Configuration method and device of cloud computing system, storage medium and electronic equipment
Patent Information
- Application Number
- CN202211228580.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-09
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2042-10-09
AI Technical Summary
[0005]本申请提供一种云计算系统的配置方法、装置、存储介质以及电子设备,以解决相关技术中在云计算系统中不同的用户分别进行网络配置,导致配置过程中存在风险并且维护难度较高的问题
[0016]This application employs the following steps: Creating a user resource set within a cloud computing system, where the user resource set includes multiple Virtual Private Clouds (VPNs); obtaining user information and creating virtual firewalls in each VPN based on this information, resulting in multiple target VPNs; sequentially associating each target VPN with the remaining target VPNs in the user resource set, and connecting each target VPN to its corresponding network, thus obtaining a configured user resource set. This solves the problem in related technologies where different users in a cloud computing system require separate network configurations, leading to risks and high maintenance difficulty during configuration. By creating firewalls with different security control levels and associating them with VPNs, while configuring different network connections for each VPN, a unified configuration standard is achieved, facilitating management by operations and maintenance personnel after configuration.
Smart Images

Figure CN115604103B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing, and more specifically, to a configuration method, apparatus, storage medium, and electronic device for a cloud computing system. Background Technology
[0002] As more and more users migrate their applications to cloud computing systems, the challenges they face when configuring complex SDN (Software Defined Network) networks are becoming increasingly prominent. Each user migrating to the cloud needs to configure multiple operation and maintenance modules, involving complex operations, and there are high similarities and partial overlaps in configurations across resource domains. These issues are placing increasing pressure and time costs on technical support personnel. Furthermore, if configuration problems are not detected in a timely manner, they can create hidden dangers for application deployment, potentially leading to production accidents and damaging company interests.
[0003] Currently, network configuration is often left to users to perform themselves. Each configuration person may use different configuration methods or rules, which will bring increasing maintenance pressure and time costs to the corresponding technical support personnel, and may also lead to configuration risks.
[0004] There is currently no effective solution to the problem of configuring networks separately for different users in cloud computing systems, which leads to risks and high maintenance difficulties during the configuration process. Summary of the Invention
[0005] This application provides a configuration method, apparatus, storage medium, and electronic device for a cloud computing system to solve the problem in related technologies where different users in a cloud computing system perform network configuration separately, resulting in risks and high maintenance difficulty during the configuration process.
[0006] According to one aspect of this application, a configuration method for a cloud computing system is provided. The method includes: creating a user resource set for a user in the cloud computing system, wherein the user resource set includes multiple virtual private clouds (VPNs); obtaining user information of the user, and creating a virtual firewall in each VPN based on the user information to obtain multiple target VPNs; sequentially associating each target VPN with the remaining target VPNs in the user resource set, and connecting the target VPNs to their corresponding networks to obtain a configured user resource set.
[0007] Optionally, the user information includes user domain and user level. Adding a virtual firewall to each virtual private cloud based on the user information to obtain multiple target virtual private clouds includes: obtaining multiple virtual firewalls corresponding to the user domain from a lookup table, where the lookup table includes multiple preset user domains and multiple virtual firewalls corresponding to each preset user domain; when the user level is level 1, obtaining a firewall of the first security level from the multiple virtual firewalls corresponding to the user domain, and configuring the firewall of the first security level in each virtual private cloud to obtain multiple target virtual private clouds; when the user level is level 2, obtaining a firewall of the first security level and a firewall of the second security level from the multiple virtual firewalls corresponding to the user domain, configuring the firewall of the first security level in a virtual private cloud with a preset identifier, and configuring the firewall of the second security level in a virtual private cloud without a preset identifier to obtain multiple target virtual private clouds, where level 1 is higher than level 2, first security level is higher than second security level, and the preset identifier indicates that the virtual private cloud has permission to connect to the Internet.
[0008] Optionally, connecting the target virtual private cloud (VPN) to the corresponding network includes: creating multiple physical interfaces in the cloud computing system, wherein the physical interfaces include an internet interface and an intranet interface, the physical switch gateway associated with the internet interface is connected to the internet, and the physical switch gateway associated with the intranet interface is connected to the local area network (LAN); obtaining a target VPN with a preset identifier from the user resource set, and connecting the target VPN with the preset identifier to the internet interface, wherein the preset identifier indicates that the VPN has the permission to connect to the internet; obtaining a target VPN without a preset identifier from the user resource set, and connecting the target VPN without the preset identifier to the intranet interface.
