Multi-domain, multi-tenant authentication method, system and medium based on distributed structure
By deploying controller clusters and control centers in a multi-domain environment, unified permission management and customized cross-domain authentication and mutual trust are provided, solving the flexibility and adaptability problems of existing multi-domain and multi-tenant authentication schemes, and achieving efficient permission isolation and mutual recognition.
Patent Information
- Application Number
- CN202211695081.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2042-12-28
AI Technical Summary
Existing authentication and authorization schemes are insufficient to meet the flexibility and adaptability requirements of increasingly complex multi-domain and multi-tenant environments.
It adopts a multi-domain, multi-tenant authentication method based on a distributed structure. By deploying controller clusters and control centers in different domains, it realizes tenant request proxy, permission verification, token authentication and cross-domain authentication mutual trust, and provides unified permission management and custom access authorization.
It improves the flexibility and adaptability of authentication and authorization in multi-domain and multi-tenant environments, and realizes permission isolation and mutual trust and recognition between different tenants.
Smart Images

Figure CN116318810B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a multi-network domain and multi-tenant authentication method and system based on a distributed structure and a medium. BACKGROUND
[0002] As a common requirement and function implementation of application systems, authentication and authorization has been developed for decades and has many mature solutions. However, with the changes in business requirements, application systems are becoming more and more complex, and the number of applications is not only increasing, but also distributed in different network domains. The authentication and security between applications have higher requirements for flexibility and adaptability. The existing authentication and authorization solutions are difficult to meet the increasing authentication requirements.
[0003] Therefore, a multi-network domain and multi-tenant authentication solution based on a distributed structure is proposed to improve the flexibility and adaptability of the authentication and authorization method. SUMMARY
[0004] In order to solve the technical problem that the existing authentication and authorization solution is difficult to solve the increasingly complex authentication requirements, the present application proposes a multi-network domain and multi-tenant authentication method, system and medium based on a distributed structure.
[0005] According to a first aspect of the present application, a multi-network domain and multi-tenant authentication method based on a distributed structure is provided, comprising:
[0006] Deploying a controller cluster in each network domain, wherein the controller cluster comprises a controller pool and a plurality of controllers, and the controller pool provides tenant request proxy services for the plurality of controllers;
[0007] Deploying a control center in an area connected to each network domain, and the controller pool provides access proxy services for the corresponding plurality of controllers to the control center;
[0008] When the controller cluster receives a tenant request, the controller pool forwards the tenant request to the corresponding controller, the controller generates login information, and accesses the control center for authentication through the push of the controller pool.
[0009] Preferably, when the controller cluster receives a tenant request, the controller pool forwards the tenant request to the corresponding controller, comprising:
[0010] Numbering and network domain setting of the controller;
[0011] The controller pool adds numbering information and network domain information about the controller in the tenant request, thereby forwarding the tenant request to the corresponding controller.
[0012] Preferably, the login information comprises tenant information, a number and a domain type of the controller, and a login token, wherein:
[0013] The controller pool determines the tenant information according to an address of the tenant request;
[0014] The controller pool provides an authority verification and token authentication function when receiving the tenant request, and the controller performs the token authentication after passing the authority verification, and generates the login token.
[0015] Preferably, the controllers of different domains achieve authentication mutual trust by sending an authentication request, and the controllers of different domains achieve access authorization by accessing the control center through the authentication mutual trust.
[0016] Preferably, the process of the authentication mutual trust comprises:
[0017] The sending controller sends the authentication request to the receiving controller, and the authentication request carries an address of a tenant request received by the sending controller, a number, a domain type and a login token of the sending controller, and login information of the sending controller;
[0018] The receiving controller obtains tenant information of the sending controller according to the address of the tenant request received by the sending controller, and verifies the login information of the sending controller according to the number, the domain type and the login token of the sending controller in the authentication request;
[0019] When the verification is passed, it is judged whether the authentication mutual trust is completed according to a configured cross-domain authentication strategy.
