk score, and conflict detection timestamp are encapsulated into a conflict risk assessment record.
[0140] The training method for the comprehensive conflict risk assessment model includes:
[0141] A comprehensive conflict risk assessment dataset is pre-constructed, comprising comprehensive conflict risk assessment data for the CT group and corresponding comprehensive conflict risk scores, where CT is a positive integer. The comprehensive conflict risk assessment data includes conflict risk weight values, subject impact scores, object impact scores, action impact scores, and priority difference scores. The comprehensive conflict risk assessment dataset is divided into a training set and a validation set. The training set is used for learning the parameters of the comprehensive conflict risk assessment model, and the validation set is used to monitor the generalization performance and overfitting degree of the comprehensive conflict risk assessment model in real time.
[0142] A deep neural network with a multilayer perceptron as its core is used as the comprehensive conflict risk assessment model. The comprehensive conflict risk assessment data is standardized and vectorized before being input into the deep neural network, which consists of an input layer, hidden layers, and an output layer. Each hidden layer uses a nonlinear activation function to extract features, and the output layer uses a softmax activation function to obtain the probability distribution corresponding to each comprehensive conflict risk score. Finally, the comprehensive conflict risk score corresponding to the highest probability is taken as the prediction result of the comprehensive conflict risk assessment model. During training, the cross-entropy loss function is used as the optimization objective, and a gradient descent-type optimization algorithm is used to update the network weights. An early stopping strategy is set: when the prediction accuracy on the validation set reaches or exceeds a preset threshold, the comprehensive conflict risk assessment model is determined to have converged and training is terminated.
[0143] It should be noted that in this application, the comprehensive conflict risk score is used to quantitatively characterize the overall risk level of access control policy conflict events in a multi-tenant cloud computing environment, and can fully reflect the risk intensity of conflict events under the superposition of multiple factors. The comprehensive conflict risk score ranges from 0 to 100 points, with a higher value indicating a more severe potential impact of the conflict on the consistency and security of system access control.
[0144] Specifically, the conflict risk weight value is used to quantify the basic impact of different conflict relationship types. The subject impact score, object impact score, and action impact score are used to characterize the scope of the conflict event's effect on the subject's authorized scope, resource sensitivity, and operational risk levels, respectively. The priority difference score is used to reflect the potential severity of strategy failure caused by the priority coverage relationship of the conflict event. By inputting the above scores into the comprehensive conflict risk assessment model, a comprehensive conflict risk score is generated.
[0145] An example of the conflict type weight table is shown in Table 1.
[0146] Table 1 Conflict Type Weight Table
[0147]
[0148] It should be noted that, , and This represents the conflict risk weight value corresponding to the conflict relationship numerical value. Conflict risk weight values are assigned to different conflict relationship types based on a predefined conflict type weight table. These weight values are used to characterize the impact of various conflicts on access control consistency and security during the comprehensive conflict risk scoring process. Specifically, the conflict type weight values are determined after comprehensively considering the disruptive nature of conflict relationships on access authorization, the risk of policy failure, and the potential propagation impact in a multi-tenant environment.
[0149] The weight value for overlapping and conflicting conditions is used to reflect the risk of uncertainty in authorization determination when two policies partially or completely overlap in their conditional logic. In a multi-tenant environment, this manifests as access behavior being matched by multiple policies but with inconsistent results. Therefore, it is set as the basic weight value. The weighting level is relatively low. The weighting value for effect conflict is used to indicate the direct destructive impact on access control results when two policy authorization decisions conflict under overlapping conditions. This usually leads to unpredictable fluctuations in the access request authorization status, so it is set to a higher weighting value than that for conditional conflict. The weight value for priority conflict is used to characterize the risk of strategy failure caused by a low-priority strategy logically overriding a high-priority strategy. This directly affects the effectiveness of the priority system and can prevent high-priority rejection strategies from taking effect. Therefore, it is set to a higher weight value than that for condition overlap conflict and effect conflict. .