[0009] Optionally, after obtaining the configured user resource set, the method further includes: determining whether there is an access request for accessing a public resource set in the user information, wherein the public resource set exists in the cloud computing system; if there is an access request in the user information, obtaining a target virtual private cloud from the configured user resource set, and connecting the target virtual private cloud with the public resource set, wherein the target virtual private cloud is the virtual private cloud that needs to access the public resource set.
[0010] Optionally, creating a user resource set in the cloud computing system includes: creating multiple virtual private clouds (VPNs) through interfaces in the cloud computing system and obtaining return information generated from the creation of VPNs, wherein the return information is an identification identifier for the VPN; creating a subnet segment corresponding to each VPN based on the return information; and determining the multiple VPNs and the subnet segment corresponding to each VPN as the user resource set.
[0011] Optionally, before obtaining the user's user information, the method further includes: deleting the initial security rules in the cloud computing system and adding preset security rules to the cloud computing system, wherein the initial security rules represent that the servers of the private virtual cloud in the user resource set have the right to access each other, and the preset security rules represent that the servers in the cloud computing system have the right to access each other.
[0012] Optionally, before creating a user's user resource set in the cloud computing system, the method further includes: obtaining the user's identity information and determining whether the user's identity information includes a preset token, wherein the preset token represents the permission to perform operations on the cloud computing system; if the user's identity information includes a preset token, performing the step of creating the user's user resource set in the cloud computing system; if the user's identity information does not include a preset token, issuing an alarm message, wherein the alarm message is used to indicate that the cloud computing system has been attacked.
[0013] According to another aspect of this application, a configuration apparatus for a cloud computing system is provided. The apparatus includes: a creation unit for creating a user resource set for a user in the cloud computing system, wherein the user resource set includes multiple virtual private clouds (VPNs); an adding unit for acquiring user information and creating a virtual firewall in each VPN based on the user information, thereby obtaining multiple target VPNs; and an association unit for sequentially associating each target VPN with the remaining target VPNs in the user resource set and connecting the target VPNs to corresponding networks, thereby obtaining a configured user resource set.
[0014] According to another aspect of the present invention, a computer storage medium is also provided for storing a program, wherein the program, when running, controls the device where the computer storage medium is located to execute a configuration method for a cloud computing system.
[0015] According to another aspect of the present invention, an electronic device is also provided, comprising one or more processors and a memory; the memory stores computer-readable instructions, and the processor is used to execute the computer-readable instructions, wherein the computer-readable instructions execute a configuration method for a cloud computing system.
[0016] This application employs the following steps: Creating a user resource set within a cloud computing system, where the user resource set includes multiple Virtual Private Clouds (VPNs); obtaining user information and creating virtual firewalls in each VPN based on this information, resulting in multiple target VPNs; sequentially associating each target VPN with the remaining target VPNs in the user resource set, and connecting each target VPN to its corresponding network, thus obtaining a configured user resource set. This solves the problem in related technologies where different users in a cloud computing system require separate network configurations, leading to risks and high maintenance difficulty during configuration. By creating firewalls with different security control levels and associating them with VPNs, while configuring different network connections for each VPN, a unified configuration standard is achieved, facilitating management by operations and maintenance personnel after configuration. Attached Figure Description
[0017] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:
[0018] Figure 1 This is a flowchart of a configuration method for a cloud computing system provided according to an embodiment of this application;
[0019] Figure 2 This is a flowchart of an optional cloud computing system configuration method provided according to an embodiment of this application;
[0020] Figure 3 This is a schematic diagram of a configuration device for a cloud computing system provided according to an embodiment of this application;
[0021] Figure 4 This is a schematic diagram of an electronic device provided according to an embodiment of this application. Detailed Implementation
[0022] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0023] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0024] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0025] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties. For example, this system has an interface with relevant users or organizations. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving consent information from the aforementioned user or organization.
[0026] It should be noted that the configuration methods, devices, storage media, and electronic devices for cloud computing systems as defined in this disclosure can be used in the field of cloud computing, or in any field other than cloud computing. The application fields of the configuration methods, devices, storage media, and electronic devices for cloud computing systems as defined in this disclosure are not limited.
[0027] For ease of description, the following explains some of the nouns or terms used in the embodiments of this application:
[0028] VPC: Virtual Private Cloud, is a dynamically configured pool of public cloud computing resources used for data transfer between enterprises and cloud service providers.
[0029] According to an embodiment of this application, a configuration method for a cloud computing system is provided.
[0030] Figure 1 This is a flowchart of a configuration method for a cloud computing system according to an embodiment of this application. Figure 1 As shown, the method includes the following steps:
[0031] Step S101: Create a user resource set for the user in the cloud computing system, wherein the user resource set includes multiple virtual private clouds.
