A cloud resource access control method based on cloud computing technology and a cloud management platform

By recording and applying resource control policies in the cloud management platform, which directly affect cloud resources within the organization, the problem of existing technologies being unable to constrain resources within the organization is solved, and refined security for access control and resource management for users outside the organization is achieved.

CN117640125BActive Publication Date: 2026-03-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-07
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing organizational management services cannot effectively constrain resources within an account, making it easy for cloud resources within an organization to be shared across accounts in a multi-account environment, and making it impossible to effectively control access by users outside the organization.

Method used

By acquiring and recording the resource control policies of the target organization through the cloud management platform, the system can directly apply these policies to cloud resources within the organization, thereby restricting access for users outside the organization and enabling fine-grained access control through resource identifiers and context information.

Benefits of technology

It enables unified access control over cloud resources within the organization, preventing unauthorized access by external users and ensuring refined and secure resource management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117640125B_ABST
    Figure CN117640125B_ABST
Patent Text Reader

Abstract

The application provides a cloud resource access control method based on cloud computing technology, applied to a cloud management platform, and the method comprises the following steps: the cloud management platform acquires and records a first resource control strategy configured by an administrator of a target organization for a target cloud resource in the target organization, wherein the first resource control strategy is used for indicating the access permission of a user outside the target organization to the target cloud resource; the cloud management platform acquires a first resource access request triggered by the user outside the target organization for the target cloud resource in the target organization; and the cloud management platform allows or rejects the first resource access request to access the target cloud resource according to the first resource control strategy recorded by itself. The cloud resource access control method based on cloud computing technology provided by the application can restrict the access of the user outside an organization to the cloud resource in the organization.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese Patent Application No. 202210972620.6, filed on August 15, 2022, entitled “A Method and Device for Access Control Based on Organizational Resources”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of computer, and particularly relates to a cloud resource access control method based on cloud computing technology and a cloud management platform. BACKGROUND

[0003] In order to meet the needs of enterprise customers for unified management of identity and resources, the IT system needs to provide organizational management services. The organizational management service mainly provides three capabilities for customers:

[0004] The separation of duty unit (SoD Unit) is used to configure different operation permissions and the smallest unit carrying different cloud resources to meet the principle of mutual separation of responsibilities and permissions between business departments and business operation personnel of the enterprise. Different cloud vendors have different names for SoD units, for example, SoD units can be called accounts, subscriptions, and projects, etc.

[0005] Hierarchical management, a general enterprise has a tree-shaped organizational structure from top to bottom, and the hierarchical management capability is to organize SoD units in a tree structure, which is convenient for enterprise department operation personnel to manage.

[0006] Organizational compliance control policy, enterprises need unified compliance control capability for operation personnel and resources applied on the cloud, such as controlling the access boundary of data storage on the cloud. The organizational compliance control policy is a kind of mandatory access control (MAC) imposed on the entire organization or part of the organization unit. It should be noted that, unlike discretionary access control (DAC), mandatory access control is not an authorization, but a constraint; the object affected by the mandatory access control policy will not have the permission beyond the scope defined by the policy.

[0007] However, the existing organizational management service provided by the organizational compliance control policy can only constrain the identity within the account, and cannot constrain the resources within the account. SUMMARY

[0008] The embodiment of the present application provides a cloud resource access control method based on cloud computing technology, a resource control strategy directly acts on resources in an organization, access to the resources in the organization is constrained, and access of a user outside the organization to cloud resources in the organization can be constrained.

[0009] In a first aspect, the present application provides a cloud resource access control method based on cloud computing technology, the method is applied to a cloud management platform, the cloud management platform is used for managing an infrastructure providing a plurality of cloud resources, the infrastructure comprises at least one cloud data center, each cloud data center is provided with a plurality of servers, one or any combination of the plurality of cloud resources is deployed in at least one server of the infrastructure, and the plurality of cloud resources are arranged in at least one organization, and the method comprises the following steps: the cloud management platform acquires and records a first resource control strategy configured by an administrator of a target organization and used for target cloud resources in the target organization, wherein the first resource control strategy is used for indicating access permission of a user outside the target organization to the target cloud resources; the cloud management platform acquires a first resource access request triggered by the user outside the target organization and used for the target cloud resources in the target organization; and the cloud management platform allows or rejects the first resource access request to access the target cloud resources according to the first resource control strategy recorded by the cloud management platform.

[0010] The cloud resource access control method based on cloud computing technology provided by the present application has the advantages that a resource control strategy directly acts on cloud resources in an organization, access to the cloud resources in the organization is constrained, an administrator of the organization can perform unified access control management on the cloud resources in the organization, and access of a user outside the organization to the cloud resources in the organization can be constrained.

[0011] For example, the first resource control strategy comprises a first constraint condition, the first constraint condition is used for constraining that an access user belongs to the target organization, when the resource access request is triggered by the user outside the target organization, that is, the access user does not satisfy the first constraint condition, the first resource access request is rejected to access the target resources.

[0012] In one possible implementation, the cloud resource access control method based on cloud computing technology provided by the present application further comprises the following steps: the cloud management platform acquires and records a second resource control strategy configured by an administrator of a target organization and used for target cloud resources in the target organization, wherein the second resource control strategy is used for indicating access permission of a user in the target organization to the target cloud resources; the cloud management platform acquires a second resource access request triggered by the user in the target organization and used for the target cloud resources in the target organization; and the cloud management platform allows or rejects the second resource access request to access the target cloud resources according to the second resource control strategy recorded by the cloud management platform.

[0013] In the possible implementation, the control over the cloud resource access of the users in the organization to the cloud resources in the organization is realized through the second resource control strategy, for example, the users of different departments are restricted to access only the cloud resources under the department to which the user belongs, and more refined resource management is realized.

[0014] For example, the second resource control strategy includes a second constraint condition, the second constraint condition is used to restrict that the access user belongs to a target organization node, when the access request is triggered by a user in the target organization, but the user is not the target organization node, the access user does not satisfy the second constraint condition, and the first resource access request is rejected to access the target resource.

[0015] In another possible implementation, before the cloud management platform acquires and records the first resource control strategy configured by the administrator of the target organization for the target cloud resource in the target organization, the cloud resource access control method based on cloud computing technology provided in the present application further includes: the cloud management platform acquires a plurality of registration requests carrying different user accounts; the cloud management platform registers and records a plurality of user accounts according to the plurality of registration requests, wherein the plurality of user accounts include the account of the administrator; the cloud management platform divides the plurality of user accounts into the target organization, and sets the account of the administrator as the administrator account of the target organization.

[0016] In other words, registration is required on the cloud management platform before using the cloud service, a plurality of accounts can be registered, the accounts are managed in the form of an organization, and each account corresponds to a corresponding cloud resource, for example, the organization is an enterprise organization, different accounts are registered for members in the enterprise, and the members have different levels or belong to different departments, and different cloud resources under the enterprise organization can be used.

[0017] In another possible implementation, the first resource access request carries a user account of a user outside the target organization registered on the cloud management platform, and the cloud management platform acquires the resource access request triggered by the user outside the target organization for the target cloud resource in the target organization, including: the cloud management platform determines that the user account carried by the first resource access request does not belong to the plurality of user accounts corresponding to the target organization, and determines that the first resource access request is triggered by the user outside the target organization.

[0018] That is, the access request comes from other users on the cloud, the user has been registered on the cloud but is not in the target organization, and the cloud management platform determines that the access request issued by the user is triggered by the user outside the target organization.

[0019] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform, and the cloud management platform acquires a resource access request triggered by a user outside the target organization and directed to a target cloud resource in the target organization, including: the cloud management platform determines that the first resource access request is triggered by a user outside the target organization when the cloud management platform determines that the first resource access request does not carry a user account registered in the cloud management platform.

[0020] In this possible implementation, the access request comes from other users under the cloud, who are not registered on the cloud (i.e., do not have an account), and the cloud management platform determines that the access request issued by such users is triggered by a user outside the target organization.

[0021] For example, the target cloud resource corresponding to the access request is a virtual machine, and the cloud provides a web page for public network use, and a terminal (such as a mobile phone or a personal computer) under the cloud can access the public network IP (target public network IP) of the web page through its own source public network IP.

[0022] In one possible implementation, the cloud resource access control method based on cloud computing technology provided by the present application further includes: the cloud management platform acquires a third resource control policy, and acquires context information of a third resource access request, the context information including IP network segment information, the IP network segment information indicating an IP network segment where a sending end of the resource access request is located; the third resource control policy further includes a third constraint condition, the third constraint condition being used to restrict that a source public network IP network segment corresponding to the resource access request belongs to a preset IP network segment; when the source public network IP network segment belongs to the preset IP network segment, the user is allowed to access the target cloud resource, that is, the cloud resource access control method based on cloud computing technology provided by the present application can prohibit or allow a user (including a user on the cloud or a user under the cloud) of a specific source public network network segment to access the target cloud resource.

