Component ordering method, system, multi-cloud management platform, medium, and program product

By receiving order requests in the multi-cloud management platform, determining the order activation mode, and obtaining the component ID and status, the problem of cumbersome and error-prone interface adaptation in the multi-cloud management platform is solved, and a stable, efficient, and secure component ordering process is achieved.

CN118827122BActive Publication Date: 2025-11-28CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410205378.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-23
Publication Date
2025-11-28
Estimated Expiration
2044-02-23

AI Technical Summary

Technical Problem

Multi-cloud management platforms need to manage the ordering logic and interfaces of multiple different cloud platforms. Existing technologies, through interface adaptation and integration, are cumbersome and error-prone, affecting operational stability and message return time.

Method used

A component ordering method is provided, which receives an order request, determines the order activation mode, obtains the component ID and status, and sends a details query request in non-running state to complete the ordering process of the security component, avoiding interface adaptation and integration.

Benefits of technology

It has implemented a standardized security component ordering process, enabling rapid integration with cloud platforms from different vendors, improving the stability and ordering convenience of multi-cloud management platforms, and reducing message return time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827122B_ABST
    Figure CN118827122B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an assembly ordering method and system, a multi-cloud management platform, a computer storage medium and a computer program product. The method comprises: receiving a subscription request for a security assembly in a target cloud platform by a target tenant, the subscription request carrying order information; determining an order opening mode corresponding to the target cloud platform according to the order information, obtaining an assembly ID and an assembly state of the security assembly based on the order opening mode; in the case that the assembly state is a non-running state, sending a detail query request carrying the assembly ID to the target cloud platform, so that the target cloud platform returns a query response message; and completing the subscription processing of the security assembly based on the query response message.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud computing, and in particular to a component ordering method and system, a multi-cloud management platform, a computer storage medium and a computer program product. BACKGROUND

[0002] At present, as the number of cloud platform manufacturers increases, the cloud platforms that need to be connected by the multi-cloud management platform will be more and more. Since the ordering processes and interfaces of the cloud platforms provided by different manufacturers are likely to be different, the multi-cloud management platform needs to manage multiple sets of ordering logic and adapt to a large number of interfaces.

[0003] In the related art, the common practice of the multi-cloud management platform is not to modify the interface of the security resource pool management platform, but to use specific internal modules for interface adaptation and interface fusion. However, this method is tedious and prone to errors, which not only increases the message return time, but also affects the running stability of the multi-cloud management platform. SUMMARY

[0004] The present application provides a component ordering method and system, a multi-cloud management platform, a computer storage medium and a computer program product.

[0005] The technical solution of the present application is implemented as follows:

[0006] The present application provides a component ordering method applied to a multi-cloud management platform, which comprises the following steps:

[0007] receiving a subscription request for a security component in a target cloud platform by a target tenant, the subscription request carrying order information; the target tenant is a pre-created tenant, and the target cloud platform is any cloud platform in a plurality of cloud platforms managed by the multi-cloud management platform;

[0008] determining an order opening mode corresponding to the target cloud platform according to the order information, and obtaining a component identity (ID) and a component state of the security component based on the order opening mode;

[0009] in a case where the component state is a non-running state, sending a detail query request carrying the component ID to the target cloud platform, so as to make the target cloud platform return a query response message;

[0010] completing the subscription processing of the security component based on the query response message.

[0011] The present application provides a component ordering system, which comprises a multi-cloud management platform and a target cloud platform, the target cloud platform being any cloud platform in a plurality of cloud platforms managed by the multi-cloud management platform, and wherein:

[0012] The multi-cloud management platform is configured to receive a subscription request of a target tenant for a security component in a target cloud platform, the subscription request carrying order information; determine an order opening mode corresponding to the target cloud platform according to the order information, obtain a component ID and a component state of the security component based on the order opening mode; in the case that the component state is a non-running state, send a detail query request carrying the component ID to the target cloud platform; complete the subscription processing of the security component based on the query response message; and the target tenant is a pre-created tenant.

[0013] The target cloud platform is configured to return the query response message to the multi-cloud management platform after receiving the detail query request.

[0014] The application provides a multi-cloud management platform, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the component subscription method provided in one or more of the preceding technical solutions when executing the program.

[0015] The application provides a computer storage medium, which stores a computer program; the computer program can implement the component subscription method provided in one or more of the preceding technical solutions after being executed.

