Authorization Method, Device, Electronic Device and Storage Medium for a Proprietary Cloud Service

By deploying authorization management services on the proprietary cloud server side and uniformly managing the authorization of each proprietary cloud service, the problem of low interaction efficiency between proprietary cloud services and public cloud servers is solved, and efficient and convenient authorization management and strong control are achieved.

CN116599816BActive Publication Date: 2025-07-18DINGTALK (CHINA) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310401318.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-14
Publication Date
2025-07-18
Estimated Expiration
2043-04-14

AI Technical Summary

Technical Problem

In the prior art, the authorization management of proprietary cloud services is inefficient in interaction between public cloud platforms and proprietary cloud platforms and has high control pressure. Especially when service authorization information needs to be updated, the public cloud server needs to manage each proprietary cloud service one by one, resulting in low efficiency and insufficient control efforts.

Method used

Deploy authorization management services on the proprietary cloud server side, and use this service to uniformly manage the authorization of each proprietary cloud service, avoid direct interaction with the public cloud server side, and use the service authorization information generated by the public cloud server for unified management, and update the service configuration information when needed.

Benefits of technology

It improves the authorization management efficiency of proprietary cloud services, reduces the control pressure on public cloud services, and realizes convenient and efficient authorization management, while ensuring strong control over proprietary cloud services by cloud manufacturers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116599816B_ABST
    Figure CN116599816B_ABST
Patent Text Reader

Abstract

One or more embodiments of this specification provide a method, apparatus, electronic device, and storage medium for authorizing a proprietary cloud service. The method is applied to a proprietary cloud service end; a proprietary cloud service authorized and managed by a public cloud service end, and an authorization management service for authorizing and managing the proprietary cloud service are deployed on the proprietary cloud service end; the method includes: obtaining service authorization information generated by the public cloud service end for the proprietary cloud service deployed on the proprietary cloud service end; in response to an authorization request sent by a target proprietary cloud service deployed on the proprietary cloud service end, invoking the authorization management service, where the authorization management service searches for service authorization information corresponding to the target proprietary cloud service in the obtained service authorization information, and returns the found service authorization information to the target proprietary cloud service, so that the target proprietary cloud service provides services based on the found service authorization information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of private cloud technology, and in particular, to an authorization method, device, electronic device, and machine-readable storage medium for private cloud services. Background Art

[0002] A private cloud is a cloud computing system with exclusive resources and elastic on-demand for users built by cloud providers. A private cloud service is a service deployed on a private cloud.

[0003] Regarding the deployment methods of private clouds, they can generally be divided into two types: self-built mode and dedicated mode. Among them, in the self-built mode, the private cloud platform can be deployed in the user data center through the method of private deployment, and the cloud provider assists the user in operating and maintaining the private cloud platform. The dedicated mode can physically isolate the cloud computing resources of the public cloud platform and deploy the private cloud platform for users based on the isolated public cloud resources to achieve private cloud deployment based on the public cloud; in addition, the user can also connect the private network to the local network of the user data center through a dedicated line to form a customized network environment on demand.

[0004] In addition to deploying the network environment of the private cloud for users, cloud providers can also provide authorization management services for private cloud services to implement a paid subscription model for private cloud services. Summary of the Invention

[0005] This application provides an authorization method for private cloud services. The method is applied to a private cloud service end; a private cloud service authorized and managed by a public cloud service end and an authorization management service for authorizing and managing the private cloud service are deployed on the private cloud service end; the method includes:

[0006] Obtain the service authorization information generated by the public cloud service end for the private cloud service deployed on the private cloud service end;

[0007] In response to an authorization request sent by the target private cloud service deployed on the private cloud service end, call the authorization management service. The authorization management service searches for the service authorization information corresponding to the target private cloud service in the obtained service authorization information and returns the found service authorization information to the target private cloud service, so that the target private cloud service provides services based on the found service authorization information.

[0008] This application also provides an authorization device for private cloud services. The device is applied to a private cloud service end; a private cloud service authorized and managed by a public cloud service end and an authorization management service for authorizing and managing the private cloud service are deployed on the private cloud service end; the device includes:

[0009] An acquisition unit, configured to acquire service authorization information generated by the public cloud server for the private cloud services deployed on the private cloud server;

[0010] An authorization management unit, configured to, in response to an authorization request sent by a target private cloud service deployed on the private cloud server, call the authorization management service, where the authorization management service searches for service authorization information corresponding to the target private cloud service in the acquired service authorization information, and returns the found service authorization information to the target private cloud service, so that the target private cloud service provides services based on the found service authorization information.

[0011] This application further provides an electronic device, including a communication interface, a processor, a memory, and a bus, where the communication interface, the processor, and the memory are interconnected through the bus;

[0012] Machine-readable instructions are stored in the memory, and the processor executes the above method by calling the machine-readable instructions.

[0013] This application further provides a machine-readable storage medium, where machine-readable instructions are stored in the machine-readable storage medium, and when the machine-readable instructions are called and executed by a processor, the above method is implemented.

[0014] Through the above embodiments, by deploying an authorization management service on the private cloud server, and the authorization management service uniformly performs authorization management on each private cloud service based on the service authorization information generated by the public cloud server for each private cloud service deployed on the private cloud server, the interaction between the private cloud service and the public cloud server can be avoided, and each private cloud service only needs to interact with the authorization management service deployed on the private cloud server, thereby improving the authorization management efficiency of the private cloud service and reducing the control pressure on the public cloud server.

