An access control method, device, equipment and medium of an asset

CN114386050BActive Publication Date: 2026-09-25HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011361997.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-10-20
Filing Date
2020-11-27
Publication Date
2026-09-25
Estimated Expiration
2040-11-27

AI Technical Summary

Technical Problem

如此给资产安全带来了极大的挑战

Benefits of technology

[0083]本申请在上述各方面提供的实现方式的基础上,还可以进行进一步组合以提供更多实现方式。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114386050B_ABST
    Figure CN114386050B_ABST
Patent Text Reader

Abstract

The application provides an access control method of an asset, comprising: obtaining a first identity feature of an application chain, the first identity feature of the application chain coming from a self logic of one or more applications in the application chain; and allowing the application chain to access the asset when the first identity feature of the application chain matches a second identity feature of the application chain recorded in an application feature library. The method uses the first identity feature inherent in the application chain to replace an external cryptographic feature to perform identity recognition, performs access control on the asset based on the identity recognition result, avoids security risks of the asset caused by application forgery or tampering, and guarantees asset security.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese patent application filed on October 20, 2020, with application number 202011126183.3 and entitled "Method, apparatus, server and storage medium for acquiring value assets", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of computer technology, and more particularly to an access control method, apparatus, device, and computer-readable storage medium for assets. Background Technology

[0003] An application is a program that runs as an independent entity. A single application or multiple applications with calling relationships can form an application chain. An application chain can access assets as a whole. Assets refer to resources that can generate benefits, such as credentials or application programming interfaces (APIs) for accessing services.

[0004] As users' security demands increase, access control for assets has become a popular research area. Currently, the industry mainly uses cryptographic features to identify applications, such as authentication factors like passwords, keys, or certificates, and then implements access control based on the identification results.

[0005] However, any application that obtains the authentication factor of a target application can impersonate that application and thus access assets. This poses a significant challenge to asset security. The industry urgently needs a reliable method for asset access control to ensure asset security. Summary of the Invention

[0006] This application provides an asset access control method. This method uses the application's intrinsic primary identity features instead of external cryptographic features for identity verification. Based on the identity verification result, access control is applied to the asset, avoiding asset security risks caused by application impersonation or tampering, thus ensuring asset security. This application also provides a system, apparatus, device, computer-readable storage medium, and computer program product corresponding to the above method.

[0007] Firstly, this application provides an access control method for assets. This method is specifically used to control access to assets by an application chain. The application chain includes one or more applications. When the application chain includes multiple applications, it is specifically a call chain formed by multiple applications with calling relationships. An asset refers to a resource that can generate benefits. In some examples, an asset may be an application programming interface (API) for accessing a service or a credential. Specifically, the credential may be an access token. This access token may be an API credential.

[0008] The access control method for the asset can be executed by the access control system. Specifically, the access control system obtains the first identity feature of the application chain, which comes from the logic of one or more applications in the application chain. When the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database, the application chain is allowed to access the asset.

[0009] Because the access control system uses the identity features derived from the logic of one or more applications in the application chain for identity verification, rather than external cryptographic features such as passwords, keys, or certificates, it can avoid asset security risks caused by application impersonation or tampering, thus ensuring asset security.

[0010] In some possible implementations, the primary identity feature of the application chain can originate from the internal logic of all applications within the chain. Thus, assuming all applications in the chain remain authentic, the primary identity feature of the application chain can be used for identity verification, allowing the access control system to grant the application chain access to the assets, thereby ensuring asset security. In other words, the access control system can ensure that all applications in the application chain that have access to the assets are authentic and have not been tampered with.

[0011] In some possible implementations, the application's own logic includes static logic or dynamic logic. Static logic refers to the logic of the application before execution, such as the logic of various functional modules of the application, including any one or more of the logic of the application's input / output module, interface call module, command execution module, or resource scheduling module. Dynamic logic refers to the logic of the application during execution, such as the behavioral logic of various functional modules of the application when performing operations, including the logic of the input / output module performing input / output operations, the logic of the interface call module performing interface call operations, the logic of the command execution module executing commands, or the logic of the resource scheduling module scheduling resources.

[0012] Different applications have different internal logic, such as static and dynamic logic, making them difficult to spoof. This prevents other applications from impersonating the current application to access assets, thus ensuring asset security. Furthermore, when an application is tampered with, its internal logic, such as static or dynamic logic, changes. The access control system uses identity features derived from the application's own logic for identification, effectively detecting tampering and preventing security risks caused by tampered applications accessing assets, further protecting asset security.

[0013] In some possible implementations, the access control system can perform feature extraction on the application chain to obtain its initial identity feature. Specifically, during an application chain's operation, before the application chain accesses the asset for the first time, feature extraction is performed on the application chain to obtain its initial identity feature. Before the application chain accesses the asset again before the operation ends, the access control device can directly obtain the initial identity feature obtained during the initial access. This reduces the number of feature extractions and computational overhead.

[0014] In some possible implementations, the access control system can extract features from the application chain before each access to the asset, obtaining a first identity feature of the application chain. That is, the access control system extracts features from the application chain in real time to obtain its first identity feature. This ensures that the first identity feature obtained by the access control system accurately represents the identity of the application chain at that moment, preventing security risks caused by the application chain being tampered with or infected with a virus, yet still accessing the asset or asset with the original identity feature.

[0015] In some possible implementations, the application chain can include multiple branches, such as multiple branches for accessing assets. The access control system can trigger an identity verification process when the application chain executes to a branch that accesses an asset with a target attribute, thereby reducing the intrusion into the application chain.

[0016] Specifically, when an application chain requests access to an asset whose attribute matches the target attribute, the application chain's first identity feature is obtained. The asset with the target attribute can be a manually labeled asset, such as a manually labeled high-value asset or a manually labeled high-risk asset. In some embodiments, the asset with the target attribute can also be an asset recommended and recorded by the system.

[0017] This method achieves maximum security benefits with minimal system overhead and minimizes the impact of access control on the application chain by triggering identity recognition on the critical path of the application chain and performing access control based on the identity recognition results.

[0018] In some possible implementations, the access control system can also filter identity features, for example, by obtaining corresponding Bloom vectors through a Bloom filter, and determining whether the first identity feature and the second identity feature match based on the Bloom vectors. Specifically, when the distance between the first Bloom vector corresponding to the first identity feature and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database.

