Access processing methods, apparatus, devices and storage media

By dynamically determining and ranking candidate permission policies based on real-time data, the problem of insufficient security and flexibility caused by static permission policies is solved, and efficient and secure access processing is achieved.

CN118965388BActive Publication Date: 2025-11-14CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410999504.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2025-11-14
Estimated Expiration
2044-07-24

AI Technical Summary

Technical Problem

Existing technologies based on static permission policies lead to permission abuse and poor security, and cannot flexibly meet the needs of dynamic user changes and complex cloud environments.

Method used

By analyzing real-time data from user terminals accessing cloud resources, candidate permission policies are identified and prioritized to dynamically determine the target permission policy for handling access requests.

Benefits of technology

It improves the security and flexibility of access processing, enables the rapid determination of target permission policies, reduces the complexity of access processing, and adapts to the security needs of different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118965388B_ABST
    Figure CN118965388B_ABST
Patent Text Reader

Abstract

This application discloses an access processing method, apparatus, device, and storage medium. This application relates to the field of data processing technology. The method includes: determining at least one candidate permission policy matching the real-time data based on real-time data during a user terminal's access to cloud environment resources and multiple preset permission policies; sorting the candidate permission policies in descending order of priority to obtain a candidate permission policy sequence; when receiving an access request from a user terminal, determining the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the user terminal's target permission policy; and processing the access request according to the target permission policy. This access processing method offers high security and flexibility, and simultaneously enables rapid determination of the target permission policy, thereby achieving efficient access processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to an access processing method, apparatus, device and storage medium. Background Technology

[0002] Cloud computing, as a crucial component of modern information technology, has been widely applied across various industries. However, with the increasing prevalence of cloud computing, security issues in cloud environments have become increasingly prominent. To enhance security, user access permissions need to be controlled when users access resources in the cloud environment through their terminals.

[0003] Currently, permission policies can be configured for users based on static user roles or rules. When a user accesses resources in the cloud environment through their user terminal, the user's access is processed according to this permission policy.

[0004] However, in the above process, processing user access based on static permission policies can easily lead to permission abuse or data leakage, resulting in poor security. Summary of the Invention

[0005] This application provides an access processing method, apparatus, device, and storage medium to solve the technical problem of poor security in access processing in related technologies.

[0006] Firstly, this application provides an access processing method, including:

[0007] Based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies, at least one candidate permission policy that matches the real-time data is determined.

[0008] The candidate permission policies are sorted in descending order of priority to obtain a sequence of candidate permission policies.

[0009] When an access request is received from the user terminal, the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request is determined as the target permission policy for the user terminal.

[0010] The access request is processed according to the target permission policy.

[0011] Secondly, this application provides an access processing apparatus, the apparatus comprising:

[0012] The first determining module is used to determine at least one candidate permission policy that matches the real-time data based on the real-time data during the process of the user terminal accessing cloud environment resources and multiple preset permission policies.

[0013] The sorting module is used to sort the candidate permission policies in descending order of priority to obtain a sequence of candidate permission policies.

[0014] The second determining module is used to, when receiving the access request from the user terminal, determine the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the target permission policy for the user terminal.

[0015] The processing module is used to process the access request according to the target permission policy.

[0016] Thirdly, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the access processing method as described in any of the present application.

[0017] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the access processing method as described in any of the claims in this application.

[0018] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the access processing method as described in any of the present application.

[0019] The technical solution provided in this application includes: determining at least one candidate permission policy that matches the real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies; sorting the candidate permission policies in descending order of priority to obtain a candidate permission policy sequence; when receiving an access request from the user terminal, determining the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the user terminal's target permission policy; and processing the access request according to the target permission policy. This access processing method, by determining candidate permission policies that match the real-time data and processing the access request based on the target permission policy among the candidate permission policies, achieves dynamic processing of access requests based on real-time data. Compared to processing access requests based on static permission policies, this access processing method offers higher security and flexibility. Furthermore, by determining the target permission policy based on the priority of the candidate permission policies and the access request, it enables rapid determination of the target permission policy, thereby achieving efficient access processing. Attached Figure Description

[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A schematic diagram illustrating an application scenario of the access processing method provided in this application embodiment;

[0022] Figure 2 A schematic diagram illustrating another application scenario of the access processing method provided in the embodiments of this application;

[0023] Figure 3 A flowchart illustrating an access processing method provided in an embodiment of this application;

[0024] Figure 4 This is a schematic diagram of real-time data in an embodiment of this application;

[0025] Figure 5 A flowchart illustrating another access processing method provided in an embodiment of this application;

[0026] Figure 6 This is a schematic diagram illustrating the behavior analysis performed in an embodiment of this application;

[0027] Figure 7 This is a schematic diagram illustrating environmental analysis in an embodiment of this application;

[0028] Figure 8 A flowchart illustrating another access processing method provided in an embodiment of this application;

[0029] Figure 9 A schematic diagram illustrating an application scenario of another access processing method provided in an embodiment of this application;

[0030] Figure 10 A flowchart illustrating another access processing method provided in an embodiment of this application;

[0031] Figure 11 A flowchart illustrating another access processing method provided in an embodiment of this application;

[0032] Figure 12 This is a schematic diagram of the structure of an access processing system provided in an embodiment of this application;

[0033] Figure 13 This is a schematic diagram of the structure of an access processing device provided in an embodiment of this application;

[0034] Figure 14 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0035] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present application, not the entire structure.

[0036] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," "candidate," and "target" are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. The acquisition, storage, use, and processing of data in the technical solution of this application all comply with relevant national laws and regulations. It should be noted that certain software, components, models, and other existing industry solutions may be mentioned in the embodiments of this application. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0037] Figure 1 This is a schematic diagram illustrating an application scenario of the access processing method provided in an embodiment of this application. For example... Figure 1 As shown, the access processing method provided in this embodiment can be applied to, for example... Figure 1 The first electronic device 11 shown in this embodiment can be a computer device, server, etc. In this embodiment, the first electronic device 11 is positioned between the user terminal 12 and the cloud environment 13. In this embodiment, the user terminal can be a mobile phone, personal computer, tablet computer, or vehicle-mounted terminal, etc. The cloud environment 13 consists of multiple second electronic devices 131. The second electronic devices 131 store various data resources or information resources. The user terminal 12 can access various resources in the cloud environment 13 through the first electronic device 11. In this embodiment, the first electronic device 11 processes the access request from the user terminal 12 by executing the access processing method provided in this embodiment, thereby improving access security.

[0038] Figure 2 This is a schematic diagram illustrating another application scenario of the access processing method provided in the embodiments of this application. For example... Figure 2 As shown, the access processing method provided in this embodiment can be applied to, for example... Figure 2The electronic device cluster 21 shown includes at least two third electronic devices 211. Figure 2 The following description uses an example of an electronic device cluster 21 comprising three third electronic devices 211. The electronic device cluster 21 is located between the user terminal 12 and the cloud environment 13. The electronic device cluster 21 processes the access requests of the user terminal 12 by executing the access processing method provided in this embodiment, thereby improving access security.