[0023] In this possible implementation, the resource control policy includes multiple constraint conditions, and only when the resource access request information satisfies all the constraint conditions, the resource access request will pass the authentication, providing more detailed resource access control. For example, by acquiring context information of the resource access request information, the context information including a public network IP network segment corresponding to the resource access request, the multiple constraint conditions in the resource control policy include that an IP network segment where a sending end of the resource access request is located belongs to a preset network segment (such as a public network network segment where the target organization is located), and only the access request issued from the preset network segment will pass the authentication and be allowed to access the target resource.

[0024] In another possible implementation, the resource access request information further comprises operation information, the operation information indicating an operation performed on the target resource; the resource control policy further comprises a fourth constraint condition, the fourth constraint condition being used to constrain the operation indicated by the operation information to belong to a preset operation; and the authentication result of the resource access request is further related to the operation information and the third constraint condition.

[0025] The operation information is further carried in the resource access request information, and the plurality of constraint conditions in the resource control policy comprises a constraint condition that the operation indicated by the operation information belongs to a preset operation, for example, the preset operation is a read operation, that is, the access is used to only allow the read operation to be performed on the target resource.

[0026] In another possible implementation, the target resource information comprises a resource identifier, the resource identifier being used to uniquely identify the target resource; and the determining the resource control policy corresponding to the target resource information comprises: querying a preset index table based on the resource identifier to obtain the resource control policy corresponding to the target resource information, the plurality of index items in the index table being determined based on a plurality of resource identifiers, the plurality of resource identifiers being a plurality of resource identifiers corresponding to a plurality of resources in an organization node of a target organization or an organization to which the target resource belongs.

[0027] In this possible implementation, the resource identifier is used as an index of the resource control policy, so that the authentication system can quickly index and obtain the free control policy acting on the target resource to perform policy calculation.

[0028] In another possible implementation, the determining the resource control policy corresponding to the target resource information comprises: determining an organization member to which the target resource belongs based on the target resource information; querying a mapping table to obtain a resource control policy associated with the target organization and / or an organization node in which the organization member is located, the mapping table recording a mapping relationship between each organization node and / or organization and each resource control policy; and determining the resource control policy corresponding to the target resource based on the resource control policy associated with the target organization and / or the organization node in which the organization member is located.

[0029] That is, another possible implementation is provided to quickly find the resource control policy corresponding to the target resource, by determining the organization member to which the target resource belongs, and then determining the organization node and / or organization in which the organization member is located, and then determining the resource control policy acting on the organization and / or organization node, which is the resource control policy corresponding to the target resource.

[0030] In another possible implementation, the resource access request is used to call an application program interface (API) to access the target resource in the target cloud service; and when the authentication result is passed, the access result of the target resource according to the access request is returned to the access user in response to the resource access request. For example, the resource access request is a read operation on the target resource, and the access result is the target resource data read.

[0031] In another possible implementation, the first resource control policy comprises a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify to reject or allow access to the target cloud resource, the request type field is used to identify a request type of the first resource access request, and the condition field is used to indicate a user outside the target organization.

[0032] Optionally, the types of the cloud resources comprise virtual machines and containers of a computing service, buckets of an object storage service, cloud disks, and cloud databases.

[0033] In a second aspect, the present application provides a cloud management platform, which is used to manage an infrastructure providing a plurality of cloud resources, the infrastructure comprising at least one cloud data center, each cloud data center being provided with a plurality of servers, one or any combination of the plurality of cloud resources being deployed in at least one server of the infrastructure, and the plurality of cloud resources being arranged in at least one organization, the cloud management platform comprising an organization management module, a service module, and an authentication module, wherein the organization management module is used to obtain and record a first resource control policy configured by an administrator of a target organization for a target cloud resource within the target organization, wherein the first resource control policy is used to indicate access permissions of a user outside the target organization to the target cloud resource; the service module is used to obtain a first resource access request triggered by the user outside the target organization for the target cloud resource within the target organization; and the authentication module is used to determine a first authentication result according to the first resource control policy recorded by the organization management module, wherein the first authentication result is to allow or reject the first resource access request to access the target cloud resource; and the service module is further used to obtain the first authentication result from the authentication module, and allow or reject the first resource access request to access the target cloud resource according to the first authentication result.

[0034] In a possible implementation, the organization management module is further used to obtain and record a second resource control policy configured by the administrator of the target organization for the target cloud resource within the target organization, wherein the second resource control policy is used to indicate access permissions of a user within the target organization to the target cloud resource; the service module is further used to obtain a second resource access request triggered by the user within the target organization for the target cloud resource within the target organization; and the authentication module is used to determine a second authentication result according to the second resource control policy recorded by the organization management module, wherein the second authentication result is to allow or reject the second resource access request to access the target cloud resource; and the service module is further used to obtain the second authentication result from the authentication module, and allow or reject the second resource access request to access the target cloud resource according to the second authentication result.

[0035] In another possible implementation, the cloud management platform further includes a registration module configured to obtain a plurality of registration requests carrying different user accounts, and register and record the plurality of user accounts according to the plurality of registration requests, wherein the plurality of user accounts include an account of an administrator; and an organization management module configured to divide the plurality of user accounts into a target organization, and set the account of the administrator as an administrator account of the target organization.

[0036] In another possible implementation, the first resource access request carries a user account of a user outside the target organization registered in the cloud management platform; and the service module is configured to determine that the first resource access request is triggered by the user outside the target organization, in a case where the service module determines that the user account carried in the first resource access request does not belong to the plurality of user accounts corresponding to the target organization recorded by the registration module.

[0037] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform; and the service module is configured to determine that the first resource access request is triggered by the user outside the target organization, in a case where the service module determines that the first resource access request does not carry a user account registered in the cloud management platform.

[0038] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is configured to identify a target cloud resource, the effect field is configured to identify to reject or allow access to the target cloud resource, the request type field is configured to identify a request type of the first resource access request, and the condition field is configured to indicate the user outside the target organization.

[0039] In another possible implementation, the types of the cloud resources include virtual machines and containers of a computing service, buckets of an object storage service, cloud disks, and cloud databases.

[0040] In a third aspect, the present application provides a server, including a memory and a processor, the memory stores executable code, and the processor executes the executable code to implement the method provided in the first aspect of the present application.

[0041] In a fourth aspect, the present application provides a computing device, including a memory and a processor, the memory stores executable code, and the processor executes the executable code to implement the method provided in the first aspect of the present application.

[0042] In a fifth aspect, the present application provides a computer readable storage medium, which stores a computer program, and the computer program, when executed in a computer, causes the computer to execute the method provided in the first aspect of the present application.

[0043] In a sixth aspect, the present application provides a computer program or computer program product, which comprises instructions for implementing the method provided in the first aspect of the present application when the instructions are executed.

[0044] In a seventh aspect, the embodiments of the present application further provide a chip, comprising at least one processor and a communication interface, and the processor is configured to execute the method provided in the first aspect of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figures 1-3 are respectively schematic diagrams of an organization management service model in the related art;

[0046] Figure 4 is a schematic diagram of an SCP rejecting access to an s3:GetObject API;

[0047] Figure 5 is a schematic diagram of an SCP being bound to a root node of an organization;

[0048] Figure 6 is a schematic diagram of a scenario after an SCP being bound to a root node of an organization and sharing an account;

[0049] Figure 7 shows an architecture schematic diagram of a system to which the cloud resource access control method based on cloud computing technology provided in the embodiments of the present application can be applied;

[0050] Figure 8 is a flow schematic diagram of a cloud resource access control method based on cloud computing technology provided in the embodiments of the present application;

[0051] Figure 9 is a schematic diagram of an RCP directly acting on cloud resources in a target organization after the RCP being bound to a root node of the target organization;

[0052] Figure 10 is a flow schematic diagram of another cloud resource access control method based on cloud computing technology provided in the embodiments of the present application;

[0053] Figure 11 shows an implementation process schematic diagram of the resource access control method provided in the embodiments of the present application in a specific application scenario;

[0054] Figure 12 is a structure schematic diagram of a cloud control platform provided in the embodiments of the present application;

[0055] Figure 13 is a structure schematic diagram of a computing device provided in the embodiments of the present application;

[0056] Figure 14A schematic diagram of an application scenario of a computing device cluster provided by the present application is shown in FIG. 1.