[0015] In addition, when it is necessary to update the service authorization information, the public cloud server can generate new service configuration information for the private cloud service and provide the new service configuration information to the authorization management service deployed on the private cloud server, and the authorization management service can uniformly perform authorization management on each private cloud service based on the new service authorization information. Therefore, the public cloud server does not need to update the service authorization information for each private cloud service one by one, thereby ensuring that the cloud provider has a strong control over the private cloud service while being able to conveniently and efficiently perform authorization management on the private cloud service. Description of the Drawings

[0016] To more clearly illustrate the technical solutions of the embodiments of this specification, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0017] Figure 1 It is a schematic structural diagram of an authorization method for a dedicated cloud service shown in an exemplary embodiment;

[0018] Figure 2 It is a flowchart of an authorization method for a dedicated cloud service shown in an exemplary embodiment;

[0019] Figure 3 It is a schematic structural diagram of an electronic device where an authorization device for a dedicated cloud service is located shown in an exemplary embodiment;

[0020] Figure 4 It is a block diagram of an authorization device for a dedicated cloud service shown in an exemplary embodiment. Detailed implementation manners

[0021] In order to enable those skilled in the art of this technology to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of them. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0022] It should be noted that: in other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.

[0023] A dedicated cloud is a cloud computing system with exclusive resources and elastic on-demand for users built by cloud providers. A dedicated cloud can also be called a dedicated cloud platform, a private network, etc., and this specification does not make special limitations on this. A dedicated cloud service is a service deployed on a dedicated cloud.

[0024] Regarding the deployment methods of private clouds, they can generally be divided into two types: self-built mode and dedicated mode. Among them, in the self-built mode, the private cloud platform can be deployed in the user's data center through private deployment, and the cloud provider can assist the user in operating and managing the private cloud platform. In the dedicated mode, the cloud computing resources of the public cloud platform can be physically isolated, and a private cloud platform can be deployed for the user based on the isolated public cloud resources to achieve the deployment of a private cloud based on the public cloud. In addition, the user can also connect the private network to the local network of the user's data center through a dedicated line to form a customized network environment according to needs.

[0025] In addition to deploying the network environment of the private cloud for the user, the cloud provider can also provide an authorization management service for the private cloud service to implement a paid subscription model for the private cloud service.

[0026] For example, the cloud provider can deploy a cloud service instance for the user on the public cloud platform. This cloud service instance can be used to manage the authorization of the private cloud service deployed on the user's private cloud platform, and there is network connectivity between this cloud service instance and the private cloud service that needs to be authorized. The private cloud service side can initiate an authorization request for a certain private cloud service to this cloud service instance to obtain the authorization information related to this private cloud service returned by this cloud service instance. Then, this private cloud service can provide services for the user based on the obtained authorization information.

[0027] It can be seen that in the above-described embodiments, when network connectivity is allowed between the private cloud platform and the public cloud platform, the cloud provider can directly provide a centralized authorization management service for the private cloud service for the user. If the number of private cloud services that need to request authorization is large, it may cause a relatively large control pressure on the authorization management service deployed on the public cloud platform.

[0028] Another example is that the cloud provider can provide the authorization information generated for the private cloud service to the management party of the private cloud platform in an offline manner. Then, the management party of the private cloud platform can perform relevant configurations for the corresponding private cloud service based on the offline-obtained authorization information, so that this private cloud service can provide services for the user based on the authorization information.

[0029] It can be seen that in the above-described embodiments, when the private cloud platform and the public cloud platform are network-isolated, the cloud provider can assist the management party of the private cloud platform in performing authorization management for the private cloud service in an offline manner. On the one hand, since processes such as offline interaction and manual configuration take a relatively long time, the efficiency of authorizing and managing the private cloud service is relatively low. On the other hand, since the private cloud service performs independent control based on the authorization information, the control strength of the cloud provider in authorizing and managing the private cloud service is relatively weak.

[0030] In view of this, this specification aims to propose a technical solution that can uniformly manage the authorization of each private cloud service deployed on a private cloud server based on an authorization management service deployed on the private cloud server.

[0031] In implementation, an authorization management service can be first deployed on the private cloud server, and the private cloud server can obtain the service authorization information generated by the public cloud server for the private cloud services deployed on the private cloud server, and can provide the obtained authorization service information to the authorization management service; subsequently, the authorization management service can manage the authorization of each private cloud service that needs to be authorized and managed by the public cloud server based on the service authorization information. That is to say, subsequently, through the service interaction between each private cloud service and the authorization management service deployed on the private cloud server, the authorization management of the private cloud service can be realized without the interaction between the private cloud server and the public cloud server, which is conducive to improving the authorization management efficiency of the private cloud service and reducing the control pressure on the public cloud server.

[0032] Among them, the service authorization information obtained by the private cloud server can be generated by the public cloud server for one or more private cloud services deployed on the private cloud server. The service authorization information may specifically include, but is not limited to: available private cloud services, available capabilities in the available private cloud services, available duration, authorization validity period, connection quantity threshold, etc.

[0033] In implementation, in response to an authorization request sent by a target private cloud service deployed on the private cloud server, the private cloud server can call the authorization management service, and the authorization management service can search for the service authorization information corresponding to the target private cloud service in the obtained service authorization information and return the found service authorization information to the target private cloud service so that the target private cloud service can provide services based on the found service authorization information. Among them, the target private cloud service may include any private cloud service deployed on the private cloud server.

[0034] For example, please refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of an authorization method for a private cloud service shown in an exemplary embodiment. As Figure 1 shown, an activation service A for generating service authorization information can be deployed on the public cloud server corresponding to the cloud provider; private cloud services C and D that need to be authorized and managed by the public cloud server can be deployed on the private cloud server corresponding to the user; and an authorization management service B for managing the authorization of private cloud services C and D can be deployed on the private cloud server.

[0035] After activation service A generates corresponding service authorization information for private cloud service C and private cloud service D, authorization management service B can obtain the service authorization information; assuming that the target private cloud service is private cloud service C, in response to the authorization request initiated by private cloud service C, the private cloud server can call authorization management service B, and authorization management service B searches for the service authorization information corresponding to private cloud service C in the obtained service authorization information; if the service authorization information corresponding to private cloud service C is found, authorization management service B can return the found service authorization information to private cloud service C, so that private cloud service C can provide services to users based on the service authorization information corresponding to it.