[0039] The access processing method of this application will be further described in detail below through several specific embodiments.

[0040] Figure 3 This is a flowchart illustrating an access processing method provided in an embodiment of this application. The method can be executed by an access processing device, which can be implemented in hardware and / or software and can be configured in an electronic device. The electronic device here can be... Figure 1 The first electronic device in or Figure 2 The third electronic device in the system. For example, the electronic device in this embodiment can be a server. Figure 3 As shown, the access processing method provided in this embodiment includes the following steps.

[0041] Step 301: Based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies, determine at least one candidate permission policy that matches the real-time data.

[0042] In this embodiment, cloud environment resources refer to resources such as text, images, audio, video, datasets, or program code stored in the cloud environment. User terminals can access cloud environment resources based on user needs.

[0043] In this embodiment, the permission policy refers to pre-set information used to control user access behavior. Optionally, the permission policy may specify at least one of the following: role, time, location, and resource information. In this embodiment, the role refers to the user's role, also known as a user group, including administrators, regular users, and guests. The time in this embodiment refers to the time when access is initiated, for example, the moment access is initiated. The location in this embodiment refers to the geographical location of the user's terminal. The resource information in this embodiment refers to resource type and resource quantity, etc. Resource types may include, for example, public resources or sensitive data.

[0044] In this embodiment, the permission policies have corresponding priorities. The priorities in this embodiment indicate the importance of the permission policies and their execution order. The higher the priority of a permission policy, the more important it is, and the earlier it is executed. Optionally, the priority of a permission policy can be determined based on the roles included in the policy. For example, a permission policy that includes the role of an administrator has a higher priority than a permission policy that includes the role of a regular user. Optionally, the priority of a permission policy can also be determined based on the resource information included in the policy. For example, a permission policy that includes sensitive data has a higher priority than a permission policy that includes public information. Optionally, the priority of a permission policy can be determined by combining the roles and resource information in the policy.

[0045] For example, the preset permission policies may include: administrators can access all resources during working hours, with a priority of 80; ordinary users can only access public resources, with a priority of 75; allow the "Editor" group to perform read and write operations, but not delete, with a priority of 70; and prohibit access to sensitive data outside of working hours, with a priority of 78.

[0046] The access processing method in this embodiment can achieve dynamic permission management. Based on the different real-time data, either Role-Based Access Control (RBAC) or Attribute-Based Access Control (ABAC) is used to implement dynamic permission management. ABAC dynamically determines the permission policy based on the attributes of the user, resource, environment, and operation.

[0047] Once a user terminal begins accessing the cloud resource environment, the access processing device can acquire real-time data during the user terminal's access to cloud resources. In step 301, based on the real-time data during the user terminal's access to the cloud resource environment and multiple permission policies, at least one candidate permission policy that matches the real-time data is determined.

[0048] Figure 4 This is a schematic diagram of real-time data in an embodiment of this application. For example... Figure 4 As shown, the real-time data 41 in this embodiment includes the following three aspects: user information 411, real-time behavior data 412, and environmental information 413.

[0049] In this embodiment, the user information 411 includes the role of the user corresponding to the user terminal.

[0050] The real-time behavioral data 412 in this embodiment includes at least one of the following: the user terminal's login time, the user terminal's login location, the user terminal's access frequency, the user terminal's operation type, the user terminal's operation frequency, the types of resources accessed by the user terminal, and the number of resources accessed by the user terminal. Optionally, the user terminal's login location refers to the physical location or network access point where the user terminal logs into the cloud environment. The user terminal's operation type includes at least one of the following: click, query, add, delete, modify, etc. The types of resources accessed by the user terminal refer to resource types or resource formats, such as text, images, audio, etc. The number of resources in this embodiment refers to the amount of data in the resources.

[0051] The environmental information 413 in this embodiment includes at least one of the following: user terminal attribute information, network information connected to the user terminal, user terminal geographic location information, and access time information. The user terminal attribute information in this embodiment includes at least one of the following: user terminal type, user terminal model, user terminal operating system, browser type when accessing cloud environment resources, and network protocol (Internet Protocol, IP) address, etc. The network information connected to the user terminal includes at least one of the following: internal network, external network, network security level, network transmission rate, and network load, etc. The user terminal geographic location information may include the latitude and longitude of the user terminal. The access time information includes access time, working hours, and non-working hours, etc.

[0052] Prior to step 301, the access processing method provided in this embodiment further includes the following steps: acquiring real-time data during the process of a user terminal accessing cloud environment resources. Optionally, the access processing device acquires real-time data in the following ways: acquiring real-time behavior data and user information of the user terminal through logs, the logs recording the user terminal's operation logs, including login, access, modification, and other operations; collecting environmental information such as the user terminal's attribute information, the network information connected to the user terminal, and the user terminal's geographical location information through network sensors or application programming interfaces (APIs).

[0053] For example, a regular user, A, logs into the cloud environment from the company network during work hours using their user terminal. After logging in, the user terminal's operation log records every access and modification operation. The real-time data acquired by the access processing device includes: user A's role (regular user), login time, IP address, access frequency, operation type, operation frequency, user terminal attribute information, and user terminal's geographical location information. The access frequency, operation type, operation frequency, login time, and IP address can be obtained from the operation log. The user terminal's attribute information can be obtained through network sensors. The user terminal's geographical location information can be obtained through the geolocation service API.

[0054] For example, based on the real-time data in the above example, the candidate permission policies determined in step 301 may include: Policy 1: Administrators can access all resources during working hours; Policy 3: Users can access sensitive data within the company network.

[0055] Step 301 enables the dynamic determination of candidate permission policies based on real-time data from the user terminal, and the dynamic adjustment of the user terminal's permission policy. For example, it can restrict the permissions of user terminals accessing sensitive data in untrusted networks.

[0056] Optionally, in order to improve the efficiency of determining candidate permission policies, in step 301, at least one candidate permission policy can be determined as follows: real-time data is parsed to extract key attribute values ​​from the real-time data, wherein the key attribute values ​​are used to characterize at least one of the following: user information, real-time behavior data, and environmental information; among multiple permission policies, the permission policy that matches the key attribute value is determined as the candidate permission policy.

[0057] One approach involves using a machine learning model to parse real-time data and extract key attribute values. Another approach involves reading the fields in the real-time data and extracting key attribute values ​​based on each field and its value.

[0058] It should be noted that, in this embodiment, real-time data refers to the real-time data of the user terminal within the preset time T after the user terminal logs into the cloud environment. Alternatively, in this embodiment, real-time data refers to all real-time data from the moment the user terminal starts logging into the cloud environment until the current moment.

[0059] Step 302: Sort the candidate permission policies in descending order of priority to obtain a sequence of candidate permission policies.