[0057] Figure 15 is Figure 14 A schematic diagram of an application scenario of a computing device cluster provided by the present application is shown in FIG. 1. DETAILED DESCRIPTION

[0058] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0059] Reference to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears at various places in the specification does not necessarily all refer to the same embodiment, nor is it necessary that every embodiment include the features described in connection with the other embodiments. It is explicitly and implicitly understood that the embodiments described herein can be combined with other embodiments.

[0060] Cloud technology refers to a kind of hosting service that unifies a series of resources such as hardware, software and network in a wide area network or a local area network to realize data calculation, storage, processing and sharing.

[0061] Public cloud refers to a cloud provided by a third party for users to use. Public cloud can be used through a network, and can be free or low-cost. There are many instances of such cloud, which can provide services in the entire open public network.

[0062] Private cloud refers to a cloud infrastructure and hardware and software resources built within a firewall for sharing resources in a data center by departments within an organization or enterprise. Private cloud is a cloud infrastructure operated entirely for a specific organization, and the manager can be the organization itself or a third party; the location can be inside or outside the organization.

[0063] Hybrid cloud refers to a cloud computing environment composed of private cloud resources and public cloud resources.

[0064] Service control policy (SCP) refers to a mandatory access control policy in an organization service, with the object being the identity within the organization.

[0065] Resource control policy (RCP) refers to a mandatory access control policy in which the object of action is the resource within an organization.

[0066] Cloud management platform and infrastructure: the cloud management platform is used to manage the infrastructure of the cloud vendor, and the infrastructure is a plurality of cloud data centers arranged in different regions, wherein at least one cloud data center is arranged in each region. The cloud management platform can provide an interface related to cloud computing services, such as a configuration page or an application program interface (API) for tenants to access cloud services. Tenants can log in to the cloud management platform through a pre-registered account password, and after successful login, select and purchase cloud services provided by the cloud data center in the predetermined region. Cloud services include object storage services, virtual machine services, container services, or other known cloud services.

[0067] Tenant: a top-level object for managing cloud services and / or cloud resources. A tenant registers a tenant account and sets a tenant password on a local client (such as a browser) in the cloud management platform. The local client remotely logs in to the cloud management platform through the tenant account and sets the tenant password. The cloud management platform provides a configuration interface or API for tenants to configure and use cloud services, which are provided by the infrastructure managed by the cloud management platform as described above.

[0068] The embodiments of the present application provide a resource access control method, which can be applied to any IT system (such as public cloud systems, private cloud systems, and hybrid cloud systems) that needs to organize and manage resources and uniformly control permissions, to take the resources within an organization as the object of action of the organization control policy, and to realize the control of the resources within an organization to reject access by external identities, thereby ensuring the security of the resources within an organization.

[0069] The specific implementation of the resource access control method provided by the embodiments of the present application will be described in detail below with reference to a public cloud system as an example. Other IT systems are similar, and for the sake of brevity, will not be described again.

[0070] It can be understood that when the resource access control method provided by the embodiments of the present application is applied to a public cloud system, it can also be referred to as a cloud resource access control method based on cloud computing technology.

[0071] Most mainstream public cloud vendors provide organization management services, Figures 1 to 3 Different public cloud vendors provide different organization management service models, as shown in the following figures. It can be seen that different public cloud vendors have different names for SoD units, Figure 1 In model 1, the SoD unit is an account; Figure 2 In model 2, the SoD unit is a subscription; Figure 3The SoD unit in the shown model 3 is a project.

[0072] The organization management service model in the related art mostly acts on the identity in the SoD, and cannot directly constrain the cloud resources in the SoD, which causes some problems.

[0073] Taking the model 1 as an example, in terms of organization compliance control capability, the model 1 provides an SCP model, which is a MAC model, and contains a domain specific language (DSL) for describing an access control policy. For example, Figure 4 A policy for denying access to the s3:GetObject API is described.

[0074] The customer can create an SCP policy and bind the SCP policy to a certain tree node of the organization management service. When the binding is completed, the identities in all accounts governed by the tree node are controlled by the SCP policy. For example, Figure 5 As shown, when the SCP policy shown in Figure 4 is bound to the root node of the organization, the identities of all accounts in the organization are denied access to the s3:GetObject API.

[0075] In the organization management service solutions of various public cloud vendors, the SoD unit contains two types of objects: one type is identity; and the other type is resource. In this scenario, it is worth pointing out that the objects acted on by the organization compliance control policy (for example, SCP) are all the identities in the organization. For example, in the example of Figure 5 , all the identities (IAM users and IAM roles) in the account 3 (Acct-3) cannot call the s3:GetObject API. The model has the following disadvantages:

[0076] In the organization management service, the account as the SoD unit also carries the responsibility of the resource container, and the SCP can only constrain the identities in the account, but cannot constrain the resources in the account; in the multi-account environment of the organization, the resources are often shared across accounts, and it is a common customer demand to control the resources in the organization from being accessed by the identities outside the organization illegally, and the above organization management service models cannot achieve this function.

[0077] For example, Figure 6In the example shown, the administrator of the organization wants to restrict the data in the S3 buckets within the organization from being accessed by identities outside the organization via SCP, but account 3 (Acct-3) can bypass the restriction by sharing a certain bucket to an account outside the organization (Acct-4). At this time, account 4 (Acct-4) still has the permission to access the bucket data in account 3 (Acct-3), because SCP cannot limit the access of identities outside the organization to resources within the organization.

[0078] Another typical scenario is that the administrator of the organization wants to limit the resources within the organization to be accessed only from a certain fixed IP network segment, such as the public network segment where the enterprise is located. This restriction cannot be achieved by the SCP policy described above.

[0079] To solve the above problems, the embodiment of the present application provides a cloud resource access control method based on cloud computing technology, so that the administrator of the organization can perform unified access control on the resources within the organization, for example, prohibit the cloud resources within the target organization from being accessed by users outside the target organization, or prohibit the cloud resources within the target organization node from being accessed by users outside the target organization node.

[0080] The specific implementation of the cloud resource access control method based on cloud computing technology and the cloud management platform device provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0081] Figure 7 The architecture schematic diagram of a system to which the cloud resource access control method based on cloud computing technology provided by the embodiment of the present application can be applied is shown. As shown in the figure, Figure 7 The system includes a cloud management platform 20 and an infrastructure 1. Tenant A can log in to the cloud management platform 20 through a client 40 via the Internet 30 by using an account and a password registered in advance in the cloud management platform 20, and manage the cloud resources in the infrastructure 1 through the cloud management platform 20. Tenant A can deploy an organization management service for its cloud resources in the cloud management platform 20. The infrastructure 1 includes a plurality of computing devices, for example, the infrastructure 1 includes a computing device 11, a computing device 12, …, and a computing device 13. For example, the computing device 11 includes a hardware layer and a software layer. The hardware layer includes a memory 116, a processor 117, a network card 118, and a hard disk 119. The software layer includes cloud resources 111, 112, 113, 114, …, and an operating system 115 of the computing device 11. The operating system 115 includes a cloud resource manager 1151 and a cloud management platform client 1152. The cloud resource manager 1151 is configured to manage a plurality of cloud resources and communicate with the cloud management platform 20 through the cloud management platform client 1152. It should be noted that in the embodiment of the present application, the number of computing devices in the infrastructure can be one or more, and the number of cloud resources in the computing device can be one or more, which are not limited in the embodiment of the present application.

[0082] For example, the infrastructure 1 includes at least one cloud data center, for example Figure 7 The cloud data center 100 and the cloud data center 200 in the cloud data center 100 and the cloud data center 200 are each provided with a plurality of computing devices, for example, the cloud data center 100 is provided with the computing device 11 and the computing device 12, and the cloud data center 200 is provided with the computing device 13… One or any combination of a plurality of cloud resources is deployed in at least one computing device of the infrastructure 1, for example, the cloud resource 111, the cloud resource 112, the cloud resource 113 and the cloud resource 114 are deployed in the computing device 11, and the cloud resource 121, the cloud resource 122, the cloud resource 123 and the cloud resource 124 are deployed in the computing device 12. A plurality of cloud resources of the same tenant can be arranged in an organization.

[0083] The computing device 11, the computing device 12 and the computing device 13 can be servers, which can be independent physical servers, or server clusters or distributed systems composed of a plurality of physical servers, and the servers provide various cloud services, such as cloud databases, cloud computing, cloud storage and other basic cloud computing services.

[0084] The servers involved in the present scheme can be hardware servers or can be implanted in a virtualization environment, for example, the servers involved in the present scheme can be virtual machines executed on a hardware server including one or more other virtual machines.