[0036] It can be seen that in the technical solution in this specification, by deploying an authorization management service on the private cloud server, and having the authorization management service uniformly perform authorization management on each private cloud service based on the service authorization information generated by the public cloud server for each private cloud service deployed on the private cloud server, the interaction between the private cloud service and the public cloud server can be avoided. Each private cloud service only needs to interact with the authorization management service deployed on the private cloud server, thereby improving the authorization management efficiency of the private cloud service and reducing the management and control pressure on the public cloud server.

[0037] In addition, when the service authorization information needs to be updated, the public cloud server can generate new service configuration information for the private cloud service and provide the new service configuration information to the authorization management service deployed on the private cloud server. The authorization management service can then uniformly manage the authorization of each private cloud service based on the new service authorization information. Therefore, the public cloud server does not need to update the service authorization information of each private cloud service one by one, thereby ensuring that cloud vendors have strong control over private cloud services while enabling convenient and efficient authorization management of private cloud services.

[0038] The present application is described below through specific embodiments and in combination with specific application scenarios.

[0039] See also Figure 2 , Figure 2 FIG. 1 is a flowchart of a method for authorizing a proprietary cloud service according to an exemplary embodiment. The method can be applied to Figure 1 The dedicated cloud server is shown.

[0040] In this specification, the private cloud service end may be deployed with a private cloud service that is authorized and managed by a public cloud service end, and an authorization management service for performing authorization management on the private cloud service.

[0041] For example, Figure 1The proprietary cloud service end shown may deploy proprietary cloud service C and proprietary cloud service D that need to be authorized and managed by the public cloud service end; as Figure 1 The proprietary cloud service end shown may also deploy an authorization management service B for authorizing and managing proprietary cloud service C and proprietary cloud service D.

[0042] It should be noted that in the above-described embodiments, Figure 1 only proprietary cloud service C and proprietary cloud service D deployed on the proprietary cloud service end are exemplarily shown, which does not represent a special limitation to this specification. In practical applications, any number of proprietary cloud services may be deployed on the proprietary cloud service end.

[0043] In an exemplary embodiment shown, the proprietary cloud service may be an extended cloud service developed based on the public cloud service provided by the public cloud service end.

[0044] In some possible embodiments, the proprietary cloud service may be an extended cloud application developed for the basic services related to cloud applications provided by the public cloud service end. Among them, the cloud application may specifically include an IM (Instant Messaging) application.

[0045] For example, the public cloud service end provides a general public cloud instant messaging service; the proprietary cloud service may be a proprietary cloud instant messaging service customized for users based on the general public cloud instant messaging service. Or, the proprietary cloud service may also be an extended cloud application developed based on the basic services related to the public cloud instant messaging application (such as message transmission, audio and video transmission, etc.).

[0046] It can be seen that in the above-described embodiments, in addition to deploying the network environment of the proprietary cloud for users, cloud providers can also deploy extended cloud services for users on the proprietary cloud and can implement a paid subscription model for proprietary cloud services, thereby providing more abundant cloud service capabilities for proprietary cloud users and being beneficial to improving the user experience.

[0047] Such as Figure 2 The authorization method for the proprietary cloud service shown may perform the following steps:

[0048] Step 202: Obtain the service authorization information generated by the public cloud service end for the proprietary cloud services deployed on the proprietary cloud service end.

[0049] For example, as Figure 1 shown, an activation service A for generating service authorization information may be deployed on the public cloud service end corresponding to the cloud provider; after the activation service A generates the corresponding service authorization information for proprietary cloud service C and proprietary cloud service D, the authorization management service B may obtain the service authorization information.

[0050] In an illustrated embodiment, the cloud service provider needs to first activate the authorization management service for the private cloud server. In this case, obtaining the service authorization information generated by the public cloud server for the private cloud services deployed on the private cloud server may specifically include: sending the server identifier of the private cloud server to the public cloud server and receiving the service activation information corresponding to the server identifier returned by the public cloud server; wherein the service activation information is used to activate the authorization management service; the service activation information contains the service authorization information generated by the public cloud server for the private cloud services; performing service activation processing on the authorization management service based on the service activation information, parsing the service activation information to obtain the service authorization information contained in the service activation information, and storing the parsed service authorization information in the activated authorization management service.

[0051] Wherein, the server identifier may be a serial number used to uniquely identify the private cloud server; the service activation information corresponding to the server identifier may be an activation code generated by the public cloud server and corresponding one-to-one to the serial number.

[0052] In some possible embodiments, in order to improve the security of authorization management for private cloud services, the interaction information between the public cloud server and the private cloud server may be encrypted based on the AK (Access Key Id) / SK (Secret Access Key) mechanism.

[0053] In this case, the server identifier of the private cloud server may be a string obtained by encrypting the cluster node information of the private cloud server; the service activation information may be a string obtained by encrypting the service authorization information and the private key in the public-private key pair assigned by the public cloud server to the private cloud server. Wherein, the cluster node information may be used to describe the relevant information of each cluster node in the service cluster corresponding to the private cloud server, such as resource information, resource requirements, etc., so that the public cloud server can provide different service authorization management capabilities for different users according to the private cloud resource scale of different users, thereby improving the user experience.

[0054] Sending the server identifier of the dedicated cloud server to the public cloud server may specifically include: obtaining the public key in the public-private key pair allocated by the public cloud server for the dedicated cloud server, encrypting the cluster node information of the dedicated cloud server based on the public key to obtain the server identifier of the dedicated cloud server, and sending the server identifier to the public cloud server, so that the public cloud server first decrypts the server identifier based on the private key in the public-private key pair to obtain the cluster node information of the dedicated cloud server, generates the service authorization information for the dedicated cloud server based on the cluster node information of the dedicated cloud server, and then encrypts the service authorization information and the private key based on the private key to obtain the service activation information corresponding to the server identifier.

