A method for processing cloud services in a cloud system and related apparatuses

By establishing cloud federation groups in the cloud system and utilizing federated identity credentials and shared service catalogs, the problem of coordinating service call requests across cloud platforms was solved, improving user experience and ensuring information security, and achieving full utilization of cloud platform resources.

CN116471029BActive Publication Date: 2025-11-07HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210028477.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-11
Publication Date
2025-11-07
Estimated Expiration
2042-01-11

AI Technical Summary

Technical Problem

In complex multi-cloud environments, users find it difficult to coordinate service call requests across different cloud platforms, impacting user experience and compromising information security.

Method used

By establishing cloud federation groups, multiple cloud platforms become partner clouds to each other, and service calls across cloud platforms are made using federated identity credentials. Combined with shared service catalogs and identity mapping, cross-cloud platform process collaboration and fine-grained access control are achieved.

Benefits of technology

It enables cross-cloud platform service call requests to be coordinated across different cloud platforms, improving user experience, ensuring information security, and making full use of the resource capabilities of each cloud platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116471029B_ABST
    Figure CN116471029B_ABST
Patent Text Reader

Abstract

The application provides a method for processing cloud services in a cloud system, the cloud system comprising a first cloud platform and a second cloud platform, the first cloud platform and the second cloud platform being partner clouds, the first cloud platform being provided with a first operation device and a first partner management device, and the second cloud platform being provided with a second operation device and a second partner management device, the method comprising the following steps: the second partner management device receiving a local identity credential acquisition request sent by the second operation device, acquiring a federated identity credential of a first user from the first partner management device according to an identity credential of the first user in the first cloud platform, converting the federated identity credential of the first user into an identity credential of the first user in the second cloud platform, and returning the identity credential of the first user in the second cloud platform to the second operation device, so that a client of the first user obtains the identity credential, and generates an API calling request according to the identity credential, thereby realizing process cooperation of the API calling request between the cloud platforms.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud computing, and in particular to a method and device for processing cloud services in a cloud system, a computer cluster, a computer readable storage medium, and a computer program product. BACKGROUND

[0002] Cloud computing is a new way of computing and service based on the Internet, which uses Internet technology to collect huge and scalable information technology (IT) capabilities (i.e., computing, storage, network, etc.) as a service to provide users.

[0003] With the development of cloud computing, more and more cloud service providers at home and abroad begin to provide cloud services to users. These cloud services can include different types of infrastructure services (Infrastructure as a Service, IaaS), platform services (Platform as a Service, PaaS), software services (Software as a Service, SaaS), etc.

[0004] In a complex multi-cloud environment, different cloud platforms are independent of each other and are connected to each other. For users of cloud platforms, it is normal to use resources of multiple cloud platforms due to the needs of business applications. However, the service call requests submitted by users in accessing different cloud platforms are difficult to be coordinated in the process between cloud platforms, which affects the user experience. SUMMARY

[0005] The present application provides a method for processing cloud services in a cloud system. The method establishes multiple cloud platforms as a cloud federation group, and converts the identity credentials of a user in one cloud platform to identity credentials in another cloud platform by means of the federated identity credentials of the user in the cloud federation group. Then, the cloud services are called across the cloud platforms according to the identity credentials in the other cloud platform, which realizes the process coordination of service call requests between cloud platforms and improves the user experience. The present application also provides a device, a computer cluster, a computer readable storage medium, and a computer program product corresponding to the above method.

[0006] In a first aspect, the present application provides a method for processing cloud services in a cloud system. The cloud system includes a first cloud platform and a second cloud platform, and the first cloud platform and the second cloud platform are partner clouds. The first cloud platform is deployed with a first operation device and a first partner management device, and the second cloud platform is deployed with a second operation device and a second partner management device.

[0007] Specifically, the second partner management apparatus receives a local identity credential obtaining request sent by the second operation apparatus, the local identity credential obtaining request being used to request obtaining an identity credential of the first user in the second cloud platform, and the identity credential of the first user in the first cloud platform is included in the local identity credential obtaining request.

[0008] The identity credential can be a credential representing the identity of the user, which can be processed by the cloud platform to correctly control various permissions of the user on the corresponding cloud platform. The identity credential can be divided into a local identity credential and a federated identity credential. The local identity credential can be an identity credential in a specific cloud platform, and the federated identity credential is a pre-agreed identity credential that can be recognized by each cloud platform. The identity credential carries identity information, which can include an identity identifier and a role type. Further, the identity information can further include an identifier of a home cloud where the user is located. For example, the identity credential of the first user in the first cloud platform can be a string spliced from the identifier of the home cloud where the first user is located, the account number of the first user in the home cloud, and the role type of the first user.

[0009] The second partner management apparatus can obtain the federated identity credential of the first user from the first partner management apparatus according to the identity credential of the first user in the first cloud platform, convert the federated identity credential of the first user into an identity credential of the first user in the second cloud platform, and return the identity credential of the first user in the second cloud platform to the second operation apparatus, so that the client of the first user obtains the identity credential of the first user in the second cloud platform returned by the second operation apparatus, and generates an application programming interface (API) call request according to the identity credential of the first user in the second cloud platform, the API call request being used to call a cloud service shared by the second cloud platform.

[0010] In the method, the first cloud platform and the second cloud platform are constructed as a cloud federation group. When a user accesses a cloud service across cloud platforms, a partner management apparatus (such as the second partner management apparatus) on the cloud platform can first determine a federated identity credential (i.e., an identity credential in the cloud federation group) of the user based on an identity credential of the user in a home cloud (such as the first cloud platform), and then determine an identity credential of the user in a visited cloud platform (such as the second cloud platform) according to the federated identity credential of the user. Based on the identity credential, the user can access the cloud service across the cloud platforms, the service call request submitted by the user when accessing different cloud platforms is coordinated among the cloud platforms, and the user experience is improved. Moreover, the user does not need to have an account in multiple cloud platforms, and does not need to pass an account number of one cloud platform to another cloud platform, thereby ensuring information security.

[0011] In some possible implementation manners, the second partner management apparatus receives the first shared service directory sent by the first partner management apparatus, and the first shared service directory includes information of cloud services shared by the first cloud platform, where the information of cloud services shared by the first cloud platform can include an identifier of the cloud services shared by the first cloud platform, such as a name of the cloud services shared by the first cloud platform, and parameters (input parameters and / or output parameters). The second partner management apparatus receives a shared service directory query request sent by the second operation apparatus, and returns the first shared service directory to the second operation apparatus, so that the second user selects a service from the first shared service directory for access.

[0012] In this way, the cloud services can be shared between the cloud platforms on demand. Since the cloud services do not need to be adaptively encapsulated, the cloud platforms can fully utilize the service capabilities of other cloud platforms in the cloud federation group, which can not only expand the resource and service capabilities of each cloud platform, but also achieve intensive construction.

[0013] In some possible implementation manners, the first shared service directory includes one or more of a scope of distribution, a maximum shared usage amount, and a characteristic limit of the cloud services shared by the first cloud platform. The scope of distribution refers to a geographical range allowed to be used when cloud resources are allocated to a user or cloud service instances are distributed, and the geographical range can include an allowed region, an available zone, and / or a cluster. For example, a cloud host service of the first cloud platform allows to be used in North China, East China, and South China, and when the cloud host service is added to the first shared service directory, the scope of distribution can be set as South China, so that only users in South China are allowed to use the cloud host service of the first cloud platform across the cloud platforms. The maximum shared usage amount refers to a quota allowed to be shared for a cloud service. For example, for the cloud host service, the maximum shared usage amount can include one or more of a quota of a processor, a quota of memory, and a quota of a disk. The characteristic limit refers to a constraint on a characteristic of a cloud service, for example, a usage range of an image, a constraint parameter of a graphics processing unit, and the like.

[0014] In the method, by setting one or more of the scope of distribution, the maximum shared usage amount, and the characteristic limit of the cloud service in the first shared service directory, more fine-grained permission control can be implemented on the use of the cloud service by the user of the second cloud platform, and personalized requirements can be met.

[0015] In some possible implementation manners, the second partner management apparatus can receive a second identity mapping configured by an administrator of the second cloud platform. The second identity mapping comprises a mapping relationship between an identity credential of a tenant in the second cloud platform and a federated identity credential. The tenant refers to a public information space opened by a customer (which can be an enterprise or a group) for the ability to use a set of services (such as software services). The tenant can comprise a plurality of users, and the users can enter the public information space to use the corresponding ability. Based on this, the mapping relationship between the identity credential of the tenant in the second cloud platform and the federated identity credential can be a mapping relationship between identity credentials of a plurality of users in the tenant in the second cloud platform and the federated identity credentials. The second partner management apparatus can convert the federated identity credential of the first user in the tenant into an identity credential of the first user in the second cloud platform according to the second identity mapping.

[0016] In the method, the second partner management apparatus converts the identity credentials through the second identity mapping relationship, thereby laying a foundation for process collaboration of cloud services between cloud platforms.

[0017] In some possible implementation manners, the second partner management apparatus can send a federated identity credential acquisition request to the first partner management apparatus. The federated identity credential acquisition request comprises an identity credential of the first user in the first cloud platform. Then the second partner management apparatus receives the federated identity credential of the first user converted by the first partner management apparatus according to a first identity mapping. The first identity mapping comprises a mapping relationship between an identity credential of a tenant in the first cloud platform and the federated identity credential, and the first user is a user in the tenant.