[0085] Figure 8 A flowchart of a cloud resource access control method based on cloud computing technology provided by an embodiment of the present application. The cloud resource access control method based on cloud computing technology can be applied to Figure 7 The cloud management platform 20 shown in the figure to realize access control of the cloud resources in the organization. As Figure 8 The cloud resource access control method based on cloud computing technology includes at least steps S801 to S803.

[0086] In step S801, the cloud management platform obtains and records the first resource control policy configured by the administrator of the target organization for the target cloud resource in the target organization, wherein the first resource control policy is used to indicate the access permission of the target cloud resource by the user outside the target organization.

[0087] The target organization can be any organizational structure that needs resource access control, such as enterprises, government departments and schools, etc. The personnel in the target organization include leaders, employees and various personnel such as visitors in the target organization.

[0088] The target cloud resource can be any resource in the target organization. Before receiving the access request for the resource in the target organization, the resources in the target organization can be divided, and specifically, the resources in the target organization can be divided into atomic resource units that cannot be further divided. In this case, the target resource can be a resource unit or a set of resource units in the target organization.

[0089] In the organization management service, the resources corresponding to the organization are often managed in a hierarchical manner. For example, an enterprise generally has a tree-shaped organization structure from top to bottom, and the hierarchical management capability is to organize the SoD units in a tree-shaped structure, facilitating management by the operation personnel of each department of the enterprise.

[0090] Optionally, the organization structure of the target organization can be established based on the department setting information of the target organization, and then the organization structure information of the target organization can be determined based on the personnel in the target organization, the department information to which the personnel belong, and the established organization structure. The organization structure can include a plurality of organization nodes, and one organization node represents one department. One department can include at least one personnel.

[0091] In one example, after the target organization is constructed, a registration step is further included before step S801. For example, the cloud management platform obtains a plurality of registration requests carrying different user accounts; the cloud management platform registers and records the plurality of user accounts according to the plurality of registration requests, wherein the plurality of user accounts include an account of an administrator; the cloud management platform divides the plurality of user accounts into the target organization, and sets the account of the administrator as an administrator account of the target organization.

[0092] The cloud resources in the target organization are divided and managed according to the organization structure information of the target organization. For example, the financial resources (such as financial statements, etc.) of an enterprise are divided into the nodes corresponding to the financial department, the sales resources (such as sales statements, etc.) of the enterprise are divided into the nodes corresponding to the sales department, and the production resources (such as production statements, etc.) of the enterprise are divided into the nodes corresponding to the production department.

[0093] The administrator of the target organization can create one or more RCPs and bind them to the entire organization (i.e., bind to the root node of the organization). The resources inside all accounts in the organization will be controlled by the RCP.

[0094] The RCP bound to the entire target organization is the RCP corresponding to the target cloud resource. For example, if only one RCP1 is bound to the root node of the target organization, then the RCP corresponding to the target cloud resource is RCP1. If RCP1, RCP2, and RCP3 are bound to the root node of the target organization, then the RCP corresponding to the target cloud resource is RCP1, RCP2, and RCP3.

[0095] There are various methods to determine the RCP corresponding to the target cloud resource information. For example, an index table is established with resource identifiers as indexes of RCPs, and the target cloud resource corresponding RCP is quickly found through the index table according to the resource identifier. The plurality of index items in the index table are determined based on a plurality of resource identifiers corresponding to a plurality of cloud resources in the target organization.

[0096] Alternatively, a mapping table recording the mapping relationship between the organization and the RCP is established, the target cloud resource information is used to determine the organization member to which the target cloud resource belongs, and then the target organization to which the organization member belongs is found; according to the target organization, the mapping table is queried to obtain the RCP associated with the target organization, and the RCP obtained through the above finding is the RCP corresponding to the target cloud resource.

[0097] It should be pointed out that the RCP is also a MAC policy, which does not provide permission by itself, but only serves as a constraint.

[0098] The cloud management platform obtains and records the first RCP in the RCP bound to the target organization, and the first RCP is the first RCP corresponding to the target cloud resource, which is used to indicate the access permission of the user outside the target organization to the target cloud resource.

[0099] For example, the first RCP at least includes a first constraint condition, and the first constraint condition is used to restrict that the access user belongs to the target organization, and when the resource access request is triggered by the user outside the target organization, that is, the access user does not satisfy the first constraint condition, the first resource access request is rejected to access the target resource.

[0100] In step S802, the cloud management platform obtains a first resource access request triggered by a user outside the target organization to a target cloud resource in the target organization.

[0101] The user triggers the first resource access request to the target cloud resource in the target organization through the client (for example, the client 40 in Figure 7 The first resource access request is sent to the cloud management platform 20 through the network (for example, the Internet 30 in Figure 7 Thus, the cloud management platform 20 obtains the first resource access request triggered by the user to the target cloud resource in the target organization.

[0102] The target cloud resource information is carried in the first resource access request, and the cloud management platform can locate the specific cloud resource according to the target cloud resource information, for example, the target cloud resource in the target organization.

[0103] The target cloud resource information includes resource identification information, which can include any information that can identify a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the area in which the resource is located. The resource identifier can identify a specific cloud resource, the information about the product to which the cloud resource belongs can include information indicating that the cloud resource belongs to the service of that cloud product, and the information about the area in which the cloud resource is located can include the name or address of the area in which the cloud resource is located, etc.

[0104] It can be understood that the target cloud resource can be any type of cloud resource, such as a virtual machine and a container of a computing service, a bucket of an object storage service, a cloud hard disk, and a cloud database, etc.

[0105] There are two cases for the user being a user outside the target organization, that is, the user does not belong to the target organization. One case is that the user has registered a cloud account on the cloud, but the account does not belong to the target organization. For example, the first resource access request carries a user account registered by a user outside the target organization on the cloud management platform. After receiving the first resource access request, the cloud management platform obtains the user account carried by the first resource access request by parsing. In the case that the user account does not belong to the multiple user accounts corresponding to the target organization, it is determined that the first resource access request is triggered by a user outside the target organization.

[0106] That is, the access request comes from other users on the cloud, and the user has registered on the cloud but is not in the target organization. The cloud management platform determines that the access request issued by such a user is triggered by a user outside the target organization.

[0107] It should be explained that the user account can be, for example, any one or a combination of a user name, a real name, a mobile phone number, an ID number, an employee number, etc., as long as it can uniquely identify the user. The embodiments of the present application do not make any limitation thereto.

[0108] It can be understood that for different public cloud vendors, the user account can also have other designations, such as a user subscription and a user project, etc.

[0109] The other case is that the user does not register an account on the cloud management platform, and the first resource access request does not carry a user account registered on the cloud management platform. In the case that the cloud management platform determines that the first resource access request does not carry a user account registered on the cloud management platform by parsing, it is determined that the first resource access request is triggered by a user outside the target organization.

[0110] In other words, the access request comes from other users under the cloud, and is not registered on the cloud (i.e., does not have an account). The cloud management platform determines that the access request issued by such a user is triggered by a user outside the target organization.

[0111] For example, the target cloud resource corresponding to the access request is a virtual machine, and a webpage is provided on the cloud for public network use, and a terminal (such as a mobile phone or a personal computer) under the cloud can access the public network IP (target public network IP) of the webpage through its own source public network IP.

[0112] In step S803, the cloud management platform allows or rejects the first resource access request to access the target cloud resource according to the first resource control policy recorded by itself.

[0113] Through steps S801 and S802, the first RCP for the target cloud resource in the target organization and the first resource access request for the target cloud resource in the target organization are obtained, and then the first resource access request is authenticated according to the first RCP, and if the authentication is passed, the first resource access request is allowed to access the target cloud resource, and if the authentication is not passed, the first resource control policy is rejected to access the target cloud resource.

[0114] Specifically, the first resource access request is calculated according to the first RCP to obtain a policy calculation result, and the policy calculation result indicates whether the resource access request is authenticated.

[0115] For example, the first RCP includes a first constraint condition, the first constraint condition is used to constrain that the access user belongs to the target organization, when the resource access request is triggered by a user outside the target organization, the policy calculation result is not satisfied, that is, the access user does not satisfy the first constraint condition, the authentication is not passed, and the first resource access request is rejected to access the target resource.

[0116] The policy calculation process is a process of judging whether the access request information satisfies the constraint condition of the RCP, for example, the RCP includes a constraint condition for constraining that the access user belongs to the target organization, and the access user must belong to the target organization to satisfy the constraint condition, that is, only when the access user belongs to the target organization, the access request can be authenticated and passed, and can be allowed to access the cloud resource in the target organization. In this way, the access of the identity outside the organization to the cloud resource in the organization is rejected, and the situation that the account in the organization shares the cloud resource for the members outside the organization to access and use is eliminated.