[0016] The application provides a computer program product, which comprises a computer program executable on a processor to implement the component subscription method provided in one or more of the preceding technical solutions.

[0017] The application provides a component subscription method, system, multi-cloud management platform, computer storage medium, and computer program product, the method is applied to a multi-cloud management platform, and the method comprises the following steps: receiving a subscription request of a target tenant for a security component in a target cloud platform, the subscription request carrying order information; the target tenant is a pre-created tenant, and the target cloud platform is any cloud platform in a plurality of cloud platforms managed by the multi-cloud management platform; determining an order opening mode corresponding to the target cloud platform according to the order information, obtaining a component ID and a component state of the security component based on the order opening mode; in the case that the component state is a non-running state, sending a detail query request carrying the component ID to the target cloud platform, so that the target cloud platform returns a query response message; and completing the subscription processing of the security component based on the query response message.

[0018] It can be seen that, in the embodiment of the present application, if the multi-cloud management platform receives the subscription request of the target tenant for the security component in the case that the target tenant is created, the order opening mode corresponding to the target cloud platform is first determined, then the component ID and the component state are obtained based on the order opening mode, and then the security component detail information is queried according to the component ID and the component state to complete the entire subscription process. That is, a standardized security component subscription process is provided, so that the multi-cloud management platform can quickly integrate different vendors' cloud platforms and provide more convenient security component subscription services. In addition, the multi-cloud management platform in the embodiment of the present application does not need to perform interface adaptation and interface fusion work, solves the problems of increasing message return time and low running stability of the multi-cloud management platform in related technologies, and better meets the application requirements. BRIEF DESCRIPTION OF DRAWINGS

[0019] Figure 1 A structural schematic diagram of an order management system provided by the embodiment of the present application is provided.

[0020] Figure 2 A flowchart of a component subscription method provided by the embodiment of the present application is provided.

[0021] Figure 3 A flowchart of another component subscription method provided by the embodiment of the present application is provided.

[0022] Figure 4 A flowchart of creating a target tenant provided by the embodiment of the present application is provided.

[0023] Figure 5 A flowchart of synchronizing tenant information provided by the embodiment of the present application is provided.

[0024] Figure 6 A structural schematic diagram of a component subscription system provided by the embodiment of the present application is provided.

[0025] Figure 7 A structural schematic diagram of a multi-cloud management platform provided by the embodiment of the present application is provided. DETAILED DESCRIPTION

[0026] The technical solutions in the present application will be described clearly and completely in the present application by combining with the drawings in the present application.

[0027] The present application will be further described in detail by combining with the drawings and embodiments. It should be understood that the embodiments provided herein are only used to explain the present application, and are not used to limit the present application. In addition, the embodiments provided below are used to implement part of the embodiments of the present application, and the technical solutions described in the present application can be implemented in any combined manner without conflict.

[0028] It should be noted that in the present application, the terms "comprising", "containing" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a method or system that comprises a list of elements does not only include those elements expressly listed, but can also include other elements not expressly listed, or inherent to the method or system. Without more limitations, the element defined by the phrase "comprising a" does not exclude the presence of other related elements (such as steps in a method or units in a system, for example, the unit can be a partial processor, a partial program or software, etc.) in the method or system comprising the element.

[0029] The term "and / or" herein is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, the term "at least one" herein means any one of a plurality or any combination of at least two of a plurality, for example, including at least one of A, B and C, which means including any one or more elements selected from the set consisting of A, B and C.

[0030] For example, the component ordering method provided by the embodiments of the present application includes a series of steps, but the component ordering method provided by the embodiments of the present application is not limited to the steps described, and similarly, the component ordering system provided by the embodiments of the present application includes a series of modules, but the component ordering system provided by the embodiments of the present application is not limited to including the modules explicitly described, and can also include modules required to be set when obtaining related messages or processing based on messages.

[0031] At present, there is no unified interface standard in the field of cloud computing. With the increasing number of cloud platform manufacturers, the number of cloud platform interfaces that need to be connected by the multi-cloud management platform will increase. Tenant management, order management and large screen function are the most basic functions of the multi-cloud management platform. After the tenant orders a security component on the multi-cloud management platform, the security event data generated during the use of the security component is reported to the multi-cloud management platform through logs, application programming interfaces (APIs) and the like. The multi-cloud management platform is responsible for analyzing and displaying security events; unified tenant management and order management can greatly reduce the workload of adaptation and connection.