[0032] Specifically, the network functions of a cloud computing system can be implemented by multiple core components. Each core component provides an API interface, which users can call to configure various basic functions and perform secondary development.
[0033] By calling the API, a user resource set can be created under the project where the user is located in the cloud computing system. The user resource set includes multiple independent and isolated virtual private clouds, such as three virtual private clouds. Each virtual private cloud corresponds to a target network area. Subnet segments can be configured for communication and firewalls can be configured for security protection for each virtual private cloud according to the network area.
[0034] For example, Table 1 shows an optional user resource set configuration, which includes three VPCs. Each VPC can correspond to a network zone and a subnet segment. Intranet, DMZExtranet, and DMZInternet are the names of different network zones. Intranet, DMZExtranet, and DMZInternet can be identified as low-risk internal network zone, medium-risk isolated network zone, and high-risk Internet network zone, respectively, based on the security of the network zones.
[0035] Table 1
[0036] Intranet XXfh_Project-Intranet-VPC Intranet-subnet AAA0 / 24 DMZExtranet XXfh_Project-DMZExtranet-VPC DMZExtranet-subnet BBB0 / 24 DMZ Internet XXfh_Project-DMZInternet-VPC DMZ Internet-subnet CCC0 / 24
[0037] Step S102: Obtain user information and create a virtual firewall in each virtual private cloud based on the user information to obtain multiple target virtual private clouds.
[0038] Specifically, after obtaining the virtual private cloud information, the virtual firewall can be configured according to the network zone security requirements corresponding to the virtual private cloud. This ensures the security of each virtual private cloud while allowing virtual private cloud services of different security levels to obtain the most granular control with minimal permissions.
[0039] For example, if a user requires a high level of security, a firewall with a higher level of security will be provided; if a user needs a wide range of access, a firewall with a lower level of security will be provided; if a user has special requirements, the firewall will be configured according to those requirements.
[0040] Step S103: Associate each target virtual private cloud with the other target virtual private clouds in the user resource set in sequence, and connect the target virtual private cloud with the corresponding network to obtain the configured user resource set.
[0041] Specifically, after configuring the virtual firewall, it is determined whether there is a need for virtual private clouds within the user resource set to access each other. If so, multiple virtual private clouds in the user resource set can be associated. That is, the isolation restrictions between each target virtual private cloud and the other virtual private clouds are broken in turn, and the connection between multiple virtual private clouds is established, so that multiple virtual private clouds can access each other.
[0042] Furthermore, the basic configuration for mutual access between the virtual private cloud and the external environment is completed, enabling the virtual private cloud to connect with the corresponding external network. This ensures that each virtual private cloud can use network services, while also allowing multiple virtual private clouds to be classified, so that each virtual private cloud has different permissions to access external resource sets. This ensures that each virtual private cloud can access different resource sets, guaranteeing the diversity of network access for virtual private clouds, and completing the network configuration of the user's resource set in the cloud computing system.
[0043] The cloud computing system configuration method provided in this application involves creating a user resource set within the cloud computing system, where the user resource set includes multiple virtual private clouds (VPNs). User information is obtained, and a virtual firewall is created in each VPN based on this information, resulting in multiple target VPNs. Each target VPN is then sequentially associated with the remaining target VPNs in the user resource set, and the target VPNs are connected to their corresponding networks, resulting in a configured user resource set. This method solves the problem in related technologies where different users in the cloud computing system are configured with separate networks, leading to risks and high maintenance difficulty during configuration. By creating firewalls with different security control levels and associating them with VPNs, while configuring different network connections for each VPN, a unified configuration standard is achieved, facilitating management by operations and maintenance personnel after configuration.
[0044] To configure virtual firewalls appropriately, optionally, in the configuration method of the cloud computing system provided in this application embodiment, user information includes user domains and user levels. Adding virtual firewalls to each virtual private cloud based on user information to obtain multiple target virtual private clouds includes: obtaining multiple virtual firewalls corresponding to user domains from a lookup table, wherein the lookup table includes multiple preset user domains and multiple virtual firewalls corresponding to each preset user domain; when the user level is first level, obtaining a firewall of first security level from the multiple virtual firewalls corresponding to the user domain, and configuring the firewall of first security level in each virtual private cloud respectively to obtain multiple target virtual private clouds; when the user level is second level, obtaining a firewall of first security level and a firewall of second security level from the multiple virtual firewalls corresponding to the user domain, configuring the firewall of first security level in a virtual private cloud with a preset identifier, and configuring the firewall of second security level in a virtual private cloud without a preset identifier to obtain multiple target virtual private clouds, wherein the first level is higher than the second level, the first security level is higher than the second security level, and the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet.