[0018] In this way, the second partner management apparatus converts the identity credentials by requesting the first partner management apparatus, thereby obtaining the federated identity credential of the first user and laying a foundation for converting the identity credential of the first user in the second cloud platform according to the federated identity credential.

[0019] In some possible implementation manners, the second partner management apparatus receives a second cloud federation relationship configured by an administrator of the second cloud platform, and the second cloud federation relationship is used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform. In this way, a cloud federation group can be constructed, and identity credential exchange between different cloud platforms can be implemented based on the cloud federation group, thereby providing help for cross-cloud platform access to cloud services.

[0020] In some possible implementation manners, the second partner management apparatus can also receive a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus, and then the second partner management apparatus verifies the first cloud federation relationship and the second cloud federation relationship.

[0021] In some possible implementation manners, the second partner management apparatus receives a coordination processing request sent by the second operation apparatus, the coordination processing request is generated by the second operation apparatus according to the API calling request, the second partner management apparatus sends the coordination processing request to the first partner management apparatus, receives a coordination processing result obtained by the first partner management apparatus from the first operation apparatus, and sends the coordination processing result to the second operation apparatus, so that the second operation apparatus generates an API calling request processing result, the API calling request processing result is generated according to the coordination processing result.

[0022] The coordination processing request can be a pre-coordination processing request and / or a post-coordination processing request. The pre-coordination processing can be a coordination processing before the second operation apparatus processes the API calling request. For example, the pre-coordination processing can include one or more of the following: auditing the API calling request, deducting the quota of the related cloud service, processing the associated or dependent cloud service, or processing the associated image (for example, loading the associated image). The post-coordination processing can be a coordination processing after the second operation apparatus processes the API calling request. For example, the post-coordination processing can include one or more of the following: adding a label to the cloud service, classifying the cloud service, performing a compliance check on the obtained cloud service, adding an agent, configuring injection, and associating other information technology systems.

[0023] Therefore, the API calling request submitted by a user when accessing different cloud platforms can be coordinated in different cloud platforms, and the user experience is improved.

[0024] In some possible implementation manners, the first cloud platform and the second cloud platform are cloud platforms provided by different cloud service providers or different cloud platforms provided by the same cloud service provider. In this way, the service capabilities of each cloud platform can be expanded, and intensive construction can be realized.

[0025] In some possible implementation manners, the first cloud platform is one of a public cloud, a private cloud, or a hybrid cloud, and the second cloud platform is one of a public cloud, a private cloud, or a hybrid cloud. In this way, cross-platform access of the same type of cloud platform can be realized, and cross-platform access of different types of cloud platforms can also be realized, to meet the needs of different businesses.

[0026] In a second aspect, the present application provides a method for processing a cloud service in a cloud system. The cloud system includes a first cloud platform and a second cloud platform, the first cloud platform and the second cloud platform are partner clouds, the first cloud platform is deployed with a first operation apparatus and a first partner management apparatus, and the second cloud platform is deployed with a second operation apparatus and a second partner management apparatus.

[0027] Specifically, the second partner management apparatus receives the first shared service catalog sent by the first partner management apparatus, the first shared service catalog including one or more of the provisioning scope, the maximum shared usage amount, and the characteristic restriction of the cloud service shared by the first cloud platform, receives a shared service catalog query request sent by the second operation apparatus, and returns the first shared service catalog to the second operation apparatus, so that the second user selects a service from the first shared service catalog for access.

[0028] In the method, by setting one or more of the provisioning scope, the maximum shared usage amount, and the characteristic restriction of the cloud service in the first shared service catalog, more fine-grained permission control can be realized for the user of the second cloud platform to use the cloud service, and personalized needs can be met.

[0029] In some possible implementation manners, the second partner management apparatus provides a configuration interface. The configuration interface is configured to receive one or more of the provisioning scope, the maximum shared usage amount, and the characteristic restriction of the cloud service shared by the second cloud platform in the second shared service catalog configured by an administrator of the second cloud platform. The second partner management apparatus sends the second shared service catalog to the first partner management apparatus. In this way, fine-grained permission control can be realized for the cloud service shared by the cloud platform on demand.

[0030] In a third aspect, the present application provides a second partner management apparatus. The second partner management apparatus and a second operation apparatus are deployed in a second cloud platform in a cloud system, the cloud system further including a first cloud platform, the first cloud platform and the second cloud platform being partner clouds of each other, the first cloud platform being deployed with a first operation apparatus and a first partner management apparatus, and the second partner management apparatus including:

[0031] The communication module is configured to receive a local identity credential acquisition request sent by the second operation apparatus, the local identity credential acquisition request being configured to request to acquire an identity credential of a first user in the second cloud platform, the local identity credential acquisition request including an identity credential of the first user in the first cloud platform, and then acquire a federated identity credential of the first user from the first partner management apparatus according to the identity credential of the first user in the first cloud platform.

[0032] The conversion module is configured to convert the federated identity credential of the first user into an identity credential of the first user in the second cloud platform.

[0033] The communication module is further configured to return the identity credential of the first user on the second cloud platform to the second operation device, so that a client of the first user obtains the identity credential of the first user on the second cloud platform returned by the second operation device, and generates an application programming interface (API) call request according to the identity credential of the first user on the second cloud platform, where the API call request is used to call a cloud service shared by the second cloud platform.

[0034] In some possible implementation manners, the communication module is further configured to:

[0035] receive a first shared service directory sent by the first partner management device, where the first shared service directory includes information of a cloud service shared by the first cloud platform;

[0036] receive a shared service directory query request sent by the second operation device, and return the first shared service directory to the second operation device, so that the second user selects a service from the first shared service directory for access.

[0037] In some possible implementation manners, the first shared service directory includes one or more of a scope of distribution, a maximum shared usage amount, and a characteristic limit of the cloud service shared by the first cloud platform.

[0038] In some possible implementation manners, the communication module is further configured to:

[0039] receive a second identity mapping configured by an administrator of the second cloud platform, where the second identity mapping includes a mapping relationship between an identity credential of a tenant on the second cloud platform and a federated identity credential;

[0040] The conversion module is specifically configured to:

[0041] The second partner management device converts, according to the second identity mapping, the federated identity credential of the first user under the tenant into an identity credential of the first user on the second cloud platform.

[0042] In some possible implementation manners, the communication module is specifically configured to:

[0043] send a federated identity credential acquisition request to the first partner management device, where the federated identity credential acquisition request includes the identity credential of the first user on the first cloud platform;

[0044] receive the federated identity credential of the first user converted by the first partner management device according to a first identity mapping, where the first identity mapping includes a mapping relationship between an identity credential of a tenant on the first cloud platform and the federated identity credential, and the first user is a user under the tenant.

[0045] In some possible implementation manners, the communication module is further configured to:

[0046] receive a second cloud federation relationship configured by an administrator of the second cloud platform, the second cloud federation relationship being used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform.

[0047] In some possible implementation manners, the communication module is further configured to:

[0048] receive a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus;

[0049] The apparatus further includes:

[0050] a verification module, configured to verify the first cloud federation relationship and the second cloud federation relationship.

[0051] In some possible implementation manners, the communication module is further configured to:

[0052] receive a coordination processing request sent by the second operation apparatus, the coordination processing request being generated by the second operation apparatus according to the API calling request;

[0053] send the coordination processing request to the first partner management apparatus, and receive a coordination processing result obtained by the first partner management apparatus from the first operation apparatus;

[0054] send the coordination processing result to the second operation apparatus, so that the second operation apparatus generates an API calling request processing result, the API calling request processing result being generated according to the coordination processing result.

[0055] In some possible implementation manners, the first cloud platform and the second cloud platform are cloud platforms provided by different cloud service providers or are different cloud platforms provided by a same cloud service provider.

[0056] In some possible implementation manners, the first cloud platform is a public cloud, a private cloud or a hybrid cloud, and the second cloud platform is a public cloud, a private cloud or a hybrid cloud.

[0057] In a fourth aspect, the present application provides a computer cluster, including at least one computer, and the at least one computer includes at least one processor and at least one memory. The at least one processor and the at least one memory communicate with each other. The at least one processor is configured to execute instructions stored in the at least one memory, so that the computer cluster performs the method for processing cloud services in a cloud system in any implementation manner of the first aspect or the second aspect.

[0058] In a fifth aspect, the present application provides a computer readable storage medium, having stored therein instructions which instruct a computer cluster to perform the method for processing cloud services in a cloud system according to any of the implementation manners of the first aspect or the second aspect.

[0059] In a sixth aspect, the present application provides a computer program product comprising instructions which, when executed on a device, cause the device to perform the method for processing cloud services in a cloud system according to any of the implementation manners of the first aspect or the second aspect.

[0060] On the basis of the implementation manners of the above aspects, the present application can be further combined to provide more implementation manners. BRIEF DESCRIPTION OF DRAWINGS

[0061] In order to more clearly illustrate the technical method of the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced as follows.