[0117] As can be seen from the above, the cloud resource access control method based on cloud computing technology provided by the application directly acts on the resources in the organization and directly constrains the access to the resources in the organization, so as to realize the access of the users outside the organization to the cloud resources in the organization, for example, to overcome the situation that the resources are often shared across accounts in the multi-account environment of the organization, and the resources in the organization cannot be illegally accessed by the users outside the organization.

[0118] Figure 9It is shown that the cloud resource access control method based on cloud computing technology provided by the embodiment of the application sets RCP on the target organization, realizes the control of the target cloud resource (for example Figure 9 in Org-1 in the target organization (for example Figure 9 in the cloud resource S3 and EC2 in Acct-3) by the user in the target organization.

[0119] Figure 10 It is shown that another cloud resource access control method based on cloud computing technology provided by the embodiment of the application, which can be applied to the cloud management platform 20 shown in Figure 7 to realize the control of the target cloud resource in the target organization by the user in the target organization. As shown in Figure 10 , the method at least includes steps S1001 to S1003.

[0120] In step S1001, the cloud management platform acquires and records the second resource control policy configured by the administrator of the target organization for the target cloud resource in the target organization, wherein the second resource control policy is used to indicate the access permission of the user in the target organization to the target cloud resource.

[0121] The construction of the target organization and the registration management of the user account are similar to the method shown in Figure 8 , which can be referred to the description above, and will not be described here for brevity.

[0122] The administrator of the target organization can create one or more RCPs and bind them to the target organization node, and all the resources inside the account in the target organization node will be controlled by the RCP.

[0123] The RCP bound to the target organization node is the RCP corresponding to the target cloud resource in the target organization node. For example, if there is only one RCP1 bound to the target organization node, the RCP corresponding to the target cloud resource is RCP1; if there are RCP1, RCP2 and RCP3 bound to the target organization node, the RCP corresponding to the target cloud resource is RCP1, RCP2 and RCP3.

[0124] There are various methods to determine the RCP corresponding to the target cloud resource information. For example, an index table is established by taking the resource identifier as the index of the RCP, and the RCP corresponding to the target cloud resource is quickly found by the resource identifier in the index table. The plurality of index items in the index table are determined based on a plurality of resource identifiers, and the plurality of resource identifiers are a plurality of resource identifiers corresponding to a plurality of cloud resources in the target organization node.

[0125] Alternatively, a mapping table can be established that records the mapping relationship between organizational nodes and RCPs. Based on the target cloud resource information, the organizational members to which the target cloud resource belongs can be determined, and then the target organizational node to which the organizational member belongs can be found. Based on the target organizational node, the mapping table can be queried to obtain the RCPs associated with the target organizational node. These found RCPs are the RCPs corresponding to the target cloud resource.

[0126] The cloud management platform obtains and records the second RCP in the RCP bound on the target organization's node. This second RCP is the second RCP corresponding to the target cloud resource. This second RCP is used to indicate the access rights of users within the target organization to the target cloud resource.

[0127] In step S1002, the cloud management platform obtains a second resource access request for a target cloud resource within the target organization, triggered by a user within the target organization.

[0128] Users within the target organization trigger a second resource access request for target cloud resources within the target organization via a client. This second resource access request is transmitted over a network (e.g., Figure 7 The Internet 30 in the middle sends the request to the cloud management platform 20, so that the cloud management platform 20 obtains the second resource access request triggered by the user for the target cloud resources within the target organization.

[0129] The first resource access request carries the target cloud resource information. The cloud management platform can locate the specific cloud resource based on the target cloud resource information, such as the target cloud resource within the target organization.

[0130] The target cloud resource information includes resource identification information, which can include any information that can identify a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the region where the resource is located. The resource identifier can identify a specific cloud resource, the information about the product to which the cloud resource belongs can include information indicating which cloud product the cloud resource belongs to, and the information about the region where the cloud resource is located can include the name or address of the region where the cloud resource is located.

[0131] After receiving the second resource access request, the cloud management platform parses the request to obtain the user account carried in the second resource access request. If the user account belongs to multiple user accounts corresponding to the target organization, it determines that the second resource access request was triggered by a user within the target organization.

[0132] In step S1003, the cloud management platform allows or denies the second resource access request to access the target cloud resource according to its own recorded second resource control policy.

[0133] The second RCP for the target cloud resource in the target organization and the second resource access request for the target cloud resource in the target organization are obtained through steps S1001 and S1002, and then the second resource access request is authenticated according to the second RCP, and if the authentication is passed, the second resource access request is allowed to access the target cloud resource, and if the authentication is not passed, the second resource control policy is denied to access the target cloud resource.

[0134] Specifically, the second resource access request is calculated according to the second RCP to obtain a policy calculation result, and the policy calculation result indicates whether the resource access request is authenticated.

[0135] For example, the second RCP includes a second constraint condition for restricting the access user to belong to the target organization node, and when the resource access request is triggered by a user outside the target organization node in the target organization, the policy calculation result is not satisfied, that is, the access user does not satisfy the second constraint condition, the authentication is not passed, and the second resource access request is denied to access the target resource.

[0136] When the administrator does not want the members of other departments to access the resources of a specific department, for example, to control the non-finance department colleagues to access the resources in the finance department, the administrator can set the second RCP, which includes a constraint condition of restricting the access user to belong to the target organization node (that is, the organization node corresponding to the finance department), and then the access user must belong to the target organization node to satisfy the constraint condition, that is, only when the access user belongs to the target organization node, the access request can be authenticated and allowed to access the resources in the target organization node. In this way, the identity outside the organization node is denied to access the resources in the organization, and the situation that the account in the organization node shares the resources to the members outside the organization node in the multi-account scenario is avoided. In other words, it avoids the members of non-specific departments to access the cloud resources under the specific department node.

[0137] The RCP is a MAC model, which is a constraint condition set described by DSL, and can accurately describe the allowed or denied access resource set, operation set and allowed condition or denied condition. An organization or organization node can bind one or more RCPs. The RCP includes a cloud resource identification field (Resource), an effect field (Effect), a request type field (Action) and a condition field (Condition), wherein the cloud resource identification field is used to identify the target cloud resource, the effect field is used to identify the denied or allowed access target cloud resource, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate the user outside the target organization.

[0138] Referring to Figure 9, multiple fields can include Version, Statement, Effect, Action, Resource, Condition, etc., each field corresponds to a policy element in RCP, the following describes each field in RCP.

[0139] Version, optional policy element (string), such as "Version":"2012-10-17", used to indicate the version of the RCP document. The RCP document version of the cloud service provider can only have one value, 2012-10-17, if there is no Version element in RCP, the default value is 2012-10-17.

[0140] Statement: mandatory element (array), such as "Statement": [{…}, {…}, {…}], the main element of the policy, used to indicate the specific constraint rule, each Statement element can contain multiple statements, each statement is enclosed in {}.

[0141] Effect: mandatory element (string), such as "Effect":"Deny", a constituent element of the constraint rule of Statement, each constraint rule must include this element, and there are only two values: Allow or Deny, representing "show authorization" and "show rejection" respectively.

[0142] Action: mandatory element (String), such as "Action":"s3:GetObject", a constituent element of the constraint rule of Statement, each constraint rule must include this element, the value includes two parts: service-name and action-name, where service-name is the namespace of cloud service (for example Figure 9 s3 in "s3:GetObject"), and action-name is the operation name of each product (for example Figure 9 GetObject in "s3:GetObject"), the values of service-name and action-name are case-insensitive, and the operation name can contain wildcard *.

[0143] Resource: mandatory element (String), which can use * to represent all resource objects, and can also use specific limited resource range and resource ownership project. For example, Figure 9 "arn:aws:s3…secret_bucket / *" in "arn:aws:s3…secret_bucket / *".

[0144] Conditon; optional element (String), limit condition, refers to the limit condition of the constraint condition.

[0145] It should be noted that when there are both Allow and Deny constraint statements in the SCP, the principle of Deny priority is followed.

[0146] When performing policy calculation on the resource access request and its corresponding RCP, if the effectiveness of the corresponding policy of the resource access request is Allow, the calculation result is true (i.e. access is allowed), and the authentication passes, and if the policy contains the effectiveness Deny, the calculation result is false (i.e. access is denied), and the authentication does not pass.