[0019] This method improves the efficiency of identity recognition by converting identity features into Bloom vectors and using these vectors to determine whether the identity features match. Furthermore, converting identity features into Bloom vectors, for example by mixing whitelisted identity features together to form a string of 0s and 1s that can be recovered, can also improve security.

[0020] In some possible implementations, the access control system can compare the first identity feature of the application chain with the second identity feature of the application chain recorded in a local or remote application feature database. Specifically, by comparing the first identity feature of the application chain locally with the second identity feature recorded in the local application feature database, the access control system can reduce its dependence on the management side. Since the remote application feature database can be updated more promptly, the comparison of the first identity feature of the application chain with the second identity feature recorded in the remote application feature database has high accuracy.

[0021] In some possible implementations, the locally deployed applications may change, such as the addition of new applications or the modification of existing applications. Based on this, the access control system can also update the local application feature database according to the remote application feature database.

[0022] In this way, the access control system can perform identity feature comparison based on the updated application feature library, thereby ensuring the accuracy of the comparison results and thus guaranteeing the accuracy of identity recognition.

[0023] In some possible implementations, the identity verification process can also be performed remotely. Specifically, the access control system includes not only local worker nodes but also remote management nodes. The access control system (specifically, worker nodes) can also send the first identity feature of the application chain to the management node, enabling the management node to compare the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

[0024] In some possible implementations, the asset includes any one or more of the following: local credentials, remote credentials, or application programming interfaces (APIs) used to access the target service. By implementing access control on local credentials, remote credentials, or APIs used to access the target service, security risks caused by the leakage of these assets can be avoided, thus ensuring asset security.

[0025] In some possible implementations, the identity features include fingerprints or behavioral characteristics. Different applications have different fingerprints or behavioral characteristics, and the fingerprints or behavioral characteristics of one application are difficult for other applications to imitate. Identity recognition based on fingerprints or behavioral characteristics has high reliability. Therefore, access control based on identity recognition results using fingerprints or behavioral characteristics can effectively protect asset security.

[0026] In some possible implementations, the method is executed by worker nodes that deploy the application chain within the access control system. This allows for the direct blocking of further operations by applications that are not permitted to access the system, avoiding the sending of access requests to the nodes where the assets are deployed, thereby preventing unnecessary resource consumption and conserving resources.

[0027] In some possible implementations, the method is executed by the worker node deploying the asset within the access control system. This allows for access control of the asset at the node where it is deployed, thereby ensuring asset security.

[0028] Secondly, embodiments of this application provide an access control system. The system includes an access control node, which is used for:

[0029] Obtain the first identity feature of the application chain, wherein the identity feature of the application chain comes from the internal logic of one or more applications in the application chain;

[0030] When the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library, the application chain is allowed to access the asset.

[0031] In some possible implementations, the application's own logic includes:

[0032] The application's input / output module or the logic by which the input / output module performs input / output operations;

[0033] The application's interface call module or the logic of the interface call module executing interface call operations;

[0034] The application's command execution module or the logic of the command execution module executing commands; or,

[0035] The application's resource scheduling module or the logic of the resource scheduling module scheduling resources.

[0036] In some possible implementations, the access control node is specifically used for:

[0037] Feature extraction is performed on the application chain to obtain the first identity feature of the application chain.

[0038] In some possible implementations, the access control node is specifically used for:

[0039] Feature extraction is performed on the application chain before each access to the asset.

[0040] In some possible implementations, the access control node is specifically used for:

[0041] When the application chain requests access to an asset whose attribute is the target attribute, the first identity feature of the application chain is obtained.

[0042] In some possible implementations, when the distance between the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

[0043] In some possible implementations, the access control node is also used for:

[0044] The first identity feature of the application chain is compared with the second identity feature of the application chain recorded in the application feature database, either locally or remotely.

[0045] In some possible implementations, the access control node is also used for:

[0046] Update the local application feature library based on the remote application feature library.

[0047] In some possible implementations, the system also includes a management node;

[0048] The access control node is also used to send the first identity feature of the application chain to the management node;

[0049] The management node is used to compare the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

[0050] In some possible implementations, the asset includes any one or more of the following: local credentials, remote credentials, or application programming interfaces for accessing the target service.

[0051] In some possible implementations, the identity features include fingerprints or behavioral characteristics.

[0052] In some possible implementations, the access control node is a worker node that deploys the application chain.

[0053] In some possible implementations, the access control node is the worker node that deploys the asset.

[0054] Thirdly, embodiments of this application provide an access control device. The device includes:

[0055] The acquisition module is used to acquire the first identity feature of the application chain, wherein the identity feature of the application chain comes from the logic of one or more applications in the application chain.

[0056] A control module is configured to allow the application chain to access the asset when the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

[0057] In some possible implementations, the application's own logic includes:

[0058] The application's input / output module or the logic by which the input / output module performs input / output operations;

[0059] The application's interface call module or the logic of the interface call module executing interface call operations;

[0060] The application's command execution module or the logic of the command execution module executing commands; or,

[0061] The application's resource scheduling module or the logic of the resource scheduling module scheduling resources.

[0062] In some possible implementations, the acquisition module is specifically used for:

[0063] Feature extraction is performed on the application chain to obtain the first identity feature of the application chain.

[0064] In some possible implementations, the acquisition module is specifically used for:

[0065] Feature extraction is performed on the application chain before each access to the asset.

[0066] In some possible implementations, the acquisition module is specifically used for:

[0067] When the application chain requests access to an asset whose attribute is the target attribute, the first identity feature of the application chain is obtained.

[0068] In some possible implementations, when the distance between the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

[0069] In some possible implementations, the device further includes:

[0070] The comparison module is used to compare the first identity feature of the application chain with the second identity feature of the application chain recorded in the application feature database locally or remotely.

[0071] In some possible implementations, the device further includes:

[0072] The update module is used to update the local application feature library based on the remote application feature library.

[0073] In some possible implementations, the device further includes:

[0074] The sending module is used to send the first identity feature of the application chain to the management node, so that the management node compares the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

[0075] In some possible implementations, the asset includes any one or more of the following: local credentials, remote credentials, or application programming interfaces for accessing the target service.

[0076] In some possible implementations, the identity features include fingerprints or behavioral characteristics.

[0077] In some possible implementations, the device and the application chain are deployed on the same working node.