[0032] In the related art, the common practice of the multi-cloud management platform is not to modify the interface of the security resource pool management platform, but to use specific internal modules for interface adaptation and interface fusion. However, this method is tedious and prone to errors, which not only increases the message return time, but also affects the running stability of the multi-cloud management platform.

[0033] To solve the above problems, the following embodiments are proposed.

[0034] The component ordering method provided by the embodiments of the present application can be applied to a multi-cloud management platform. The multi-cloud management platform is a product providing unified integration and management services for public clouds, private clouds and hybrid clouds, and can provide services across multiple cloud infrastructures for enterprises using the product.

[0035] Exemplarily, the multi-cloud management platform comprises an order management system. Figure 1 A structural diagram of the order management system provided by the embodiments of the present application is shown in Figure 1 The order management system mainly comprises three modules: an application module, a gateway module and a support module. The application module comprises functions such as tenant management, order management and component management. The gateway module comprises functions such as interface combination, application protocol conversion, routing and forwarding. The support module comprises functions such as service detection, database, connection management and order pushing.

[0036] The application module calls the gateway module through a unified Restful API interface. The gateway module interfaces with the managed multiple cloud platforms (corresponding to cloud platform 1 to cloud platform N in Figure 1 , where N is an integer greater than 1) through the same encapsulation interface. The support module mainly assists in completing the tenant creation and order opening process, and assists in completing the routing and forwarding functions of the gateway module.

[0037] Exemplarily, the application module is mainly for users. The users perform tenant management, order management and device management through a unified interactive interface. When ordering a security component, the user can select the type, deployment location, product specification and ordering duration of the security component. After the ordering of the security component is completed, the user can log in to the configuration page of the security component and remotely execute a power-on / off command. The gateway module serves as an application layer proxy and interfaces with the related interfaces of the cloud platform to send messages through interface combination and application protocol conversion. The support module assists in realizing unified ordering opening services and tenant creation of different heterogeneous cloud platforms.

[0038] The component ordering method provided by the embodiments of the present application will be exemplarily described below based on the order management system shown in Figure 1 . Figure 2 A flowchart of the component ordering method provided by the embodiments of the present application is shown in Figure 2 The flowchart can comprise the following steps:

[0039] Step 100: receiving a subscription request for a security component in a target cloud platform by a target tenant, the subscription request carrying order information.

[0040] In the embodiments of the present application, the target tenant is a tenant pre-created on the multi-cloud management platform; it should be noted that the tenant information of the multi-cloud management platform is the same as the tenant information of the target cloud platform, that is, the target tenant is also a tenant pre-created on the target cloud platform.

[0041] Exemplarily, the target cloud platform is any one of a plurality of cloud platforms managed by the multi-cloud management platform; it should be noted that the plurality of cloud platforms managed by the multi-cloud management platform can be heterogeneous cloud platforms provided by different manufacturers.

[0042] Here, the cloud scenario of the target cloud platform is not specifically limited, for example, the target cloud platform can be a cloud platform in a private cloud scenario, or a cloud platform in a public cloud scenario.

[0043] Exemplarily, the security resource pool of the target cloud platform can include a plurality of different types of security components, such as firewalls, vulnerability scans, log audits, and database audits, etc., wherein the security components are also referred to as security products or cloud security products.

[0044] In the embodiments of the present application, the security component corresponding to the subscription request refers to a security component that the target tenant wants to subscribe to, which can be any type of security component in the target cloud platform, for example, it can be a firewall, a vulnerability scan, a log audit, or a database audit, etc.

[0045] Exemplarily, after the multi-cloud management platform creates the target tenant, the target tenant can subscribe to the security component on the multi-cloud management platform, so that the multi-cloud management platform can receive the subscription request of the target tenant for the security component in the target cloud platform.

[0046] In the embodiments of the present application, the subscription request carries order information; the order information can include the number of subscriptions, the manufacturer type, the global order number, the tenant ID, the duration of opening, the network element type, the specification, and the scenario, etc., but here it is not limited in any way.

