A private cloud network construction method and device, electronic equipment and storage medium
By generating customized access control lists and implementing real-time monitoring mechanisms, the security deficiencies of private cloud networks are addressed, enabling fine-grained access control and encryption protection at each layer, thereby improving security and management efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2024-08-19
- Publication Date
- 2026-04-14
AI Technical Summary
Existing private cloud networks face cybersecurity threats and attacks, including risks such as physical device information leakage, virtualization vulnerabilities, and configuration errors, resulting in insufficient security.
By extracting key configuration features from each layer of the private cloud network system, a customized access control list is generated. Combined with real-time monitoring and dynamically adjusted security policies, fine-grained access control and encryption protection for each layer are achieved.
It improves the security and management efficiency of private cloud networks, reduces the risk of data breaches and unauthorized access, ensures the flexibility and adaptability of access control policies, and enables rapid response to security threats.
Smart Images

Figure CN119030768B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method, apparatus, electronic device, and storage medium for building a private cloud network. Background Technology
[0002] A private cloud is a cloud computing environment independently built and operated by a specific organization. Unlike public clouds, private clouds are not provided to the general public but are tailored to meet the specific business and technical needs of a particular organization. While private clouds need to provide organizations with higher levels of data privacy and security, they currently still face various cybersecurity threats and attacks, including risks such as physical device information leakage, virtualization vulnerabilities, and misconfigurations, resulting in insufficient actual security. Summary of the Invention
[0003] This invention proposes a method, apparatus, electronic device, and storage medium for building a private cloud network, aiming to at least partially solve one of the technical problems in related technologies. The embodiments of this invention can securely realize the construction of a private cloud network.
[0004] On one hand, embodiments of the present invention provide a method for constructing a private cloud network, applied to a security protection layer in a private cloud network system. The method includes the following steps:
[0005] In response to the received first information, extract several key configuration features that obtained the first information;
[0006] The first information includes configuration information sent by the target layer; the target layer includes the hardware layer, virtualization layer, application layer, or management layer in the private cloud network system.
[0007] Based on the target-level exclusive categories and key configuration characteristics, a target access control list is compiled.
[0008] Send the target access control list to the target layer.
[0009] Optionally, when the target layer is a virtualization layer, the first information includes resource configuration information and virtual device configuration information; extracting multiple key configuration features for obtaining the first information includes the following steps:
[0010] The resource configuration information is matched with the first database to determine several key resource configuration features; the first database includes several standard key resource configuration information.
[0011] The virtual device configuration information is matched with the second database to determine several key virtual device configuration characteristics; the second database includes multiple standard virtual device configuration information.
[0012] Key configuration features are derived from key resource configuration features and key virtual device configuration features.
[0013] Optionally, when the target layer is a virtualization layer; based on the target layer's specific categories and key configuration characteristics, a target access control list is compiled, including the following steps:
[0014] The first identifier corresponding to the virtualization layer is determined according to the specific category of the virtualization layer, and the first identifier is vectorized to obtain the first vector;
[0015] Each key configuration feature is vectorized to obtain multiple second vectors;
[0016] Multiple first data encryption rules corresponding to the virtualization layer are determined based on the first vector and multiple second vectors;
[0017] The target access control list corresponding to the virtualization layer is generated based on multiple first data encryption rules.
[0018] Optionally, when the target layer is the application layer, the first information includes application configuration information of multiple target applications, and multiple key configuration features are obtained by feature extraction based on the application configuration information of each target application; based on the target layer's specific categories and key configuration features, a target access control list is compiled, including the following steps:
[0019] The second identifier corresponding to the application layer is determined based on the application layer's specific category. The second identifier is then vectorized to obtain the third vector.
[0020] Obtain the third identifier corresponding to each target application, and vectorize each third identifier to obtain multiple fourth vectors;
[0021] The key configuration features corresponding to each target application are vectorized to obtain multiple fifth vectors;
[0022] Multiple second data encryption rules corresponding to the application layer are determined based on the third vector, multiple fourth vectors, and multiple fifth vectors.
[0023] A target access control list corresponding to the application layer is generated based on multiple secondary data encryption rules.
[0024] Optionally, when the target layer is the management layer, the first information includes user configuration information for multiple management users, and multiple key configuration features are extracted based on the user configuration information of each management user; based on the target layer's exclusive categories and key configuration features, a target access control list is compiled, including the following steps:
[0025] The fourth identifier corresponding to the management is determined based on the management's exclusive category. The fourth identifier is then vectorized to obtain the sixth vector.
[0026] Obtain the fifth identifier corresponding to each management user, and perform vectorization processing on each fifth identifier to obtain multiple seventh vectors;
[0027] The key configuration features corresponding to each management user are vectorized to obtain multiple eighth vectors;
[0028] The security level of each management user is determined based on the sixth vector, multiple seventh vectors, and multiple eighth vectors.
[0029] Generate the target access control list for the management layer based on the security level of each management user.
[0030] Optionally, when the target layer is a hardware layer, the first information includes hardware configuration information of multiple target hardwares, and multiple key configuration features are obtained by feature extraction based on the hardware configuration information of each target hardware; based on the target layer's specific categories and key configuration features, a target access control list is compiled, including the following steps:
[0031] The sixth identifier corresponding to the hardware layer is determined based on the hardware layer's specific category. The sixth identifier is then vectorized to obtain the ninth vector.