[0020] Preferably, the process of the access authorization comprises:
[0021] The sending controller obtains tenant information of the receiving controller through the authentication mutual trust;
[0022] According to the tenant information of the receiving controller, the sending controller accesses the control center and sends an access request for obtaining corresponding tenant authority, and the access request carries a number and a domain type of the receiving controller;
[0023] The control center obtains the corresponding tenant authority according to the number and the domain type of the receiving controller, and judges whether to authorize the sending controller according to a configured cross-domain mutual trust strategy.
[0024] According to a second aspect of the present application, a multi-domain and multi-tenant authentication system based on a distributed structure is provided, comprising:
[0025] a controller cluster deployment module configured to deploy a controller cluster in different network domains, the controller cluster comprising a controller pool and a plurality of controllers, the controller pool providing tenant request proxy services for the plurality of controllers;
[0026] a control center deployment module configured to deploy a control center in an area in network communication with each of the network domains, the controller pool providing access proxy services for the corresponding plurality of controllers to the control center;
[0027] an authentication module configured to, in response to the controller cluster receiving a tenant request, forward the tenant request to the corresponding controller by the controller pool, the controller generating login information and accessing the control center for authentication through the push of the controller pool.
[0028] Preferably, the controller pool forwards the tenant request to the corresponding controller in response to the controller cluster receiving the tenant request, comprising: numbering and network domain setting of the controller; the controller pool adding number information and network domain information about the controller in the tenant request, thereby forwarding the tenant request to the corresponding controller;
[0029] The login information comprises tenant information, number network domain type of the controller, and login token, wherein: the controller pool determines the tenant information according to the address of the tenant request; the controller pool provides authority verification and token authentication function when receiving the tenant request, and the controller performs the token authentication after the authority verification, generating the login token.
[0030] Preferably, the controllers of different network domains achieve mutual authentication by sending authentication requests, and the controllers of different network domains achieve access authorization by accessing the control center through the mutual authentication;
[0031] The process of mutual authentication comprises: a sending-end controller sending the authentication request to a receiving-end controller, the authentication request carrying the address of the tenant request received by the sending-end controller, the number, network domain type and login token of the sending-end controller, and the login information of the sending-end controller; the receiving-end controller obtains the tenant information of the sending-end controller according to the address of the tenant request received by the sending-end controller, and verifies the login information of the sending-end controller according to the number, network domain type and login token of the sending-end controller in the authentication request; when the verification is passed, it is judged whether the mutual authentication is completed according to the configured cross-network domain authentication strategy;
[0032] The process of the access authorization comprises: the sending end controller acquires tenant information of the receiving end controller through the authentication mutual trust; according to the tenant information of the receiving end controller, the sending end controller accesses the control center and sends an access request for acquiring corresponding tenant authority, wherein the access request carries the number and domain type of the receiving end controller; the control center acquires the corresponding tenant authority according to the number and domain type of the receiving end controller, and judges whether to authorize the sending end controller according to a configured cross-domain mutual trust strategy.
[0033] According to a third aspect of the present application, a computer readable storage medium is provided, which stores a computer program, the computer program, when executed by a processor, implements the multi-domain and multi-tenant authentication method based on a distributed structure according to the first aspect of the present application.
[0034] The present application provides a multi-domain and multi-tenant authentication method and system based on a distributed structure, which provides independent authentication and authorization functions through controller clusters deployed in different logical domains or physical domains, and simultaneously manages users, institutions and corresponding authorities of different domains through a control center. Meanwhile, the control center realizes authority isolation between different tenants. Based on the above functions, the present application further provides custom authentication mutual trust and access authorization, which realizes authentication mutual trust and mutual authentication of authorities when a same user requests across domains. In summary, the present application realizes custom differentiated authority isolation and mutual authentication of authorities between multi-domain and multi-tenants. BRIEF DESCRIPTION OF DRAWINGS
[0035] The accompanying drawings are included to provide a further understanding of embodiments and are incorporated in and constitute a part of this specification. The drawings illustrate embodiments and, together with the description, serve to explain principles of the present application. Other embodiments and many of the intended advantages of the present application will be readily appreciated as the same becomes better understood by reference to the following detailed description when considered in connection with the accompanying drawings. The elements of the drawings are not necessarily to scale relative to each other. Like reference numerals designate corresponding similar parts.