[0060] In this embodiment, to improve access processing efficiency, after determining at least one candidate permission policy, the candidate permission policies are sorted in descending order of priority to obtain a candidate permission policy sequence. In this sequence, the candidate permission policy with higher priority is ranked higher. For example, assuming there are four candidate permission policies: candidate permission policy 31, priority: 50; candidate permission policy 32, priority: 80; candidate permission policy 33, priority: 60; and candidate permission policy 34, priority: 75, then the candidate permission policy sequence is: candidate permission policy 32, candidate permission policy 34, candidate permission policy 33, and candidate permission policy 31.

[0061] Optionally, candidate permission policies can be sorted as follows: if the priority of the first candidate permission policy is greater than the priority of the second candidate permission policy, then the first candidate permission policy is ranked before the second candidate permission policy; if the priority of the first candidate permission policy is the same as the priority of the second candidate permission policy, then they are sorted according to the policy type of the first candidate permission policy and the policy type of the second candidate permission policy; if the policy type of the first candidate permission policy and the priority of the second candidate permission policy are the same and the policy type is the same, then they are sorted according to the creation time of the first candidate permission policy and the creation time of the second candidate permission policy.

[0062] The candidate permission policies in this embodiment include basic permission policies and composite permission policies. A basic permission policy in this embodiment refers to a permission policy that includes only one type of element. This element refers to any one of role, time, location, or resource information. That is, a basic permission policy includes only one type of role, one type of time, one type of location, or one type of resource information. A composite permission policy refers to a permission policy that includes multiple types of elements. For example, permission policy: Ordinary users can access public resources during working hours. Since this only includes one type of role, namely ordinary users, this permission policy is a basic permission policy. Permission policy: During working hours, ordinary users can access public resources; administrators can access all resources at any time; all users are prohibited from accessing sensitive data outside of working hours, including two types of roles, namely ordinary users and administrators. This permission policy is a composite permission policy.

[0063] Optionally, when sorting according to the policy type of the first candidate permission policy and the policy type of the second candidate permission policy, the composite permission policy may be placed before the basic permission policy, so as to quickly determine the target permission policy in step 303.

[0064] Optionally, when sorting by the creation time of the first candidate permission policy and the second candidate permission policy, the permission policy with a later creation time may be placed before the permission policy with an earlier creation time. Since permission policies with a later creation time may better meet the latest security requirements of the cloud environment, this sorting method can make permission policies with a later creation time more likely to become the target permission policy in step 303.

[0065] Step 303: When an access request from a user terminal is received, the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request is determined as the target permission policy for the user terminal.

[0066] In this embodiment, the access request can be an access request from the real-time data in step 301, or an access request obtained after the candidate permission policy sequence has been determined. This embodiment is not limited to this.

[0067] In this embodiment, the access request indicates the target cloud environment resource to be accessed. Optionally, the access request may also indicate information such as the user's role, access time, and access location corresponding to the user terminal.

[0068] In step 303, according to the order of the candidate permission policies in the candidate permission policy sequence, the first candidate permission policy that allows the user terminal to access the target cloud environment resources corresponding to the access request is determined as the target permission policy for the user terminal.

[0069] The specific process of step 303 can be as follows: Based on the access request and the i-th candidate permission policy in the candidate permission policy sequence, determine whether the i-th candidate permission policy allows the access request to access the target cloud environment resource corresponding to the access request; if the i-th candidate permission policy allows the access request to access the target cloud environment resource corresponding to the access request, then determine the i-th candidate permission policy as the target permission policy; if the i-th candidate permission policy does not allow the access request to access the target cloud environment resource corresponding to the access request, then use the value of i+1 as the new value of i; if the new value of i is less than or equal to M, then return to the step of "determining whether the i-th candidate permission policy allows the access request to access the target cloud environment resource corresponding to the access request based on the access request and the candidate permission policy sequence"; if the new value of i is greater than M, then stop executing step 303. Here, M represents the number of candidate permission policies, and the initial value of i is 1.

[0070] Step 303 allows the system to stop checking other candidate permission policies once a candidate permission policy that allows a user terminal to access resources in the target cloud environment is found according to the priority of the candidate permission policies, thus avoiding unnecessary further checks. This approach improves the efficiency of access processing and reduces the complexity of determining the target permission policy. Simultaneously, it allows the system to continue determining whether other candidate permission policies allow the user terminal to access resources in the target cloud environment even when a candidate permission policy that denies the user terminal access is found. For example, suppose a user terminal attempts to access a resource, and the system evaluates policies sequentially. When the first policy (policy A) allows access to the resource, policy A is determined as the target permission policy, and the evaluation of subsequent policies is terminated. As another example, suppose a user terminal attempts to access a resource, and the system evaluates policies sequentially. When the first policy (policy B) denies access to the resource, other policies need to be evaluated to ensure that no higher-priority or more important policy allows access.

[0071] Optionally, when an access request from a user terminal is received, if it is determined that all candidate permission policies in the candidate permission policy sequence deny the user terminal access to the target cloud environment resource corresponding to the access request, then the access request is denied. This indicates that the access request may be harmful to the cloud environment resource, and to improve security, the access request is denied.

[0072] Step 304: Process the access request according to the target permission policy.

[0073] After determining the target permission policy, the access request can be processed according to the target permission policy. That is, the access request is allowed to access the corresponding target cloud environment resources. In this embodiment, the access request can be used to perform at least one of the following operations on the target cloud environment resources: read, delete, modify, or add.

[0074] Optionally, to improve the execution efficiency of step 304, after obtaining the target permission policy and before executing step 304, the access processing method provided in this embodiment further includes: obtaining the initial permission information of the user corresponding to the user terminal; adjusting the initial permission information according to the target permission policy to obtain the adjusted permission policy; and writing the adjusted permission policy into the user's permission configuration information. Correspondingly, the implementation process of step 304 is as follows: obtaining the adjusted permission policy from the permission configuration information; and processing the access request according to the adjusted permission policy. For example, user A's initial permission information is ordinary user permissions. The target permission policy is to allow administrators to access all resources. Then the adjusted permission policy is: allowing administrators to access all resources, and the adjusted permission policy is written into user A's permission configuration information. In step 304, the adjusted permission policy is obtained from the permission configuration information, and the access request is processed.

[0075] Optionally, after writing the adjusted permission policy into the user's permission configuration information, permission verification can be performed to determine whether the adjusted permission policy has been successfully written into the permission configuration information. The verification process can test whether the read permission configuration information is the adjusted permission policy. After successful permission verification, the user or system administrator can be notified of the permission adjustment result. For example, writing administrator permissions into user A's permission configuration; verifying that user A's permission update is correct, ensuring that they have permission to access all resources; and notifying user A and the system administrator that their permissions have been updated to administrator permissions.

[0076] The following example illustrates steps 301 to 304. Assume the determined candidate permission policies include: Policy 1: Regular users access public resources during working hours, priority: 50; Policy 2: Administrators access all resources at any time, priority: 80; Policy 3: Access to sensitive data is prohibited outside of working hours, priority: 70; Composite Policy 1: During working hours, regular users can access public resources, administrators can access all resources at any time, and all users are prohibited from accessing sensitive data outside of working hours, priority: 75. Then the candidate permission policy sequence is: Policy 2, Composite Policy 1, Policy 3, and Policy 1.