[0078] In some possible implementations, the device and the asset are deployed on the same working node.

[0079] Fourthly, embodiments of this application provide an apparatus. The apparatus is used to implement the functions of the access control node in the access control system as described in the second aspect or any implementation thereof.

[0080] Fifthly, embodiments of this application provide an apparatus. The apparatus includes a processor and a memory. The processor and the memory communicate with each other. The processor is configured to execute instructions stored in the memory to cause the apparatus to perform the asset access control method as described in the first aspect or any implementation thereof.

[0081] In a sixth aspect, this application provides a computer-readable storage medium storing instructions that instruct a device to perform the asset access control method described in the first aspect or any implementation thereof.

[0082] In a seventh aspect, this application provides a computer program product containing instructions that, when run on a device, causes the device to execute the asset access control method described in the first aspect or any implementation thereof.

[0083] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description

[0084] To more clearly illustrate the technical methods of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly described below.

[0085] Figure 1 A system architecture diagram of an access control system provided in this application embodiment;

[0086] Figure 2 A schematic diagram illustrating access control for assets provided in an embodiment of this application;

[0087] Figure 3A A schematic diagram of the architecture of an access control system provided in an embodiment of this application;

[0088] Figure 3B A schematic diagram of the architecture of an access control system provided in an embodiment of this application;

[0089] Figure 4 A flowchart illustrating an asset access control method provided in an embodiment of this application;

[0090] Figure 5 A schematic diagram illustrating access control for assets provided in an embodiment of this application;

[0091] Figure 6 A flowchart illustrating an asset access control method provided in an embodiment of this application;

[0092] Figure 7 A schematic diagram of a Bloom filter provided for an embodiment of this application;

[0093] Figure 8 A flowchart illustrating an asset access control method provided in an embodiment of this application;

[0094] Figure 9 This is a schematic diagram of the structure of an access control device provided in an embodiment of this application;

[0095] Figure 10 This is a schematic diagram of the structure of a device provided in an embodiment of this application. Detailed Implementation

[0096] The terms "first" and "second" used in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature.

[0097] First, some technical terms involved in the embodiments of this application will be introduced.

[0098] An application is a program that runs as an independent entity. In some possible implementations, an application can be a microservice in a system based on a microservices framework. An application can also call another application, thus forming an application chain. An application chain can include one or more applications, where multiple applications refer to multiple applications with calling relationships. For example, if application A calls application B, and application B calls application C, then applications A, B, and C can form an application chain.

[0099] An asset is a resource that can generate benefits. In some embodiments, an asset can be, for example, an application programming interface (API) for accessing a service or a credential. Specifically, a credential can be an access token. This access token can be an API credential. This token can be used for authentication, allowing access to the corresponding service via the API after successful authentication. The credential can be any one or more of the following: a session ID, a secure shell (SSH) login key, a JSON web token (JWT), a one-time password, etc.

[0100] In practical applications, application chains can access assets as a whole. To ensure asset security, access control is often required for application chains to access assets. Currently, the industry mainly uses cryptographic features for application chain identification, such as authentication factors like passwords, keys, or certificates, and then implements access control based on the identification results. However, any application that obtains the authentication factors of a target application can impersonate the target application and thus access assets. This poses a significant challenge to asset security.

[0101] In view of this, embodiments of this application provide an access control method for assets. This method can be executed by an access control system. Specifically, the access control system obtains a first identity feature of an application chain, which originates from the logic of one or more applications within the application chain, for example, from the logic of all applications within the application chain. When the first identity feature of the application chain matches a second identity feature of the application chain recorded in an application feature database, the application chain is allowed to access the aforementioned asset.

[0102] Because the access control system uses the identity features derived from the logic of one or more applications in the application chain for identity verification, rather than external cryptographic features such as passwords, keys, or certificates, it can avoid asset security risks caused by application impersonation or tampering, thus ensuring asset security.

[0103] When the primary identity feature of an application chain originates from the internal logic of all applications within the chain, and assuming none of the applications have been tampered with, this primary identity feature can be used for identity verification. The access control system then allows the application chain to access the assets, thus ensuring asset security. In other words, the access control system can ensure that all applications within the application chain that have access to the assets are tamper-proof.

[0104] Furthermore, the access control system can extract features from the application chain before each access to assets, obtain the application chain's primary identity feature, and perform identity recognition based on the intrinsic primary identity feature. This can avoid security risks caused by applications being infected with viruses or tampered with, resulting in changes to the application's behavioral logic, but still using the original identity feature to continue performing operations, thus further ensuring asset security.

[0105] To make the technical solution of this application clearer and easier to understand, the access control system provided in the embodiments of this application will be described below with reference to the accompanying drawings.

[0106] See Figure 1 The system architecture diagram of the access control system shown is as follows: Figure 1 As shown, the access control system 100 includes at least one worker node 102. Each worker node 102 is deployed with one or more applications. The one or more applications can form a call chain. This application chain can be a call chain formed by multiple applications with calling relationships, or it can be a single application.

[0107] The application chain on worker node 102 can be used as a whole to access assets, such as APIs or credentials. These assets can be local or remote. Local assets are those deployed on the same worker node 102 as the application chain; for example, they may include local credentials or APIs used to access local target services. Remote assets are those not deployed on the same worker node 102 as the application chain; for example, they may be deployed on other worker nodes 102. These remote assets may specifically include remote credentials or APIs used to access remote target services.

[0108] See Figure 2 The worker node 102 for deploying the application chain or the worker node 102 for deploying the asset can act as an access control node, executing access control methods for the asset. Specifically, having the worker node 102 for deploying the application chain (or, when the asset is an API using the target service, it can also be called a service user node) implement access control methods for the asset, rather than having the worker node 102 for deploying the asset (or, when the asset is an API using the target service, it can also be called a service provider node), allows control to be implemented from the service user node. Applications that are not allowed to access the asset can be blocked from further operations locally, avoiding sending access requests to the service provider node, thereby avoiding unnecessary resource consumption and saving resources.

[0109] For ease of description, the following text will use the worker node 102 of the application chain as the access control node to illustrate the implementation of access control methods.

[0110] Specifically, the access control node (e.g., the worker node 102 that deploys the application chain) is equipped with an access control device. Before the application chain accesses the asset, the access control device obtains the first identity feature of the application chain. This first identity feature comes from the logic of one or more applications in the application chain, specifically the logic of some or all of the applications in the application chain. When the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database, the application chain is allowed to access the asset.