[0047] It should be noted that the multi-cloud management platform mainly realizes the subscription of the security component through an application module, a gateway module, and an order pushing module; the order pushing module is a module for realizing the order pushing function; in the following, the three modules will be exemplarily described. Exemplarily, when the target tenant triggers the subscription request for the security component on the interactive interface of the multi-cloud management platform, the application module can receive the subscription request carrying the order information.

[0048] Here, the triggering manner of the subscription request is not limited, for example, the multi-cloud management platform can provide a unified interactive interface for the target tenant, and the target tenant can input the order information on the interactive interface, and trigger the subscription request in any one or more ways such as clicking a control, voice, etc.

[0049] Step 101: determining an order opening mode corresponding to a target cloud platform according to order information, and obtaining a component ID and a component state of a security component based on the order opening mode.

[0050] Exemplarily, after receiving the subscription request carrying the order information, the application module sends the subscription request to the gateway module. After receiving the subscription request, the gateway module returns a response message of the subscription request to the application module, and determines the order opening mode corresponding to the target cloud platform according to the order information carried by the subscription request. In an embodiment, the gateway module can determine the order opening mode corresponding to the target cloud platform according to the scene in the order information. Here, the scene represents a cloud scene of the target cloud platform corresponding to the security component, and the cloud scene is pre-configured with a corresponding order opening mode.

[0051] In the embodiment of the application, the order opening mode can include a manual opening mode or an automatic opening mode. Exemplarily, a developer or an operation and maintenance personnel can pre-configure the order opening mode of different cloud scenes through a configuration interface. Here, the order opening mode configured for the cloud scene is the order opening mode corresponding to the cloud platform in the cloud scene, that is, the gateway module can determine the order opening mode corresponding to the target cloud platform according to the scene in the order information after receiving the order information, and determine the order opening mode as the order opening mode corresponding to the target cloud platform.

[0052] It can be understood that, considering that some cloud scenes do not have a unified cloud management platform, the multi-cloud management platform cannot realize automatic order through API, and therefore for this type of cloud scene, a manual opening mode needs to be configured, and at this time, the order opening mode corresponding to the cloud platform in this type of cloud scene is the manual opening mode. For cloud scenes that have a unified cloud management platform, the order opening mode can be configured as a manual opening mode or an automatic opening mode, and at this time, the order opening mode corresponding to the cloud platform in this type of cloud scene can be a manual opening mode or an automatic opening mode. For example, the order opening mode of a mobile cloud scene without a unified cloud management platform can be configured as a manual opening mode, and the order opening mode of a private cloud scene with a unified cloud management platform can be configured as a manual opening mode or an automatic opening mode.

[0053] As can be seen, in the embodiment of the application, the order opening mode corresponding to different cloud scenes can be flexibly configured, and thus the security component subscription in multiple cloud scenes such as public clouds and private clouds can be covered, and the application range of the component subscription method is improved.

[0054] Further, after determining the order opening mode corresponding to the target cloud platform, the gateway module can obtain the component ID and the component state of the security component based on the order opening mode. Here, the component ID is unique identification information of the security component, and the component state can include a running state or a non-running state.

[0055] In an embodiment, based on the order opening mode, obtaining the component ID and the component state of the security component can comprise: in a case where the order opening mode is a manual opening mode, receiving input Internet Protocol (IP) information of the security component; in response to an order opening operation on the security component, sending, to a target cloud platform, an order opening request carrying updated order information, so that the target cloud platform returns an order response message; the order response message comprises the component ID and the component state of the security component, and the updated order information comprises the IP information of the security component.

[0056] Exemplarily, referring to Figure 3 , if the gateway module determines that the order opening mode corresponding to the target cloud platform is the manual opening mode, the order information can be first synchronized to the database of the order pushing module, and then the IP information of the security component is input by the development or operation and maintenance personnel of the order pushing module, and the order opening operation on the security component is manually triggered; at this time, the order pushing module can receive the IP information of the security component and the order opening operation on the security component; in response to the order opening operation on the security component, the order pushing module sends an order opening request carrying updated order information to the target cloud platform, so that the target cloud platform returns an order response message; at this time, the order pushing module can obtain the component ID and the component state of the security component from the received order response message.

[0057] Further, after obtaining the component ID and the component state of the security component, the order pushing module can write the component ID and the component state of the security component into the subscription device table.

[0058] In another embodiment, based on the order opening mode, obtaining the component ID and the component state of the security component can comprise: in a case where the order opening mode is an automatic opening mode, sending, to a target cloud platform, an order opening request carrying order information, so that the target cloud platform returns an order response message.