[0055] Performing service activation processing on the authorization management service based on the service activation information, and parsing the service activation information to obtain the service authorization information included in the service activation information, and storing the service authorization information in the activated authorization management service may specifically include: decrypting the service activation information based on the public key in the public-private key pair to obtain the service authorization information included in the service activation information and the private key in the public-private key pair, and storing the decrypted service authorization information and the private key in the public-private key pair in the activated authorization management service.

[0056] For example, the public cloud server may allocate a public-private key pair (ak, sk) to the dedicated cloud server, where ak is the public key and sk is the private key. As Figure 1 shown, the dedicated cloud server may first obtain the public key sk, and may collect the cluster node information of its own dedicated cloud server, and then encrypt the cluster node information of its own dedicated cloud server based on the obtained public key sk to obtain the serial number of its own dedicated cloud server; further, the dedicated cloud server may send the serial number of its own dedicated cloud server to the public cloud server; the public cloud server may first decrypt the serial number based on the private key sk to obtain the cluster node information of the dedicated cloud server, and then use the decrypted cluster node information as a call parameter to call the activation service A to generate service authorization information for the dedicated cloud server, and then encrypt the generated service authorization information and the private key sk based on the private key sk to obtain the activation code corresponding to the serial number; the dedicated cloud server may receive the activation code and decrypt the activation code based on the public key ak to obtain the service authorization information (i.e., the service authorization information generated by the activation service A for the dedicated cloud service C and the dedicated cloud service D) and the private key sk included therein, and may store the decrypted service authorization information and the private key sk in the activated authorization management service B.

[0057] It should be noted that in the above - shown embodiments, if the private cloud server decrypts the activation code successfully based on the public key ak and obtains the service authorization information and the private key sk contained therein, it can be determined that the activation of the authorization management service is successful; if the private cloud server fails to decrypt the activation code based on the public key ak, it can notify the public cloud server that the activation code is abnormal, or directly resend the serial number to the public cloud server to obtain a new activation code.

[0058] In some possible embodiments, there is network isolation between the public cloud server and the private cloud server. Then, the public cloud server and the private cloud server can interact in an offline manner, and the administrator of the private cloud server can manually activate the authorization management service deployed on the private cloud server.

[0059] In this case, the sending of the server identifier of the private cloud server to the public cloud server and receiving the service activation information corresponding to the server identifier returned by the public cloud server may specifically include: sending the server identifier of the private cloud server to the public cloud server in an offline manner and receiving the service activation information corresponding to the server identifier returned by the public cloud server in an offline manner. The service activation process for the authorization management service based on the service activation information may specifically include: in response to the activation operation triggered by the administrator of the private cloud server, obtaining the service activation information input by the administrator and performing the service activation process for the authorization management service based on the obtained service activation information.

[0060] For example, the interaction between the public cloud server and the private cloud server in an offline manner may mean that the administrator of the private cloud server and the cloud provider corresponding to the public cloud server can interact by sending emails, instant messaging, etc.

[0061] In some possible embodiments, in addition to the authorization management service being able to uniformly manage and control each private cloud service, each private cloud service can also manage and control its own service content in a personalized manner. In this case, the private cloud server can also send the authorization requirements of each private cloud service to the public cloud server, so that the public cloud server generates corresponding service authorization information for each private cloud service based on the authorization requirements.

[0062] Among them, the authorization requirement refers to at least some of the capabilities that need to request authorization among one or more capabilities that the private cloud service can provide.

[0063] For example, the private cloud service B can provide multiple capabilities, namely, the capability b1 corresponding to the function identifier key1, the capability b2 corresponding to the function identifier key2, etc.; if only the authorization management for the capability b1 is required, the private cloud service provider can carry the function identifier key1 corresponding to the capability b1 in the authorization requirements of the private cloud service B, so that the public cloud service provider can generate the corresponding service authorization information for the private cloud service B based on the authorization requirements.

[0064] Step 204: In response to the authorization request sent by the target private cloud service deployed on the private cloud service provider, call the authorization management service deployed on the private cloud service provider. The authorization management service searches for the service authorization information corresponding to the target private cloud service in the obtained service authorization information and returns the found service authorization information to the target private cloud service, so that the target private cloud service can provide services based on the found service authorization information.

[0065] For example, as Figure 1 shown, assume that the target private cloud service is the private cloud service C. In response to the authorization request initiated by the private cloud service C, the private cloud service provider can call the authorization management service B. The authorization management service B searches for the service authorization information corresponding to the private cloud service C in the obtained service authorization information; if the service authorization information corresponding to the private cloud service C is found, the authorization management service B can return the found service authorization information to the private cloud service C, so that the private cloud service C can provide services for users based on the corresponding service authorization information; if the service authorization information corresponding to the private cloud service C is not found, the authorization management service B can return a failure response corresponding to the authorization request to the private cloud service C, and then the private cloud service C cannot provide services for users.

[0066] Specifically, each private cloud service can be equipped with an SDK (Software Development Kit) corresponding to the authorization management service, and the SDK can be used to handle the encrypted communication protocol between the authorization management service and each private cloud service. As Figure 1As shown, if a cluster node in the service cluster corresponding to the private cloud server initiates a call request for the private cloud service C, in response to the call request, the private cloud service C can further initiate a remote call request for the authorization management service B based on the SDK corresponding to the authorization management service B; in response to the remote call request, the authorization management service B can search for the service authorization information corresponding to the private cloud service C in the obtained service authorization information; if the service authorization information corresponding to the private cloud service C is found, the authorization management service B can return the found service authorization information as the remote call result to the private cloud service C, and then the private cloud service C can provide services for the cluster node based on the service authorization information corresponding to it.