[0036] Figure 1 is a flowchart of a multi-domain and multi-tenant authentication method based on a distributed structure according to an embodiment of the present application;
[0037] Figure 2 is a flowchart of a cross-domain authentication mutual trust method according to an embodiment of the present application;
[0038] Figure 3 is a flowchart of a cross-domain access authorization method according to an embodiment of the present application;
[0039] Figure 4 is a block diagram of a multi-domain and multi-tenant authentication system based on a distributed structure according to an embodiment of the present application. Detailed Implementation
[0040] The features and exemplary embodiments of various aspects of this application will now be described in detail. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only configured to explain this application and are not configured to limit this application. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples of this application.
[0041] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0042] According to the first aspect of this application, a multi-domain, multi-tenant authentication method based on a distributed structure is proposed. Figure 1 A flowchart of a multi-domain, multi-tenant authentication method based on a distributed structure according to an embodiment of this application is shown, such as... Figure 1 As shown, the method includes the following steps:
[0043] S101. Deploy controller clusters in different network domains. The controller cluster includes a controller pool and multiple controllers. The controller pool provides tenant request broker services for multiple controllers.
[0044] In a specific embodiment, controller clusters are deployed in different logical or physical network domains. A controller pool provides tenant request proxy services for multiple controllers, thus providing a unified access point and acting as an access proxy for other requests. This reduces the number of network interfaces exposed externally and enhances network security. Each controller corresponds to one application.
[0045] S102. Deploy a control center in the area connected to each domain network, and the controller pool provides access proxy services to the control center for the corresponding multiple controllers.
[0046] In specific embodiments, the controller pool in the controller cluster of each network domain provides the controller with access to the access agent service of the control center, ensuring that the control center and the controller can communicate with each other and other applications cannot directly access the control center. The control center provides independent authentication functions, and the controllers of different network domains support simultaneous online of users, and the control center manages permissions, which are divided from the perspective of the controller. The permissions corresponding to different controllers are inconsistent, and the permissions of the controllers are isolated from each other.
[0047] S103, in response to the controller cluster receiving a tenant request, the controller pool forwards the tenant request to the corresponding controller, the controller generates login information, and accesses the control center for authentication through the push of the controller pool.
[0048] In specific embodiments, the controller is first numbered and set with a network domain. When the controller cluster receives a tenant request, the controller pool adds the number information and network domain information of the controller in the tenant request, so as to forward the tenant request to a specific controller, realize the tenant request proxy service, and the controller pool also provides the functions of permission verification and token authentication. The controller pool forwards the tenant request to the controller, and at the same time determines the tenant information according to the address of the tenant request. The controller performs token authentication after permission verification, and generates a login token. In this way, the tenant information, the number and network domain type of the controller, and the login token constitute the login information of the controller, and the login information of the controller is accessed to the control center for authentication through the push of the controller pool.
[0049] In this way, through the controllers deployed in different logical network domains or physical network domains, independent authentication functions are provided, and at the same time, through the control center, the users, institutions and corresponding permissions of different network domains are uniformly managed. At the same time, the control center realizes the permission isolation between different tenants.
[0050] Based on the above functions, the embodiment also provides a cross-network domain authentication mutual trust and access authorization scheme. Specifically, the controllers between different network domains realize authentication mutual trust by sending authentication requests, and the controllers between different network domains that have realized authentication mutual trust realize access authorization by accessing the control center. The cross-network domain authentication mutual trust and access authorization scheme will be described in detail below based on the above multi-network domain and multi-tenant authentication scheme.