[0077] If the access request indicates that the administrator is attempting to access the resource, then policy 2 will be selected as the target permission policy, and other candidate permission policies will no longer be evaluated.

[0078] If the access request represents a regular user or administrator attempting to access public resources during working hours, then composite policy 1 will be selected as the target permission policy, and other candidate permission policies will no longer be evaluated.

[0079] If the access request indicates that a user is attempting to access sensitive data outside of working hours, then the target access policy cannot be determined, and the access request should be denied.

[0080] In related technologies, the static permission policy-based approach to handling user access is inflexible and cannot flexibly address dynamically changing user needs and complex cloud environments, resulting in insufficient flexibility. Furthermore, static permission policies are easily exploited by attackers, leading to permission abuse or data leakage. Simultaneously, as cloud resources and the number of users increase, permission management becomes increasingly complex, and static permission policy configurations struggle to meet actual needs, leading to high complexity in access processing. The access processing method provided in this embodiment can dynamically process access requests based on real-time user data, improving the security and flexibility of the access processing method. It can adapt to the security requirements of different scenarios and enhance the level of security management. Moreover, this access processing method can be implemented in complex cloud environments, reducing the complexity of access processing implementation.

[0081] The access processing method provided in this embodiment includes: determining at least one candidate permission policy that matches the real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies; sorting the candidate permission policies in descending order of priority to obtain a candidate permission policy sequence; when an access request from the user terminal is received, determining the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the user terminal's target permission policy; and processing the access request according to the target permission policy. This access processing method, by determining candidate permission policies that match the real-time data and processing the access request based on the target permission policy among the candidate permission policies, achieves dynamic processing of access requests based on real-time data. Compared to processing access requests based on static permission policies, this access processing method offers higher security and flexibility. Furthermore, by determining the target permission policy based on the priority of the candidate permission policies and the access request, the target permission policy can be determined quickly, thereby achieving efficient access processing.

[0082] Figure 5 This is a flowchart illustrating another access processing method provided in an embodiment of this application. This embodiment... Figure 3 Based on the illustrated embodiments and various optional implementations, the other steps included in this access processing method will be described in detail. For example... Figure 5 As shown, the access processing method provided in this embodiment includes the following steps.

[0083] Step 501: Based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies, determine at least one candidate permission policy that matches the real-time data.

[0084] Step 502: Sort the candidate permission policies in descending order of priority to obtain a sequence of candidate permission policies.

[0085] Step 503: When an access request from a user terminal is received, the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request is determined as the target permission policy for the user terminal.

[0086] Step 504: Process the access request according to the target permission policy.

[0087] The implementation process and technical principles of steps 501 and 301, 502 and 302, 503 and 303, and 504 and 304 are similar and will not be repeated here.

[0088] Optionally, in this embodiment, real-time data includes user information, real-time behavioral data, and environmental information.

[0089] This embodiment and Figure 3 The difference between the illustrated embodiment and various optional implementations is that behavioral analysis and environmental analysis can also be implemented in this embodiment.

[0090] Step 505: Input the real-time behavior data, access requests, and target permission policies into the pre-trained behavior analysis model to obtain the behavior analysis results output by the behavior analysis model.

[0091] In step 505, behavior analysis can be performed based on a pre-trained behavior analysis model. This behavior analysis model can be a model trained based on a machine learning algorithm.

[0092] Figure 6 This is a schematic diagram illustrating behavior analysis in an embodiment of this application. For example... Figure 6 As shown, real-time behavior data, access requests, and target permission policies are input into a pre-trained behavior analysis model 61 to obtain the behavior analysis results output by the model. In this embodiment, the behavior analysis results include: normal behavior patterns and abnormal behavior patterns.

[0093] Optionally, before inputting real-time behavior data, access requests, and target permission policies into the pre-trained behavior analysis model, the data can be preprocessed to remove noise and invalid data. This can be done through operations such as data cleaning, format conversion, and data aggregation.

[0094] Step 506: Input the environment information, access request, and target permission policy into the pre-trained environment analysis model to obtain the environment analysis results output by the environment analysis model.

[0095] In step 506, environmental analysis can be performed based on a pre-trained environmental analysis model. This environmental analysis model can be a model trained based on a machine learning algorithm.

[0096] Figure 7 This is a schematic diagram illustrating environmental analysis in an embodiment of this application. Figure 7 As shown, environmental information, access requests, and target permission policies are input into a pre-trained environmental analysis model 71 to obtain the environmental analysis results output by the model. In this embodiment, the environmental analysis results include: whether the user's operating environment is secure, whether access is within a trusted network, and whether a trusted device is being used.

[0097] Optionally, before inputting the environmental information, access requests, and target permission policies into the pre-trained environmental analysis model, the environmental information, access requests, and target permission policies can be preprocessed to remove noise and invalid data. For example, data cleaning, format conversion, and data aggregation operations can be performed.

[0098] Optionally, when the behavior analysis results indicate abnormal behavior, and / or when the environmental analysis results indicate an abnormal environment, the access processing device triggers an alarm mechanism to send alarm information to the administrator's corresponding device, or takes automatic response measures, such as locking the user's account or restricting the user's permissions.

[0099] For example, the access processing device cleans the operation logs of the terminal device corresponding to user A, removing duplicate and invalid records. These operation logs include: real-time behavior data, access requests, target permission policies, and environmental information. Step 505 evaluates the behavior of the terminal device corresponding to user A, and step 506 evaluates the environment of the terminal device corresponding to user A.

[0100] The access processing method provided in this embodiment can analyze the behavior of user terminals based on a behavior analysis model and analyze the environment of user terminals based on an environment analysis model, thereby accurately and quickly detecting abnormal behavior and potential security threats, and further improving the security of cloud environment resources.

[0101] Figure 8 This is a flowchart illustrating another access processing method provided in an embodiment of this application. This embodiment... Figure 3 or Figure 5 Based on the illustrated embodiment, the steps prior to determining at least one candidate permission policy are described in detail. For example... Figure 8 As shown, the access processing method provided in this embodiment also includes the following steps.

[0102] Step 801: Obtain the login request from the user terminal.

[0103] The login request includes a username and password.

[0104] The access processing method provided in this embodiment can perform multi-factor authentication of user identity before step 301 or step 501.

[0105] In this embodiment, multi-factor authentication (MFA) refers to an authentication method that uses multiple independent verification factors, such as passwords, SMS verification codes, and biometrics, to confirm the user's identity.

[0106] When logging into the cloud environment, a user terminal can enter a login request. The access processing device obtains the user terminal's login request.

[0107] Step 802: Send the login request to the first authentication server so that the first authentication server can verify the identity of the user corresponding to the user terminal based on the login request, and return the user's basic attribute information after the verification is successful.

[0108] The basic attribute information includes the user's verification factor distribution address information.

[0109] In step 802, one-factor authentication is implemented. That is, the user's identity is verified using a password.

[0110] Optionally, to improve verification efficiency, the first authentication server in this embodiment can be a Lightweight Directory Access Protocol (LDAP) server.