[0150] By setting the above weight values, this application can quantitatively weight conflict events according to the type of conflict relationship during the conflict risk assessment process, ensuring that the comprehensive conflict risk score fully reflects the differentiated impact of different conflict types on security consistency, and provides an accurate basis for the rational formulation of subsequent conflict handling strategies.
[0151] An example of the main resource impact level table is shown in Table 2.
[0152] Table 2 Impact Level Table of Main Resources
[0153]
[0154] An example of the object resource sensitivity level table is shown in Table 3.
[0155] Table 3. Sensitivity Levels of Object Resources
[0156]
[0157] An example of the risk level table for the aforementioned actions is shown in Table 4.
[0158] Table 4 Risk Level Table for Operations
[0159]
[0160] An example of the priority difference score table is shown in Table 5.
[0161] Table 5 Priority Difference Score Table
[0162]
[0163] It should be noted that the priority difference score table is used to quantify the priority difference between two access control policies into a priority difference score. The priority difference score refers to the difference between the priority field values of the two policies. The larger the score, the more significant the priority difference, and the higher the potential risk of a lower-priority policy overriding a higher-priority policy. Specifically, when two access control policies have identical priorities, the system sets the priority difference score to 1, which is only used to represent conflicts of the same priority. When the priority difference is between 1 and 2, the score is set to 2, indicating a minor priority difference. When the priority difference is between 3 and 4, the score is set to 3, indicating a moderate priority difference. When the priority difference is between 5 and 6, the score is set to 4, indicating a relatively high priority difference. When the priority difference is greater than or equal to 7, the score is set to 5, indicating a high priority difference, which has a high potential disruptive effect on access control consistency.
[0164] The intelligent conflict resolution module adaptively generates and automatically executes access conflict resolution strategies based on conflict risk assessment records and predefined access conflict handling rules.
[0165] like Figure 3 As shown, the method for adaptively generating and automatically executing access conflict handling strategies includes:
[0166] Obtain the comprehensive conflict risk score corresponding to the conflict risk assessment record; classify the access conflict risk level based on the comprehensive conflict risk score; the access conflict risk level includes low access conflict risk level, medium access conflict risk level and high access conflict risk level.
[0167] If the access conflict risk level is low, continue to monitor the conflict risk assessment records;
[0168] If the access conflict risk level is not the low access conflict risk level, then the policy version consistency check is performed on the conflict policy corresponding to the conflict risk assessment record and the conflict detection timestamp. If the check passes, the adjustment process continues. If the check fails, the adjustment process is stopped and the latest conflict risk assessment record is re-detected.
[0169] For medium-risk access conflicts, an interval adaptive boosting algorithm is used to correct the priority of the low-priority policy.
[0170] For high-risk access conflicts, when the sandbox verification result indicates that a conflict will cause authorization drift or denial of service on the live network, an adaptive blocking or rollback solution will be generated and executed.
[0171] It should be noted that in high-risk access conflict scenarios, the sandbox verification environment employs a three-step joint analysis mechanism of "mirroring-decision-differentiation" to determine whether conflicting policies will trigger authorization drift or denial of service in the live network. Specifically, the system performs a complete mirroring of the production environment's identity directory, resource hierarchy, and effective access control policy set within an isolated container, generating a policy decision engine instance semantically equivalent to the online one. This policy decision engine instance is used only for offline computation and does not affect live network traffic.
[0172] The system extracts subject-object-action request trajectories with a coverage rate of no less than 95% from the audit flow and access logs within the most recent statistical period, and automatically supplements boundary requests based on the Cartesian product of triples to form a verification request set. The sandbox engine performs two rounds of judgment on each request in the verification request set: the first round loads the existing baseline policy set, and the second round loads the combination of "baseline policy set + conflicting policy pair". The system compares the authorization results of the two rounds one by one. Cases where the existing baseline policy set determines that the request is allowed, but the combination of "baseline policy set + conflicting policy pair" determines that the request is denied are recorded as potential denial of service; cases where the existing baseline policy set determines that the request is denied, but the combination of "baseline policy set + conflicting policy pair" determines that the request is allowed are recorded as potential over-authorization.