[0062] Figure 1 A schematic diagram of an architecture of a cloud system provided by the embodiments of the present application;

[0063] Figure 2 A flowchart of establishing a cloud federation group and obtaining an identity credential provided by the embodiments of the present application;

[0064] Figure 3 A flowchart of publishing a shared service catalog provided by the embodiments of the present application;

[0065] Figure 4 A flowchart of service request coordination provided by the embodiments of the present application;

[0066] Figure 5 A schematic diagram of a cloud federation group provided by the embodiments of the present application;

[0067] Figure 6 A schematic diagram of a second partner management apparatus provided by the embodiments of the present application;

[0068] Figure 7 A schematic diagram of a computer cluster provided by the embodiments of the present application. DETAILED DESCRIPTION

[0069] The terms "first", "second" in the embodiments of the present application are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features.

[0070] First, some technical terms involved in the embodiments of the present application are introduced.

[0071] Cloud computing: a mode of using Internet technology to collect large and scalable IT capabilities (i.e., computing, storage, network, etc. resources) as cloud services to provide users.

[0072] Cloud: also known as cloud platform, specifically a collection of hardware resources and software resources. Generally, a cloud platform has multiple regions in each country / region, each region includes at least one data center, and each data center includes hardware resources and software resources. Different cloud service providers establish different cloud platforms, such as Huawei's Huawei Cloud, Microsoft's Azure Cloud, etc. Different cloud platforms provide resources (including computing, storage, network, application, etc.) for rent in the form of cloud services to users.

[0073] The scale of the cloud platform is dynamically scalable, and more resources can be aggregated to meet the needs of application and user scale growth. Cloud computing supports users to access cloud services in multiple locations using multiple terminals, and the hardware resources and software resources of cloud services come from the cloud platform. Common cloud services include three types: infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS).

[0074] Among them, the infrastructure service includes virtual machine computing service, data storage service, etc., mainly provides hardware devices and other resources in the form of virtual machines / containers as services to users, and users can load and run their own applications on the virtual machines or storage resources provided by cloud services. Platform services mainly allow developers to build and deploy their own applications on the infrastructure and runtime environment provided by the cloud platform, and allow these applications to use the resources in the cloud infrastructure. Software services are some applications running in the cloud platform that are provided as services to users on demand, such as cloud-based voice transcription services, cloud-based face recognition services, etc.

[0075] Hosted cloud: the cloud platform where the user opens an account, referred to as the user's hosted cloud. The hosted cloud can directly provide cloud services to the user. The cloud services directly provided by the hosted cloud to the user are also referred to as local cloud services of the hosted cloud. The hosted cloud can be a public cloud, a private cloud, a hybrid cloud, etc.

[0076] Cloud federation group: a group established by multiple independent cloud platforms. The cloud platforms in the cloud federation group are in a cloud federation relationship. The cloud federation relationship specifically refers to a relationship of jointly providing cloud services. For example, cloud platform A and cloud platform B form a cloud federation group, cloud platform A can share cloud services 1 to m, and cloud platform B can share cloud services m+1 to n, then the user of cloud platform A can access the local cloud services of cloud platform A and the cloud services (for example, cloud services m+1 to n) shared by cloud platform B, and the user of cloud platform B can access the local cloud services of cloud platform B and the cloud services (for example, cloud services 1 to m) shared by cloud platform A. Wherein, m, n are positive integers.

[0077] Allied cloud: a cloud platform in a cloud federation group that is in a cloud federation relationship with a home cloud. In this application, each cloud platform in a cloud federation group can be an allied cloud. For example, when cloud platform A and cloud platform B form a cloud federation group, cloud platform A and cloud platform B are allied clouds. An allied cloud can be a public cloud, a private cloud, a hybrid cloud, etc.

[0078] In a complex multi-cloud environment, different cloud platforms are independent of each other and are connected to each other. For users of cloud platforms, it is normal to use resources of multiple cloud platforms due to the needs of business applications. However, the service call requests submitted by users when accessing different cloud platforms are difficult to be coordinated between cloud platforms, which affects the user experience.

[0079] Next, a multi-cloud architecture is introduced. Taking a multi-cloud architecture including cloud platform A and cloud platform B as an example, cloud platform A and cloud platform B are two independent clouds, cloud platform A provides a cloud service adaptation layer open to cloud platform B, encapsulates the service capabilities of cloud platform B, and provides them to users uniformly. After logging in to cloud platform A, the user can use the services of cloud platform B through cloud platform A.

[0080] Therefore, an embodiment of the present application provides a method for processing cloud services in a cloud system. Referring to Figure 1 the architecture schematic diagram of the cloud system, the cloud system 10 includes multiple cloud platforms (i.e., the cloud described above), the multiple cloud platforms are allied clouds, Figure 1 Taking a cloud system 10 including a first cloud platform 102 and a second cloud platform 104 as an example. Wherein, the first cloud platform 102 is deployed with a first operation device 1022 and a first partner management device 1024, the second cloud platform 104 is deployed with a second operation device 1042 and a second partner management device 1044. The first partner management device 1024 and the second partner management device 1044 have a communication connection.

[0081] The first operation device 1022 and the second operation device 1042 are devices for managing the use of the cloud. Specifically, the operation devices can manage tenants on the cloud, manage a service catalog of the cloud platform, or manage service invocation requests. A tenant refers to a common information space opened by a customer (which can be an enterprise or a group) for using a set of SaaS capabilities. The tenant can include a plurality of users, and the users can enter the common information space to use the corresponding capabilities.

[0082] The first partner management device 1024 and the second partner management device 1044 are devices for implementing a cloud federation group. Specifically, the partner management devices can also be referred to as cloud federation agents, such as a cloud federation agent of the first cloud platform and a cloud federation agent of the second cloud platform. The partner management devices (such as the first partner management device 1024 and the second partner management device 1044) can exchange data by interacting with the operation devices (such as the first operation device 1022 and the second operation device 1042), thereby processing cloud services and enabling the service invocation requests submitted by users of different cloud platforms to be processed in a process collaboration manner among the cloud platforms.

[0083] Unlike the multi-cloud architecture described above, the cloud federation group formed by the first cloud platform 102 and the second cloud platform 104 in the embodiment of the present application is a peer-to-peer cloud federation group. The cloud federation relationship between the cloud platforms in the cloud federation group, such as the first cloud platform 102 and the second cloud platform 104, is a peer-to-peer cloud federation relationship. Any cloud platform in the cloud federation group can share cloud services with users of other cloud platforms, and is not limited to a specific cloud platform. For example, the first cloud platform 102 can share cloud services with users (such as second users) of the second cloud platform 104, and the second cloud platform 104 can share cloud services with users (such as first users) of the first cloud platform. Moreover, the cloud platforms in the cloud federation group do not need to encapsulate the service capabilities of other cloud platforms, and can fully use the service capabilities of other cloud platforms.

[0084] It should be noted that the first operation device 1022 and the second operation device 1024 can be software devices or hardware devices, and the embodiment of the present application does not limit the same. Similarly to the first operation device 1022 and the second operation device 1024, the first partner management device 1024 and the second partner management device 1044 can be software devices or hardware devices. For ease of description, the devices are taken as software devices in the embodiment of the present application.

[0085] The first partner management apparatus 1024 can be an independent apparatus or integrated in the first operation apparatus 1022, for example, a plug-in or a functional module of the first operation apparatus 1022, and the like. Similarly, the second partner management apparatus 1042 can be an independent apparatus or integrated in the second operation apparatus 1042, for example, a plug-in or a functional module of the second operation apparatus 1042. Further, the first operation apparatus 1022 and the second operation apparatus 1042 can also be part of a cloud management system or a cloud platform, and do not necessarily mean that there must be independent operation apparatuses.

[0086] In addition, Figure 1 The cloud system 10 is only exemplarily described as including the first cloud platform 102 and the second cloud platform 104. In some possible implementations, the cloud system 10 can further include more cloud platforms, for example, the cloud system 10 can further include a third cloud platform. The peer-to-peer cloud federation relationship can be established among multiple independent cloud platforms, and is not limited to two clouds. One cloud can also simultaneously establish a peer-to-peer cloud federation relationship with multiple clouds, so as to realize cloud-to-cloud piecewise of multiple clouds.

[0087] The key to process cooperation of the service invocation request submitted by the user in accessing different cloud platforms (for example, a partner cloud) among the cloud platforms is to establish a cloud federation group. According to the federation identity credential of the user in the cloud federation group, the identity credential of the user in the partner cloud is obtained, and then the partner cloud is accessed through the identity credential of the user in the partner cloud.

[0088] The identity credential can be a credential representing the identity of the user, which can be processed by the cloud platform to correctly control various permissions of the user on the corresponding cloud platform. The identity credential can be divided into a local identity credential and a federation identity credential. The local identity credential can be an identity credential in a specific cloud platform, and the federation identity credential is a pre-agreed identity credential that can be recognized by each cloud platform.

[0089] The identity credential usually carries identity information. The identity information can include an identity of the user and a role type of the user. The identity of the user can be an account of the user in a home cloud and / or a username of the user in the home cloud, and the account and the username have uniqueness in the home cloud. The role type of the user can be set according to requirements, for example, can include a tenant administrator, a normal user, a customer, a supplier, and the like. In some possible implementations, the identity information can further include an identity of the home cloud where the user is located, and the identity of the home cloud is unique in the cloud federation group. The form of the identity credential can be a string or an identification code (for example, a bar code or a two-dimensional code), for example, the identity credential can be a string spliced by the identity of the user, the role type of the user, and the like.