[0111] Upon receiving a login request, the first authentication server verifies the user's identity based on the username and password provided in the request. Verification methods may include at least one of the following: determining if the username and password match; and, if they match, determining if the username is authorized to log in to the cloud environment. After successful verification, the first authentication server returns the user's basic attribute information to the access processing device.

[0112] The basic attribute information in this embodiment includes the verification factor sending address information. Furthermore, the basic attribute information may also include information such as username and user role.

[0113] In this embodiment, the verification factor sending address information refers to the address that issues the verification factor. This address information can be the user's phone number, the user's username in an application (e.g., email address), etc.

[0114] Step 803: Generate a verification factor retrieval request.

[0115] The verification factor acquisition request includes verification factor distribution address information.

[0116] After obtaining the verification factor distribution address information, the access processing device can generate a verification factor acquisition request.

[0117] Optionally, in order to improve the efficiency of subsequent authentication, the verification factor acquisition request in this embodiment can be an Open Authorization (OAuth) request.

[0118] Step 804: Send a verification factor acquisition request to the second authentication server so that the second authentication server sends the information of the first verification factor to the device corresponding to the verification factor distribution address information.

[0119] In this embodiment, authentication of another factor is achieved through a second authentication server. This second authentication server can be an open authorization server. Upon receiving a verification factor acquisition request, the second authentication server sends the information of the first verification factor to the device corresponding to the verification factor distribution address information. It should be noted that the device corresponding to the verification factor distribution address information and the user terminal in this embodiment can be the same device or different devices. This embodiment is not limited to this.

[0120] Optionally, the second authentication server may also send information about the first authentication factor to the access processing device.

[0121] In this embodiment, the first verification factor can be an SMS verification code, a time-based one-time password algorithm (TOTP), or biometric features (e.g., facial features, fingerprints, etc.). The information of the first verification factor in this embodiment can include: the first verification factor itself, such as a verification code, and the type identification information of the first verification factor, such as information like "fingerprint" or "face" used to identify the type of the first verification factor.

[0122] After the second authentication server sends the first verification factor information to the device corresponding to the verification factor distribution address information, the user can obtain the first verification factor information through the device corresponding to the verification factor distribution address information. The user can then input the second verification factor in the user terminal based on the first verification factor information.

[0123] It should be noted that the first authentication server in this embodiment can be a server in a cloud environment or a server independent of a cloud environment. Similarly, the second authentication server in this embodiment can be a server in a cloud environment or a server independent of a cloud environment.

[0124] Step 805: Receive the information of the second verification factor input by the user terminal and the first verification factor sent by the second authentication server.

[0125] The access processing device receives a second verification factor input by the user terminal, and also receives information about a first verification factor sent by a second authentication server.

[0126] Step 806: When it is determined that the information of the second verification factor matches that of the first verification factor, the user's identity is verified.

[0127] The information matching between the second verification factor and the first verification factor means that the type of the second verification factor is the same as the type of the first verification factor, and / or, the second verification factor itself is the same as the first verification factor itself. When the information matching between the second verification factor and the first verification factor indicates that the user is a normal user and the user's identity has been verified.

[0128] Optionally, in steps 802 to 806, a blockchain-based distributed identity authentication system can also be used to achieve identity authentication, further enhancing the security and credibility of identity verification.

[0129] Optionally, after verifying the user's identity, the access processing device may send a verification success indication to the user terminal. Upon receiving the verification success indication, the user terminal can access cloud environment resources.

[0130] After step 806, steps 301 to 304 can be executed, or steps 501 to 506 can be executed.

[0131] Optionally, when it is determined that the information of the second verification factor does not match that of the first verification factor, it is determined that the user's identity has not been verified and the user's login request is rejected.

[0132] Figure 9 This is a schematic diagram illustrating an application scenario of another access processing method provided in an embodiment of this application. For example... Figure 9As shown, the access processing device 91 interacts with the first authentication server 92 and the second authentication server 93 to achieve user authentication. The user terminal 94 sends a login request to the access processing device 91. The access processing device 91 sends the login request to the first authentication server 92. The first authentication server 92 returns basic attribute information to the access processing device 91. Based on the verification factor distribution address information in the basic attribute information, the access processing device 91 generates a verification factor retrieval request and sends it to the second authentication server 93. The second authentication server 93 sends the first verification factor information to the device corresponding to the verification factor distribution address information (assuming the device is the same as the user terminal 94) and also sends the first verification factor information to the access processing device 91. The user inputs a second verification factor through the user terminal 94. The access processing device 91 receives the second verification factor sent by the user terminal 94 and the first verification factor information sent by the second authentication server. When the access processing device 91 determines that the second verification factor matches the first verification factor, the user's identity is verified.

[0133] The access processing method provided in this embodiment can perform multi-factor authentication of user identity, enhance the security of identity authentication, reduce the risk of user impersonation, and further improve the security of access processing.

[0134] Figure 10 This is a flowchart illustrating another access processing method provided in an embodiment of this application. This embodiment... Figure 3 , Figure 5 or Figure 8 Based on the illustrated embodiment, the implementation method of obtaining the permission policy is explained in detail. The permission policy in this embodiment includes a basic permission policy and a composite permission policy. For example... Figure 10 As shown, the access processing method provided in this embodiment also includes the following steps.

[0135] Step 1001: Based on the access requirements of cloud environment resources, determine multiple basic permission policies and the priority of each basic permission policy.

[0136] In this embodiment, access demands for cloud environment resources can be statistically analyzed, and multiple basic permission policies and the priority of each basic permission policy can be determined based on various access demands. The access demands in this embodiment are used to indicate user information and / or environment information. This embodiment can also determine the priority of each basic permission policy.

[0137] In this embodiment, the priority range can be from 1 to N. N is a number greater than 1. For example, N is 100.

[0138] For example, the basic access control policies in this embodiment may include the following policies: Basic Access Control Policy 1: Administrators can access all resources during working hours. Basic Access Control Policy 2: Ordinary users can only access public resources. Basic Access Control Policy 3: Users can access sensitive data within the company network. Basic Access Control Policy 4: Users are prohibited from accessing financial data when they are in a specific geographical location.

[0139] Step 1002: Combine some of the basic permission policies from multiple basic permission policies to obtain at least one composite permission policy.

[0140] In this embodiment, some basic permission policies can be combined to obtain at least one composite permission policy, so as to achieve more complex and granular permission control. For example, basic permission policy 10A is used to control read permission, basic permission policy 10B is used to control write permission, and the composite permission policy 10C obtained by combining basic permission policy 10A and basic permission policy 10B can control both read permission and write permission at the same time.

[0141] In this embodiment, the combination of basic permission policies includes at least one of the following: AND, OR, and NOT. For example, a composite permission policy can be: access to a resource requires both basic permission policy A and basic permission policy B to be satisfied. Another example is: access to a public resource requires basic permission policy C to be satisfied but basic permission policy D to be satisfied.

[0142] Step 1003: Determine the priority of the composite permission policy based on the priority of the basic permission policy that makes up the composite permission policy.