[0173] Methods for determining access conflict risk levels based on comprehensive conflict risk scoring include:
[0174] Preset comprehensive conflict risk scoring threshold 1 and comprehensive conflict risk scoring threshold 2; comprehensive conflict risk scoring threshold 1 is less than comprehensive conflict risk scoring threshold 2;
[0175] For example, in a preferred embodiment of this application, the comprehensive conflict risk score threshold one can be set to 40, and the comprehensive conflict risk score threshold two can be set to 80.
[0176] If the overall conflict risk score is less than the overall conflict risk score threshold, then the access conflict risk level of the overall conflict risk score is the low access conflict risk level.
[0177] If the overall conflict risk score is less than the second threshold of the overall conflict risk score but greater than or equal to the first threshold of the overall conflict risk score, then the access conflict risk level of the overall conflict risk score is the medium risk level of access conflict.
[0178] If the overall conflict risk score is greater than or equal to the overall conflict risk score threshold two, then the access conflict risk level of the overall conflict risk score is the high access conflict risk level.
[0179] Methods for verifying policy version consistency based on conflict policies corresponding to conflict risk assessment records and conflict detection timestamps include:
[0180] Based on the conflict policy pair identifier, retrieve the latest version number corresponding to the conflict policy pair in the policy version repository;
[0181] If the update time of the latest version number is earlier than the conflict detection time, it indicates that the policy has not been modified after the detection and can continue to be adjusted. In this case, the policy version consistency check result is that the check passes.
[0182] If the update time of the latest version number is not earlier than the conflict detection time, it indicates that the access control policy corresponding to the conflict policy has been modified subsequently. The conflict risk assessment record should be abandoned immediately and a re-detection should be triggered to ensure that subsequent adjustment actions always target the latest valid version. In this case, the verification result of the policy version consistency check will be that the check fails.
[0183] like Figure 4 As shown, the methods for correcting the policy priorities corresponding to low-priority policies using the interval adaptive boosting algorithm include:
[0184] Obtain the policy priority value corresponding to the conflicting policy pair identifier, and record the policy priority with the larger value as the high priority policy, and the policy priority with the smaller value as the low priority policy.
[0185] Calculate the remaining gap difference between the upper limit of policy priority and the higher priority policy; for example, in this application, the upper limit of policy priority is set to 100.
[0186] If the remaining gap difference is greater than the preset remaining gap difference threshold, the backoff algorithm is activated. Starting from the policy priority value of the high priority policy, the algorithm searches downwards to find the first unoccupied policy priority value, which is recorded as the gap priority value. The policy priority of the low priority policy is then updated to the gap priority value.
[0187] If the remaining gap difference is not greater than a preset remaining gap difference threshold, then the policy priority value difference between the high-priority policy and the low-priority policy is calculated. Based on a preset safety interval constant and the policy priority value difference, the target policy priority value is calculated, and the policy priority of the low-priority policy is updated to the target policy priority value. For example, in a preferred embodiment of this application, the safety interval constant can be set to 2. The range of the remaining gap difference threshold is... For example, in the application, the remaining gap difference threshold can be set to 5.
[0188] Complete the repriority adjustment of low-priority strategies.
[0189] The method for calculating the target strategy priority value includes:
[0190] ;
[0191] in, This represents the priority value of the target strategy. This refers to the policy priority value of the priority strategy. This represents the numerical difference in policy priority between high-priority and low-priority policies. For safety interval constant, This indicates rounding up to the nearest integer.