[0045] Specifically, since there are many types of firewalls and the protection types of firewalls differ, you can first select the firewall type that best suits the user from among many firewalls based on the user's domain, and then configure that type of firewall in the user's virtual private cloud.
[0046] Furthermore, after obtaining the type of virtual firewall corresponding to the user domain through the lookup table, the firewall corresponding to each virtual private cloud can be selected from a variety of firewalls of that type. The firewall selection type can be determined by the user's level. If the user level is Level 1, indicating a high level of protection, then all firewalls corresponding to the user's multiple virtual private clouds need to be configured as Level 1 firewalls, i.e., high-level firewalls, thus ensuring that each of the user's virtual private clouds is under high protection.
[0047] Furthermore, if the user's level is Level 2, indicating a lower protection level, then the firewall configuration for that user needs to be adjusted. Virtual Private Clouds (VPNs) with preset identifiers can be obtained from the user's multiple VPNs. Since these preset identifiers indicate that the VPNs have permission to connect to the internet, to ensure the security of the entire VPN and the cloud computing system, a higher-level firewall (Level 1) needs to be configured in the VPN connected to the internet. In the remaining VPNs without preset identifiers, a lower-level firewall (Level 2) can be configured, thus completing the virtual firewall configuration for the user's VPNs. This embodiment standardizes the firewall configuration process by configuring the firewall according to user information, thereby achieving the effect of standardized firewall configuration.
[0048] To enable a virtual private cloud (VPN) to access resources on other cloud platforms, optionally, in the configuration method of the cloud computing system provided in this application embodiment, connecting the target VPN to the corresponding network includes: creating multiple physical interfaces in the cloud computing system, wherein the physical interfaces include an internet interface and an intranet interface, the physical switch gateway associated with the internet interface is connected to the internet, and the physical switch gateway associated with the intranet interface is connected to the local area network; obtaining a target VPN with a preset identifier from the user resource set, and connecting the target VPN with the preset identifier to the internet interface, wherein the preset identifier indicates that the VPN has the permission to connect to the internet; obtaining a target VPN without a preset identifier from the user resource set, and connecting the target VPN without the preset identifier to the intranet interface.
[0049] It should be noted that the intranet, or local area network, requires a dedicated cloud line to meet user network connectivity needs. Because multiple virtual private clouds (VPNs) have different functions and security levels, they need to connect to different network resources to ensure both network connectivity and VPN security.
[0050] Specifically, firstly, multiple physical interfaces need to be established, each corresponding to a physical switch gateway, which can connect to the Internet or a local area network. Then, a virtual gateway is created for each virtual private cloud, and the virtual gateway is associated with the physical interface through the virtual interface. This allows the virtual private cloud to connect to the physical switch gateway of the corresponding physical interface through the virtual gateway and virtual interface, and then connect to the network corresponding to each virtual private cloud through the physical switch gateway, thus completing the configuration of the cloud leased line for each virtual private cloud.
[0051] It should be noted that since different Virtual Private Clouds (VPNs) need to access different networks, each physical switch gateway connects to different networks. Therefore, the corresponding network connection needs to be determined based on the security level of the VPN. Target VPNs with a preset identifier (i.e., VPNs that can connect to the internet) are retrieved from the user resource set. These VPNs are then connected to the internet interface among multiple physical interfaces, enabling them to access the internet. Conversely, target VPNs without a preset identifier are connected to the local area network (LAN) interface among multiple physical interfaces, restricting their access to information only within the LAN and thus ensuring their security.
[0052] Table 2 shows an optional association table for connecting a Virtual Private Cloud (VPC) to a physical switch gateway. As shown in Table 2, the VPC is associated with the virtual gateway based on its subnet segment, and the subnet segment is associated with the remote address, i.e., the access address, based on the association between the virtual interface and the physical interface. For example, Table 2 connects the VPC with subnet segment AAA0 / 24 to the virtual interface corresponding to the LAN interface, thus allowing access to address XXXX in the LAN. Similarly, connecting the VPCs with subnet segments BBB0 / 24 and CCC0 / 24 to the virtual interfaces corresponding to the Internet interface allows access to address YYYY in the LAN.
[0053] Table 2
[0054]
[0055] Optionally, in the configuration method of the cloud computing system provided in this application embodiment, after obtaining the configured user resource set, the method further includes: determining whether there is an access requirement for accessing a public resource set in the user information, wherein the public resource set exists in the cloud computing system; if there is an access requirement in the user information, obtaining a target virtual private cloud from the configured user resource set, and connecting the target virtual private cloud with the public resource set, wherein the target virtual private cloud is a virtual private cloud that needs to access the public resource set.