[0143] In this embodiment, the priority of the composite permission policy can be the weighted average, maximum, median, or minimum priority of the basic permission policies that make up the composite permission policy.

[0144] Optionally, in this embodiment, the system administrator can configure and update the permission policy through the management interface.

[0145] The above process will be illustrated with two specific examples below.

[0146] For example, suppose we have basic permission policy 10D: allowing the "Admin" group to perform all operations, with a priority of 80; and basic permission policy 10E: allowing the "Editor" group to perform read and write operations, but not delete, with a priority of 70. Combining basic permission policies 10D and 10E results in a composite permission policy: only members of both the "Admin" and "Editor" groups can delete resources, with a priority of 75.

[0147] For example, suppose we have basic access control policy 10F: administrators can access all resources during working hours, with a priority of 78; and basic access control policy 10G: ordinary users can only access public resources, with a priority of 75. Combining basic access control policies 10F and 10G results in composite access control policy 10H: administrators can access all resources during working hours, while ordinary users can only access public resources, with a priority of 75.

[0148] The access processing method provided in this embodiment supports complex combinations of permission policies and priority settings, enabling fine-grained control over different types of users, resources, and operations, thus improving the granularity and operability of access processing. For example, different permission policies can be set for access behavior in specific time periods and locations to achieve more refined access processing. Furthermore, permission policies can be dynamically expanded to quickly adapt to the ever-increasing cloud environment resources and user demands.

[0149] Optionally, after step 1003, steps 301 to 304, or steps 501 to 506, or steps 801 to 806 may be performed.

[0150] The access processing method provided in this embodiment can determine the basic permission policy and its priority, as well as the composite permission policy and its priority. This allows for flexible determination of various permission policies, supports multiple policy combinations and priority settings, improves the granularity of the determined permission policies, and enhances the operability of the determined permission policies, enabling the permission policies to adapt to the security requirements of different scenarios.

[0151] Figure 11 This is a flowchart illustrating another access processing method provided in an embodiment of this application. This embodiment... Figure 3 , Figure 5 , Figure 8 or Figure 10 Based on the illustrated embodiment, the steps following the processing of the access request will be described in detail. For example... Figure 11 As shown, the access processing method provided in this embodiment includes the following steps.

[0152] Step 1101: Based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies, determine at least one candidate permission policy that matches the real-time data.

[0153] Step 1102: Sort the candidate permission policies in descending order of priority to obtain a sequence of candidate permission policies.

[0154] Step 1103: When an access request from a user terminal is received, the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resources corresponding to the access request is determined as the target permission policy for the user terminal.

[0155] Step 1104: Process the access request according to the target permission policy.

[0156] The implementation process and technical principles of steps 1101 and 301, 1102 and 302, 1103 and 303, and 1104 and 304 are similar and will not be repeated here.

[0157] Step 1105: Store real-time data, target permission policies, and access requests to obtain the corresponding logs for each user.

[0158] An efficient logging and auditing mechanism is a crucial component in ensuring the security and traceability of access processing methods. The access processing method provided in this embodiment can also record user logs and audit them. In step 1105, real-time data, target permission policies, and access requests can be stored. Optionally, access results can also be stored.

[0159] The log in this embodiment can record detailed information about every user operation, including login, resource access, and permission changes. The user-specific log in this embodiment includes: operation time, user, operation type, and operation result.

[0160] Optionally, in this embodiment, distributed storage technology can be used when storing logs to ensure efficient storage and fast retrieval. Simultaneously, logs can be backed up to multiple nodes to prevent data loss.

[0161] Alternatively, in this embodiment, the logs can also be stored in a log server.

[0162] Step 1106: Analyze the logs and obtain the analysis results.

[0163] The analysis results serve as reference information for determining the permission policies of user terminals.

[0164] In this embodiment, log analysis tools can be used to periodically analyze recorded logs to identify potential security threats and abnormal behaviors, yielding analysis results. These results are used as reference information to determine the user terminal's permission policy; specifically, they are used to determine candidate permission policies for the user terminal. It can be understood that, upon receiving updated real-time data, the analysis results, and preset permission policies, the analysis results are used to determine at least one candidate permission policy that matches the updated real-time data.

[0165] Correspondingly, step 1101 in this embodiment is implemented as follows: based on real-time data, historical log analysis results, and multiple permission policies, at least one candidate permission policy that matches both the real-time data and the historical log analysis results is determined. That is, in determining the candidate permission policy, in addition to considering real-time data, historical log analysis results are also taken into account, making the determined candidate permission policy more consistent with the actual scenario and further improving the security of access processing.

[0166] Optionally, this embodiment can also perform real-time auditing based on logs. That is, user logs are monitored in real time to promptly detect and respond to abnormal behavior. For example, if a user is detected frequently attempting to access unauthorized resources, the access processing device can immediately notify the administrator or trigger an automatic response policy.

[0167] Optionally, in this embodiment, audit reports can also be generated periodically based on the analysis results to ensure that access requests comply with relevant regulations and security standards. Audit reports include operation logs, permission change records, and policy adjustment records.

[0168] For example, the access processing device records the operation logs and permission adjustment logs of the user terminal corresponding to user A, including the time, reason, and result of each permission adjustment, thus obtaining the logs for user A. The access processing device stores these logs in a secure log server to ensure the integrity and security of the log data. The access processing device periodically analyzes the logs to identify abnormal operations by user A, such as accessing sensitive data outside of working hours, and obtains the analysis results. The access processing device generates a detailed audit report, recording user A's operation and permission adjustment details, for administrator review.

[0169] The access processing method in this embodiment can record the process and results of permission adjustment, achieve efficient logging and auditing, further improve the security of access control and ensure the traceability of operations.

[0170] Figure 12 This is a schematic diagram of the structure of an access processing system provided in an embodiment of this application. Figure 12As shown, the access processing system provided in this embodiment includes an identity authentication module 121, a real-time monitoring and analysis module 122, a policy engine module 123, and a log auditing module 124 connected in sequence.

[0171] The identity authentication module 121 is used to execute steps 801 to 806.

[0172] The real-time monitoring and analysis module 122 is used to acquire real-time data during the process of user terminals accessing cloud environment resources, and to execute steps 505 and 506.

[0173] The policy engine module 123 is used to execute steps 301 to 304, and steps 1001 to 1003. The policy engine module is the core component of this access processing system and can adjust user permission policies in real time. Optionally, the policy engine module 123 can feed back the matched target permission policy to the identity authentication module 121. The identity authentication module 121 can control the front-end display according to the target permission policy.

[0174] The log auditing module 124 is used to perform steps 1105 and 1106.

[0175] The access processing system provided in this embodiment has the following advantages: scalability, with a flexible system architecture that supports dynamic expansion and can quickly adapt to the ever-increasing cloud computing resources and user demands; flexibility, capable of dynamically adjusting permission policies based on real-time user data to adapt to the security requirements of different scenarios; security, capable of real-time monitoring and analysis of user behavior, timely detection and response to abnormal behavior; and granularity, with a flexible policy engine that supports multiple permission policy combinations and priority settings, improving the granularity and operability of access processing.