[0192] It should be noted that the use of the aforementioned interval adaptive boosting algorithm to perform localized priority correction on low-priority policies is a technical consideration in this application. Specifically, in multi-tenant cloud computing environments, the total number of policies is enormous and the priority fields are distributed in an increasing manner. If low-priority policies are simply boosted uniformly by "priority +1", it will inevitably lead to high-density priority aggregation, disrupting the existing gradient and rapidly approaching the policy priority upper limit during continuous conflict reconciliation, ultimately triggering a global reordering. Furthermore, policy priority gaps are not uniformly distributed; directly interpolating at adjacent positions would waste originally usable gap resources, creating redundant holes and increasing subsequent maintenance costs.
[0193] Based on this, this application first dynamically determines whether there is still enough space in the current priority interval by calculating the difference between the upper limit of the policy priority and the remaining gap between the high-priority policies. When there is enough space, the system uses a backoff algorithm to retrieve the first unoccupied priority value from the high-priority policy downwards and assign it to the low-priority policy, so as to make full use of the existing gaps and avoid global reordering. If there is insufficient space, the target priority is locally calculated between the high-priority and low-priority policies: the minimum gap is limited by a safety interval constant, and then the priority is smoothly increased proportionally according to the difference, which ensures that the high-priority policy is still in an advantageous position and maintains the original priority gradient distribution. This interval adaptive boosting algorithm ensures that the priority correction of a single policy can be completed in O(logN) complexity in any embodiment, significantly reducing the reconciliation latency; at the same time, it avoids triggering a full priority reordering due to frequent conflict adjustment, maintaining the overall stability and maintainability of the policy set, and plays a key supporting role in realizing the real-time conflict adaptive adjustment closed loop proposed in this application.
[0194] like Figure 5 As shown, the method for adaptively generating and executing blocking or rollback schemes includes:
[0195] A preset time difference threshold is provided; for example, in a preferred embodiment of this application, the time difference threshold is set in the range of 15 minutes to 2 hours, including the two values of 15 minutes and 2 hours. In this application, the time difference threshold can be set to 30 minutes.
[0196] The first time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the low-priority policy.
[0197] The second time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the high-priority policy.
[0198] Determine whether the conditions are met: the first time difference is greater than the time difference threshold and the second time difference is less than the time difference threshold.
[0199] If the conditions are met, the latest change is determined to be the root cause of the conflict, triggering a rollback plan. The high-priority policy is rolled back to the previous version of the current version, and the dependency hash is updated synchronously to replace the online high-priority policy version in an atomic write manner.
[0200] If the conditions are not met, the latest change is determined to be a fixed contradiction, triggering the blocking scheme. The low-priority policy status is marked as disabled, and a new overriding declaration sub-policy with the same subject, object, and action as the low-priority policy and the effect of rejection is created. The overriding declaration sub-policy is assigned a policy priority value no lower than the current global highest priority to ensure that the rejection rule takes precedence under any conditions.
[0201] It should be noted that by introducing a time difference threshold and calculating the latest change lag of high-priority and low-priority strategies based on the conflict detection timestamp, this application can determine the conflict triggering mechanism within milliseconds and select the adaptive handling path with the least disruptive impact. If the first time difference is significantly greater than the time difference threshold (i.e., the interval between the last modification of the low-priority strategy and the detection time is significantly greater than the time difference threshold), and the second time difference is less than the time difference threshold (i.e., the interval between the last modification of the high-priority strategy and the detection time is less than the time difference threshold), it can be inferred that the high-priority strategy was recently added or adjusted, while the low-priority strategy has been stable for a long time. In this case, directly rolling back the high-priority strategy to its previous stable version can immediately remove authorization drift and avoid additional disturbance to historical business logic; the dependency hash is synchronously recalculated during rollback and replaced with the online version in an atomic write manner to ensure the consistency of the strategy graph and the integrity of the audit chain.