[0147] Taking the RCP shown in FIG. 8 as an example, the policy calculation of the RCP on the resource access request is introduced. The main elements of the Statement policy in the RCP are: "Effect": "Deny"; "Action": "s3:GetObject"; "Conditon": { "StringNotEquals": { "aws:PrincepalOrgID": "org-1"}}. That is, all buckets in the org-1 organization (i.e. the target organization) are prohibited from being accessed by identities in non-org-1 organizations (i.e. non-target organizations). That is, only when the access user belongs to the target organization, the access request will pass the authentication and be allowed to access the bucket resources in the target organization. Figure 9 The RCP can be set according to actual needs. For example, the RCP includes a constraint condition that the source public IP of the resource access request belongs to a preset IP network segment, the cloud management platform parses the resource access request information to obtain the context information of the resource access request, and the context information includes IP network segment information, i.e. the source public IP of the resource access request. The RCP corresponding to the target cloud resource includes a constraint condition that the source public IP of the resource access request belongs to a preset IP network segment; only if the source public IP of the resource access request must belong to the preset IP network segment can the constraint condition be met, that is, only when the source public IP of the resource access request belongs to the preset IP network segment, the resource access request can pass the authentication and be allowed to access the resources in the target organization. In this way, only the access request initiated from a specific network segment can access the resources in the target organization.

[0148] For example, an administrator creates an RCP bound to the root node of the target organization, and the RCP includes a constraint condition that the source public IP of the resource access request belongs to the public network segment where the target organization is located, thereby limiting that only the resource access request initiated from the public network segment where the target organization is located can be allowed to access the cloud resources in the organization.

[0149]

[0150] ​In another example, in order to manage resources in the organization more specifically, the administrator can also create an RCP bound to the target organization or a target node of the target organization, the RCP including a constraint that the operation on the target resource belongs to a preset operation; the resource access request information carries operation information, the operation information indicating the operation performed on the target resource; it is limited that only the resource access request whose operation belongs to the preset operation can pass the authentication and be allowed to operate the resource in the target organization.

[0151] For example, the administrator creates an RCP bound to the target organization node, the RCP including a constraint condition that the operation belongs to a read operation, it is limited that only the resource access request of the read operation can be allowed to access the resource in the organization, that is, only the read operation on the resource in the target organization node is allowed.

[0152] It can be understood that when there are multiple RCPs corresponding to the target resource, the authentication passes only when the resource access request satisfies all the RCPs corresponding to the target resource. For example, the resource access request information includes target resource information, access user information, operation information on the target resource, and IP network segment information; the RCPs corresponding to the target resource include RCP1, RCP2 and RCP3, wherein the constraint condition included in RCP1 is that the access user belongs to the target organization node, the constraint condition included in RCP2 is that the operation is a read operation, and the constraint condition included in RCP3 is that the IP network segment is a public network segment where the target organization is located; the policy calculation is performed on the resource access request and RCP1, RCP2 and RCP3 respectively, and the authentication passes only when all the policy calculation results pass. That is, the target resource passes RCP1, RCP2 and RCP3, it is limited that only the read operation request on the target resource initiated by the member in the target organization node from the public network segment where the target organization is located can pass the authentication, that is, the resource in the target organization node is allowed to be read only by the member in the target organization node from the public network segment where the target organization is located.

[0153] The following describes the specific implementation of the cloud resource access control method based on the cloud computing technology provided by the embodiments of the present application through a specific example.

[0154] As Figure 11As shown, the cloud management platform includes three parts of system, i.e. organization management system, authentication system and service system, wherein the organization management system faces customers (e.g. organization administrator) and provides an interface for creating RCP and binding RCP; the service system provides specific API, collects resource information (e.g. resource identifier) contained in user request (e.g. resource access request) and delivers it to the authentication system; the authentication system queries the organization where the account to which the resource belongs to from the organization management system according to the received resource identifier, and acquires all RCPs which have effect on the account. The authentication system performs policy calculation according to the RCP corresponding to the target account and the user request, judges whether the user request is allowed to be accessed, and returns the result to the service system.

[0155] Figure 11 The implementation process of the cloud resource access control method based on cloud computing technology provided by the embodiment of the application in a specific application scenario is shown. As shown in Figure 11 As shown, the organization administrator first creates RCP through step S1, and then binds the RCP to a certain organization node through step S2, so as to realize access control on resources in the organization or organization node.

[0156] When a normal user needs to access resources in the organization, the user sends a request of calling API to the service system through step S3, the request of calling API carries a resource identifier, and then the service system sends an authentication request to the authentication system through step S4, the authentication request carries the resource identifier, and the resource identifier is used to uniquely identify the target resource. Optionally, the composition of the resource identifier includes account information where the resource is located.

[0157] In step S5, the authentication system sends a request of querying RCP corresponding to the target resource to the organization management system, and the organization management system queries the organization where the account is located and the RCP acting on it according to the account information carried by the resource identifier.

[0158] In step S6, the organization management system returns the RCP set corresponding to the target resource queried to the authentication system.

[0159] In step S7, the authentication system performs policy calculation according to the RCP and request context (i.e. target resource information, access user information, operation information and IP network segment information carried by the resource access request), and the policy calculation result is used to indicate whether the authentication passes.

[0160] In step S8, the authentication system returns the authentication result to the service system. In step S9, the service system responds to the user's request, and feeds back the access result to the user if the authentication passes, or returns the result of rejecting the request to the user if the authentication does not pass.

[0161] It is understood that the organization management system, authentication system, and service system can be distributed across different servers or implemented as different modules within a server; this application does not limit this. In a public cloud scenario, the organization management system is the corresponding cloud service, with different names used by different public cloud vendors, such as resource catalog service or organization service. The authentication system corresponds to the access control service on the cloud. The service system corresponds to various cloud services, such as S3, EC2, and OBS.

[0162] To implement the cloud resource access control method based on cloud computing technology provided in this application embodiment, this application embodiment also provides a cloud management platform. The cloud management platform is used to manage the infrastructure that provides multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center is equipped with multiple servers, one or any combination of multiple cloud resources is deployed in at least one server of the infrastructure, and the multiple cloud resources are set up in at least one organization.

[0163] Figure 12 This is a schematic diagram of the structure of a cloud management platform provided in an embodiment of this application. Figure 12 As shown, the cloud management platform 20 includes an organization management module 2001, a service module 2002, and an authentication module 2003. The organization management module 2001 is used to acquire and record a first resource control policy configured by the administrator of the target organization for target cloud resources within the target organization. This first resource control policy instructs users outside the target organization on their access rights to the target cloud resources. The service module 2002 is used to acquire first resource access requests triggered by users outside the target organization for target cloud resources within the target organization. The authentication module 2003 is used to determine a first authentication result based on the first resource control policy recorded by the organization management module. This first authentication result either allows or denies the first resource access request to access the target cloud resources. The service module is also used to acquire the first authentication result from the authentication module and allow or deny the first resource access request to access the target cloud resources based on the first authentication result.

[0164] In a possible implementation, the organization management module 2001 is further configured to acquire and record a second resource control policy configured by an administrator of the target organization for a target cloud resource in the target organization, where the second resource control policy is used to indicate access rights of a user in the target organization to the target cloud resource; the service module 2002 is further configured to acquire a second resource access request triggered by the user in the target organization for the target cloud resource in the target organization; the authentication module 2003 is configured to determine a second authentication result according to the second resource control policy recorded by the organization management module, where the second authentication result is to allow or reject the second resource access request to access the target cloud resource; and the service module is further configured to acquire the second authentication result from the authentication module, and allow or reject the second resource access request to access the target cloud resource according to the second authentication result.

[0165] In another possible implementation, the cloud management platform further includes a registration module 2004 configured to acquire a plurality of registration requests carrying different user accounts, and register and record the plurality of user accounts according to the plurality of registration requests, where the plurality of user accounts include an account of an administrator; and the organization management module 2001 is configured to divide the plurality of user accounts into the target organization, and set the account of the administrator as an administrator account of the target organization.

[0166] In another possible implementation, the first resource access request carries a user account of a user outside the target organization registered in the cloud management platform; and the service module is configured to determine that the first resource access request is triggered by the user outside the target organization in a case where the service module determines that the user account carried by the first resource access request does not belong to the plurality of user accounts corresponding to the target organization recorded by the registration module.

[0167] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform; and the service module is configured to determine that the first resource access request is triggered by the user outside the target organization in a case where the service module determines that the first resource access request does not carry the user account registered in the cloud management platform.

[0168] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, where the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify rejection or permission of access to the target cloud resource, the request type field is used to identify a request type of the first resource access request, and the condition field is used to indicate the user outside the target organization.