[0176] Figure 13 This is a schematic diagram of an access processing device provided in an embodiment of this application. Figure 13 As shown, the access processing device provided in this embodiment includes the following modules: a first determination module 1301, a sorting module 1302, a second determination module 1303, and a processing module 1304.

[0177] The first determining module 1301 is used to determine at least one candidate permission policy that matches the real-time data based on the real-time data during the process of the user terminal accessing cloud environment resources and multiple preset permission policies.

[0178] The sorting module 1302 is used to sort the candidate permission policies in descending order of priority to obtain a candidate permission policy sequence.

[0179] The second determining module 1303 is used to, when receiving the access request from the user terminal, determine the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the target permission policy for the user terminal.

[0180] The processing module 1304 is used to process the access request according to the target permission policy.

[0181] In one embodiment, the device further includes: a first acquisition module, a first transmission module, a generation module, a second transmission module, a receiving module, and a third determination module.

[0182] The first acquisition module is used to acquire the login request of the user terminal.

[0183] The login request includes a username and a password.

[0184] The first sending module is configured to send the login request to the first authentication server, so that the first authentication server verifies the identity of the user corresponding to the user terminal based on the login request, and returns the user's basic attribute information after successful verification. The basic attribute information includes the user's verification factor distribution address information.

[0185] The generation module is used to generate a verification factor acquisition request. The verification factor acquisition request includes the verification factor distribution address information.

[0186] The second sending module is used to send the verification factor acquisition request to the second authentication server, so that the second authentication server sends the information of the first verification factor to the device corresponding to the verification factor distribution address information.

[0187] The receiving module is used to receive the information of the second verification factor input by the user terminal and the first verification factor sent by the second authentication server.

[0188] The third determining module is used to determine that the user's identity has passed verification when it is determined that the information of the second verification factor matches that of the first verification factor.

[0189] In one embodiment, the real-time data includes user information, real-time behavioral data, and environmental information.

[0190] The user information includes the role of the user corresponding to the user terminal.

[0191] The real-time behavioral data includes at least one of the following: the user terminal's login time, the user terminal's login location, the user terminal's access frequency, the user terminal's operation type, the user terminal's operation frequency, the types of resources accessed by the user terminal, and the number of resources accessed by the user terminal.

[0192] The environmental information includes at least one of the following: the attribute information of the user terminal, the information of the network to which the user terminal is connected, the geographical location information of the user terminal, and the access time information.

[0193] In one embodiment, the first determining module 1301 is specifically used to: parse the real-time data and extract key attribute values ​​from the real-time data, wherein the key attribute values ​​are used to characterize at least one of the following: the user information, the real-time behavior data, and the environmental information; and determine the permission policy that matches the key attribute value among the multiple permission policies as the candidate permission policy.

[0194] In one embodiment, the device further includes a fourth determining module and a fifth determining module. The fourth determining module is used to input the real-time behavior data, the access request, and the target permission policy into a pre-trained behavior analysis model to obtain the behavior analysis result output by the behavior analysis model. The fifth determining module is used to input the environmental information, the access request, and the target permission policy into a pre-trained environment analysis model to obtain the environment analysis result output by the environment analysis model.

[0195] In one embodiment, the device further includes a second acquisition module, an adjustment module, and a writing module.

[0196] The second acquisition module is used to acquire the initial permission information of the user corresponding to the user terminal.

[0197] The adjustment module is used to adjust the initial permission information according to the target permission policy to obtain the adjusted permission policy.

[0198] The writing module is used to write the adjusted permission policy into the user's permission configuration information.

[0199] In one embodiment, the processing module 1304 is specifically used to: obtain the adjusted permission policy from the permission configuration information; and process the access request according to the adjusted permission policy.

[0200] In one embodiment, in the aspect of sorting the candidate permission policies according to the priority from largest to smallest, the sorting module 1302 is specifically configured to: if the priority of the first candidate permission policy is greater than the priority of the second candidate permission policy, then determine that the first candidate permission policy is ranked before the second candidate permission policy; if the priority of the first candidate permission policy is the same as the priority of the second candidate permission policy, then sort according to the policy type of the first candidate permission policy and the policy type of the second candidate permission policy; if the policy type of the first candidate permission policy and the priority of the second candidate permission policy are the same and the policy type is the same, then sort according to the creation time of the first candidate permission policy and the creation time of the second candidate permission policy.

[0201] In one embodiment, the permission policy includes a basic permission policy and a composite permission policy. The device further includes a sixth determining module, a combining module, and a seventh determining module.

[0202] The sixth determining module is used to determine multiple basic permission policies and the priority of each basic permission policy based on the access requirements of the cloud environment resources.

[0203] The combination module is used to combine some of the basic permission policies from the multiple basic permission policies to obtain at least one composite permission policy.

[0204] The seventh determining module is used to determine the priority of the composite permission policy based on the priority of the basic permission policies that make up the composite permission policy.

[0205] In one embodiment, the device further includes a storage module and an analysis module.

[0206] The storage module is used to store the real-time data, the target permission policy, and the access request, and to obtain the logs corresponding to the user.

[0207] The analysis module is used to analyze the logs and obtain log analysis results. These log analysis results serve as reference information for determining the permission policy for the user terminal.

[0208] In one embodiment, the first determining module 1301 is specifically used to: determine at least one candidate permission policy that matches both the real-time data and the historical log analysis results, based on the real-time data, the historical log analysis results, and the multiple permission policies.

[0209] In one embodiment, the device further includes a rejection module, configured to reject the access request when the user terminal receives the access request, if it is determined that all candidate permission policies in the candidate permission policy sequence reject the user terminal's access to the target cloud environment resource corresponding to the access request.

[0210] The access processing apparatus provided in this application embodiment can be used to execute the technical solution of the access processing method in the above embodiment. Its implementation principle and technical effect are similar, and will not be described again here.

[0211] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing elements; they can be fully implemented in hardware; or some modules can be implemented by processing elements calling software, while others are implemented in hardware. For example, the first determining module 1301, the sorting module 1302, the second determining module 1303, and the processing module 1304 can be separate processing elements, or they can be integrated into a chip in the above device. Alternatively, they can be stored as program code in the memory of the above device, and their functions can be called and executed by a processing element of the above device. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. In the implementation process, each step or module of the above method can be completed by the integrated logic circuit in the hardware of the processor element or by instructions in the form of software.

[0212] Figure 14 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 14 As shown, the electronic device may include a processor 142 and a memory 143.

[0213] Processor 142 executes computer execution instructions stored in memory, causing processor 142 to perform the scheme in the above embodiments. Processor 142 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0214] The memory 143 is connected to the processor 142 via the system bus and completes communication between them. The memory 143 is used to store computer program instructions.

[0215] Optionally, the electronic device may also include a transceiver 141. The transceiver 141 can be used to receive access requests from user terminals.