[0111] The access control device can extract features from the application chain before each access to an asset, obtaining a primary identity feature. Then, it performs identity verification based on this real-time extracted primary identity feature, for example, by comparing a primary identity feature with a secondary identity feature. When the primary identity feature matches the secondary identity feature, the application chain is allowed to access the asset. This enables real-time prevention and control, avoiding security risks caused by changes in some or all applications within the application chain that still access assets with the original identity features, thus further ensuring asset security.

[0112] Furthermore, the access control device can also initiate identity verification when the attribute of an asset requested by an application chain is a target attribute. The asset with the target attribute can be a manually marked asset, such as a manually marked high-value asset, a manually marked high-risk asset, etc. In some embodiments, the asset with the target attribute can also be an asset recommended and recorded by the system. When the attribute of an asset requested by an application chain is the aforementioned target attribute, such as high value, the first identity feature of the application chain is obtained. If the first identity feature matches a second identity feature recorded in the application feature database, the application chain is allowed to access the asset; otherwise, access is denied. This ensures the security of high-value, high-risk assets while reducing the intrusiveness to the application. Moreover, by using the above access control method when the application chain accesses an asset with the target attribute, rather than controlling access to the entire application chain, the maximum security benefit is achieved with minimal system overhead, minimizing the impact of access control on the application chain.

[0113] In some possible implementations, the access control system 100 also includes a management node 104. The management node 104 can maintain a remote application feature library. For example... Figure 1 As shown, N (N is a positive integer) working nodes 102 each maintain a local application feature library, such as application feature library 11 to application feature library 1N, and management node 104 maintains a remote application feature library, such as application feature library 21 to application feature library 2N.

[0114] The management node 104 can extract features from the applications deployed on each worker node 102 during the initialization phase to obtain the identity features of the applications deployed on each worker node 102. These identity features originate from the application's own logic. Specifically, this logic could be the application's input / output module or the logic of the input / output module performing input / output operations; the application's interface call module or the logic of the interface call module performing interface call operations; the application's command execution module or the logic of the command execution module executing commands; or the application's resource scheduling module or the logic of the resource scheduling module scheduling resources. Correspondingly, this identity feature could be, for example, a static fingerprint or dynamic behavioral features (the application's runtime behavioral features).

[0115] When the management node 104 extracts features from applications deployed on worker nodes 102, it can do so by extracting features from whitelisted applications deployed on worker nodes 102. Whitelisted applications are those added to a whitelist. The management node 104 extracts features from the whitelisted applications on each worker node 102 to obtain corresponding identity features, and forms an application feature library corresponding to each worker node 102 based on these identity features. This application feature library is a remote application feature library. This remote application feature library records the second identity features of the application chain.

[0116] Furthermore, the management node 104 can maintain the remote application feature database. Specifically, when an application deployed on worker node 102 changes, such as adding a new application or modifying an existing one, worker node 102 can report the application change information, such as the name, directory, and source of the new application. Based on this information, the management node 104 determines whether to add the new application to the whitelist. If so, it extracts the identity features of the new application and updates the remote application feature database corresponding to worker node 102.

[0117] In some possible implementations, worker node 102 (e.g., the access control device on worker node 102) can update its local application feature library based on the remote application feature library. This allows the identity feature matching process to be completed locally without reporting to management node 104, thereby reducing dependence on management node 104. Furthermore, by updating its local application feature library based on the remote library and comparing the first identity feature with the updated second identity feature recorded in the local application feature library, the accuracy of the comparison can be improved.

[0118] There are several ways to implement the updating of the local application signature database by the worker node 102 (e.g., the access control device on the worker node 102). For example, the worker node 102 can update the local application signature database in real time when the remote application signature database is updated. Or, the worker node 102 can update the local application signature database according to a preset period.

[0119] It should be noted that when the worker node 102 (e.g., the access control device on the worker node 102) compares the first identity feature with the second identity feature recorded in the local application feature database locally, if the first identity feature matches the second identity feature recorded in the local application feature database, it indicates that the application in the application chain is in the whitelist, and the worker node 102 (e.g., the access control device) allows the application chain to access the assets. If the first identity feature does not match the second identity feature recorded in the local application feature database, the worker node 102 can also report the application chain's attribute information, such as the application chain's process identifier, to the management node 104.

[0120] The management node 104 determines the risk of applications in the application chain based on process identifiers. Based on this risk, it decides whether to add the application to the whitelist. If so, it extracts features from the whitelisted applications and updates the remote application feature database. The worker node 102 can update its local application feature database based on the remote database. Then, the worker node 102 (e.g., the access control device on worker node 102) compares the first identity feature with the second identity feature recorded in the local application feature database. If the first and second identity features still do not match, it indicates that at least one application in the application chain is not on the whitelist, or at least one application, although on the whitelist, has been tampered with. The worker node 102 (e.g., the access control device) then prohibits the application chain from accessing assets. Therefore, the access control system 100 can achieve a loosely coupled architecture of centralized application management and distributed control, with high overall availability and reliability.

[0121] In some possible implementations, worker node 102 (e.g., an access control device on worker node 102) may also obtain the second identity feature of the application chain from a remote application feature library, and then compare the first identity feature and the second identity feature locally to determine whether the first identity feature and the second identity feature match.

[0122] In some possible implementations, worker node 102 (e.g., an access control device on worker node 102) may also send a first identity feature to management node 104. Management node 104 remotely compares the first identity feature and the second identity feature, and then sends the comparison result to worker node 102. This comparison result is used to characterize whether the first identity feature and the second identity feature match.

[0123] To improve comparison efficiency, worker node 102 (e.g., an access control device on worker node 102) or management node 104 can obtain the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain, determine the distance between the first Bloom vector and the second Bloom vector, and thus achieve the comparison of the first identity feature and the second identity feature. When the distance between the first Bloom vector and the second Bloom vector is less than a preset distance, it indicates that the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library; otherwise, it indicates that the first identity feature of the application chain does not match the second identity feature of the application chain recorded in the application feature library.