[0056] Specifically, the public resource set exists within the cloud computing system and is managed by a dedicated administrator for the external public resource set. When a user's information indicates an access request to the public resource set, a connection request is initiated from the configured target virtual private cloud (VPN) to a target VPN within the public resource set. After approval by the dedicated administrator for the external public resource set, the connection between the user's target VPN and the target VPN within the public resource set is established. This ensures that the user can connect to the public resource set through their VPN while also guaranteeing secure access after the connection is established.
[0057] Optionally, in the configuration method of the cloud computing system provided in this application embodiment, creating a user resource set in the cloud computing system includes: creating multiple virtual private clouds through an interface in the cloud computing system and obtaining return information generated by creating virtual private clouds, wherein the return information is an identification identifier of the virtual private cloud; creating a subnet segment corresponding to each virtual private cloud according to the return information; and determining the multiple virtual private clouds and the subnet segment corresponding to each virtual private cloud as the user resource set.
[0058] Specifically, when creating a user resource set, multiple virtual private cloud (VPN) interfaces need to be created first, and a subnet segment needs to be created for each VPN interface to form a VPN. After creating each VPN interface, each VPN interface will generate a unique return value, which can be used to identify the VPN interface. When generating the subnet segment corresponding to each VPN interface, the VPN interface corresponding to the subnet segment can be directly determined through this return value, thereby completing the creation of each VPN.
[0059] For example, Table 3 shows an optional user resource set configuration method, which includes three Virtual Private Clouds (VPCs). Intranet, DMZExtranet, and DMZInternet are the names of different network zones. Based on network zone security, Intranet, DMZExtranet, and DMZInternet can be sequentially designated as low-risk, medium-risk, and high-risk network zones. Further, a corresponding subnet name and subnet segment are created for each VPC, that is, corresponding network segment information is added to each VPC, thus completing the VPC creation.
[0060] Table 3
[0061] Intranet XXfh_Project-Intranet-VPC Intranet-subnet AAA0 / 24 DMZExtranet XXfh_Project-DMZExtranet-VPC DMZExtranet-subnet BBB0 / 24 DMZ Internet XXfh_Project-DMZInternet-VPC DMZ Internet-subnet CCC0 / 24
[0062] To unify the security rules of each virtual private cloud in the cloud computing system and ensure that the virtual private clouds in the cloud computing system can access any website, optionally, in the configuration method of the cloud computing system provided in this application embodiment, before obtaining the user's user information, the method further includes: deleting the initial security rules in the cloud computing system and adding the preset security rules to the cloud computing system, wherein the initial security rules indicate that the servers of the private virtual clouds in the user resource set have the right to access each other, and the preset security rules indicate that the servers in the cloud computing system have the right to access each other.
[0063] Specifically, because the cloud computing system initially generates nested security group rules for each Virtual Private Cloud (VPC), meaning that by default, access between VPCs of each user is allowed, but other access is prohibited. To allow VPCs to access other networks, the initial nested security group rules need to be deleted, and the default security rules added to the cloud computing system. This changes the initial security rules in the cloud computing system, allowing user VPCs to access any network.
[0064] Optionally, in the configuration method of the cloud computing system provided in the embodiments of this application, before creating a user resource set for a user in the cloud computing system, the method further includes: obtaining the user's identity information and determining whether the user's identity information includes a preset token, wherein the preset token represents the permission to perform operations on the cloud computing system; if the user's identity information includes a preset token, performing the step of creating a user resource set for the user in the cloud computing system; if the user's identity information does not include a preset token, issuing an alarm message, wherein the alarm message is used to indicate that the cloud computing system has been attacked.
[0065] Specifically, before configuring a virtual private cloud (VPC) in a user's cloud computing system, an API service authorization token must be obtained. VPC configuration can only proceed after obtaining the API service authorization token. Without the API service authorization token, VPC configuration is impossible and will be flagged as an attack by the cloud computing system, triggering an alert. This embodiment enhances the security of the cloud computing system by verifying the token.
[0066] Figure 2 This is a flowchart of an optional cloud computing system configuration method provided according to an embodiment of this application, such as... Figure 2 As shown, the system first obtains the user's identity information and determines whether the user's identity information includes a preset token. If the API service authorization token is obtained, multiple virtual private clouds and subnet segments of each virtual private cloud are created in the cloud computing system. The initial security rules in the cloud computing system are deleted, and the preset security rules are added to the cloud computing system.