[0216] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between the access processing unit and other computer devices. Memory may include random access memory (RAM) and may also include non-volatile memory.

[0217] This application also provides a chip for executing instructions, which is used to execute the access processing method described in the above embodiments.

[0218] This application also provides a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the access processing method described in the above embodiments.

[0219] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the access processing method provided in any embodiment of this application.

[0220] In the implementation of the computer program product, computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0221] Note that the above description is merely a preferred embodiment and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments. Many other equivalent embodiments may be included without departing from the concept of this application, and the scope of this application is determined by the scope of the appended claims.

Claims

1. An access processing method, characterized in that, include: Based on real-time data during user terminal access to cloud environment resources and multiple preset permission policies, at least one candidate permission policy matching the real-time data is determined; wherein, the permission policy includes basic permission policies and composite permission policies; the method further includes: determining multiple basic permission policies and the priority of each basic permission policy based on the access requirements of the cloud environment resources; combining some of the basic permission policies among the multiple basic permission policies to obtain at least one composite permission policy; and determining the priority of the composite permission policy based on the priority of the basic permission policies that make up the composite permission policy. The candidate permission policies are sorted in descending order of priority to obtain a sequence of candidate permission policies; wherein, when sorting by the policy type of the first candidate permission policy and the policy type of the second candidate permission policy, the composite permission policy is placed before the basic permission policy. When an access request is received from the user terminal, the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request is determined as the target permission policy for the user terminal. The access request is processed according to the target permission policy.

2. The method according to claim 1, characterized in that, Before determining at least one candidate permission policy matching the real-time data based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies, the method further includes: Obtain the login request from the user terminal; wherein the login request includes a username and a password; The login request is sent to the first authentication server, so that the first authentication server verifies the identity of the user corresponding to the user terminal based on the login request, and returns the user's basic attribute information after successful verification; wherein, the basic attribute information includes the user's verification factor distribution address information; Generate a verification factor acquisition request; wherein, the verification factor acquisition request includes the verification factor distribution address information; Send the verification factor acquisition request to the second authentication server so that the second authentication server sends the information of the first verification factor to the device corresponding to the verification factor distribution address information; Receive the information of the second verification factor input by the user terminal and the first verification factor sent by the second authentication server; When it is determined that the information of the second verification factor matches that of the first verification factor, the user's identity is verified.

3. The method according to claim 1, characterized in that, The real-time data includes user information, real-time behavioral data, and environmental information; The user information includes the role of the user corresponding to the user terminal; The real-time behavioral data includes at least one of the following: the login time of the user terminal, the login location of the user terminal, the access frequency of the user terminal, the operation type of the user terminal, the operation frequency of the user terminal, the types of resources accessed by the user terminal, and the number of resources accessed by the user terminal. The environmental information includes at least one of the following: the attribute information of the user terminal, the information of the network to which the user terminal is connected, the geographical location information of the user terminal, and the access time information.

4. The method according to claim 3, characterized in that, The step of determining at least one candidate permission policy that matches the real-time data based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies includes: The real-time data is parsed to extract key attribute values; wherein the key attribute values ​​are used to represent at least one of the following: user information, real-time behavior data, and environmental information; The permission policy that matches the key attribute value among the multiple permission policies is determined as the candidate permission policy.

5. The method according to claim 3 or 4, characterized in that, The method further includes: The real-time behavior data, the access request, and the target permission policy are input into a pre-trained behavior analysis model to obtain the behavior analysis results output by the behavior analysis model. The environmental information, the access request, and the target permission policy are input into a pre-trained environmental analysis model to obtain the environmental analysis results output by the environmental analysis model.

6. The method according to any one of claims 1 to 4, characterized in that, Before processing the access request according to the target permission policy, the method further includes: Obtain the initial permission information of the user corresponding to the user terminal; The initial permission information is adjusted according to the target permission policy to obtain the adjusted permission policy; Write the adjusted permission policy into the user's permission configuration information.

7. The method according to claim 6, characterized in that, The step of processing the access request according to the target permission policy includes: Obtain the adjusted permission policy from the permission configuration information; The access request is processed according to the adjusted permission policy.

8. The method according to any one of claims 1 to 4, characterized in that, The step of sorting the candidate permission policies according to their priority from highest to lowest includes: If the priority of the first candidate permission policy is greater than the priority of the second candidate permission policy, then the first candidate permission policy is determined to be ranked before the second candidate permission policy. If the priority of the first candidate permission policy is the same as the priority of the second candidate permission policy, then they are sorted according to the policy type of the first candidate permission policy and the policy type of the second candidate permission policy. If the first candidate permission policy and the second candidate permission policy have the same policy type and priority, they are sorted according to the creation time of the first candidate permission policy and the creation time of the second candidate permission policy.

9. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Store the real-time data, the target permission policy, and the access request to obtain the log corresponding to the user; The logs are analyzed to obtain log analysis results; wherein, the log analysis results are used to characterize reference information when determining the permission policy of the user terminal.

10. The method according to claim 9, characterized in that, The step of determining at least one candidate permission policy that matches the real-time data based on real-time data during the user terminal's access to cloud environment resources and multiple preset permission policies includes: Based on the real-time data, historical log analysis results, and the multiple permission policies, at least one candidate permission policy that matches both the real-time data and the historical log analysis results is determined.

11. The method according to any one of claims 1 to 4, characterized in that, The method further includes: When an access request is received from the user terminal, if it is determined that all candidate permission policies in the candidate permission policy sequence deny the user terminal access to the target cloud environment resources corresponding to the access request, then the access request is denied.

12. An access processing apparatus, characterized in that, include: The first determining module is used to determine at least one candidate permission policy that matches the real-time data during the user terminal's access to cloud environment resources and a plurality of preset permission policies; wherein the permission policy includes basic permission policies and composite permission policies; the device further includes: a sixth determining module, a combining module, and a seventh determining module; the sixth determining module is used to determine a plurality of basic permission policies and the priority of each basic permission policy according to the access requirements of the cloud environment resources; the combining module is used to combine some of the basic permission policies among the plurality of basic permission policies to obtain at least one composite permission policy; the seventh determining module is used to determine the priority of the composite permission policy according to the priority of the basic permission policies that make up the composite permission policy; The sorting module is used to sort the candidate permission policies in descending order of priority to obtain a candidate permission policy sequence; wherein, when sorting according to the policy type of the first candidate permission policy and the policy type of the second candidate permission policy, the composite permission policy is placed before the basic permission policy. The second determining module is used to, when receiving the access request from the user terminal, determine the first candidate permission policy in the candidate permission policy sequence that allows the user terminal to access the target cloud environment resource corresponding to the access request as the target permission policy for the user terminal. The processing module is used to process the access request according to the target permission policy.

13. An electronic device, characterized in that, The system includes a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor, when executing the computer program, implements the access processing method as described in any one of claims 1 to 11.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the access processing method as described in any one of claims 1 to 11.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the access processing method as described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Access permission control method and device for multi-cloud system and authentication server

    CN112580006A

  • Resource access control method and device, equipment and storage medium

    CN115935328A