[0124] exist Figure 1In the illustrated embodiment, the access control device can be deployed on the local worker node 102 in the form of a computer program such as a script or plugin. The script or plugin is executed before the application chain accesses the asset, thereby implementing the asset access control method. The worker node 102 and management node 104 in the access control system 100 can be physical nodes or logical nodes virtualized from physical nodes. A physical node can correspond to a physical machine, such as a physical server or a terminal, and a logical node can correspond to a virtual machine. In some embodiments, a logical node can also correspond to a container.

[0125] Next, the deployment method of the access control system 100 will be described in detail with reference to the accompanying drawings.

[0126] like Figure 3A As shown, the various components of the access control system 100 can be centrally deployed in a cloud environment, specifically as one or more computing devices (e.g., a central server) within the cloud environment. Alternatively, the various components of the access control system 100 can be centrally deployed in an edge environment, specifically as one or more computing devices (edge ​​computing devices) within the edge environment. Edge computing devices can be servers, computing boxes, etc. The cloud environment refers to a central computing device cluster owned by a cloud service provider, used to provide computing, storage, and communication resources; the edge environment refers to an edge computing device cluster geographically close to the end devices (i.e., end-side devices), used to provide computing, storage, and communication resources. For example, the access control system 100 can be deployed in a public cloud to identify application chains formed by services in various Service-Oriented Architecture (SOA) systems, and to control access to assets by the application chains based on the identification results.

[0127] In some possible implementations, the various parts of the access control system 100 can also be centrally deployed on end devices. End devices include, but are not limited to, user terminals such as desktop computers, laptops, and smartphones.

[0128] like Figure 3B As shown, the various parts of the access control system 100 can also be deployed in a distributed manner in different environments. For example, a portion of the access control system 100 can be deployed in three environments: a cloud environment, an edge environment, and an end device, or any two of these environments.

[0129] Figure 3A and Figure 3B This is merely an illustrative representation of some deployment methods of the access control system 100. In other possible implementations of the embodiments of this application, the access control system 100 can also be deployed in other ways, which will not be elaborated here.

[0130] Next, with reference to the accompanying drawings, the asset access control method provided in the embodiments of this application will be described from the perspective of the access control system 100 (specifically, the access control device in the access control system 100).

[0131] See Figure 4 The flowchart shown illustrates an access control method, which includes:

[0132] S402: The access control device obtains the first identity feature of the application chain.

[0133] An application chain comprises one or more applications with a calling relationship. An application can include multiple branches, each representing an operation. Branches in the application chain that access assets can have pre-set control embedding points. When an application in the chain executes a branch that accesses assets, especially when accessing assets with specific target attributes, the application chain's identity verification process can be triggered through these control embedding points.

[0134] Specifically, the control embedding point can be implemented using hooks. Hook events can be pre-set in the application chain. These hook events include events related to accessing assets. Furthermore, hook events can be events related to accessing assets with specific target attributes, such as accessing high-value assets or high-risk assets. When the application chain reaches the control embedding point, the control embedding point can send the application chain's attribute information, such as the application chain's process identifier (e.g., process ID), to the access control device. The access control device obtains the first identity characteristic of the corresponding application chain based on the process identifier.

[0135] The primary identity feature originates from the internal logic of one or more applications within the application chain. This internal logic can be either static or dynamic. Static logic includes any one or more of the following: the logic of the application's input / output module, the logic of its interface call module, the logic of its command execution module, or the logic of its resource scheduling module. Dynamic logic includes any one or more of the following: the logic of the input / output module performing input / output operations, the logic of the interface call module performing interface call operations, the logic of the command execution module executing commands, or the logic of the resource scheduling module scheduling resources.

[0136] The access control device can extract features from the application chain to obtain a first identity feature of the application chain, which can be used for identity recognition of the application chain. Specifically, the access control device can extract one or more of the fingerprint or behavioral features of the application chain as the first identity feature of the application chain.

[0137] In this system, the fingerprint of the application chain is a static identity feature. The static logic of the applications in the application chain can be carried in the application's binary file, such as an executable file in .exe format. The access control device can perform static extraction on some or all of the binary files (such as executable files in .exe format) of the applications in the application chain to obtain the fingerprint of the application chain. Static extraction includes hash function operations or verification operations based on verification algorithms. In some embodiments, the access control device can use Message-Digest Algorithm 5 (MD5) to calculate the MD5 value of the binary files of each application in the application chain, which can serve as the fingerprint of the application chain.

[0138] The behavioral characteristics of an application chain are dynamic identity characteristics. The dynamic logic of applications within the application chain can be carried within various behaviors of those applications. Access control devices can dynamically capture the behaviors of some or all applications within the application chain to obtain its behavioral characteristics. Specifically, in a clean monitoring environment, by running the functions of applications within the application chain, the access control device captures various behaviors of some or all applications in the application chain, as well as data related to those behaviors. This allows the acquisition of the dynamic behavioral relationships and data dependencies within the application chain. The access control device can then obtain the behavioral characteristics of the application chain based on these dynamic behavioral relationships and data dependencies. It should be noted that the access control device can also compress these dynamic behavioral relationships and data dependencies, thereby simplifying the behavioral characteristics.

[0139] In some possible implementations, the access control device can perform feature extraction on the application chain before its first access to an asset or an asset with a target attribute during a single job, obtaining the application chain's initial identity feature. Before the job ends and the application chain accesses the asset or the asset with the target attribute again, the access control device can directly retrieve the initial identity feature obtained during the initial access. This reduces the number of feature extractions and computational overhead.

[0140] In other possible implementations, the access control device can extract features from the application chain before each access to an asset or an asset with a target attribute, obtaining the application chain's initial identity feature. That is, the access control device extracts features from the application chain in real time to obtain its initial identity feature. This ensures that the initial identity feature obtained by the access control device accurately represents the application chain's identity at that moment, preventing security risks caused by the application chain being tampered with or infected with a virus, yet still accessing assets or assets with the original identity feature.

[0141] The target asset can be a manually labeled asset, such as a manually labeled high-value asset or a manually labeled high-risk asset. In some embodiments, the target asset can also be an asset recommended and recorded by the system. When accessing the target asset, the access control device triggers an identity verification process, which can ensure the security of the target asset and reduce the intrusion into the application chain.

[0142] S404: When the first identity feature of an application chain matches the second identity feature of the application chain recorded in the application feature database, the access control device allows the application chain to access the assets.