[0090] Further, in order to facilitate users to use the cloud services shared by different cloud platforms, the cloud platforms in the cloud federation group can also publish a shared service directory. Each cloud platform in the cloud federation group can publish a shared service directory. The shared service directory is not limited in terms and quantity of cloud services.

[0091] The cloud federation group is established, and the identity credential of the user in the partner cloud is obtained based on the federation identity credential of the user in the cloud federation group, which can be implemented based on a cloud federation user identity exchange protocol. The cloud platforms in the cloud federation group publish a shared service directory, which can be implemented based on a cloud federation service directory sharing protocol. The service call request submitted by the user in accessing different cloud platforms is transferred between the cloud platforms, which can be implemented based on a cloud federation service request coordination protocol.

[0092] In order to make the technical solutions of the present application clearer and easier to understand, the processes corresponding to the three cloud federation protocols are described in detail below.

[0093] First, the cloud federation user identity exchange protocol is used to exchange and confirm the identity credentials of users between multiple cloud platforms. Still taking the cloud system 10 shown in Figure 1 The administrator of the first cloud platform 102 and the administrator of the second cloud platform 104 respectively configure the cloud federation relationship and the identity mapping through the respective partner management devices, such as the first partner management device 1024 and the second partner management device 1044, and then the user can log in to the home cloud and access the partner cloud with the identity credential of the home cloud. The following will be described by taking the first user logging in to the first cloud platform 102, obtaining the identity credential of the first user in the first cloud platform 102, and accessing the second cloud platform 104 with the identity credential of the first user in the first cloud platform 102 as an example.

[0094] Referring to the flowchart of establishing a cloud federation group and obtaining an identity credential shown in Figure 2 The method comprises the following steps.

[0095] S202: The first partner management device 1024 receives the first cloud federation relationship and the first identity mapping configured by the administrator of the first cloud platform 102.

[0096] The cloud federation relationship configured by the administrator of the first cloud platform 102 through the first partner management device 1024 is called the first cloud federation relationship, and the identity mapping configured by the administrator of the first cloud platform 102 through the first partner management device 1024 is called the first identity mapping.

[0097] The first cloud federation relationship indicates the cloud federation relationship of the first cloud platform 102 and other cloud platforms (e.g., the second cloud platform 104) in a cloud federation group with the first cloud platform 102. Based on this, the first cloud federation relationship can carry the identity of the first cloud platform 102 and the identity of other cloud platforms (e.g., the second cloud platform 104) in a cloud federation group with the first cloud platform 102.

[0098] The first identity mapping indicates the mapping relationship between the identity credential of the tenant on the first cloud platform 102 and the federated identity credential of the tenant. The identity credential is used to represent the identity of the user / tenant and can be processed by the cloud platform to correctly control various permissions of the user / tenant on the corresponding cloud platform. Considering that a tenant can include multiple users, the first identity mapping can indicate the mapping relationship between the identity credential of a user of different role types under the tenant on the first cloud platform 102 and the federated identity credential of the user. The role type can be set as required, for example, the role type can include tenant administrator, ordinary user, customer, supplier, etc. The role type can be further subdivided, for example, the ordinary user can include sales manager, sales supervisor, sales clerk, etc.

[0099] The identity credential can include different types such as local identity credential and federated identity credential. The local identity credential refers to the identity credential of the user / tenant on the home cloud, for example, the identity credential of the first user on the first cloud platform 102 is the local identity credential of the first user. The federated identity credential refers to the public identity credential agreed by the administrators of the cloud platforms in the cloud federation group. The public identity credential can be a public identity identifier, which can be in the form of a string or an identification code (such as a bar code or a two-dimensional code). When the first user accesses a non-home cloud (e.g., the second cloud platform 104) in the same cloud federation group, the accessed cloud platform can identify the first user through the federated identity credential and grant the first user the correct access permission.

[0100] S204: The second partner management apparatus 1044 receives the second cloud federation relationship and the second identity mapping configured by the administrator of the second cloud platform 102.

[0101] The cloud federation relationship configured by the administrator of the second cloud platform 104 through the second partner management apparatus 1044 is called the second cloud federation relationship, and the identity mapping configured by the administrator of the second cloud platform 104 through the second partner management apparatus 1044 is called the second identity mapping.

[0102] The second cloud federation relationship indicates the cloud federation relationship of the second cloud platform 104 and other cloud platforms (e.g., the first cloud platform 102) in a cloud federation group with the second cloud platform 104. Based on this, the second cloud federation relationship can carry the identity of the second cloud platform 104 and the identity of other cloud platforms (e.g., the first cloud platform 102) in a cloud federation group with the second cloud platform 104.

[0103] The second identity mapping indicates the mapping relationship between the identity credential of a tenant in the second cloud platform 104 and the federated identity credential of the tenant. The identity credential is used to represent the identity of a user / tenant and can be processed by a cloud platform to correctly control various permissions of the user / tenant on the corresponding cloud platform. A tenant can include multiple users, and based on this, the second identity mapping can indicate the mapping relationship between the identity credential of a user of different role types in the tenant in the second cloud platform 104 and the federated identity credential of the user.

[0104] The S202 can be executed in parallel or in a set order, and the embodiment does not limit the execution order.

[0105] S206: The first partner management device 1024 sends the first cloud federation relationship to the second partner management device 1044.

[0106] S208: The second partner management device 1044 performs verification according to the first cloud federation relationship and the second cloud federation relationship.

[0107] S210: The second partner management device 1044 returns the verification result to the first partner management device 1024.

[0108] The second partner management device 1044 can perform consistency verification on the first cloud federation relationship and the second cloud federation relationship to avoid errors in establishing a cloud federation group. For example, the second partner management device 1044 can compare the identity of the cloud platform carried in the first cloud federation relationship with the identity of the cloud platform carried in the second cloud federation relationship to determine whether the members in the cloud federation group configured by the administrator of the first cloud platform 102 are the same as the members in the cloud federation group configured by the administrator of the second cloud platform 104.

[0109] If the identity of the cloud platform carried in the first cloud federation relationship is consistent with the identity of the cloud platform carried in the second cloud federation relationship, it indicates that the consistency verification is passed, and the members in the cloud federation group configured by the administrator of the first cloud platform 102 are the same as the members in the cloud federation group configured by the administrator of the second cloud platform 104. Accordingly, the verification result can be that the verification is passed, and the user can perform the subsequent process.

[0110] If the identity of the cloud platform carried in the first cloud federation relationship and the identity of the cloud platform carried in the second cloud federation relationship are inconsistent, it indicates that the consistency check fails, the members in the cloud federation group configured by the administrator of the first cloud platform 102 are different from the members in the cloud federation group configured by the administrator of the second cloud platform 104, and accordingly, the check result can be that the check fails. The administrator of the first cloud platform 102 and / or the administrator of the second cloud platform 104 can reconfigure the cloud federation relationship.

[0111] It should be noted that the method of the embodiment of the present application can also not perform the above S206 to S210. For example, the second partner management apparatus 1044 can send the second cloud federation relationship to the first partner management apparatus 1024, and the first partner management apparatus 1024 can perform consistency check according to the first cloud federation relationship and the second cloud federation relationship. In some embodiments, the first cloud platform 102 and the second cloud platform 104 can also ensure the consistency of the first cloud federation relationship and the second cloud federation relationship by other manners. For example, the administrator of the first cloud platform 102 and the administrator of the second cloud platform 104 can enter the respective cloud federation relationship by copying.

[0112] S212: The client of the first user sends registration information to the first operation apparatus 1022.

[0113] The registration information can specifically include a username and a password. The username can be a username configured manually by the first user, or a username automatically generated by the client. In some possible implementation manners, the registration information can further include a check parameter and a check code. The check parameter can be, for example, a mobile phone number or an email address used for check.

[0114] S214: The first operation apparatus 1022 stores the registration information.

[0115] The first operation apparatus 1022 can maintain a user information library for storing the related information of the user. Specifically, the first operation apparatus 1022 can store the registration information in the user information library, so as to be used for login verification.

[0116] It should be noted that when the first cloud platform 102 is a public cloud, the client of the first user can send the registration information to the first operation apparatus 1022. In some embodiments, the method of the embodiment of the present application can also not perform the above S212 to S214. For example, when the first cloud platform 102 is a private cloud, the administrator of the first cloud platform 102 can directly create a tenant and a user. Further, the administrator of the first cloud platform 102 can also assign a corresponding role type to the user.

[0117] S216: The client of the first user sends login information to the first operation apparatus 1022. When the login verification is passed, S218 is performed.

[0118] The login information can include information used for login verification. In some embodiments, the login information can include a username and a password, or an account number and a password. In other embodiments, the login information can also include a username and a verification code, which can be a verification code received through a mobile phone or an email.

[0119] The first operation apparatus 1022 can compare the login information with the information of the first user stored in the user information library (e.g., registration information) to perform login verification on the first user. When the login information is consistent with the information of the first user stored in the user information library, the first operation apparatus 1022 determines that the login verification is passed. When the login information is inconsistent with the information of the first user stored in the user information library, the first operation apparatus 1022 determines that the login verification is not passed.

[0120] S218: The first operation apparatus 1022 returns the identity credential of the first user on the first cloud platform 102 to the client of the first user.

[0121] The identity credential of the first user on the first cloud platform 102 is a credential used to prove the true identity of the first user, which can be generated according to a login password or an access key. Specifically, the first operation apparatus 1022 can generate the identity credential of the first user on the first cloud platform 102 according to the login password in the login information or according to the access key when the login verification is passed.