[0067] In an illustrated embodiment, when calling the authorization management service, it is necessary to first determine whether the authorization management service is activated. In this case, the calling of the authorization management service may specifically include: determining whether the authorization management service is activated; if the authorization management service has been activated, then calling the activated authorization management service.

[0068] For example, in response to an authorization request initiated by the private cloud service C, the private cloud server can determine whether the authorization management service B is activated; if it has been activated, the authorization management service B can be called, and the authorization management service B can search for the service authorization information corresponding to the private cloud service C in the obtained service authorization information; if it has not been activated, a failure response corresponding to the authorization request can be returned to the private cloud service C, and then the private cloud service C cannot provide services for users.

[0069] In an illustrated embodiment, in order to improve the security of authorization management for private cloud services, the interaction information between the authorization management service and the target private cloud service can also be encrypted based on the ak / sk mechanism.

[0070] In this case, the authorization request may be encrypted based on the public key in the public-private key pair. The calling of the authorization management service in response to the authorization request sent by the target private cloud service deployed on the private cloud server may specifically include: in response to the encrypted authorization request sent by the target private cloud service deployed on the target private cloud server, decrypting the encrypted authorization request based on the private key in the public-private key pair; if the encrypted authorization request is successfully decrypted based on the private key, then calling the authorization management service.

[0071] For example, the private cloud service C can encrypt the authorization request based on the public key ak and send the encrypted authorization request to the authorization management service B; in response to the encrypted authorization request sent by the private cloud service C, the encrypted authorization request can be decrypted first based on the private key sk; if the decryption is successful, it indicates that the authorization request sent by the private cloud service C is reliable, and then the authorization management service B can be further called, and the authorization management service B can search for the service authorization information corresponding to the private cloud service C in the obtained service authorization information; if the decryption fails, a failure response corresponding to the authorization request can be returned to the private cloud service C, and thus the private cloud service C cannot provide services to users.

[0072] In this case, if the authorization management service B finds the service authorization information corresponding to the private cloud service C in the obtained service authorization information, the service authorization information corresponding to the private cloud service C found can be encrypted based on the private key sk and the encrypted service authorization information corresponding to the private cloud service C can be returned to the private cloud service C; the private cloud service C can first decrypt the encrypted service authorization information corresponding to the private cloud service C based on the public key ak, and then provide services to users based on the decrypted service authorization information corresponding to the private cloud service C.

[0073] In an illustrated embodiment, the service authorization information may include the authorization validity period preset by the public cloud server for the private cloud service. In this case, before returning the found service authorization information to the target private cloud service, the method may further include: determining whether the found service authorization information has expired according to the authorization validity period included in the found service authorization information; if the found service authorization information has not expired, returning the found service authorization information to the target private cloud service.

[0074] For example, in response to the authorization request initiated by the private cloud service C, the private cloud server can call the authorization management service B, and the authorization management service B can search for the service authorization information corresponding to the private cloud service C in the obtained service authorization information; if the service authorization information corresponding to the private cloud service C is found, the authorization management service B can first determine whether the found service authorization information has expired according to the authorization validity period included in the found service authorization information; if the found service authorization information has not expired, returning the found service authorization information to the private cloud service C so that the private cloud service C can provide services to users based on the corresponding service authorization information; if the found service authorization information has expired, a failure response corresponding to the authorization request can be returned to the private cloud service C, and thus the private cloud service C cannot provide services to users.

[0075] In one of the illustrated embodiments, the service authorization information may include a connection quantity threshold preset by the public cloud server for the private cloud service. In this case, before returning the found service authorization information to the target private cloud service, the method may further include: determining, according to the connection quantity threshold included in the found service authorization information, whether the number of cluster nodes that have established call connections with the target private cloud service in the service cluster corresponding to the private cloud server exceeds the connection quantity threshold; if the number of cluster nodes that have established call connections with the target private cloud service does not exceed the connection quantity threshold, returning the found service authorization information to the target private cloud service, and updating the number of cluster nodes that have established call connections with the target private cloud service.

[0076] Wherein, the connection quantity threshold refers to the maximum number of cluster nodes that the authorization management service supports to simultaneously authorize for the service cluster corresponding to the private cloud server.

[0077] For example, in response to an authorization request initiated by private cloud service C, the private cloud server may call authorization management service B, and authorization management service B may search for the service authorization information corresponding to private cloud service C in the obtained service authorization information; if the service authorization information corresponding to private cloud service C is found, authorization management service B may first determine, according to the connection quantity threshold included in the found service authorization information, whether the number of cluster nodes that have established call connections with private cloud service C in the service cluster corresponding to the private cloud server exceeds the connection quantity threshold; if it does not exceed the connection quantity threshold, it indicates that authorization management service B still supports authorizing private cloud service C, then a long connection can be established between authorization management service B and private cloud service C, and a call connection can be established between private cloud service C and the cluster node that initiated the call request, and the found service authorization information can be returned to private cloud service C, and the number of cluster nodes that have established call connections with private cloud service C is incremented by 1; if the number of cluster nodes that have established call connections with private cloud service C exceeds the connection quantity threshold, a failure response corresponding to the authorization request may be returned to private cloud service C, and thus private cloud service C cannot provide services to users.

[0078] It can be seen that in the above - illustrated embodiment, by adding a preset connection quantity threshold to the service authorization information generated for the private cloud service, each private cloud service uniformly establishes a connection with the authorization management service, and the cluster scale of the service cluster corresponding to the private cloud server can be controlled.