[0143] The application feature database records the identity features of applications deployed on worker node 102. In some embodiments, the application feature database records the identity features of whitelisted applications deployed on worker node 102. The applications deployed on worker node 102 may include applications in an application chain; therefore, the application feature database records the identity features of the application chain. For ease of distinction, the identity features recorded in the application feature database are referred to as second identity features in this embodiment.

[0144] The access control device can determine whether the first identity feature and the second identity feature match based on their similarity. For example, it can determine the similarity between the first identity feature and the second identity feature in the local application feature library locally to perform identity feature comparison locally, or it can send the first identity feature to the management node 104 so that the management node 104 can determine the similarity between the first identity feature and the second identity feature in the remote application feature library remotely to perform identity feature comparison remotely, thereby realizing identity recognition of the application chain.

[0145] In addition to performing identity feature comparison locally, the access control device can also update the local application feature database based on the remote application feature database, thereby improving the comparison accuracy. It should be noted that in some embodiments, the access control device can also obtain a second identity feature from the remote application feature database, and then compare the first and second identity features locally to determine whether the first and second identity features match, thereby achieving identity recognition of the application chain.

[0146] The access control device determines the corresponding access control policy based on the identity recognition result. For example, when the first identity feature and the second identity feature match, the identity recognition result is "identity recognition passed," the application in the application chain is a whitelisted application, and the access control device determines the access control policy to allow access; when the first identity feature and the second identity feature do not match, the identity recognition result is "identity recognition failed," the application chain includes a non-whitelisted application, and the access control device determines the access control policy to deny access.

[0147] For ease of understanding, this application also provides a specific example.

[0148] like Figure 5 As shown, the application chain includes multiple branches. Among these branches, three are for accessing assets: branch 1, branch 2, and branch 3. Branches 1 and 2 are for accessing high-value assets, while branch 3 is for accessing low-value assets. Branches 1 and 2 have pre-set control embedding points. When the application chain executes to branch 1 or branch 2, the corresponding control embedding point triggers an identity verification process for the application chain.

[0149] Specifically, the control embedding point transmits the process ID of the application chain to the access control device. The access control device extracts features from the application chain based on the process ID to obtain the first identity features of the application chain, such as the first fingerprint and the first behavioral features. Then, it compares the first identity features of the application chain with the second identity features, such as the second fingerprint and the second behavioral features, recorded in the application feature library (e.g., a local application feature library). Based on the comparison result, it obtains the corresponding access control policy and returns the access control policy to the control embedding point so as to control the application chain's access to assets.

[0150] Specifically, when the comparison result indicates that the first identity feature and the second identity feature match, the access control policy obtained by the access control device can be to allow the application chain to access the asset; when the comparison result indicates that the first identity feature and the second identity feature do not match, the access control policy obtained by the access control device can be to prohibit the application chain from accessing the asset.

[0151] exist Figure 5 In the example, when the application chain executes to branch 1, it is allowed to access the aforementioned high-value asset. When the application chain executes to branch 2, it is not allowed to access the aforementioned high-value asset. When the application chain executes to branch 3, since the asset requested for access in branch 3 is a low-value asset, the identity verification process is not triggered, and the application chain can directly access the low-value asset.

[0152] Based on the above, this application provides an asset access control method. This method obtains the inherent first identity feature of the application chain and performs identity recognition based on this inherent first identity feature, rather than external cryptographic features, etc. Access control is then performed based on the identity recognition result, thereby avoiding asset security risks caused by application impersonation or tampering and ensuring asset security.

[0153] Next, taking application chain access to local credentials and remote credentials as examples, we will introduce the asset access control method provided in the embodiments of this application.

[0154] See Figure 6The flowchart shown illustrates the access control method for assets. This method specifically includes the following steps:

[0155] Step 1: The management node 104 extracts features from the whitelisted applications on the worker node 102 to obtain the second identity features of the whitelisted applications, and generates a remote application feature library based on the second identity features.

[0156] Specifically, the management node 104 can store the second identity feature as a file in a remote application feature library. For security reasons, the management node 104 can encrypt the file containing the second identity feature. In some possible implementations, the management node 104 can also input the second identity feature into a Bloom filter to obtain a second Bloom vector corresponding to the second identity feature, and then store the second Bloom vector in the remote application feature library. By mixing the fingerprints and other identity features of the whitelisted applications together to form an unrecoverable string of 0s and 1s, security and the efficiency of feature comparison can be improved.

[0157] The principle of the Bloom filter will be explained below with reference to the accompanying drawings.

[0158] See Figure 7 The schematic diagram of the Bloom filter shown is as follows: Figure 7 As shown, the Bloom filter first initializes all bits in a Bloom vector (b1, b2, ..., bm) of length m bits to 0. Then, it applies k independent fast hash functions (h1, h2, ..., hk) with return values ​​between 1 and m to the second identity feature of each input, such as the fingerprint of each input, to obtain k return values ​​(r1, r2, ..., rk). Next, it sets the bits in the Bloom vector at positions r1, r2, ..., rk to 1, thus obtaining the Bloom vector corresponding to the identity feature.

[0159] Step 2: The access control device on worker node 102 updates the local application feature database based on the remote application feature database.

[0160] Step 3: When the application chain executes to the branch that accesses local credentials, the embedded control point on worker node 102 sends the application chain's process ID.

[0161] Step 4: The access control device on worker node 102 obtains the first identity feature of the application chain based on the process ID.

[0162] Specifically, the access control device on worker node 102 searches for applications included in the application chain based on the process ID, extracts features from the applications included in the application chain, and obtains the first identity feature of the application chain. The first identity feature of the application chain includes the first identity features of some or all of the applications in the application chain, such as fingerprints or behavioral characteristics of some or all of the applications.

[0163] Step 5: The access control device on worker node 102 inputs the first identity feature into the Bloom filter to obtain the first Bloom vector.

[0164] In cases where the remote application feature library stores the second identity feature, but not the second Bloom vector corresponding to the second identity feature, the access control device may not execute step 5.

[0165] Step 6: The access control device on worker node 102 determines whether the first identity feature matches the second identity feature recorded in the local application feature database. If yes, proceed to step 7; otherwise, end the current process.

[0166] Specifically, the access control device on worker node 102 can determine whether the first identity feature and the local second identity feature match by measuring the distance between the first Bloom vector and the second Bloom vector. When the distance between the first Bloom vector and the second Bloom vector is less than a preset distance, it indicates that the first identity feature and the second identity feature match; otherwise, the first identity feature and the second identity feature match.