[0059] Exemplarily, continuing to refer to Figure 3 , if the gateway module determines that the order opening mode corresponding to the target cloud platform is the automatic opening mode, the gateway module can directly send an order opening request carrying order information to the target cloud platform, so that the target cloud platform returns an order response message; at this time, the gateway module can obtain the component ID and the component state of the security component from the received order response message.

[0060] Further, after obtaining the component ID and the component state of the security component, the gateway module can write the component ID and the component state of the security component into the subscription device table.

[0061] It can be seen that, for different order opening modes, such as manual opening mode or automatic opening mode, the embodiments of the application respectively adopt a standardized manner to obtain related information required for component ordering, thereby facilitating unified ordering processing of security components in different cloud scenarios.

[0062] Step 102: In the case that the component state is a non-running state, a detail query request carrying the component ID is sent to the target cloud platform, so that the target cloud platform returns a query response message.

[0063] Exemplarily, according to the above content, it can be known that, after the order pushing module or the gateway module obtains the component ID and the component state of the security component, the component ID and the component state of the security component are written into the ordering device table; then, it is determined by the gateway module that the component state is a non-running state, and in the case that the component state is a non-running state, a detail query request carrying the component ID is sent to the target cloud platform.

[0064] In some embodiments, in the case that the component state is a non-running state, sending a detail query request carrying the component ID to the target cloud platform can include: performing a timed reading on the ordering device table, determining whether the component state is a non-running state according to the reading result; in the case that the component state is a non-running state, sending a detail query request carrying the component ID to the target cloud platform.

[0065] Exemplarily, the gateway module performs a timed reading on the ordering device table, and a corresponding reading result is obtained; the reading result can represent whether there is a security component with a non-running state in the ordering device table.

[0066] Here, the time length of the timed reading can be pre-set according to actual scenarios, and the embodiments of the application do not limit this, for example, the reading can be performed once per minute.

[0067] Exemplarily, after the gateway module obtains the reading result, it can determine whether the component state of the security component is a non-running state according to the reading result; in the case that the component state is a running state, it indicates that the security component is ready, at this time, the target tenant can start using the security component, that is, the ordering process of the security component is completed; in the case that the component state is a non-running state, it indicates that the security component is not ready, at this time, a detail query request carrying the component ID needs to be sent to the target cloud platform, so that the target cloud platform returns a query response message.

[0068] Exemplarily, the query response message can include a global order number, a tenant ID, a device ID, an access address, a device IP, a device port, etc., but here it is not limited in any way.

[0069] It can be seen that, in the embodiment of the application, the component ID and the component state of the security component are written into the subscription device table, so as to facilitate the gateway module to read the component state and improve the sending efficiency of the detail query request.

[0070] Step 103: completing the subscription processing of the security component based on the query response message.

[0071] In the embodiment of the application, after receiving the query response message returned by the target cloud platform, the gateway module can complete the subscription processing of the security component based on the query response message.

[0072] In some embodiments, completing the subscription processing of the security component based on the query response message can include: obtaining the current component state of the security component from the query response message; and completing the subscription processing of the security component based on the query response message in the case that the current component state is a running state.

[0073] For example, the query response message further includes the current component state of the security component, and the current component state includes a running state or a non-running state; the gateway module can obtain the current component state of the security component from the received query response message and determine whether the current component state is a running state.

[0074] For example, if the gateway module determines that the current component state is a running state, the gateway module sends a subscription callback message to the application module and stops sending the detail query request to the target cloud platform; after receiving the subscription callback message, the application module returns a response message to the gateway module, and the response message represents that the subscription callback message is successfully received; at this time, the subscription process of the security component is completed.

[0075] For example, the subscription callback message can include a global order number, a tenant ID, a device ID, an access address, IP information, a device port, etc., but no limitation is made herein.

[0076] For example, if it is determined that the current component state is a non-running state, the gateway module continues to send the detail query request to the target cloud platform until the gateway module determines that the current component state is a running state, and processes according to the above process; to avoid repeated description, details are not described herein.

[0077] In the embodiment of the application, before receiving the subscription request of the target tenant to the security component in the target cloud platform, the target tenant also needs to be created; the process is described below. Figure 4 The process is described below.