[0067] Furthermore, based on user needs, corresponding firewalls are configured for virtual private clouds (VPNs), and VPNs are connected to each other to enable communication. When needed, VPNs are also connected to public resource aggregates, and dedicated cloud lines are created to allow users to access the Internet. Through the above process, the user's VPN is configured correctly and in compliance with standards, thereby improving the efficiency of VPN management and maintenance.
[0068] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0069] This application also provides a configuration device for a cloud computing system. It should be noted that this configuration device can be used to execute the configuration method for a cloud computing system provided in this application. The following describes the configuration device for a cloud computing system provided in this application.
[0070] Figure 3 This is a schematic diagram of a configuration device for a cloud computing system provided according to an embodiment of this application. Figure 3 As shown, the device includes: a creation unit 31, an addition unit 32, and an association unit 33.
[0071] Specifically, creation unit 31 is used to create a user resource set in the cloud computing system, wherein the user resource set includes multiple virtual private clouds.
[0072] Add unit 32 to obtain user information and create a virtual firewall in each virtual private cloud based on the user information, thereby obtaining multiple target virtual private clouds.
[0073] The association unit 33 is used to sequentially associate each target virtual private cloud with the other target virtual private clouds in the user resource set, and connect the target virtual private cloud with the corresponding network to obtain the configured user resource set.
[0074] The cloud computing system configuration apparatus provided in this application embodiment includes a creation unit 31 for creating a user resource set within the cloud computing system, wherein the user resource set includes multiple virtual private clouds (VPNs). An adding unit 32 is used to obtain user information and create a virtual firewall in each VPN based on the user information, resulting in multiple target VPNs. An association unit 33 is used to sequentially associate each target VPN with the remaining target VPNs in the user resource set and connect the target VPNs to their corresponding networks, resulting in a configured user resource set. This solves the problem in related technologies where different users in a cloud computing system are configured with separate networks, leading to risks and high maintenance difficulty during configuration. By configuring corresponding firewalls for users, associating VPNs with each other, and configuring different network connections for VPNs, a unified configuration standard is achieved, facilitating management by operations and maintenance personnel after configuration.
[0075] Optionally, in the configuration device of the cloud computing system provided in this application embodiment, the user information includes user domain and user level. The adding unit 32 includes: a first acquisition module, used to acquire multiple virtual firewalls corresponding to the user domain from a lookup table, wherein the lookup table includes multiple preset user domains and multiple virtual firewalls corresponding to each preset user domain; a second acquisition module, used to acquire a firewall of first security level from the multiple virtual firewalls corresponding to the user domain when the user level is first level, and configure the firewall of first security level in each virtual private cloud to obtain multiple target virtual private clouds; a third acquisition module, used to acquire a firewall of first security level and a firewall of second security level from the multiple virtual firewalls corresponding to the user domain when the user level is second level, configure the firewall of first security level in a virtual private cloud with a preset identifier, and configure the firewall of second security level in a virtual private cloud without a preset identifier to obtain multiple target virtual private clouds, wherein the first level is higher than the second level, the first security level is higher than the second security level, and the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet.
[0076] Optionally, in the configuration device of the cloud computing system provided in this application embodiment, the association unit 33 includes: a first creation module, used to create multiple physical interfaces in the cloud computing system, wherein the physical interfaces include an Internet interface and an intranet interface, the physical switch gateway associated with the Internet interface is connected to the Internet, and the physical switch gateway associated with the intranet interface is connected to the local area network; a first connection module, used to obtain a target virtual private cloud with a preset identifier from the user resource set, and connect the target virtual private cloud with the preset identifier to the Internet interface, wherein the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet; and a second connection module, used to obtain a target virtual private cloud without a preset identifier from the user resource set, and connect the target virtual private cloud without the preset identifier to the intranet interface.
[0077] Optionally, in the configuration device of the cloud computing system provided in the embodiments of this application, the device further includes: determining whether there is an access request for accessing a public resource set in the user information, wherein the public resource set exists in the cloud computing system; and a first acquisition unit, configured to acquire a target virtual private cloud from the configured user resource set when there is an access request in the user information, and connect the target virtual private cloud to the public resource set, wherein the target virtual private cloud is a virtual private cloud that needs to access the public resource set.
[0078] Optionally, in the configuration device of the cloud computing system provided in this application embodiment, the creation unit 31 includes: a second creation module, used to create multiple virtual private clouds through the interface in the cloud computing system and obtain the return information generated by creating the virtual private clouds, wherein the return information is the identification identifier of the virtual private cloud; a third creation module, used to create a subnet segment corresponding to each virtual private cloud according to the return information; and a determination module, used to determine the multiple virtual private clouds and the subnet segment corresponding to each virtual private cloud as a user resource set.