[0169] In another possible implementation, the type of the cloud resource includes a virtual machine and a container of a computing service, a bucket of an object storage service, a cloud disk, and a cloud database.

[0170] It can be understood that the organization management module, the service module, the authentication module and the registration module in the cloud management platform can be distributed in different servers or implemented as different modules in the server, and the embodiments of the application do not limit this. In a public cloud scenario, the organization management module is the corresponding organization management service, different public cloud vendors correspond to different names, such as resource directory service, organization service, etc. The service module corresponds to various cloud services, such as computing service, storage service and network service, etc. The authentication module corresponds to the authentication service on the cloud, and the registration module corresponds to the registration service on the cloud.

[0171] The organization management module 2001, the service module 2002, the authentication module 2003 and the registration module 2004 can be implemented by software or by hardware. For example, the implementation of the organization management module 2001 is described below. Similarly, the implementation of the service module 2002, the authentication module 2003 and the registration module 2004 can refer to the implementation of the organization management module 2001.

[0172] As an example of a software functional unit, the organization management module 2001 can include code running on a computing instance. The computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance can be one or more. For example, the organization management module 2001 can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code can be distributed in the same region, or can be distributed in different regions. Further, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same availability zone (AZ), or can be distributed in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Generally, one region can include multiple AZs.

[0173] Similarly, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC), or can be distributed in multiple VPCs. Generally, one VPC is set in one region, and a communication gateway needs to be set in each VPC for cross-zone communication between two VPCs in the same region and between VPCs in different regions to realize interconnection between VPCs through the communication gateway.

[0174] As an example of a hardware functional unit, the organization management module 2001 can include at least one computing device, such as a server or the like. Alternatively, the organization management module 2001 can also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), and the like. The PLD can be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0175] The plurality of computing devices included in the organization management module 2001 can be distributed in the same region or in different regions. The plurality of computing devices included in the organization management module 2001 can be distributed in the same AZ or in different AZs. Similarly, the plurality of computing devices included in the acquisition module 1001 can be distributed in the same VPC or in multiple VPCs. The plurality of computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0176] It should be noted that in other embodiments, the organization management module 2001 can be used to perform any step of the cloud resource access control method based on cloud computing technology, the service module 2002 can be used to perform any step of the cloud resource access control method based on cloud computing technology, and the authentication module 2003 can be used to perform any step of the cloud resource access control method based on cloud computing technology. The steps implemented by the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004 can be specified as needed, and the entire function of the cloud control platform can be achieved by the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004 respectively implementing different steps of the cloud resource access control method based on cloud computing technology.

[0177] The present application also provides a computing device 1300. As shown in FIG. 13, the computing device 1300 includes a processor 1301, a memory 1302, and a bus 1303. Figure 13As shown, the computing device 1300 includes a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. The processor 1304, the memory 1306, and the communication interface 1308 communicate with each other through the bus 1302. The computing device 1300 can be a server or a terminal device. It should be understood that the number of processors and memories in the computing device 1300 is not limited.

[0178] The bus 1302 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 Although only one line is used in the figure, it does not mean that there is only one bus or only one type of bus. The bus 1302 can include a path for transmitting information between various components (e.g., the memory 1306, the processor 1304, the communication interface 1308) of the computing device 1300.

[0179] The processor 1304 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.

[0180] The memory 1306 can include a volatile memory (e.g., a random access memory (RAM)) and a non-volatile memory (e.g., a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD)).

[0181] The memory 1306 stores executable program codes, and the processor 1304 executes the executable program codes to respectively implement the functions of the aforementioned organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004, thereby implementing the cloud resource access control method based on cloud computing technology. That is, the memory 1306 stores instructions for executing the cloud resource access control method based on cloud computing technology.

[0182] The communication interface 1308 enables communication among the computing device 1300 and other devices or communication networks using, for example but not limited to, a transceiver module such as a network interface card, a Bluetooth® transceiver, a Bluetooth® Low Energy transceiver, a Near Field Communication transceiver, or the like.

[0183] The embodiments of the present disclosure also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a notebook computer, or a smart phone.

[0184] As shown in Figure 14 , the computing device cluster includes at least one computing device 1300. The memory 1306 in one or more computing devices 1300 in the computing device cluster can store the same instructions for performing the cloud resource access control method based on cloud computing technology.

[0185] In some possible implementations, the memory 1306 in one or more computing devices 1300 in the computing device cluster can also respectively store partial instructions for performing the cloud resource access control method based on cloud computing technology. In other words, the combination of one or more computing devices 1300 can collectively execute the instructions for performing the cloud resource access control method based on cloud computing technology.

[0186] It should be noted that the memory 1306 in different computing devices 1300 in the computing device cluster can store different instructions for respectively performing part of the functions of the cloud management platform. That is, the instructions stored in the memory 1306 in different computing devices 1300 can implement the functions of one or more of the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004.

[0187] In some possible implementations, one or more computing devices in the computing device cluster can be connected through a network. The network can be a wide area network or a local area network, etc. Figure 15 A possible implementation is shown. As shown in Figure 15 , two computing devices 1300A and 1300B are connected through a network. Specifically, the communication interface in each computing device is connected to the network. In this type of possible implementation, the memory 1306 in the computing device 1300A stores instructions for performing the functions of the organization management module 2001 and the service module 2002. Meanwhile, the memory 1306 in the computing device 1300B stores instructions for performing the functions of the authentication module 2003 and the registration module 2004.

[0188] It should be understood, Figure 15 The functions of the computing device 1300A shown in Figure 13B can also be completed by multiple computing devices 1300. Likewise, the functions of the computing device 1300B can also be completed by multiple computing devices 1300.

[0189] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or program product containing instructions, which can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, the at least one computing device is caused to execute the cloud resource access control method based on cloud computing technology.

[0190] The embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium can be any available medium or data storage device that the computing device can store or be a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk) and the like. The computer readable storage medium contains instructions, which instruct the computing device to execute the cloud resource access control method based on cloud computing technology.

[0191] In the above embodiments, the description of each embodiment has its own focus, and the parts not described or recorded in detail in a certain embodiment can be referred to the related description of other embodiments.

[0192] The basic principles of the present application are described above in combination with specific embodiments, but it should be pointed out that the advantages, advantages, effects and the like mentioned in the present application are only examples and not limitations, and these advantages, advantages, effects and the like cannot be considered as the necessary possession of each embodiment of the present disclosure. In addition, the specific details of the above disclosure are only for the purpose of example and for the purpose of understanding, and the above details do not limit the present disclosure to the above specific details.

[0193] The block diagrams of the devices, apparatuses, systems involved in the present disclosure are only illustrative examples and are not intended to require or imply the connection, arrangement, configuration shown in the block diagram. As those skilled in the art will recognize, these devices, apparatuses, systems can be connected, arranged, configured in any manner. Words such as "include", "contain", "have" and the like are open-ended words, which mean "including but not limited to", and can be used interchangeably. The words "or" and "and" used herein mean the word "and / or", and can be used interchangeably unless the context clearly indicates otherwise. The word "such as" used herein means the phrase "such as but not limited to", and can be used interchangeably.

[0194] It is also important to note that the construction and arrangement of the devices, equipment, and methods as shown in the various examples is illustrative only. Although only a few embodiments have been described in detail in this disclosure, many modifications are possible (e.g., variations in sizes, dimensions, structures, shapes and proportions of the various elements, values of parameters, mounting arrangements, use of materials, colors, orientations, etc.) without materially departing from the novel teachings and advantages of the disclosure. Some of the variations are disclosed or are clear to one of ordinary skill in the art in light of this disclosure. Accordingly, all such variations are intended to be included within the scope of the examples described in this disclosure. The examples described herein are not meant to be limiting. It will be readily understood that the components of the present disclosure, as generally described and illustrated in the Figures herein, could be arranged and designed in a wide variety of different configurations.

[0195] The foregoing description has been presented for the purposes of illustration and description. It is not intended to be exhaustive or to limit the embodiments of the disclosure to the precise form disclosed. Although the foregoing has been described in some detail for purposes of clarity, it will be apparent that certain changes and modifications can be made to the embodiments disclosed without departing from the scope of the embodiments of the disclosure.

[0196] It is to be understood that the various numbers involved in the embodiments of the present application are only for the convenience of description and do not limit the scope of the embodiments of the present application.