[0078] In some embodiments, the method can further include: receiving a creation request for a target tenant; sending tenant information to a plurality of cloud platforms managed by the multi-cloud management platform, so that the plurality of cloud platforms create the target tenant corresponding to the tenant information; and receiving a creation response message returned by each of the plurality of cloud platforms, and completing creation of the target tenant according to the creation response message.

[0079] For example, when a user of the multi-cloud management platform triggers a creation request for a target tenant on an interactive interface, the application module can receive the creation request; the creation request carries tenant information. Here, the triggering manner of the creation request is not limited, for example, the user of the multi-cloud management platform can input tenant information on the interactive interface, and trigger the creation request by clicking a control, voice, or any one or more manners.

[0080] For example, the tenant information can include a tenant ID, a tenant name, an account name, an email address, and a mobile phone number, but here is not limited in any way.

[0081] For example, referring to Figure 4 , after receiving the creation request carrying the tenant information, the application module sends the creation request to the gateway module, the gateway module returns a response message of the creation request to the application module after receiving the creation request, and sends the tenant information carried by the creation request to each cloud platform managed by the multi-cloud management platform, each cloud platform creates the target tenant corresponding to the tenant information after receiving the tenant information, that is, the same target tenant is created on all cloud platforms managed by the multi-cloud management platform; each cloud platform returns a creation response message to the gateway module, and the gateway module sends the creation response messages returned by all cloud platforms to the application module asynchronously after receiving them; the application module creates the target tenant after receiving the creation response messages, and returns a response message of completion of creation of the target tenant to the gateway module, at which time the creation process of the target tenant ends; here, the creation response message indicates that the target tenant is created successfully; that is, the application module creates the same tenant only when the tenant is successfully created on each cloud platform, that is, the tenant information of each cloud platform is consistent with the tenant information of the multi-cloud management platform.

[0082] It can be understood that, considering that the time when each cloud platform is managed is earlier or later, the tenant information may not be synchronized to some cloud platforms; to ensure the consistency of the tenant information of each cloud platform, each cloud platform should also synchronize all created tenant information from the multi-cloud management platform when it is first started; next, the process of synchronizing the tenant information of the target cloud platform is described by way of example. Figure 5

[0083] ​In some embodiments, before receiving the creation request for the target tenant, the above method can further include: detecting whether the target cloud platform is online for the first time; when the detection result is that the target cloud platform is online for the first time, obtaining the tenant messages of the created tenants, and synchronizing the tenant messages of the created tenants to the target cloud platform.

[0084] Exemplarily, the gateway module of the multi-cloud management platform is built-in with a detection function, and the gateway module can detect whether the target cloud platform is online for the first time by using the detection function to obtain a detection result; wherein, the implementation process of the detection function is as follows: if the Hyper Text Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) service of the target cloud platform is detected to exist, the time will be recorded as the first online time Tstart of the target cloud platform. The gateway module can check the record according to a set time length Timer, and if it is determined that the current time T-Tstart<=Timer, it means that the target cloud platform is online for the first time; otherwise, it means that the target cloud platform is not online for the first time.

[0085] Exemplarily, referring to Figure 5 When the detection result is that the target cloud platform is online for the first time, the gateway module will actively send a tenant synchronization request to the application module, and the application module will obtain the tenant messages of the created tenants on the multi-cloud management platform after receiving the tenant synchronization request. Here, the created tenants refer to all the tenants that have been created on the multi-cloud management platform; and the gateway module will feed back the tenant messages of these created tenants to the application module in the form of a return response message; after receiving the tenant messages of the created tenants, the gateway module will synchronize these tenant information to the target cloud platform; after receiving these tenant information, the target cloud platform will return a corresponding response message to the gateway module, at which time the tenant information synchronization process of the target cloud platform ends.

[0086] It should be noted that in the case of a large number of tenant messages that need to be synchronized, in order to improve the efficiency of message synchronization, a batch synchronization method can be used to synchronize these tenant information to the target cloud platform.

[0087] The embodiment of the application provides a component ordering method, which comprises the following steps: receiving an ordering request of a target tenant for a security component in a target cloud platform, wherein the ordering request carries order information; the target tenant is a pre-created tenant, and the target cloud platform is any cloud platform in a plurality of cloud platforms managed by a multi-cloud management platform; determining an order opening mode corresponding to the target cloud platform according to the order information, obtaining a component ID and a component state of the security component based on the order opening mode; in the case that the component state is a non-running state, sending a detail query request carrying the component ID to the target cloud platform, so that the target cloud platform returns a query response message; and completing the ordering process of the security component based on the query response message.