[0079] Optionally, in the configuration device of the cloud computing system provided in the embodiments of this application, the device further includes: a deletion unit, used to delete the initial security rules in the cloud computing system and add the preset security rules to the cloud computing system, wherein the initial security rules represent that the servers of the private virtual cloud in the user resource set have the right to access each other, and the preset security rules represent that the servers in the cloud computing system have the right to access each other.
[0080] Optionally, in the configuration apparatus of the cloud computing system provided in the embodiments of this application, the apparatus further includes: a second acquisition unit, configured to acquire the user's identity information and determine whether the user's identity information includes a preset token, wherein the preset token represents the permission to perform operations on the cloud computing system; an execution unit, configured to execute the step of creating a user resource set for the user in the cloud computing system if the user's identity information includes the preset token; and an alarm unit, configured to issue an alarm message if the user's identity information does not include the preset token, wherein the alarm message is used to indicate that the cloud computing system has been attacked.
[0081] The configuration device of the aforementioned cloud computing system includes a processor and a memory. The creation unit 31, the addition unit 32, the association unit 33, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0082] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and adjusting kernel parameters can address the issue of different users in cloud computing systems requiring separate network configurations, leading to risks and high maintenance complexity during the configuration process.
[0083] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0084] This invention provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the configuration method of the cloud computing system.
[0085] This invention provides a processor for running a program, wherein the program executes a configuration method for the cloud computing system during runtime.
[0086] like Figure 4 As shown, this embodiment of the invention provides an electronic device 40, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: creating a user resource set in a cloud computing system, wherein the user resource set includes multiple virtual private clouds (VPNs); obtaining user information and creating virtual firewalls in each VPN based on the user information to obtain multiple target VPNs; sequentially associating each target VPN with the remaining target VPNs in the user resource set, and connecting each target VPN to its corresponding network to obtain a configured user resource set. The device in this document can be a server, PC, PAD, mobile phone, etc.
[0087] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program with the following method steps: creating a user resource set for a user in a cloud computing system, wherein the user resource set includes multiple virtual private clouds; obtaining user information of the user, and creating a virtual firewall in each virtual private cloud according to the user information, thereby obtaining multiple target virtual private clouds; sequentially associating each target virtual private cloud with the remaining target virtual private clouds in the user resource set, and connecting the target virtual private clouds with the corresponding networks, thereby obtaining a configured user resource set.
[0088] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0089] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0090] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0091] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0092] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0093] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0094] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0095] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0096] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A configuration method for a cloud computing system, characterized in that, include: In a cloud computing system, a user resource set is created for each user, wherein the user resource set includes multiple virtual private clouds; The user information of the user is obtained, and a virtual firewall is created in each of the virtual private clouds based on the user information to obtain multiple target virtual private clouds. The user information includes the user domain and user level. Each target virtual private cloud is sequentially associated with the remaining target virtual private clouds in the user resource set, and the target virtual private cloud is connected to the corresponding network to obtain the configured user resource set; Based on the user information, a virtual firewall is added to each of the virtual private clouds, resulting in multiple target virtual private clouds including: Obtain multiple virtual firewalls corresponding to the user domain from the lookup table, wherein the lookup table includes multiple preset user domains and multiple virtual firewalls corresponding to each preset user domain; When the user level is the first level, a firewall of the first security level is obtained from a variety of virtual firewalls corresponding to the user domain, and the firewall of the first security level is configured in each of the virtual private clouds to obtain a plurality of target virtual private clouds; When the user level is the second level, the firewalls of the first security level and the firewalls of the second security level are obtained from the multiple virtual firewalls corresponding to the user domain. The firewalls of the first security level are configured in virtual private clouds with preset identifiers, and the firewalls of the second security level are configured in virtual private clouds without the preset identifiers, thereby obtaining multiple target virtual private clouds. The first level is higher than the second level, the first security level is higher than the second security level, and the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet. Connecting the target virtual private cloud to the corresponding network includes: Multiple physical interfaces are created in the cloud computing system, including an Internet interface and an intranet interface. The physical switch gateway associated with the Internet interface is connected to the Internet, and the physical switch gateway associated with the intranet interface is connected to the local area network. Obtain a target virtual private cloud with a preset identifier from the user resource set, and connect the target virtual private cloud with the preset identifier to the Internet interface, wherein the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet; Obtain a target virtual private cloud without a preset identifier from the user resource set, and connect the target virtual private cloud without a preset identifier to the intranet interface; The method further includes associating the virtual private cloud with the virtual gateway based on the subnet segment in the virtual private cloud, and associating the subnet segment with the remote address based on the association relationship between the virtual interface and the physical interface.