[0167] In some implementations, the access control device on the working node 102 can also directly determine the similarity between the first identity feature and the second identity feature, thereby determining whether the first identity feature and the second identity feature match.

[0168] Step 7: The control embedding point on worker node 102 decrypts the ciphertext of the local credential to obtain the local credential.

[0169] This application implements a whitelist to control the acquisition of local credentials in plaintext form. Any application chain not on the whitelist, or an application chain on the whitelist that has been tampered with, cannot obtain local credentials in plaintext, thereby ensuring the security of local credentials.

[0170] Next, see Figure 8 The flowchart shown illustrates the access control method for assets. This method specifically includes the following steps:

[0171] Step 1: The management node 104 extracts features from the whitelisted applications on the worker node 102 to obtain the second identity features of the whitelisted applications, and generates a remote application feature library based on the second identity features.

[0172] Step 2: The access control device on worker node 102 updates the local application feature database based on the remote application feature database.

[0173] Step 3: When the application chain executes to the branch that accesses remote credentials, the embedded control point on worker node 102 sends the application chain's process ID.

[0174] Step 4: The access control device on worker node 102 obtains the first identity feature of the application chain based on the process ID.

[0175] Step 5: The access control device on worker node 102 inputs the first identity feature into the Bloom filter to obtain the first Bloom vector.

[0176] In cases where the remote application feature library stores the second identity feature, but not the second Bloom vector corresponding to the second identity feature, the access control device may not execute step 5.

[0177] Step 6: The access control device on worker node 102 determines whether the first identity feature matches the second identity feature recorded in the local application feature database. If yes, proceed to step 7; otherwise, end the current process.

[0178] Step 7: The control embedding point on worker node 102 obtains remote credentials from the credential hosting service.

[0179] Cloud Credential Management Service (CCMS) can remotely host credentials. When the first and second identity characteristics match, the control embedding point can retrieve the remote credentials, for example, through a RESTful application programming interface (API) in the style of representational state transfer (REST).

[0180] The above text combined Figures 1 to 8 The access control system and asset access control method provided in the embodiments of this application have been described in detail. The apparatus and equipment provided in the embodiments of this application are described below.

[0181] See Figure 9 The schematic diagram shown illustrates the structure of the access control device 900, which includes:

[0182] The acquisition module 902 is used to acquire the first identity feature of the application chain, wherein the identity feature of the application chain comes from the logic of one or more applications in the application chain.

[0183] The control module 904 is configured to allow the application chain to access the asset when the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

[0184] In some possible implementations, the application's own logic includes:

[0185] The application's input / output module or the logic by which the input / output module performs input / output operations;

[0186] The application's interface call module or the logic of the interface call module executing interface call operations;

[0187] The application's command execution module or the logic of the command execution module executing commands; or,

[0188] The application's resource scheduling module or the logic of the resource scheduling module scheduling resources.

[0189] In some possible implementations, the acquisition module 902 is specifically used for:

[0190] Feature extraction is performed on the application chain to obtain the first identity feature of the application chain.

[0191] In some possible implementations, the acquisition module 902 is specifically used for:

[0192] Feature extraction is performed on the application chain before each access to the asset.

[0193] In some possible implementations, the acquisition module 902 is specifically used for:

[0194] When the application chain requests access to an asset whose attribute is the target attribute, the first identity feature of the application chain is obtained.

[0195] In some possible implementations, when the distance between the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

[0196] In some possible implementations, the device 900 further includes:

[0197] The comparison module is used to compare the first identity feature of the application chain with the second identity feature of the application chain recorded in the application feature database locally or remotely.

[0198] In some possible implementations, the device 900 further includes:

[0199] The update module is used to update the local application feature library based on the remote application feature library.

[0200] In some possible implementations, the device 900 further includes:

[0201] The sending module is used to send the first identity feature of the application chain to the management node, so that the management node compares the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

[0202] In some possible implementations, the asset includes any one or more of the following: local credentials, remote credentials, or application programming interfaces for accessing the target service.

[0203] In some possible implementations, the identity features include fingerprints or behavioral characteristics.

[0204] In some possible implementations, the device 900 and the application chain are deployed on the same working node.

[0205] The access control device provided according to the embodiments of this application can correspond to the execution of the methods described in the embodiments of this application, and the above and other operations and / or functions of each module / unit of the access control device are respectively for implementing Figures 4 to 8 For the sake of brevity, the corresponding processes of each method in the illustrated embodiments will not be described in detail here.

[0206] This application also provides a device, which can be a computing device such as a terminal or server. The device can be a single device or a cluster of multiple devices. For ease of description, this application uses a single device as an example. This device can specifically be used to implement, for example... Figure 9 The functions of the access control device 900 shown are described below. Next, the device provided in this application embodiment will be described from a hardware implementation perspective.

[0207] Figure 10 A structural schematic diagram of a device 1000 is provided, as follows: Figure 10 As shown, device 1000 includes a bus 1001, a processor 1002, a communication interface 1003, and a memory 1004. The processor 1002, the memory 1004, and the communication interface 1003 communicate with each other via the bus 1001.

[0208] Bus 1001 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 10 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0209] The processor 1002 can be any one or more of the following processors: central processing unit (CPU), graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).

[0210] Communication interface 1003 is an input / output (I / O) device. Communication interface 1003 is used for communication with external systems. Specifically, communication interface 1003 can obtain second identity features recorded in a remote application feature database to update the local application feature database, or report application change information to management node 104 so that management node 104 can determine whether to add the corresponding application to the whitelist based on the application change information, etc.

[0211] The memory 1004 may include volatile memory, such as random access memory (RAM). The memory 1004 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0212] The memory 1004 stores executable program code, and the processor 1002 executes the executable program code to perform the step of obtaining the first identity feature of the application chain, which comes from the logic of one or more applications in the application chain. When the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library, the step of allowing the application chain to access the asset is executed, thereby executing the aforementioned asset access control method.

[0213] This application also provides a computer-readable storage medium including instructions that instruct device 1000 to perform the above-described asset access control method.

[0214] This application also provides a computer-readable storage medium including instructions that instruct device 1000 to perform the above-described asset access control method.