[0088] As can be seen, in the embodiment of the application, in the case that the target tenant is created, if the multi-cloud management platform receives an ordering request of the target tenant for the security component, the order opening mode corresponding to the target cloud platform is first determined, then the component ID and the component state are obtained based on the order opening mode, and then the security component detail information is queried according to the component ID and the component state to complete the entire ordering process. That is, a standardized security component ordering process is provided, so that the multi-cloud management platform can quickly integrate cloud platforms of different manufacturers to provide more convenient security component ordering services. In addition, the multi-cloud management platform does not need to perform interface adaptation and interface fusion work in the embodiment of the application, thereby solving the problems of the related art, such as the increase in the message return time length and the low running stability of the multi-cloud management platform, and better meeting the application requirements.

[0089] In order to better reflect the purpose of the application, further description is made on the basis of the above-mentioned embodiments of the application.

[0090] Figure 6 A structural schematic diagram of a component ordering system provided by the embodiment of the application is shown in FIG. 1. Figure 6 As shown in FIG. 1, the component ordering system comprises a multi-cloud management platform 20 and a target cloud platform 21, the target cloud platform 21 is any cloud platform in a plurality of cloud platforms managed by the multi-cloud management platform 20, and the multi-cloud management platform 20 is configured to perform the following steps.

[0091] The multi-cloud management platform 20 is configured to receive an ordering request of a target tenant for a security component in a target cloud platform, wherein the ordering request carries order information; determine an order opening mode corresponding to the target cloud platform according to the order information, obtain a component ID and a component state of the security component based on the order opening mode; in the case that the component state is a non-running state, send a detail query request carrying the component ID to the target cloud platform; complete the ordering process of the security component based on the query response message; and the target tenant is a pre-created tenant.

[0092] The target cloud platform 21 is configured to return a query response message to the multi-cloud management platform after receiving the detail query request.

[0093] It should be noted that the steps 100 to 103 described above describe the interaction process between the multi-cloud management platform and the target cloud platform in the component ordering system, and the specific implementation of the interaction process has been described in the above embodiments. To avoid repetition, it will not be described here.

[0094] The embodiment of the application further provides a computer storage medium, which stores computer program instructions, and the computer program instructions make the processor execute any one of the component ordering methods of the foregoing embodiments when the processor runs.

[0095] Specifically, the computer program instructions corresponding to the component ordering method in the embodiment can be stored on a storage medium such as an optical disc, a hard disk, a U disk, etc. When the computer program instructions corresponding to the component ordering method in the storage medium are read by a server or executed, any one of the component ordering methods of the foregoing embodiments is implemented.

[0096] Based on the same technical concept as the foregoing embodiments, refer to Figure 7 which shows the multi-cloud management platform 300 provided by the embodiment of the application, which can include a memory 301 and a processor 302; wherein,

[0097] The memory 301 is configured to store computer programs and data.

[0098] The processor 302 is configured to execute the computer programs stored in the memory to implement any one of the component ordering methods of the foregoing embodiments.

[0099] In actual application, the memory 301 can be a volatile memory such as RAM, or a non-volatile memory such as ROM, a flash memory, a hard disk (HDD) or a solid-state disk (SSD), or a combination of the above kinds of memories, and provides instructions and data to the processor 302.

[0100] The processor 302 can be at least one of an ASIC, a DSP, a DSPD, a PLD, an FPGA, a CPU, a controller, a microcontroller, a microprocessor. It can be understood that for different medical systems, the electronic device for implementing the functions of the processor can also be other, and the embodiment of the application does not make specific limitation.

[0101] In some embodiments, the embodiment of the application further provides a computer program product, which includes a computer program, and the computer program is executed by the processor to implement any one of the component ordering methods of the foregoing embodiments.

[0102] In some embodiments, the apparatus provided by the embodiments of the present application has functions or includes modules which can be used to execute the methods described in the above method embodiments, and the specific implementation can be referred to the description of the above method embodiments, and here will not be repeated.

[0103] The above description of each embodiment tends to emphasize the differences between the embodiments, and the same or similar parts can be mutually referred to, and here will not be repeated for the sake of brevity.