[0079] In some possible embodiments, the method may further include: if the number of cluster nodes that have established a call connection with the target proprietary cloud service does not exceed the connection number threshold, the authorization management service generates a service key for the cluster nodes requesting to call the target proprietary cloud service and returns the service key to the target proprietary cloud service; wherein, the service key is used for the target proprietary cloud service to initiate a service call to the authorization management service.

[0080] For example, if the number of cluster nodes that have established a call connection with the proprietary cloud service C does not exceed the connection number threshold, it indicates that the authorization management service B still supports authorizing the proprietary cloud service C. Then, the authorization management service B can generate a service key (a, b) for the cluster nodes requesting to call the proprietary cloud service C and can return the found service authorization information and the generated service key (a, b) to the proprietary cloud service C.

[0081] Wherein, the service key may specifically include but is not limited to a public-private key pair, a key, a password pair, etc., and this specification does not make any limitations thereto. The service key can be used to count the number of cluster nodes that have established call connections with each proprietary cloud service, and can also be used for heartbeat maintenance, querying service authorization information, etc.

[0082] In this case, the method may further include: in response to a service call request initiated by the target proprietary cloud service to the authorization management service, obtaining the service key carried in the service call request and verifying the obtained service key; if the verification of the obtained service key is successful, the authorization management service executes the service call logic corresponding to the service call request and returns the execution result as the call result for the authorization management service to the target proprietary cloud service.

[0083] Wherein, the service call request may specifically include but is not limited to a heartbeat maintenance request, a service authorization information query request, a service authorization information update request, etc.

[0084] For example, after the authorization management service B returns the service authorization information found for the dedicated cloud service C and the generated service key (a, b) to the dedicated cloud service C, the dedicated cloud service C can initiate a service call request for the authorization management service B, and the service key (a, b) is carried in the service call request; in response to the service call request, the authorization management service B can first obtain the service key (a, b) carried therein and verify the obtained service key (a, b); if the service key (a, b) carried in the service call request matches the service key (a, b) previously generated by the authorization management service B for the cluster nodes, the verification is successful, and the authorization management service B can execute the service call logic corresponding to the service call request and return the execution result as the call result to the dedicated cloud service C; if the verification fails, a failure response corresponding to the service call request can be returned to the dedicated cloud service C.

[0085] As can be seen from the above technical solutions, by deploying the authorization management service on the dedicated cloud service side and having the authorization management service uniformly manage the authorization of each dedicated cloud service based on the service authorization information generated by the public cloud service side for the dedicated cloud services deployed on the dedicated cloud service side, the interaction between the dedicated cloud service and the public cloud service side can be avoided, and each dedicated cloud service only needs to interact with the authorization management service deployed on the dedicated cloud service side, thereby improving the authorization management efficiency of the dedicated cloud service and reducing the control pressure on the public cloud service side.

[0086] In addition, when the service authorization information needs to be updated, the public cloud service side can generate new service configuration information for the dedicated cloud service and provide the new service configuration information to the authorization management service deployed on the dedicated cloud service side, and the authorization management service can uniformly manage the authorization of each dedicated cloud service based on the new service authorization information. Therefore, the public cloud service side does not need to update the service authorization information for each dedicated cloud service one by one, thereby ensuring that the cloud provider has a strong control over the dedicated cloud service while being able to conveniently and efficiently manage the authorization of the dedicated cloud service.

[0087] Corresponding to the embodiment of the authorization method for the dedicated cloud service described above, this specification also provides an embodiment of an authorization device for the dedicated cloud service.

[0088] Please refer to Figure 3 , Figure 3It is a hardware structure diagram of an electronic device where an authorization device for a proprietary cloud service shown in an exemplary embodiment is located. At the hardware level, the device includes a processor 302, an internal bus 304, a network interface 306, a memory 308, and a non-volatile memory 310. Of course, it may also include other required hardware. One or more embodiments of this specification can be implemented in software. For example, the processor 302 reads the corresponding computer program from the non-volatile memory 310 into the memory 308 and then runs it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of software and hardware. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and can also be hardware or logic devices.

[0089] Please refer to Figure 4 , Figure 4 It is a block diagram of an authorization device for a proprietary cloud service shown in an exemplary embodiment. The authorization device for the proprietary cloud service can be applied to an electronic device as shown in Figure 3 to implement the technical solutions of this specification. Among them, a proprietary cloud service authorized and managed by a public cloud service provider is deployed on the proprietary cloud service provider, and an authorization management service for authorizing and managing the proprietary cloud service is provided; the authorization device for the proprietary cloud service may include:

[0090] An acquisition unit 402, configured to acquire service authorization information generated by the public cloud service provider for the proprietary cloud service deployed on the proprietary cloud service provider;

[0091] An authorization management unit 406, configured to, in response to an authorization request sent by a target proprietary cloud service deployed on the proprietary cloud service provider, call the authorization management service, and the authorization management service searches for service authorization information corresponding to the target proprietary cloud service in the acquired service authorization information, and returns the found service authorization information to the target proprietary cloud service, so that the target proprietary cloud service provides services based on the found service authorization information.

[0092] In this embodiment, the proprietary cloud service is an extended cloud service developed based on the public cloud service provided by the public cloud service provider.

[0093] In this embodiment, the acquisition unit 402 is specifically configured to:

[0094] Send the service provider identifier of the proprietary cloud service provider to the public cloud service provider, and receive the service activation information returned by the public cloud service provider corresponding to the service provider identifier; wherein, the service activation information is used to activate the authorization management service; the service activation information includes the service authorization information generated by the public cloud service provider for the proprietary cloud service.

[0095] Perform service activation processing on the authorization management service based on the service activation information, parse the service activation information to obtain the service authorization information contained in the service activation information, and store the parsed service authorization information in the activated authorization management service;

[0096] The authorization management unit 406 is specifically configured to:

[0097] Determine whether the authorization management service has been activated;

[0098] If the authorization management service has been activated, then call the activated authorization management service.