[0122] The first operation apparatus 1022 can generate the identity credential of the first user on the first cloud platform 102 according to the login password and / or the access key and the like information, using an identity credential generation algorithm or rule. In some embodiments, the identity credential generation algorithm can be a hash algorithm. In view of security, the first operation apparatus 1022 can also add random numbers or time information and the like in the above identity credential to ensure the security of the identity credential. In order to facilitate use, the identity credential can be represented by a string or an identification code, wherein the identification code can be a bar code or a two-dimensional code.

[0123] It should be noted that when the client of the first user stores the identity credential of the first user on the first cloud platform 102, the first operation apparatus 1022 can also not perform the above S218. For example, when the first user is not logging in for the first time, and the identity credential of the first user on the first cloud platform 102 cached by the client of the first user is not deleted, the first operation apparatus 1022 can also not perform the above S218.

[0124] S220: The client of the first user initiates an access request for the second cloud platform 104 according to the identity credential of the first user in the first cloud platform 102.

[0125] The client of the first user can generate an access request according to the identity credential of the first user in the first cloud platform 102, and the access request is used to request access to the second cloud platform 104. The access request carries the identity credential of the first user in the first cloud platform 102.

[0126] S222: The second operation apparatus 1042 generates a local identity credential obtaining request according to the access request for the second cloud platform 104, and sends the local identity credential obtaining request to the second partner management apparatus 1044.

[0127] Specifically, the local identity credential obtaining request is used to request the identity credential of the first user in the second cloud platform 102. The local identity credential obtaining request carries the identity credential of the first user in the first cloud platform 102, so that the first cloud platform 102 identifies the first user according to the identity credential of the first user in the first cloud platform 102, and returns the federated identity credential of the first user, and then the second cloud platform 104 obtains the identity credential of the first user in the second cloud platform 104 according to the federated identity credential of the first user.

[0128] S224: The second partner management apparatus 1044 sends a federated identity credential obtaining request to the first partner management apparatus 1024.

[0129] The second partner management apparatus 1044 stores the mapping relationship between the identity credential of the user under the tenant in the second cloud platform 104 and the federated identity credential of the user. In order to obtain the identity credential of the first user in the second cloud platform 104, the second partner management apparatus 1044 can generate a federated identity credential obtaining request, and send the federated identity credential obtaining request to the first partner management apparatus 1024. The federated identity credential obtaining request includes the identity credential of the first user in the first cloud platform 102, so that the first partner management apparatus 1024 determines the federated identity credential of the first user according to the identity credential of the first user in the first cloud platform 102.

[0130] S226: The first partner management apparatus 1024 sends a local identity verification request to the first operation apparatus 1022.

[0131] S228: The first operation apparatus 1022 verifies the local identity credential in the local identity verification request and returns a verification result. When the verification result represents that the verification is passed, S230 is executed.

[0132] Optionally, the first partner management apparatus 1024 can request the first operation apparatus 1022 to verify the local identity credential of the first user in the federation identity credential acquisition request. The first operation apparatus 1022 can compare the identity credential of the first user generated after login with the local identity credential of the first user in the federation identity credential acquisition request to implement identity verification. The first operation apparatus 1022 performs S230 described above after verification is passed.

[0133] S230: The first partner management apparatus 1024 converts the identity credential of the first user in the first cloud platform 102 into the federation identity credential of the first user, and returns the federation identity credential of the first user to the second partner management apparatus 1044.

[0134] The first partner management apparatus 1024 can find the mapping relationship between the identity credential of the user under the tenant in the first cloud platform 102 and the federation identity credential of the user according to the identity credential of the first user in the first cloud platform 102, and convert the identity credential of the first user in the first cloud platform 102 into the federation identity credential of the first user based on the mapping relationship.

[0135] S232: The second partner management apparatus 1044 converts the federation identity credential of the first user into the identity credential of the first user in the second cloud platform 104, and returns the identity credential of the first user in the second cloud platform 104 to the second operation apparatus 1042.

[0136] The second partner management apparatus 1044 can convert the federation identity credential of the first user into the identity credential of the first user in the second cloud platform 104 according to the pre-defined mapping relationship. In some embodiments, the first user can be regarded as a federation user of the second cloud platform 104, and accordingly, the identity credential of the first user in the second cloud platform 104 can be a temporary identity credential. In this way, resources can be saved by avoiding long-term maintenance of the identity credential of the first user in the second cloud platform 104.

[0137] S234: The second operation apparatus 1022 returns the identity credential of the first user in the second cloud platform 104 to the client of the first user.

[0138] It should be noted that the method of the embodiments of the present application can also not perform S230 to S234 described above. For example, when the client of the first user stores the identity credential of the first user in the second cloud platform 104, S230 to S234 described above can not be performed.

[0139] Figure 2The illustrated embodiment takes the first user accessing the second cloud platform 104 according to the identity credential of the first user in the first cloud platform 102 as an example. In some possible implementations, the second user can also access the first cloud platform 102 according to the identity credential of the second user in the second cloud platform 104. The specific implementation can refer to the first user accessing the second cloud platform 104, and the embodiment is not limited in this regard.

[0140] In the method, each cloud platform (for example, the first cloud platform 102 and the second cloud platform 104) in the cloud system 10 establishes a cloud federation group, and each cloud platform in the cloud federation group maintains a mapping relationship between the identity credential of the user in the cloud platform and the federated identity credential through a respective partner management device (for example, the first partner management device 1024 and the second partner management device 1044). When the client of the user accesses a partner cloud (a cloud platform in the cloud federation group other than the home cloud) in the identity credential of the home cloud (the cloud platform where the user opens an account), the partner management device of the home cloud can convert the identity credential of the home cloud into the federated identity credential based on the mapping relationship stored by the home cloud, and then the partner management device on the partner cloud can convert the federated identity credential into the identity credential of the partner cloud based on the mapping relationship stored by the partner cloud. Based on the identity credential in the partner cloud, the cloud service shared by the partner cloud can be invoked, meeting the needs of the business. Moreover, the method does not require the user to have an account of multiple cloud platforms, nor does it require the user to provide the account of the partner cloud to the home cloud, thereby reducing the risk of account leakage and ensuring the security of the account.

[0141] Secondly, the cloud federation service directory protocol is used to publish shared service directories among the multiple cloud platforms in the cloud federation group. The shared service directory is a directory of shared cloud services, which can include one or more of cloud host services (also referred to as elastic compute service (ECS)), cloud volume services (EVS), relational database services (RDS), container services (also referred to as cloud container engine (CCE)), and object storage services (OBS). Specifically, an administrator of a cloud platform can configure the shared service directory of the cloud platform and publish the shared service directory to other cloud platforms in the cloud federation group. The following takes the first cloud platform 102 publishing a first shared service directory as an example.

[0142] Referring to Figure 3 The illustrated flowchart of publishing a shared service directory includes the following steps.

[0143] S302: The administrator of the first cloud platform 102 configures the first shared service directory through the first partner management device configuration 1024.

[0144] The first shared service directory is a directory of cloud services shared by the first cloud platform 102. The first shared service directory includes information of the cloud services shared by the first cloud platform 102. The information of the cloud services shared by the first cloud platform 102 includes an identifier of the cloud service shared by the first cloud platform 102, which can be an API name of the cloud service for example. Further, the information of the cloud service shared by the first cloud platform 102 also includes input parameters and / or output parameters of the cloud service.

[0145] In some possible implementation manners, the first shared service directory includes one or more of a provisioning scope, a maximum shared usage, and a characteristic limit of the cloud service shared by the first cloud platform 102. The maximum shared usage can include a maximum shared usage of virtual central processing units (vCPUs) and / or a maximum shared usage of storage, and the characteristic limit can be a usage scope of an image or a constraint parameter of a graphical processing unit (GPU) for example. In this way, more fine-grained permission control can be implemented for users of the second cloud platform 104.

[0146] As with the fine-grained control of the local cloud service directory, the provisioning scope and the maximum shared usage of the shared cloud service can be set based on the identity credential of the user. The provisioning scope refers to a geographical scope allowed to be used when allocating cloud resources or provisioning cloud service instances for the user, which can include regions, available zones, and / or clusters allowed to be used. For example, the ECS of the first cloud platform 102 allows to be used in the North China region, the East China region, and the South China region, and when adding the ECS to the first shared service directory, the provisioning scope can be set as the South China region, so that only users in the South China region are allowed to use the ECS of the first cloud platform 102 across cloud platforms. The maximum shared usage refers to a quota allowed to be shared for a cloud service. For example, for the ECS, the maximum shared usage can include one or more of a quota of vCPUs, a quota of memory, and a quota of disks.

[0147] S304: The first partner management device configuration 1024 sends the first shared service directory to the second partner management device 1044.

[0148] S306: The client of the second user can generate a shared service directory query request and send the shared service directory query request to the second operation device 1042.

[0149] The client of the second user can send login information of the second user to log in the second operation apparatus 1042 first. When the login verification is passed, a shared service directory query request is generated and sent to the second operation apparatus 1042.

[0150] S308: The second operation apparatus 1042 sends the shared service directory query request to the second partner management apparatus 1044.

[0151] S310: The second partner management apparatus 1044 returns the first shared service directory to the second operation apparatus 1042.