Claims

1. A cloud resource access control method based on cloud computing technology, characterized in that, The method is applied to a cloud management platform for managing infrastructure providing multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center having multiple servers. One or any combination of the multiple cloud resources is deployed in the at least one cloud data center, and the multiple cloud resources are located within at least one organization. The method includes: The cloud management platform acquires and records the first resource control policy bound to the target organization. The first resource control policy is created by the administrator of the target organization. The first resource control policy includes a first constraint condition for restricting accessing users to belong to the target organization. All resources within the target organization are controlled by the first resource control policy. The cloud management platform obtains a first resource access request triggered by a user outside the target organization for a target cloud resource within the target organization, wherein the target cloud resource is any resource within the target organization; The cloud management platform determines, based on its own recorded first resource control policy, that the first resource access request does not meet the first constraint condition, and therefore rejects the first resource access request from accessing the target cloud resource.

2. The method according to claim 1, characterized in that, The method further includes: The cloud management platform obtains a second resource access request for the target cloud resource within the target organization, triggered by a user within the target organization. The cloud management platform allows the second resource access request to access the target cloud resource according to the first resource control policy it records.

3. The method according to claim 1 or 2, characterized in that, Before the cloud management platform acquires and records the first resource control policy bound to the target organization, the method further includes: The cloud management platform receives multiple registration requests carrying different user accounts; The cloud management platform registers and records multiple user accounts based on the multiple registration requests, wherein the multiple user accounts include the administrator's account; The cloud management platform assigns the multiple user accounts to the target organization and sets the administrator's account as the administrator account of the target organization.

4. The method according to claim 3, characterized in that, The first resource access request carries a user account registered on the cloud management platform by a user outside the target organization. The cloud management platform obtains resource access requests for the target cloud resources within the target organization triggered by users outside the target organization, including: The cloud management platform determines that the first resource access request was triggered by a user outside the target organization because the user account carried in the first resource access request is not within the target organization.

5. The method according to claim 3, characterized in that, The first resource access request does not carry a user account registered in the cloud management platform. The cloud management platform obtains resource access requests for the target cloud resources within the target organization triggered by users outside the target organization, including: If the cloud management platform determines that the first resource access request does not carry a user account registered in the cloud management platform, it determines that the first resource access request was triggered by a user outside the target organization.

6. The method according to claim 1, characterized in that, The first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify whether to deny or allow access to the target cloud resource, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate users outside the target organization.

7. The method according to claim 1, characterized in that, The types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

8. The method according to claim 1, characterized in that, The method further includes: The cloud management platform acquires and records the second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, wherein the second resource control policy includes a second constraint condition for restricting the source public IP in the resource access request to a preset IP network segment; The cloud management platform obtains a third resource access request, wherein the source public IP of the third resource access request belongs to the preset IP network segment; The cloud management platform determines, based on the second resource control policy, that the third resource access request meets the second constraint condition, and allows the third resource access request to access the target cloud resource.

9. The method according to claim 1, characterized in that, The first resource access request includes target cloud resource information, which includes a resource identifier and product information to which the resource belongs. The product information to which the resource belongs is used to indicate the business information of the cloud product to which the target cloud resource belongs.

10. The method according to claim 1, characterized in that, The cloud management platform records service control policies created by the administrator of the target organization for target identities within the target organization. These service control policies are used to instruct the target identities within the target organization not to access the target cloud resources.

11. The method according to claim 1, characterized in that, The method further includes: The cloud management platform acquires and records the third resource control policy bound to the target organization node. The third resource control policy is created by the administrator of the target organization. The third resource control policy includes a third constraint condition for restricting accessing users to belong to the target organization node. All resources within the target organization node are controlled by the third resource control policy. The cloud management platform obtains a fourth resource access request for target cloud resources within the target organization's nodes, triggered by a user within the target organization but outside the target organization's nodes. The cloud management platform determines, based on its own recorded third resource control policy, that the fourth resource access request does not meet the third constraint condition, and therefore rejects the fourth resource access request from accessing the target cloud resource within the target organization node.

12. A cloud management platform, characterized in that, The cloud management platform is used to manage infrastructure providing multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center having multiple servers. One or any combination of the multiple cloud resources is deployed in the at least one cloud data center, and the multiple cloud resources are located within at least one organization. The cloud management platform includes: The organization management module is used to acquire and record the first resource control policy bound to the target organization. The first resource control policy is created by the administrator of the target organization. The first resource control policy includes a first constraint condition for restricting accessing users to belong to the target organization. All resources within the target organization are controlled by the first resource control policy. The service module is used to obtain a first resource access request triggered by a user outside the target organization for a target cloud resource within the target organization, wherein the target cloud resource is any resource within the target organization; The authentication module is used to determine a first authentication result based on the first resource control policy recorded by the organization management module, wherein the first authentication result is to deny the first resource access request to access the target cloud resource; The service module is further configured to obtain the first authentication result from the authentication module and reject the first resource access request to access the target cloud resource based on the first authentication result.

13. The cloud management platform according to claim 12, characterized in that, The service module is also used to obtain a second resource access request for the target cloud resource within the target organization triggered by a user within the target organization; The authentication module is used to determine a second authentication result based on the first resource control policy recorded by the organization management module, wherein the second authentication result is to allow the second resource access request to access the target cloud resource; The service module is further configured to obtain the second authentication result from the authentication module, and allow or deny the second resource access request to access the target cloud resource based on the second authentication result.

14. The cloud management platform according to claim 12 or 13, characterized in that, The cloud management platform also includes: The registration module is used to obtain multiple registration requests carrying different user accounts, register and record multiple user accounts according to the multiple registration requests, wherein the multiple user accounts include the administrator's account; The organization management module is used to assign the multiple user accounts to the target organization and set the administrator's account as the administrator account of the target organization.

15. The cloud management platform according to claim 14, characterized in that, The first resource access request carries a user account registered on the cloud management platform by a user outside the target organization. The service module is configured to determine that the first resource access request was triggered by a user outside the target organization, based on the fact that the user account carried in the first resource access request is not within the target organization.

16. The cloud management platform according to claim 14, characterized in that, The first resource access request did not carry the user account registered in the cloud management platform. The service module is used to determine that the first resource access request was triggered by a user outside the target organization if the first resource access request does not carry a user account registered in the cloud management platform.

17. The cloud management platform according to claim 12, characterized in that, The first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify whether to deny or allow access to the target cloud resource, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate users outside the target organization.

18. The cloud management platform according to claim 12, characterized in that, The types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

19. The cloud management platform according to claim 12, characterized in that, The organization management module is also used to acquire and record the second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, wherein the second resource control policy includes a constraint condition for restricting the source public IP in the resource access request to be a preset IP network segment; The service module is also used to obtain a third resource access request, wherein the source public IP of the third resource access request belongs to the preset IP network segment; The authentication module is further configured to determine a third authentication result based on the second resource control policy recorded by the organization management module, wherein the third authentication result is to allow the third resource access request to access the target cloud resource; The service module is further configured to obtain the third authentication result from the authentication module, and allow the third resource access request to access the target cloud resource based on the third authentication result.

20. The cloud management platform according to claim 12, characterized in that, The first resource access request includes target cloud resource information, which includes a resource identifier and product information to which the resource belongs. The product information to which the resource belongs is used to indicate the business information of the cloud product to which the target cloud resource belongs.

21. The cloud management platform according to claim 12, characterized in that, The cloud management platform records service control policies created by the administrator of the target organization for target identities within the target organization. These service control policies are used to instruct the target identities within the target organization not to access the target cloud resources.

22. The cloud management platform according to claim 12, characterized in that, The organization management module is used to acquire and record the third resource control policy bound to the target organization node. The third resource control policy is created by the administrator of the target organization. The third resource control policy includes a third constraint condition for restricting accessing users to belong to the target organization node. All resources within the target organization node are controlled by the third resource control policy. The service module is used to obtain a fourth resource access request for target cloud resources within the target organization node triggered by a user within the target organization but outside the target organization node. The authentication module is used to determine a fourth authentication result based on the third resource control policy recorded by the organization management module, wherein the fourth authentication result is to reject the fourth resource access request from accessing the target cloud resource within the target organization node. The service module is further configured to obtain the fourth authentication result from the authentication module, and reject the fourth resource access request to access the target cloud resource within the target organization node based on the fourth authentication result.

23. A computing device cluster, characterized in that, The computing device cluster includes at least one computing device, each computing device including a processor and memory: The memory is used to store instructions; The processor is configured to, according to the instructions, cause the computing device cluster to perform the method of any one of claims 1 to 11.

24. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it causes the method as described in any one of claims 1 to 11 to be implemented.

25. A computer program product comprising instructions that, when run on a computing device, cause the computing device to perform the method as described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Extending organizational boundaries throughout a cloud architecture

    CN103916454A