[0051] Figure 2 A method flowchart for cross-network domain authentication mutual trust according to an embodiment of the application is shown in FIG. 1. Figure 2 As shown in FIG. 1, the method for cross-network domain authentication mutual trust includes the following steps:
[0052] S201, the sending end controller sends an authentication request to the receiving end controller, and the authentication request carries an address of a tenant request received by the sending end controller, a number of the sending end controller, a network domain type and a login token, and login information of the sending end controller;
[0053] S202, the receiving end controller acquires tenant information of the sending end controller according to the address of the tenant request received by the sending end controller, and checks the login information of the sending end controller according to the number, the network domain type and the login token of the sending end controller in the authentication request.
[0054] S203, when the check passes, it is judged whether authentication and trust are completed according to a configured cross-network domain authentication strategy.
[0055] Through the above scheme, the sending end controller of the current network domain sends an authentication request to the receiving end controller of another network domain, and the authentication request carries login information generated by the sending end controller, and an address of an original tenant request, a number of the controller, a network domain type and a login token in the login information. After the receiving end controller receives the information, the login information generated by the sending end controller is checked according to the original information in the login information, and after the check passes, it is determined whether authentication and trust can be completed according to a cross-network domain authentication strategy configured by a control center. The cross-network domain authentication strategy can be configured according to actual conditions, and is not limited in the embodiment.
[0056] Figure 3 A method flowchart of cross-network domain access authorization according to an embodiment of the application is shown, as shown in Figure 2 The method of cross-network domain access authorization includes the following steps:
[0057] S301, the sending end controller acquires tenant information of the receiving end controller through authentication and trust;
[0058] S302, the sending end controller accesses a control center and sends an access request for acquiring corresponding tenant permissions according to the tenant information of the receiving end controller, and the access request carries a number and a network domain type of the receiving end controller.
[0059] S303, the control center acquires corresponding tenant permissions according to the number and the network domain type of the receiving end controller, and judges whether to authorize the sending end controller according to a configured cross-network domain trust strategy.
[0060] Through the above scheme, after the sending end controller and the receiving end controller realize authentication and mutual trust, the sending end controller obtains the tenant information of the receiving end controller. The sending end controller accesses the control center according to the tenant information, and sends an access request for obtaining the tenant permission of the tenant to the control center. The access request carries the number and domain type of the receiving end controller. The control center finds the corresponding tenant according to the number and domain type of the controller in the access request, and obtains the corresponding tenant permission. Then the control center determines whether to authorize the tenant permission to the sending end controller according to the configured cross-domain mutual trust strategy. The cross-domain mutual trust strategy can be configured according to actual conditions, and is not limited in the embodiment.
[0061] In this way, when the same tenant sends a request in different domains, authentication and mutual trust and permission mutual authentication can be realized when the same user sends a cross-domain request, thereby improving the flexibility and adaptability of authentication and authorization.
[0062] The application provides a multi-domain and multi-tenant authentication method based on a distributed structure. A controller cluster deployed in different logical domains or physical domains provides independent authentication and authorization functions, and a control center uniformly manages users, institutions and corresponding permissions in different domains. At the same time, the control center realizes permission isolation between different tenants. Based on the above functions, the application also provides customized cross-domain authentication and mutual trust and access authorization, and realizes authentication and mutual trust and permission mutual authentication when the same user sends a cross-domain request. In summary, the application realizes customized differentiated permission isolation and permission mutual trust and mutual authentication between multi-domain and multi-tenant, improves the flexibility and adaptability of authentication and authorization for increasingly complex authentication requirements.