[0152] It should be noted that when the cloud federation group includes other partner clouds in addition to the first cloud platform 102, the second partner management apparatus 1044 can return a collection including the first shared service directory, which includes the shared service directories of the other partner clouds.

[0153] S312: The second partner management apparatus 1044 presents the local cloud service directory and the first shared service directory to the second user.

[0154] The local cloud service directory is a directory of cloud services directly provided by the second cloud platform 104. The first shared service directory is a directory of cloud services shared by the first cloud platform 102.

[0155] S314: The client of the second user sends a service access request to the first operation apparatus 1022.

[0156] Specifically, the second user can select a service from the first shared service directory, and the client of the second user generates a service access request according to the service selected by the second user, which is used to request access to the service selected by the second user in the cloud services shared by the first cloud platform 102.

[0157] S316: The first operation apparatus 1022 sends a configuration query request to the first partner management apparatus 1024.

[0158] S317: The first partner management apparatus 1024 returns configuration information to the first operation apparatus 1022.

[0159] The configuration query request is used to indicate the configuration information of the service selected by the second user. The configuration information may, for example, be address information and the like of the service. The configuration query request includes the identifier of the service selected by the second user. The identifier of the service may, for example, be the name of the service, such as an API name.

[0160] The first partner management apparatus 1024 receives the configuration query request, finds the configuration information of the service according to the identifier of the service in the configuration query request, and returns the configuration information to the first operation apparatus 1022.

[0161] S318: The first operation apparatus 1022 presents a cloud service page to the second user according to the configuration information of the service selected by the second user.

[0162] The cloud service page can be a page for subscribing to the cloud service. In some embodiments, when the cloud service needs to be expanded or contracted, the cloud service page can also be a change page or a deletion page of the cloud service, for example, the cloud service is a subscribed cloud service.

[0163] In this embodiment, the operation apparatuses of the plurality of cloud platforms, for example, the first operation apparatus 1022 and the second operation apparatus 1024, can be integrated into a cloud federation operation apparatus, and correspondingly, the shared service directories of the plurality of cloud platforms can be integrated for unified management. For example, when the plurality of cloud platforms are cloud platforms of different organizations in a group, the operation apparatuses of the plurality of cloud platforms can be integrated into a cloud federation operation apparatus.

[0164] It should be noted that the first cloud platform 102 and the second cloud platform 104 can be a public cloud, a private cloud or a hybrid cloud. Through the method of this embodiment, not only the cloud services provided by the public cloud can be shared to the private cloud on demand, but also the cloud services provided by the private cloud can be shared to the public cloud on demand, so as to realize the sale and monetization of the services provided by the private cloud.

[0165] Next, the cloud federation service request coordination protocol is used for service request coordination between different cloud platforms. Referring to Figure 4 the flowchart of service request coordination, the method comprises the following steps:

[0166] S402: The client of the first user sends login information to the first operation apparatus 1022.

[0167] S404: The first operation apparatus 1024 returns a login verification result to the client of the first user. When the login verification result is login verification passed, S406 is performed.

[0168] It should be noted that the method of this embodiment can also not perform the above S402 and S404.

[0169] S406: The client of the first user sends a shared service directory query request to the first operation apparatus 1022.

[0170] S408: The first operation apparatus 1024 returns the second shared service directory to the client of the first user.

[0171] The second shared service directory is a directory of cloud services shared by the second cloud platform 104. The process in which the first operation apparatus 1024 queries the second shared service directory can refer to the process in which the second operation apparatus 1044 queries the first shared service directory, which will not be described herein again. Figure 3 The process in which the second operation apparatus 1044 queries the first shared service directory in the illustrated embodiment will not be described herein again.

[0172] S410: The client of the first user sends an API invocation request to the second operation apparatus 1042.

[0173] Specifically, the first user can select a service from the second shared service directory, generate an API invocation request according to the configuration information of the selected service, and send the API invocation request to the second operation apparatus. The process in which the first user obtains the configuration information of the selected service can refer to the process in which the second user obtains the configuration information of the selected service, which will not be described herein again. Figure 3 The process in which the second user obtains the configuration information of the selected service in the illustrated embodiment will not be described herein again,

[0174] S412: The second operation apparatus 1042 generates a pre-coordination processing request according to the API invocation request, and sends the pre-coordination processing request to the second partner management apparatus 1044.

[0175] S414: The second partner management apparatus 1044 sends the pre-coordination processing request to the first partner management apparatus 1024.

[0176] S416: The first partner management apparatus 1024 sends the pre-coordination processing request to the first operation apparatus 1022.

[0177] S418: The first operation apparatus 1022 performs pre-coordination processing according to the pre-coordination processing request.

[0178] The pre-coordination processing can also be referred to as first coordination processing. The pre-coordination processing is specifically used to provide preparation for API invocation. Based on this, the pre-coordination processing can include one or more of the following processes: (1) approval of the API invocation request; (2) deduction of the quota of the related cloud service; (3) processing of the associated or dependent cloud service; (4) processing of the associated image (for example, loading the associated image).

[0179] S420: The first operation apparatus 1022 returns the pre-coordination processing result to the first partner management apparatus 1024.

[0180] The pre-coordination processing result can be different according to different processes included in the pre-coordination processing. For example, the pre-coordination processing includes processing of the associated image, and the pre-coordination processing result can include the associated image.

[0181] S422: The first partner management apparatus 1024 returns the pre-coordination processing result to the second partner management apparatus 1044.

[0182] S424: The second partner management apparatus 1044 returns the pre-coordination processing result to the second operation apparatus 1042.

[0183] S425: The second operation apparatus 1042 judges whether to continue processing the API invocation request according to the pre-coordination processing result.

[0184] When the pre-coordination processing includes approving the API invocation request, the pre-coordination result can include the approval result of the API invocation request. When the approval result is approval, the second operation apparatus 1042 can execute the following steps to continue processing the API invocation request. When the approval result is disapproval, the second operation apparatus 1042 can not execute the following steps and stop processing the API invocation request.

[0185] It should be noted that the above pre-coordination processing (for example, S412 to S425) can be optionally executed according to pre-configuration, which is not limited in the embodiment.

[0186] S426: The second operation apparatus 1042 processes the API invocation request to obtain an initial processing result.

[0187] The initial processing result can be different according to different API invocation requests. In order to facilitate understanding, a specific example is described below. In the example, the API invocation request is used to request to create a cloud host, and the initial processing result can be a cloud host created according to the image obtained from the first operation apparatus 1022.

[0188] S428: The second operation apparatus 1042 generates a post-coordination processing request according to the API invocation request, and sends the post-coordination processing request to the second partner management apparatus 1044.

[0189] S430: The second partner management apparatus 1044 sends the post-coordination processing request to the first partner management apparatus 1024.

[0190] S432: The first partner management apparatus 1024 sends the post-coordination processing request to the first operation apparatus 1022.

[0191] S434: The first operation apparatus 1022 executes post-coordination processing according to the post-coordination processing request.

[0192] The post-position coordination processing can also be referred to as second coordination processing. The second coordination processing is used for post-processing. The post-position coordination processing can include one or more of the following processes: (1) adding a label for the cloud service, such as adding a use label, a department label, etc.; (2) classifying the cloud service, such as classifying by attributes based on a configuration management database (CMDB); (3) performing a compliance check on the obtained cloud resource; (4) adding an agent, such as a log collection agent; (5) configuration injection; (6) associating other information technology systems, such as associating an asset management system.

[0193] S436: The first operation apparatus 1022 returns the post-position coordination processing result to the first partner management apparatus 1024.

[0194] S438: The first partner management apparatus 1024 returns the post-position coordination processing result to the second partner management apparatus 1044.

[0195] S440: The second partner management apparatus 1044 returns the post-position coordination processing result to the second operation apparatus 1042.

[0196] It should be noted that the above post-position coordination processing can be selectively executed according to pre-configuration, which is not limited in the present embodiment.

[0197] S442: The second operation apparatus 1042 obtains an API call request processing result according to the post-position coordination processing result.

[0198] It should be noted that when the first operation apparatus 1022 does not perform the pre-position coordination processing and the post-position coordination processing, the second operation apparatus 1042 can directly determine the initial processing result as the API call request processing result. When the first operation apparatus 1022 performs the post-position coordination processing, the second operation apparatus 1042 can determine the API call request processing result according to the post-position coordination processing result. When the first operation apparatus 1022 performs the pre-position coordination processing and does not perform the post-position coordination processing, the second operation apparatus 1042 can obtain the API call request processing result according to the initial processing result.

[0199] S444: The second operation apparatus 1042 returns the API call request processing result to the client of the first user.

[0200] In the embodiment shown in FIG. 8, the API call requests submitted by users accessing different cloud platforms are coordinated among different cloud platforms through the cloud federation service request coordination protocol, meeting the needs of the business and improving the user experience. Figure 4

[0201] ​For ease of understanding, the scheme of the embodiments of the present application is described below with respect to a cloud platform of a large and medium-sized enterprise.

[0202] Referring to Figure 5 As shown in the schematic diagram of the cloud federation group, in a large and medium-sized enterprise, a plurality of different business organizations establish a plurality of dispersed cloud platforms. For example, department one establishes cloud platform A, department two establishes cloud platform B, and department X establishes cloud platform X. These dispersed cloud platforms can have the following situations: (1) limited service capabilities, difficult to continuously develop and maintain; (2) based on the development of business capabilities of the organization, the superior service can support the service capability overflow. Therefore, a group cloud platform can be established, and the group cloud platform and the cloud platforms of the business organizations are constructed as a cloud federation group. The group cloud platform can share the service capabilities of the group cloud platform with the cloud platforms of the business organizations, and the cloud platforms of the business organizations can also share the superior cloud services to the group cloud platform.