2. The method according to claim 1, characterized in that, After obtaining the configured user resource set, the method further includes: Determine whether there is an access request for a public resource set in the user information, wherein the public resource set exists in the cloud computing system; If the access request exists in the user information, a target virtual private cloud is obtained from the configured user resource set, and the target virtual private cloud is connected to the public resource set, wherein the target virtual private cloud is the virtual private cloud that needs to access the public resource set.
3. The method according to claim 1, characterized in that, The user resource set created in a cloud computing system includes: Multiple virtual private clouds are created through the interface of the cloud computing system, and the return information generated by creating the virtual private clouds is obtained, wherein the return information is the identification identifier of the virtual private cloud; Create a subnet segment for each virtual private cloud based on the returned information; The multiple virtual private clouds and the subnet segments corresponding to each virtual private cloud are defined as the user resource set.
4. The method according to claim 1, characterized in that, Before obtaining the user's user information, the method further includes: Delete the initial security rule in the cloud computing system and add a preset security rule to the cloud computing system. The initial security rule indicates that the servers of the private virtual cloud in the user resource set have the right to access each other, and the preset security rule indicates that the servers in the cloud computing system have the right to access each other.
5. The method according to claim 1, characterized in that, Before creating a user's user resource set in a cloud computing system, the method further includes: Obtain the user's identity information and determine whether the user's identity information includes a preset token, wherein the preset token represents the permission to perform operations on the cloud computing system; If the user's identity information includes the preset token, then the step of creating the user's user resource set in the cloud computing system is executed. If the preset token is not included in the user's identity information, an alarm message is issued, wherein the alarm message is used to indicate that the cloud computing system is under attack.
6. A configuration device for a cloud computing system, characterized in that, include: A creation unit is used to create a user resource set for a user in a cloud computing system, wherein the user resource set includes multiple virtual private clouds; An addition unit is used to obtain the user's user information and create a virtual firewall in each of the virtual private clouds based on the user information, thereby obtaining multiple target virtual private clouds. The user information includes the user domain and user level. The association unit is used to sequentially associate each of the target virtual private clouds with the remaining target virtual private clouds in the user resource set, and connect the target virtual private clouds with the corresponding networks to obtain the configured user resource set. The adding unit includes: a first acquisition module, used to acquire multiple virtual firewalls corresponding to user domains from a lookup table, wherein the lookup table includes multiple preset user domains and multiple virtual firewalls corresponding to each preset user domain; a second acquisition module, used to acquire a firewall of first security level from the multiple virtual firewalls corresponding to the user domain when the user level is first level, and configure the firewall of first security level in each virtual private cloud to obtain multiple target virtual private clouds; a third acquisition module, used to acquire a firewall of first security level and a firewall of second security level from the multiple virtual firewalls corresponding to the user domain when the user level is second level, configure the firewall of first security level in a virtual private cloud with a preset identifier, and configure the firewall of second security level in a virtual private cloud without a preset identifier to obtain multiple target virtual private clouds, wherein the first level is higher than the second level, the first security level is higher than the second security level, and the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet; The associated unit includes: a first creation module, used to create multiple physical interfaces in the cloud computing system, wherein the physical interfaces include an Internet interface and an intranet interface, the physical switch gateway associated with the Internet interface is connected to the Internet, and the physical switch gateway associated with the intranet interface is connected to the local area network; a first connection module, used to obtain a target virtual private cloud with a preset identifier from the user resource set, and connect the target virtual private cloud with the preset identifier to the Internet interface, wherein the preset identifier indicates that the virtual private cloud has the permission to connect to the Internet; and a second connection module, used to obtain a target virtual private cloud without a preset identifier from the user resource set, and connect the target virtual private cloud without the preset identifier to the intranet interface; The device further includes associating the virtual private cloud with a virtual gateway based on the subnet segment in the virtual private cloud, and associating the subnet segment with a remote address based on the association relationship between the virtual interface and the physical interface.
7. A computer storage medium, characterized in that, The computer storage medium is used to store a program, wherein the program, when running, controls the device where the computer storage medium is located to execute the configuration method of the cloud computing system according to any one of claims 1 to 5.
8. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the configuration method of the cloud computing system according to any one of claims 1 to 5.
Citation Information
Patent Citations
Contract data-based security management system, storage medium and electronic terminal
CN108133150A
A method for constructing a VPC network model and related equipment
CN108989110A