[0202] Conversely, if the time difference combination does not meet the above conditions, it indicates that both strategies are already stable or are in long-term historical versions, and the conflict is a fixed contradiction; further rollback will not eliminate the hidden dangers. Therefore, the system chooses to block: first, the low-priority strategy is marked as disabled; then, a sub-strategy with completely identical subject, object, and action, and an effect of rejection, is automatically generated, and this sub-strategy is assigned a value no lower than the highest global priority, fundamentally ensuring that the rejection rule takes precedence under any matching path. This approach completely cuts off the interference of the low-priority strategy on the authorization results, while preserving the original strategy's subject information for subsequent auditing and replay.
[0203] The aforementioned judgment and handling logic can achieve deterministic and adaptive decision-making through a single threshold, avoiding subjective judgment errors caused by human intervention. This significantly improves the real-time performance, accuracy, and operational controllability of access control policy conflict resolution in multi-tenant cloud platforms, providing key support for the closed-loop security control system constructed in this application.
[0204] Example 2:
[0205] Please see Figure 2 As shown, this embodiment provides a multi-tenant cloud policy conflict adaptive adjustment method, including:
[0206] Collect access control policies at different levels in a multi-tenant cloud computing environment in real time, and convert access control policies of different formats into a standardized policy description model;
[0207] Based on the standardized strategy description model, an incremental strategy graph with dependency and condition overlap is constructed.
[0208] Based on the event listening mechanism, policy change events are obtained to perform real-time analysis on the incremental policy graph, identify potential conflict relationships between access control policies, and generate access conflict event records.
[0209] Based on access conflict event records, quantitative analysis and hierarchical assessment are performed to determine the risk level of access conflict events and generate conflict risk assessment records.
[0210] Based on conflict risk assessment records and predefined access conflict handling rules, an adaptive access conflict regulation strategy is generated and executed automatically.
[0211] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
[0212] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A multi-tenant cloud policy conflict adaptive adjustment method, characterized in that, include: Collect access control policies at different levels in a multi-tenant cloud computing environment in real time, and convert access control policies of different formats into a standardized policy description model; Based on the standardized strategy description model, an incremental strategy graph with dependency and condition overlap is constructed. Based on the event listening mechanism, policy change events are obtained to perform real-time analysis on the incremental policy graph, identify potential conflict relationships between access control policies, and generate access conflict event records. Based on access conflict event records, quantitative analysis and hierarchical assessment are performed to determine the risk level of access conflict events and generate conflict risk assessment records. Based on conflict risk assessment records and predefined access conflict handling rules, an adaptive access conflict regulation strategy is generated and executed automatically.
2. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 1, characterized in that, Methods for adaptively generating and automatically executing access conflict resolution strategies include: Obtain the comprehensive conflict risk score corresponding to the conflict risk assessment record; classify the access conflict risk level based on the comprehensive conflict risk score; the access conflict risk level includes low access conflict risk level, medium access conflict risk level and high access conflict risk level. If the access conflict risk level is low, continue to monitor the conflict risk assessment records; If the access conflict risk level is not the low access conflict risk level, then the policy version consistency check is performed on the conflict policy corresponding to the conflict risk assessment record and the conflict detection timestamp. If the check passes, the adjustment process continues. If the check fails, the adjustment process is stopped and the latest conflict risk assessment record is re-detected. For medium-risk access conflicts, an interval adaptive boosting algorithm is used to correct the priority of the low-priority policy. For high-risk access conflicts, when the sandbox verification result indicates that a conflict will cause authorization drift or denial of service on the live network, an adaptive blocking or rollback solution will be generated and executed.
3. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 2, characterized in that, Methods for determining access conflict risk levels based on comprehensive conflict risk scoring include: Preset comprehensive conflict risk scoring threshold 1 and comprehensive conflict risk scoring threshold 2; comprehensive conflict risk scoring threshold 1 is less than comprehensive conflict risk scoring threshold 2; If the overall conflict risk score is less than the overall conflict risk score threshold, then the access conflict risk level of the overall conflict risk score is the low access conflict risk level. If the overall conflict risk score is less than the second threshold of the overall conflict risk score but greater than or equal to the first threshold of the overall conflict risk score, then the access conflict risk level of the overall conflict risk score is the medium risk level of access conflict. If the overall conflict risk score is greater than or equal to the overall conflict risk score threshold two, then the access conflict risk level of the overall conflict risk score is the high access conflict risk level.
4. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 2, characterized in that, Methods for verifying policy version consistency based on conflict policies corresponding to conflict risk assessment records and conflict detection timestamps include: Based on the conflict policy pair identifier, retrieve the latest version number corresponding to the conflict policy pair in the policy version repository; If the update time of the latest version number is earlier than the conflict detection time, the verification result of the policy version consistency check is that the verification passes. If the update time of the latest version number is not earlier than the conflict detection time, the policy version consistency check result will be a failure.
5. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 2, characterized in that, Methods for correcting the policy priorities of low-priority policies using interval adaptive boosting algorithms include: Obtain the policy priority value corresponding to the conflicting policy pair identifier, and record the policy priority with the larger value as the high priority policy, and the policy priority with the smaller value as the low priority policy. Calculate the difference in remaining gaps between the upper priority limit of the calculated policy and the higher priority policy; If the remaining gap difference is greater than the preset remaining gap difference threshold, the backoff algorithm is activated. Starting from the policy priority value of the high priority policy, the algorithm searches downwards to find the first unoccupied policy priority value, which is recorded as the gap priority value. The policy priority of the low priority policy is then updated to the gap priority value. If the remaining gap difference is not greater than the preset remaining gap difference threshold, the policy priority value difference between the high-priority policy and the low-priority policy is calculated. Based on the preset safety interval constant and the policy priority value difference, the target policy priority value is calculated, and the policy priority of the low-priority policy is updated to the target policy priority value.
6. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 5, characterized in that, The methods for adaptively generating and executing blocking or rollback schemes include: Preset time difference threshold; The first time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the low-priority policy. The second time difference is obtained by subtracting the conflict detection timestamp from the latest change time of the high-priority policy. Determine whether the conditions are met: the first time difference is greater than the time difference threshold and the second time difference is less than the time difference threshold. If the conditions are met, the latest change is determined to be the root cause of the conflict, triggering a rollback plan. The high-priority policy is rolled back to the previous version of the current version, and the dependency hash is updated synchronously to replace the online high-priority policy version in an atomic write manner. If the conditions are not met, the latest change is determined to be a fixed contradiction, triggering the blocking scheme. The low-priority policy status is marked as disabled, and a new overriding declaration sub-policy with the same subject, object, and action as the low-priority policy and the effect of rejection is created. The overriding declaration sub-policy is assigned a policy priority value no lower than the current highest global priority.
7. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 1, characterized in that, The method for generating the conflict risk assessment record includes: Obtain the conflict policy pair identifier, conflict relationship type set, conflict condition expression, and conflict detection timestamp corresponding to the access conflict event record; Based on the predefined conflict type weight table, each conflict relationship in the set of conflict relationship types is mapped to the corresponding conflict risk weight value; The subject corresponding to the conflict condition expression is matched with the pre-built subject resource impact level table to obtain the corresponding subject impact score; the object corresponding to the conflict condition expression is matched with the pre-built object resource sensitivity level table to obtain the corresponding object impact score; the action corresponding to the conflict condition expression is matched with the pre-built action operation risk level table to obtain the corresponding action impact score. If there is a priority conflict in the set of conflict relationship types, the corresponding priority difference score is obtained based on the pre-built priority difference score table; The conflict risk weight, subject impact score, object impact score, action impact score, and priority difference score are input into the comprehensive conflict risk assessment model to obtain the comprehensive conflict risk score. The conflict strategy pair identifier, comprehensive conflict risk score, and conflict detection timestamp are encapsulated into a conflict risk assessment record.
8. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 1, characterized in that, The method for generating the access conflict event record includes: Based on the strategy graph node numbers contained in the strategy change event, upstream and downstream strategy graph nodes that have direct dependencies on the strategy graph nodes are determined through local strategy subgraphs, and a set of affected strategy graph nodes is constructed; the set of affected strategy graph nodes only contains strategy graph node pairs that are related to this strategy change event; For any two policy graph nodes in the affected policy graph node set, perform condition overlap comparison, effect difference comparison, and priority relationship parsing operations respectively to generate the corresponding comparison result data set; The conflict relationship is determined based on the predefined conflict determination rules and the comparison result data set, and an access conflict event record is generated.
9. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 1, characterized in that, The method for constructing the incremental strategy graph includes: For each standardized strategy metadata structure contained in the standardized strategy description model, a corresponding strategy graph node entity is constructed based on the subject, object, action, condition expression, effect, and strategy source record index corresponding to the standardized strategy metadata structure; that is, a one-to-one mapping relationship is formed between each standardized strategy metadata structure and the corresponding strategy graph node entity. Perform policy condition overlap detection and priority relationship parsing operations on policy graph node entities to construct condition overlap dependency edges between policy graph nodes; Construct an incremental strategy graph by combining all strategy graph nodes and conditionally overlapping dependency edges. The incremental strategy graph includes E local strategy subgraphs, which are local dependency subgraphs centered on each strategy graph node and consisting of the strategy graph node itself, all upstream strategy graph nodes that have conditionally overlapping dependencies or priority coverage dependencies with the strategy graph node, and downstream strategy graph nodes.
10. The multi-tenant cloud policy conflict adaptive adjustment method according to claim 1, characterized in that, The method for obtaining the standardized strategy description model includes: The policy monitoring channel is connected to the management plane access interface of the cloud service provider, the policy management access interface of each tenant, and the third-party policy distribution channel. The access control policy retrieval operation is performed through periodic polling or based on an event-driven mechanism to obtain the basic meta-information associated with each access control policy. The basic meta-information includes tenant identifier, policy unique identifier, policy version number, effective timestamp, expiration timestamp, policy priority, and scope of application. The basic metadata is encapsulated into a policy source record entity, and a unique policy source record index is assigned to each policy. Based on the data format type of the access control policy, the matching policy parsing adapter is invoked to perform format parsing and normalization on the policy content, generate a standardized policy metadata structure, and associate it with the policy source record index. All standardized strategy metadata structures are constructed into a standardized strategy description model.
11. A multi-tenant cloud policy conflict adaptive adjustment system, used to implement the multi-tenant cloud policy conflict adaptive adjustment method according to any one of claims 1-10, characterized in that, include: The policy standardization module is used to collect access control policies at different levels in a multi-tenant cloud computing environment in real time and convert access control policies of different formats into a standardized policy description model. The strategy graph construction module, based on a standardized strategy description model, constructs an incremental strategy graph with dependencies and overlapping conditions. The access conflict detection module analyzes the incremental policy graph in real time based on policy change events obtained by the event listening mechanism, identifies potential conflict relationships between access control policies, and generates access conflict event records. The conflict risk assessment module performs quantitative analysis and hierarchical assessment based on access conflict event records, determines the risk level of access conflict events, and generates conflict risk assessment records. The intelligent conflict resolution module adaptively generates and automatically executes access conflict resolution strategies based on conflict risk assessment records and predefined access conflict handling rules.
Citation Information
Patent Citations
System and method for detecting access control strategy collision in collaborative environment
CN102387145B
Specifying an access control policy
CN102341808A
ASP-based conflict access control strategy method
CN116389079A
Cloud platform network equipment strategy management method
CN120185910A
Data synchronization method, mirror image mounting method, equipment and medium
CN120448358A
Cited By
Hierarchical role permission dynamic authorization management and control system and method
CN122114752A