[0203] On the one hand, for the business organization with limited capabilities, the service capabilities of the group cloud platform can be shared to the cloud platform of the business organization through the cloud federation group, and the shared service capabilities can help the business organization to strengthen and expand the business capabilities; on the other hand, for the business organization that has developed superior cloud services, the superior cloud services of the business organization can be shared to the group cloud platform or the cloud platforms of other business organizations through the cloud federation group, so that the entire enterprise benefits. In this way, the IT resources and service capabilities of each business organization can be quickly expanded, and the purpose of intensive construction can be achieved.

[0204] Moreover, compared with the data cut to unify the dispersed IT resources in the enterprise, the scheme can avoid the problem of business interruption caused by data cut, and the existing network business is not affected. In addition, the scheme does not need to perform application migration, and solves the problem that the technical stack levels of different cloud platforms in the enterprise are not uniform, and the application migration across the technical stack is difficult to implement.

[0205] It should be noted that Figure 5 The cloud platform in the above description can be a private cloud built by the enterprise. In some possible implementation manners, the cloud platform used to establish the cloud federation group can also be a public cloud or a hybrid cloud. The enterprise can use the cloud services of the public cloud through the cloud federation group, or share the cloud services in the enterprise to the public cloud through the cloud federation group, so that the cloud services in the enterprise can be sold and monetized to the outside.

[0206] Based on the above method provided by the embodiments of the present application, the embodiments of the present application also provide a partner management device. For ease of description, the second partner management device 1044 is exemplarily described below.

[0207] Referring to Figure 6A structural schematic diagram of a second partner management apparatus 1044 is shown, the second partner management apparatus 1044 and a second operation apparatus 1042 are deployed in a second cloud platform 104 in a cloud system 10, the cloud system 10 further includes a first cloud platform 102, the first cloud platform 102 and the second cloud platform 104 are partner clouds, and the first cloud platform 102 is deployed with a first operation apparatus 1022 and a first partner management apparatus 1024. The second partner management apparatus 1044 includes:

[0208] A communication module 10442, configured to receive a local identity credential acquisition request sent by the second operation apparatus, the local identity credential acquisition request is used to request to acquire an identity credential of a first user in the second cloud platform, and the identity credential of the first user in the first cloud platform is included in the local identity credential acquisition request, and then the federated identity credential of the first user is acquired from the first partner management apparatus according to the identity credential of the first user in the first cloud platform;

[0209] A conversion module 10444, configured to convert the federated identity credential of the first user into an identity credential of the first user in the second cloud platform;

[0210] The communication module 10442 is further configured to return the identity credential of the first user in the second cloud platform to the second operation apparatus, so that a client of the first user obtains the identity credential of the first user in the second cloud platform returned by the second operation apparatus, and generates an application programming interface (API) call request according to the identity credential of the first user in the second cloud platform, the API call request is used to call a cloud service shared by the second cloud platform.

[0211] In some possible implementation manners, the communication module 10442 is further configured to:

[0212] Receive a first shared service directory sent by the first partner management apparatus, and the first shared service directory includes information of cloud services shared by the first cloud platform;

[0213] Receive a shared service directory query request sent by the second operation apparatus, and return the first shared service directory to the second operation apparatus, so as to facilitate the second user to select a service from the first shared service directory for access.

[0214] In some possible implementation manners, the first shared service directory includes one or more of a scope of distribution, a maximum shared usage amount and a characteristic limit of the cloud services shared by the first cloud platform.

[0215] In some possible implementation manners, the communication module 10442 is further configured to:

[0216] receiving a second identity mapping configured by an administrator of the second cloud platform, the second identity mapping comprising a mapping relationship between an identity credential of a tenant at the second cloud platform and a federated identity credential;

[0217] The conversion module 10444 is specifically configured to:

[0218] The second partner management apparatus converts, according to the second identity mapping, the federated identity credential of the first user under the tenant into an identity credential of the first user at the second cloud platform.

[0219] In some possible implementation manners, the communication module 10442 is specifically configured to:

[0220] sending, to the first partner management apparatus, a federated identity credential obtaining request, the federated identity credential obtaining request comprising the identity credential of the first user at the first cloud platform;

[0221] receiving the federated identity credential of the first user converted by the first partner management apparatus according to a first identity mapping, the first identity mapping comprising a mapping relationship between an identity credential of a tenant at the first cloud platform and the federated identity credential, and the first user being a user under the tenant.

[0222] In some possible implementation manners, the communication module 10442 is further configured to:

[0223] receiving a second cloud federation relationship configured by an administrator of the second cloud platform, the second cloud federation relationship being used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform.

[0224] In some possible implementation manners, the communication module 10442 is further configured to:

[0225] receiving a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus;

[0226] The apparatus 1044 further comprises:

[0227] a verification module 10446, specifically configured to verify the first cloud federation relationship and the second cloud federation relationship.

[0228] In some possible implementation manners, the communication module 10442 is further configured to:

[0229] receiving a coordination processing request sent by the second operation apparatus, the coordination processing request being generated by the second operation apparatus according to the API calling request;

[0230] Send the coordination processing request to the first partner management device and receive the coordination processing result obtained by the first partner management device from the first operating device;

[0231] The coordination processing result is sent to the second operating device so that the second operating device generates an API call request processing result, which is generated based on the coordination processing result.

[0232] In some possible implementations, the first cloud platform and the second cloud platform are cloud platforms provided by different cloud service providers or different cloud platforms provided by the same cloud service provider.

[0233] In some possible implementations, the first cloud platform is a public cloud, a private cloud, or a hybrid cloud, and the second cloud platform is a public cloud, a private cloud, or a hybrid cloud.

[0234] The second partner management device 1044 according to the embodiments of this application can correspondingly execute the method described in the embodiments of this application, and the above and other operations and / or functions of each module / unit of the second partner management device 1044 are respectively for implementing Figures 2 to 4 For the sake of brevity, the corresponding processes of each method in the illustrated embodiments will not be described in detail here.

[0235] This application also provides a computer cluster. The computer cluster includes at least one computer, any one of which can originate from a cloud environment or an edge environment, or be a terminal device. Specifically, the computer cluster is used to implement... Figure 6 The second partner management device 1044 in the illustrated embodiment has the following functions.

[0236] Figure 7 A schematic diagram of a computer cluster structure is provided, such as... Figure 7 As shown, the computer cluster 70 includes multiple computers 700. Each computer 700 includes a bus 701, a processor 702, a communication interface 703, and a memory 704. The processor 702, the memory 704, and the communication interface 703 communicate with each other via the bus 701.

[0237] The 701 bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0238] The processor 702 can be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor, a microcontroller, a digital signal processor (DSP), or the like.

[0239] The communication interface 703 is configured to communicate with the outside. For example, the communication interface 703 is configured to receive the local identity credential acquisition request sent by the second operation apparatus 1042, acquire the federated identity credential of the first user from the first partner management apparatus 1024 according to the identity credential of the first user on the first cloud platform 102, return the identity credential of the first user on the second cloud platform 104 to the second operation apparatus 1042, and the like.

[0240] The memory 704 can include volatile memory, such as random access memory (RAM), and non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD).

[0241] The memory 704 stores computer-readable instructions, and the processor 702 executes the computer-readable instructions to cause the computer cluster 70 to perform the method of processing cloud services in the cloud system 10 described above (or implement the functions of the second partner management apparatus 1044 described above).

[0242] Specifically, in the case of implementing the embodiments of the system shown, and Figure 6 the functions of the modules of the second partner management apparatus 1044 described above, such as the communication module 10442, the conversion module 10444, or the verification module 10446, are implemented by software. Figure 6 In the case of implementing the functions of the modules described above by software, the software or program code required to implement the functions of the modules can be stored in at least one memory 704 in the computer cluster 70. The at least one processor 702 executes the program code stored in the memory 704 to cause the computer cluster 70 to perform the method of processing cloud services in the cloud system 10 described above. Figure 6

[0243] ​The embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium can be any available medium or data storage that can be used to store data that is accessible by a computer, or a data center containing one or more available media, etc. The available medium can be a magnetic medium, (e.g., a floppy diskette, a hard disk drive, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state hard drive), etc. The computer readable storage medium includes instructions that instruct a computer or a computer cluster to perform the method of processing cloud services in the cloud system 10.

[0244] The embodiments of the present application also provide a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the computer instructions generate, in whole or in part, the processes or functions described in the embodiments of the present application. The computer instructions can be stored in a computer readable storage medium, or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transferred from one website, computer or data center to another website, computer or data center through a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) manner. The computer program product can be a software installation package, which can be downloaded and executed on a computer or a computer cluster when any of the methods of the method of processing cloud services in the cloud system 10 is needed.

[0245] The descriptions of the processes or structures corresponding to the above respective figures are each focused on a certain aspect, and the parts not described in detail in a certain process or structure can be referred to the relevant descriptions of other processes or structures.