[0099] In this embodiment, the server identifier of the dedicated cloud server is a string obtained by encrypting the cluster node information of the dedicated cloud server; the service activation information is a string obtained by encrypting the service authorization information and the private key in the public-private key pair allocated by the public cloud server for the dedicated cloud server;

[0100] The sending the server identifier of the dedicated cloud server to the public cloud server includes:

[0101] Obtain the public key in the public-private key pair allocated by the public cloud server for the dedicated cloud server, encrypt the cluster node information of the dedicated cloud server based on the public key to obtain the server identifier of the dedicated cloud server, and send the server identifier to the public cloud server, so that the public cloud server first decrypts the server identifier based on the private key in the public-private key pair to obtain the cluster node information of the dedicated cloud server, generates the service authorization information for the dedicated cloud server based on the cluster node information of the dedicated cloud server, and then encrypts the service authorization information and the private key based on the private key to obtain the service activation information corresponding to the server identifier.

[0102] In this embodiment, the performing service activation processing on the authorization management service based on the service activation information, parsing the service activation information to obtain the service authorization information contained in the service activation information, and storing the service authorization information in the activated authorization management service includes:

[0103] Decrypt the service activation information based on the public key in the public-private key pair to obtain the service authorization information contained in the service activation information and the private key in the public-private key pair, and store the decrypted service authorization information and the private key in the public-private key pair in the activated authorization management service.

[0104] In this embodiment, network isolation is performed between the public cloud server and the private cloud server;

[0105] Sending the server identifier of the private cloud server to the public cloud server and receiving the service activation information corresponding to the server identifier returned by the public cloud server includes:

[0106] Sending the server identifier of the private cloud server to the public cloud server in an offline manner and receiving the service activation information corresponding to the server identifier returned by the public cloud server in an offline manner;

[0107] Performing service activation processing on the authorization management service based on the service activation information includes:

[0108] In response to the activation operation triggered by the administrator of the private cloud server, obtaining the service activation information input by the administrator, and performing service activation processing on the authorization management service based on the obtained service activation information.

[0109] In this embodiment, the authorization request is encrypted based on the public key in the public-private key pair;

[0110] The authorization management unit 406 is specifically configured to:

[0111] In response to the encrypted authorization request sent by the target private cloud service deployed on the target private cloud server, decrypting the encrypted authorization request based on the private key in the public-private key pair;

[0112] If the decryption of the encrypted authorization request based on the private key is successful, then call the authorization management service.

[0113] In this embodiment, the service authorization information includes the authorization validity period preset by the public cloud server for the private cloud service;

[0114] The authorization management unit 406 is further configured to:

[0115] Determine whether the found service authorization information has expired according to the authorization validity period included in the found service authorization information;

[0116] If the found service authorization information has not expired, then return the found service authorization information to the target private cloud service.

[0117] In this embodiment, the service authorization information includes the connection quantity threshold preset by the public cloud server for the private cloud service;

[0118] The authorization management unit 406 is further configured to:

[0119] Determine whether the number of cluster nodes that have established call connections with the target dedicated cloud service in the service cluster corresponding to the dedicated cloud server exceeds the connection number threshold according to the connection number threshold included in the found service authorization information;

[0120] If the number of cluster nodes that have established call connections with the target dedicated cloud service does not exceed the connection number threshold, return the found service authorization information to the target dedicated cloud service, and update the number of cluster nodes that have established call connections with the target dedicated cloud service.

[0121] In this embodiment, the authorization management unit 406 is further configured to:

[0122] If the number of cluster nodes that have established call connections with the target dedicated cloud service does not exceed the connection number threshold, generate a service key for the cluster node that requests to call the target dedicated cloud service by the authorization management service, and return the service key to the target dedicated cloud service; wherein, the service key is used for the target dedicated cloud service to initiate a service call to the authorization management service.

[0123] In this embodiment, the device further includes:

[0124] A verification unit, configured to obtain the service key carried in the service call request in response to the service call request initiated by the target dedicated cloud service to the authorization management service, and verify the obtained service key;

[0125] A service call unit, configured to, if the verification of the obtained service key is successful, execute the service call logic corresponding to the service call request by the authorization management service, and return the execution result as the call result for the authorization management service to the target dedicated cloud service.

[0126] The implementation processes of the functions and roles of each unit in the above device are specifically detailed in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0127] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions of the method embodiments. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution in this specification. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0128] The systems, devices, modules or units described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver device, a game console, a tablet computer, a wearable device, or a combination of any several of these devices.

[0129] In a typical configuration, a computer includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0130] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0131] Computer-readable media includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0132] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0133] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.

[0134] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0135] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a", "the" and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0136] It should be understood that although the terms first, second, third, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0137] The above are only the preferred embodiments of one or more embodiments of this specification, and are not intended to limit one or more embodiments of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of protection of one or more embodiments of this specification.

Claims

1. A licensing method for a proprietary cloud service, where the method is applied to a proprietary cloud service server; A proprietary cloud service and an authorization management service for authorizing and managing the proprietary cloud service are deployed on the proprietary cloud server; the method includes: Obtain the service authorization information generated by the public cloud server for the proprietary cloud service deployed on the proprietary cloud server; In response to an authorization request sent by the target proprietary cloud service deployed on the proprietary cloud server, call the authorization management service. The authorization management service searches for the service authorization information corresponding to the target proprietary cloud service in the obtained service authorization information and returns the found service authorization information to the target proprietary cloud service, so that the target proprietary cloud service provides services based on the found service authorization information.

2. The method according to claim 1, wherein the proprietary cloud service is an extended cloud service developed based on the public cloud service provided by the public cloud server.