[0215] This application also provides a computer program product, which, when executed by a computer, enables the computer to perform any of the aforementioned methods of access control for providing assets. The computer program product can be a software installation package; when any of the aforementioned methods of access control for providing assets is required, the computer program product can be downloaded and executed on the computer.

Claims

1. An access control method for an asset, characterized in that, The method is applied to a worker node, which is equipped with an access control device and an application chain. The application chain includes one or more applications with calling relationships, and each application includes multiple branches. A control embedding point is set in the branch of the application chain that accesses the asset. The method includes: The access control device obtains the process identifier of the application chain sent by the management embedding point when the application chain is executed to the management embedding point; The access control device obtains the first identity feature of the application chain corresponding to the process identifier based on the process identifier, and the first identity feature of the application chain comes from the logic of one or more applications in the application chain. When the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database, the access control device allows the application chain to access the asset; when the first identity feature and the second identity feature do not match, the access control device denies the application chain access to the asset.

2. The method according to claim 1, characterized in that, The application's own logic includes: The application's input / output module or the logic by which the input / output module performs input / output operations; The application's interface call module or the logic of the interface call module executing interface call operations; The application's command execution module or the logic by which the command execution module executes commands; or, The application's resource scheduling module or the logic of the resource scheduling module scheduling resources.

3. The method according to claim 1, characterized in that, The access control device obtains the first identity feature of the application chain corresponding to the process identifier based on the process identifier, including: The access control device extracts features from the application chain based on the process identifier to obtain the first identity feature of the application chain.

4. The method according to claim 3, characterized in that, The access control device performs feature extraction on the application chain based on the process identifier, including: The access control device extracts features from the application chain based on the process identifier before each access to the asset by the application chain.

5. The method according to any one of claims 1 to 4, characterized in that, The access control device obtains the first identity feature of the application chain based on the process identifier, including: When the application chain requests access to an asset with the attribute of the target attribute, the access control device obtains the first identity feature of the application chain based on the process identifier.

6. The method according to any one of claims 1 to 4, characterized in that, When the distance between the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

7. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The access control device compares the first identity feature of the application chain with the second identity feature of the application chain recorded in the application feature database, either locally or remotely.

8. The method according to claim 7, characterized in that, The method further includes: The access control device updates the local application feature database based on the remote application feature database.

9. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The access control device sends the first identity feature of the application chain to the management node, so that the management node compares the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

10. The method according to any one of claims 1 to 4, characterized in that, The assets include any one or more of the following: local credentials, remote credentials, or application programming interfaces used to access the target service.

11. The method according to any one of claims 1 to 4, characterized in that, The identity features include fingerprints or behavioral characteristics.

12. An access control system, characterized in that, The system includes worker nodes, each deployed with access control devices and an application chain. The application chain includes one or more applications with calling relationships, and each application has multiple branches. The branches within the application chain that access assets have control embedding points set up. The access control device is used to obtain the process identifier of the application chain sent by the management embedding point when the application chain is executed to the management embedding point, and to obtain the first identity feature of the application chain corresponding to the process identifier based on the process identifier. The identity feature of the application chain comes from the logic of one or more applications in the application chain. The access control device is further configured to allow the application chain to access the asset when the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database; and to deny the application chain access to the asset when the first identity feature and the second identity feature do not match.

13. The system according to claim 12, characterized in that, The application's own logic includes: The application's input / output module or the logic by which the input / output module performs input / output operations; The application's interface call module or the logic of the interface call module executing interface call operations; The application's command execution module or the logic by which the command execution module executes commands; or, The application's resource scheduling module or the logic of the resource scheduling module scheduling resources.

14. The system according to claim 12, characterized in that, The access control device is specifically used for: Based on the process identifier, feature extraction is performed on the application chain to obtain the first identity feature of the application chain.

15. The system according to claim 14, characterized in that, The access control device is specifically used for: Based on the process identifier, feature extraction is performed on the application chain before each access to the asset in the application chain.

16. The system according to any one of claims 12 to 15, characterized in that, The access control device is specifically used for: When the application chain requests access to an asset with the target attribute, the first identity feature of the application chain is obtained based on the process identifier.

17. The system according to any one of claims 12 to 15, characterized in that, When the distance between the first Bloom vector corresponding to the first identity feature of the application chain and the second Bloom vector corresponding to the second identity feature of the application chain is less than a preset distance, the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature library.

18. The system according to any one of claims 12 to 15, characterized in that, The access control device is also used for: The first identity feature of the application chain is compared with the second identity feature of the application chain recorded in the application feature database, either locally or remotely.

19. The system according to claim 18, characterized in that, The access control device is also used for: Update the local application feature library based on the remote application feature library.

20. The system according to any one of claims 12 to 15, characterized in that, The system also includes a management node; The access control device is also used to send the first identity feature of the application chain to the management node; The management node is used to compare the first identity feature of the application chain with the second identity feature of the application chain recorded in the remote application feature database.

21. The system according to any one of claims 12 to 15, characterized in that, The assets include any one or more of the following: local credentials, remote credentials, or application programming interfaces used to access the target service.

22. The system according to any one of claims 12 to 15, characterized in that, The identity features include fingerprints or behavioral characteristics.

23. A device, characterized in that, The device is used to implement the function of the access control device in the access control system as described in any one of claims 12 to 22.

24. A device, characterized in that, The device includes a processor and a memory; The processor is configured to execute instructions stored in the memory to cause the device to perform the method as described in any one of claims 1 to 11.

25. An access control device, characterized in that, The device includes: The acquisition module is used to acquire the process identifier of the application chain sent by the control embedding point when the application chain is executed to the control embedding point, and to acquire the first identity feature of the application chain corresponding to the process identifier based on the process identifier. The application chain includes one or more applications with calling relationships. The application includes multiple branches. The branch in the application chain that accesses assets sets the control embedding point. The identity feature of the application chain comes from the logic of one or more applications in the application chain. The control module is configured to allow the application chain to access the asset when the first identity feature of the application chain matches the second identity feature of the application chain recorded in the application feature database; and to deny the application chain access to the asset when the first identity feature and the second identity feature do not match.

26. A computer-readable storage medium, characterized in that, Includes instructions that instruct the device to perform the method as described in any one of claims 1 to 11.

27. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Systems and Methods for Mutual Integrity Attestation Between A Network Endpoint And A Network Appliance

    US20150288659A1