Claims

1. A method of processing a cloud service in a cloud system, the method comprising: The cloud system comprises a first cloud platform and a second cloud platform, the first cloud platform and the second cloud platform are partner clouds, the first cloud platform is deployed with a first operation device and a first partner management device, the second cloud platform is deployed with a second operation device and a second partner management device, and the method comprises the following steps: The second partner management device receives a local identity credential acquisition request sent by the second operation device, the local identity credential acquisition request is used for requesting to acquire an identity credential of a first user in the second cloud platform, and the local identity credential acquisition request comprises an identity credential of the first user in the first cloud platform; The second partner management device acquires a federated identity credential of the first user from the first partner management device according to the identity credential of the first user in the first cloud platform, converts the federated identity credential of the first user into an identity credential of the first user in the second cloud platform, and returns the identity credential of the first user in the second cloud platform to the second operation device, so that a client of the first user obtains the identity credential of the first user in the second cloud platform returned by the second operation device, and generates an application programming interface (API) call request according to the identity credential of the first user in the second cloud platform, the API call request being used for calling a cloud service shared by the second cloud platform. The method further comprises the following steps:

2. The method of claim 1, wherein, The second partner management device receives a first shared service directory sent by the first partner management device, and the first shared service directory comprises information of a cloud service shared by the first cloud platform; The second partner management device receives a shared service directory query request sent by the second operation device, and returns the first shared service directory to the second operation device, so as to facilitate a second user to select a service from the first shared service directory for access. The first shared service directory comprises one or more of a scope of distribution, a maximum shared usage amount and a characteristic limit of the cloud service shared by the first cloud platform.

3. The method of claim 2, wherein, The method further comprises the following steps:

4. The method according to any one of claims 1 to 3, characterized in that, The second partner management device receives a second identity mapping configured by an administrator of the second cloud platform, and the second identity mapping comprises a mapping relationship between an identity credential and a federated identity credential of a tenant in the second cloud platform; The second partner management device converts the federated identity credential of the first user into the identity credential of the first user in the second cloud platform, comprising the following steps: The second partner management device converts the federated identity credential of the first user into the identity credential of the first user in the second cloud platform according to the second identity mapping. The second partner management device acquires the federated identity credential of the first user from the first partner management device according to the identity credential of the first user in the first cloud platform, comprising the following steps:

5. The method according to any one of claims 1 to 3, characterized in that, The second partner management device sends a federated identity credential acquisition request to the first partner management device, and the federated identity credential acquisition request comprises the identity credential of the first user in the first cloud platform; ​ The second partner management apparatus receives a federated identity credential of the first user converted by the first partner management apparatus according to a first identity mapping, the first identity mapping comprising a mapping relationship between an identity credential of a tenant on the first cloud platform and the federated identity credential, the first user being a user under the tenant.

6. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: The second partner management apparatus receives a second cloud federation relationship configured by an administrator of the second cloud platform, the second cloud federation relationship being used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform.

7. The method of claim 6, wherein, The method further comprises: The second partner management apparatus receives a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus; The second partner management apparatus checks the first cloud federation relationship and the second cloud federation relationship.

8. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: The second partner management apparatus receives a coordination processing request sent by the second operation apparatus, the coordination processing request being generated by the second operation apparatus according to the API calling request; The second partner management apparatus sends the coordination processing request to the first partner management apparatus, and receives a coordination processing result obtained by the first partner management apparatus from the first operation apparatus; The second partner management apparatus sends the coordination processing result to the second operation apparatus, so that the second operation apparatus generates an API calling request processing result, the API calling request processing result being generated according to the coordination processing result.

9. The method according to any one of claims 1 to 3, characterized in that, The first cloud platform and the second cloud platform are respectively a cloud platform provided by different cloud service providers or different cloud platforms provided by the same cloud service provider.

10. The method according to any one of claims 1 to 3, characterized in that, The first cloud platform is a public cloud, a private cloud or a hybrid cloud, and the second cloud platform is a public cloud, a private cloud or a hybrid cloud.

11. A second partner management device, characterized by, The second partner management apparatus and the second operation apparatus are deployed in a second cloud platform in a cloud system, the cloud system further comprising a first cloud platform, the first cloud platform and the second cloud platform being partner clouds of each other, the first cloud platform being deployed with a first operation apparatus and a first partner management apparatus, and the second partner management apparatus comprising: The communication module is configured to receive a local identity credential obtaining request sent by the second operation apparatus, the local identity credential obtaining request being used to request to obtain an identity credential of a first user on the second cloud platform, the local identity credential obtaining request comprising an identity credential of the first user on the first cloud platform, and then obtain a federated identity credential of the first user from the first partner management apparatus according to the identity credential of the first user on the first cloud platform; The conversion module is configured to convert the federated identity credential of the first user into an identity credential of the first user on the second cloud platform; The second partner management apparatus receives a second cloud federation relationship configured by an administrator of the second cloud platform, the second cloud federation relationship being used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform. The method further comprises: The second partner management apparatus receives a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus; The second partner management apparatus checks the first cloud federation relationship and the second cloud federation relationship. The method further comprises: The second partner management apparatus receives a coordination processing request sent by the second operation apparatus, the coordination processing request being generated by the second operation apparatus according to the API calling request; The second partner management apparatus sends the coordination processing request to the first partner management apparatus, and receives a coordination processing result obtained by the first partner management apparatus from the first operation apparatus; The second partner management apparatus sends the coordination processing result to the second operation apparatus, so that the second operation apparatus generates an API calling request processing result, the API calling request processing result being generated according to the coordination processing result. The communication module is further configured to return the identity credential of the first user on the second cloud platform to the second operation apparatus, so that a client of the first user obtains the identity credential of the first user on the second cloud platform returned by the second operation apparatus, and generates an application programming interface (API) call request according to the identity credential of the first user on the second cloud platform, the API call request being used to call a cloud service shared by the second cloud platform.

12. The apparatus of claim 11, wherein, The communication module is further configured to: receive a first shared service directory sent by the first partner management apparatus, the first shared service directory including information of a cloud service shared by the first cloud platform; receive a shared service directory query request sent by the second operation apparatus, and return the first shared service directory to the second operation apparatus, so that a second user selects a service from the first shared service directory for access.

13. The apparatus of claim 12, wherein, The first shared service directory includes one or more of a distribution range, a maximum shared usage amount, and a characteristic limit of the cloud service shared by the first cloud platform.

14. The apparatus of any one of claims 11 to 13, wherein, The communication module is further configured to: receive a second identity mapping configured by an administrator of the second cloud platform, the second identity mapping including a mapping relationship between an identity credential of a tenant on the second cloud platform and a federated identity credential; The conversion module is specifically configured to: convert, according to the second identity mapping, the federated identity credential of the first user under the tenant into an identity credential of the first user on the second cloud platform.

15. The apparatus of any one of claims 11 to 13, wherein, The communication module is specifically configured to: send a federated identity credential acquisition request to the first partner management apparatus, the federated identity credential acquisition request including the identity credential of the first user on the first cloud platform; receive the federated identity credential of the first user converted by the first partner management apparatus according to a first identity mapping, the first identity mapping including a mapping relationship between an identity credential of a tenant on the first cloud platform and the federated identity credential, the first user being a user under the tenant.

16. The apparatus of any one of claims 11 to 13, wherein, The communication module is further configured to: receive a second cloud federation relationship configured by an administrator of the second cloud platform, the second cloud federation relationship being used to indicate a cloud federation relationship between the first cloud platform and the second cloud platform.

17. The apparatus of claim 16, wherein, The communication module is further configured to: receive a first cloud federation relationship configured by an administrator of the first cloud platform and sent by the first partner management apparatus; The device further includes: a verification module, specifically configured to verify the first cloud federation relationship and the second cloud federation relationship.

18. The apparatus of any one of claims 11 to 13, wherein, The communication module is further configured to: receive a coordination processing request sent by the second operation apparatus, the coordination processing request being generated by the second operation apparatus according to the API call request; send the coordination processing request to the first partner management apparatus, and receive a coordination processing result obtained by the first partner management apparatus from the first operation apparatus; send the coordination processing result to the second operation apparatus, so that the second operation apparatus generates an API call request processing result, the API call request processing result being generated according to the coordination processing result.

19. The apparatus of any one of claims 11 to 13, wherein, The first cloud platform and the second cloud platform are cloud platforms provided by different cloud service providers or different cloud platforms provided by the same cloud service provider.

20. The apparatus of any one of claims 11 to 13, wherein, The first cloud platform is a public cloud, a private cloud or a hybrid cloud, and the second cloud platform is a public cloud, a private cloud or a hybrid cloud.

21. A computer cluster, characterized by The computer cluster comprises at least one computer, the at least one computer comprising at least one processor and at least one memory, the at least one memory storing computer readable instructions, and the at least one processor executing the computer readable instructions to cause the computer cluster to perform the method of any one of claims 1 to 10.

22. A computer-readable storage medium, characterized in that, Computer readable instructions to cause a computer cluster to perform the method of any one of claims 1 to 10 when the computer readable instructions are run on the computer cluster.

23. A computer program product, characterised in that, Computer readable instructions to cause a computer cluster to perform the method of any one of claims 1 to 10 when the computer readable instructions are run on the computer cluster.

Citation Information

Patent Citations

  • Method, device and equipment for processing cloud service in cloud system

    CN109819061A

  • Hybrid cloud management method and system and cloud service platform

    CN111797414A