3. The method according to claim 1, wherein the obtaining the service authorization information generated by the public cloud server for the proprietary cloud service deployed on the proprietary cloud server includes: Send the server identifier of the proprietary cloud server to the public cloud server and receive the service activation information returned by the public cloud server corresponding to the server identifier; wherein the service activation information is used to activate the authorization management service; the service activation information includes the service authorization information generated by the public cloud server for the proprietary cloud service; Perform service activation processing on the authorization management service based on the service activation information, parse the service activation information, obtain the service authorization information included in the service activation information, and store the parsed service authorization information in the activated authorization management service; The calling the authorization management service includes: Determine whether the authorization management service has been activated; If the authorization management service has been activated, call the activated authorization management service.

4. The method according to claim 3, wherein the server identifier of the proprietary cloud server is a string obtained by encrypting the cluster node information of the proprietary cloud server; the service activation information is a string obtained by encrypting the service authorization information and the private key in the public-private key pair assigned by the public cloud server to the proprietary cloud server; The sending the server identifier of the proprietary cloud server to the public cloud server includes: Obtain the public key in the public-private key pair allocated by the public cloud server for the private cloud server, encrypt the cluster node information of the private cloud server based on the public key to obtain the server identifier of the private cloud server, and send the server identifier to the public cloud server, so that the public cloud server first decrypts the server identifier based on the private key in the public-private key pair to obtain the cluster node information of the private cloud server, and generates the service authorization information for the private cloud server based on the cluster node information of the private cloud server, and then encrypts the service authorization information and the private key based on the private key to obtain the service activation information corresponding to the server identifier.

5. The method according to claim 4, where the service activation process is performed on the authorization management service based on the service activation information, and the service activation information is parsed to obtain the service authorization information included in the service activation information, and the service authorization information is stored in the activated authorization management service, including: Decrypt the service activation information based on the public key in the public-private key pair to obtain the service authorization information included in the service activation information and the private key in the public-private key pair, and store the decrypted service authorization information and the private key in the public-private key pair in the activated authorization management service.

6. The method according to claim 3, where there is network isolation between the public cloud server and the private cloud server; The sending the server identifier of the private cloud server to the public cloud server and receiving the service activation information corresponding to the server identifier returned by the public cloud server includes: Send the server identifier of the private cloud server to the public cloud server in an offline manner, and receive the service activation information corresponding to the server identifier returned by the public cloud server in an offline manner; The performing the service activation process on the authorization management service based on the service activation information includes: In response to the activation operation triggered by the administrator of the private cloud server, obtain the service activation information input by the administrator, and perform the service activation process on the authorization management service based on the obtained service activation information.

7. The method according to claim 4, where the authorization request is encrypted based on the public key in the public-private key pair; The responding to the authorization request sent by the target private cloud service deployed on the private cloud server and invoking the authorization management service includes: In response to the encrypted authorization request sent by the target private cloud service deployed on the target private cloud server, decrypt the encrypted authorization request based on the private key in the public-private key pair; If the decryption of the encrypted authorization request based on the private key is successful, then invoke the authorization management service.

8. The method according to claim 1, where the service authorization information includes the authorization validity period preset by the public cloud server for the private cloud service; Before returning the found service authorization information to the target private cloud service, the method further includes: Determine whether the found service authorization information has expired according to the authorization validity period included in the found service authorization information; If the found service authorization information has not expired, return the found service authorization information to the target private cloud service.

9. The method according to claim 1, wherein the service authorization information includes a connection quantity threshold preset by the public cloud service end for the private cloud service; Before returning the found service authorization information to the target private cloud service, the method further includes: Determine whether the number of cluster nodes that have established call connections with the target private cloud service in the service cluster corresponding to the private cloud service end exceeds the connection quantity threshold according to the connection quantity threshold included in the found service authorization information; If the number of cluster nodes that have established call connections with the target private cloud service does not exceed the connection quantity threshold, return the found service authorization information to the target private cloud service, and update the number of cluster nodes that have established call connections with the target private cloud service.

10. The method according to claim 9, the method further includes: If the number of cluster nodes that have established call connections with the target private cloud service does not exceed the connection quantity threshold, the authorization management service generates a service key for the cluster node requesting to call the target private cloud service, and returns the service key to the target private cloud service; wherein, the service key is used for the target private cloud service to initiate a service call to the authorization management service.

11. The method according to claim 10, the method further includes: In response to a service call request initiated by the target private cloud service to the authorization management service, obtain the service key carried in the service call request, and verify the obtained service key; If the verification of the obtained service key is successful, the authorization management service executes the service call logic corresponding to the service call request, and returns the execution result as the call result for the authorization management service to the target private cloud service.

12. An authorization device for a proprietary cloud service, the device being applied to a proprietary cloud service end; A private cloud service end is deployed with a private cloud service authorized and managed by a public cloud service end, and an authorization management service for authorizing and managing the private cloud service; the device includes: An acquisition unit, configured to acquire service authorization information generated by the public cloud service end for the private cloud service deployed on the private cloud service end; An authorization management unit, configured to, in response to an authorization request sent by a target private cloud service deployed on the private cloud service end, call the authorization management service, and the authorization management service searches for service authorization information corresponding to the target private cloud service in the acquired service authorization information, and returns the found service authorization information to the target private cloud service, so that the target private cloud service provides services based on the found service authorization information.

13. An electronic device, comprising a communication interface, a processor, a memory, and a bus, wherein the communication interface, the processor, and the memory are interconnected with each other via the bus; Machine-readable instructions are stored in the memory, and the processor executes the method according to any one of claims 1 to 11 by calling the machine-readable instructions.

14. A machine-readable storage medium storing machine-readable instructions, which, when called and executed by a processor, implement the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Security management for cloud services

    CN104054321A

  • Cloud-based data transmission system and data transmission and acquisition method

    CN111030967A