[0063] According to a second aspect of the application, based on the same concept, a multi-domain and multi-tenant authentication system based on a distributed structure is also provided. Figure 4 A block diagram of a multi-domain and multi-tenant authentication system based on a distributed structure according to an embodiment of the application is shown, as shown in the figure, the system includes: Figure 4
[0064] A controller cluster deployment module 1 configured to deploy a controller cluster in different domains respectively, the controller cluster including a controller pool and a plurality of controllers, the controller pool providing tenant request proxy services for the plurality of controllers;
[0065] A control center deployment module 2 configured to deploy a control center in an area in network communication with each domain, the controller pool providing access proxy services for the corresponding plurality of controllers to the control center;
[0066] The authentication module 3 is configured to, in response to the controller cluster receiving a tenant request, control the controller pool to forward the tenant request to a corresponding controller, the controller to generate login information, and access the control center through the push of the controller pool to perform authentication.
[0067] In the preferred embodiment, in response to the controller cluster receiving a tenant request, the controller pool forwards the tenant request to a corresponding controller, including: numbering and domain setting of the controller; the controller pool adding numbering information and domain information of the controller in the tenant request to forward the tenant request to the corresponding controller; the login information including tenant information, numbering domain type of the controller, and a login token, wherein: the controller pool determines the tenant information according to the address of the tenant request; the controller pool provides an authority verification and token authentication function when receiving the tenant request, and the controller performs token authentication after passing the authority verification to generate the login token.
[0068] In the preferred embodiment, the controllers of different domains implement authentication mutual trust through sending authentication requests, and the controllers of different domains implementing authentication mutual trust implement access authorization through accessing the control center.
[0069] Specifically, the process of authentication mutual trust includes: a sending controller sending an authentication request to a receiving controller, the authentication request carrying the address of the tenant request received by the sending controller, the numbering, domain type, and login token of the sending controller, and the login information of the sending controller; the receiving controller obtaining the tenant information of the sending controller according to the address of the tenant request received by the sending controller, and verifying the login information of the sending controller according to the numbering, domain type, and login token of the sending controller in the authentication request; when the verification passes, judging whether to complete authentication mutual trust according to a configured cross-domain authentication strategy.
[0070] The process of access authorization includes: the sending controller obtaining the tenant information of the receiving controller through authentication mutual trust; the sending controller accessing the control center and sending an access request to obtain corresponding tenant authority according to the tenant information of the receiving controller, the access request carrying the numbering and domain type of the receiving controller; the control center obtaining the corresponding tenant authority according to the numbering and domain type of the receiving controller, and judging whether to authorize the sending controller according to a configured cross-domain mutual trust strategy.
[0071] According to a third aspect of the present application, based on the same concept, a computer readable storage medium is further provided, which stores a computer program, the computer program being executed by a processor to implement the distributed structure based multi-domain and multi-tenant authentication method according to the first aspect of the present application.
[0072] In the embodiments of the present application, it should be understood that the disclosed technology can be implemented in other manners. The described embodiments of the apparatus / system / method are merely illustrative, for example, the division of the units can be a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between the units can be indirect coupling or communication connection through some interfaces, and can be electrical or other forms.
[0073] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place or distributed on multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0074] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0075] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various program codes that can be stored in the medium.
[0076] It is clear that many modifications and changes can be made to the embodiments of the application without departing from the spirit and scope of the application. In that manner, the application also intends to cover what falls within the scope of the following claims and their equivalents. The word "comprising" does not exclude the presence of elements or steps not listed in a claim. The mere fact that different claims depend on a common parent claim does not indicate that combinations of measures of the different dependent claims cannot be used in advantage. Any reference signs in the claims should not be construed as limiting the scope.
Claims
1. A multi-domain, multi-tenant authentication method based on a distributed architecture, characterized in that, include: Controller clusters are deployed in different network domains. Each controller cluster includes a controller pool and multiple controllers. The controller pool provides tenant request proxy services for the multiple controllers. A control center is deployed in the area connected to each of the aforementioned domain networks, and the controller pool provides access proxy services to the control center for the corresponding multiple controllers. In response to a tenant request received by the controller cluster, the controller pool forwards the tenant request to the corresponding controller. This includes: assigning a number and setting a domain for the controller; adding the controller's number and domain information to the tenant request; and generating login information for the controller and accessing the control center for authentication via a push notification from the controller pool. The login information includes tenant information, the controller's number and domain type, and a login token. Specifically, the controller pool determines the tenant information based on the address requested by the tenant; and provides permission verification and token authentication upon receiving the tenant request. The controller performs token authentication after passing the permission verification and generates the login token.