[0104] The methods disclosed in each of the method embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new method embodiments.

[0105] The features disclosed in each of the product embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new product embodiments.

[0106] The features disclosed in each of the method or device embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new method embodiments or device embodiments.

[0107] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage, etc.) containing computer-usable program code.

[0108] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.

[0109] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable data processing apparatus to produce a computer-implemented process such that the instructions executed by the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams.Figure 1 one or more processes and / or functions specified in one or more blocks Figure 1 one or more processes and / or functions specified in one or more blocks

[0110] The above merely provides the preferred embodiment of the present application, and not intended to limit the protection scope of the present application.

Claims

1. A component ordering method, characterized in that, Applied to a multi-cloud management platform, the method includes: Receive a subscription request from a target tenant for a security component in a target cloud platform. The subscription request carries order information. The target tenant is a pre-created tenant, and the target cloud platform is any one of multiple cloud platforms managed by the multi-cloud management platform. Based on the order information, determine the order activation mode corresponding to the target cloud platform, and based on the order activation mode, obtain the component ID and component status of the security component; If the component is in a non-running state, a detailed query request carrying the component ID is sent to the target cloud platform so that the target cloud platform returns a query response message; The ordering process for the security component is completed based on the query response message.

2. The method according to claim 1, characterized in that, The step of obtaining the component ID and component status of the security component based on the order activation mode includes: When the order activation mode is manual activation mode, the IP information of the security component is received. In response to an order activation operation for the security component, an order activation request carrying updated order information is sent to the target cloud platform, so that the target cloud platform returns an order response message; the order response message includes the component ID and component status of the security component, and the updated order information includes the IP information of the security component.

3. The method according to claim 1, characterized in that, The step of obtaining the component ID and component status of the security component based on the order activation mode includes: When the order activation mode is automatic activation mode, an order activation request carrying the order information is sent to the target cloud platform so that the target cloud platform returns an order response message; the order response message includes the component ID and component status of the security component.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: After obtaining the component ID and component status of the security component, the component ID and component status are written into the ordered equipment table; When the component is in a non-running state, sending a details query request carrying the component ID to the target cloud platform includes: The ordered equipment list is read periodically, and the status of the component is determined based on the reading results. If the component is in a non-running state, a details query request carrying the component ID is sent to the target cloud platform.

5. The method according to claim 1, characterized in that, The process of ordering the security component based on the query response message includes: Obtain the current component status of the security component from the query response message; If the current component status is running, the ordering process for the security component is completed based on the query response message.

6. The method according to claim 1, characterized in that, Before receiving the target tenant's order request for security components in the target cloud platform, the method further includes: Receive a creation request for the target tenant, the creation request carrying tenant information; The tenant information is sent to multiple cloud platforms managed by the multi-cloud management platform, so that the multiple cloud platforms create the target tenant corresponding to the tenant information; The system receives a creation response message from each of the multiple cloud platforms and completes the creation of the target tenant based on the creation response message; the creation response message indicates that the target tenant has been successfully created.

7. The method according to claim 6, characterized in that, Before receiving a creation request for the target tenant, the method further includes: Detect whether the target cloud platform is going live for the first time; When the detection result indicates that the target cloud platform is online for the first time, the tenant information of the created tenant is obtained and the tenant information of the created tenant is synchronized to the target cloud platform.

8. A component ordering system, characterized in that, The system includes a multi-cloud management platform and a target cloud platform. The target cloud platform is any one of multiple cloud platforms managed by the multi-cloud management platform, wherein: The multi-cloud management platform is used to receive a subscription request from a target tenant for a security component in a target cloud platform, the subscription request carrying order information; determine the order activation mode corresponding to the target cloud platform based on the order information; obtain the component ID and component status of the security component based on the order activation mode; if the component status is non-running, send a details query request carrying the component ID to the target cloud platform; and complete the subscription process for the security component based on the query response message; the target tenant is a pre-created tenant. The target cloud platform is used to return the query response message to the multi-cloud management platform after receiving the details query request.

9. A multi-cloud management platform, characterized in that, The multi-cloud management platform includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method according to any one of claims 1 to 7.

10. A computer storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the method described in any one of claims 1 to 7.

11. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Security service delivery method and system

    CN107204980A

  • Cloud computing network security service method

    CN110535817A