2. The method according to claim 1, characterized in that, The controllers in different network domains achieve mutual authentication trust by sending authentication requests, and the controllers in different network domains that achieve mutual authentication trust achieve access authorization by accessing the control center.
3. The method according to claim 2, characterized in that, The authentication and mutual trust process includes: The sending controller sends the authentication request to the receiving controller. The authentication request carries the address of the tenant request received by the sending controller, the sending controller's number, domain type and login token, and the sending controller's login information. The receiving controller obtains the tenant information of the sending controller based on the address of the tenant request received by the sending controller, and verifies the login information of the sending controller based on the sending controller's number, domain type, and login token in the authentication request; Once the verification passes, the system determines whether the authentication and mutual trust have been completed based on the configured cross-domain authentication policy.
4. The method according to claim 3, characterized in that, The access authorization process includes: The sending controller obtains the tenant information of the receiving controller through the authentication mutual trust; Based on the tenant information of the receiving controller, the sending controller accesses the control center and sends an access request to obtain the corresponding tenant permissions. The access request carries the number and domain type of the receiving controller. The control center obtains the corresponding tenant permissions based on the receiver controller's number and domain type, and determines whether to authorize the sender controller based on the configured cross-domain mutual trust policy.
5. A multi-domain, multi-tenant authentication system based on a distributed architecture, characterized in that, include: A controller cluster deployment module is configured to deploy controller clusters in different network domains. The controller cluster includes a controller pool and multiple controllers. The controller pool provides tenant request proxy services for the multiple controllers. The control center deployment module is configured to deploy a control center in an area connected to each of the domain networks, and the controller pool provides access proxy services to the control center for the corresponding multiple controllers. The authentication module is configured to, in response to a tenant request received by the controller cluster, forward the tenant request to the corresponding controller via the controller pool. This includes: assigning a number and domain to the controller; the controller pool adding the controller's number and domain information to the tenant request, thereby forwarding the request to the corresponding controller; the controller generating login information and accessing the control center for authentication via push notification from the controller pool; the login information including tenant information, the controller's number and domain type, and a login token; wherein: the controller pool determines the tenant information based on the address of the tenant request; the controller pool provides permission verification and token authentication functions upon receiving the tenant request; the controller performs token authentication after passing the permission verification, generating the login token.
6. The system according to claim 5, characterized in that, The controllers of different network domains achieve mutual authentication trust by sending authentication requests, and the controllers of different network domains that achieve mutual authentication trust achieve access authorization by accessing the control center; The authentication and trust process includes: the sending controller sending the authentication request to the receiving controller, the authentication request carrying the address of the tenant request received by the sending controller, the sending controller's ID, domain type, login token, and login information of the sending controller; the receiving controller obtaining the tenant information of the sending controller based on the address of the tenant request received by the sending controller, and verifying the login information of the sending controller based on the sending controller's ID, domain type, and login token in the authentication request; and, upon successful verification, determining whether the authentication and trust process is complete based on the configured cross-domain authentication policy. The access authorization process includes: the sending controller obtaining the tenant information of the receiving controller through the authentication mutual trust; based on the tenant information of the receiving controller, the sending controller accesses the control center and sends an access request to obtain the corresponding tenant permissions, the access request carrying the number and domain type of the receiving controller; the control center obtains the corresponding tenant permissions based on the number and domain type of the receiving controller, and determines whether to authorize the sending controller according to the configured cross-domain mutual trust policy.
7. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the method as described in any one of claims 1-4.
Citation Information
Patent Citations
Multi-heterogeneous cluster job unified scheduling method and API interface
CN110636103A
Security authentication method for realizing multi-cloud management and control across public network
CN110855700A