[0032] Obtain the seventh identifier corresponding to each target hardware, and perform vectorization processing on each seventh identifier to obtain multiple tenth vectors;
[0033] The key configuration features corresponding to each target hardware are vectorized to obtain multiple eleventh vectors;
[0034] The access level of each target hardware is determined based on the ninth vector and multiple tenth vectors;
[0035] The target access control list corresponding to the hardware layer is determined based on the access level of each target hardware and multiple eleventh vectors.
[0036] Optionally, the method further includes the following steps:
[0037] In response to the received second information, the security factor of the target layer is determined based on the second information;
[0038] The second information includes log information and event information from the target layer;
[0039] Determine the security strategy for the target layer based on the security factor;
[0040] Send the security policy to the target layer.
[0041] On the other hand, embodiments of the present invention provide a private cloud network construction apparatus, comprising:
[0042] The first data processing module is used to extract multiple key configuration features of the first information in response to the received first information.
[0043] The first information includes configuration information sent by the target layer; the target layer includes the hardware layer, virtualization layer, application layer, or management layer in the private cloud network system.
[0044] The second data processing module is used to compile a target access control list based on the target layer’s exclusive categories and key configuration features.
[0045] The third data processing module is used to send the target access control list to the target layer.
[0046] Optionally, the device further includes:
[0047] The fourth data processing module is used to determine the security factor of the target layer based on the received second information in response to the second information.
[0048] The second information includes log information and event information from the target layer;
[0049] The fifth data processing module is used to determine the security strategy of the target layer based on the security factor;
[0050] The sixth data processing module is used to send security policies to the target layer.
[0051] On the other hand, embodiments of the present invention provide an electronic device, including: a processor and a memory; the memory is used to store a program; the processor executes the program to implement the above-described private cloud network construction method.
[0052] On the other hand, embodiments of the present invention provide a computer storage medium storing a processor-executable program, which, when executed by a processor, is used to implement the above-described private cloud network construction method.
[0053] This invention, in response to received first information, extracts multiple key configuration features from the first information. The first information includes configuration information sent by the target layer. The target layer includes the hardware layer, virtualization layer, application layer, or management layer in the private cloud network system. Based on the target layer's specific categories and key configuration features, a target access control list is generated. The target access control list is then sent to the target layer. The private cloud network construction method provided by this invention, through a specific security protection layer, extracts key configuration features from the configuration information of the target layer in the private cloud network system. Combined with the corresponding target layer's specific categories, it enables the construction of customized access control lists. This, in turn, ensures the security of access control at each target layer through the security protection layer, addressing the current problems of poor security in private clouds due to various network security threats and attacks, including physical device information leakage, virtualization vulnerabilities, and configuration errors. Attached Figure Description
[0054] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.
[0055] Figure 1 This is a schematic diagram of an implementation environment for building a private cloud network, provided by an embodiment of the present invention.
[0056] Figure 2 A flowchart illustrating a method for constructing a private cloud network according to an embodiment of the present invention;
[0057] Figure 3 This is a schematic diagram of the structure of a private cloud network construction system provided in an embodiment of the present invention;
[0058] Figure 4 This is a schematic diagram of an example of the interactive process of a private cloud network construction method provided in an embodiment of the present invention;
[0059] Figure 5 This is a schematic diagram of an example two of the interactive processes of a private cloud network construction method provided in an embodiment of the present invention;
[0060] Figure 6 This is a schematic diagram of an example three of the interactive processes of a private cloud network construction method provided in an embodiment of the present invention;
[0061] Figure 7 A schematic diagram of the interaction process example four of a private cloud network construction method provided in an embodiment of the present invention;
[0062] Figure 8 This is a schematic diagram of the interaction process example five of a private cloud network construction method provided in an embodiment of the present invention;
[0063] Figure 9 This is a schematic diagram of a private cloud network construction device provided in an embodiment of the present invention;
[0064] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0065] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0066] It should be noted that although functional modules are divided in the system diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first / S100," "second / S200," etc., in the specification, claims, and the aforementioned figures are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0067] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0068] To facilitate understanding of the technical solution of this invention, the technical features and proper nouns that may appear in the embodiments of this invention will first be explained:
[0069] A database (also known as a data management system) is a collection of data that is stored together in a specific way, allowing multiple users to share it while minimizing redundancy. Simply put, it can be viewed as an electronic filing cabinet—a place to store electronic files. A database can consist of multiple tablespaces, allowing users to perform operations such as adding, retrieving, updating, and deleting data within the files.
[0070] Memory: A general term for electronic, magnetic, laser, chemical, and other products used for temporary or long-term data storage. Computers typically include ROM, RAM, hard disks, optical discs, and associated drives.
[0071] Central Processing Unit (CPU): Generally composed of a logic unit, a control unit, and a storage unit. The logic and control units include registers used for temporary data storage during CPU processing. Simply put, it consists of two parts: a control unit and an arithmetic logic unit (ALU).
[0072] It is understood that the private cloud network construction method provided in this embodiment of the invention can be applied to any computer device with data processing and computing capabilities, and this computer device can be various types of terminals or servers. When the computer device in the embodiment is a server, the server is an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Optionally, the terminal can be a smartphone, tablet computer, laptop computer, or desktop computer, but it is not limited to these.
[0073] like Figure 1 The diagram shown is a schematic representation of an implementation environment provided by an embodiment of the present invention. (Refer to...) Figure 1 The implementation environment includes at least one terminal 102 and a server 101. The terminal 102 and the server 101 can be connected via a network, either wirelessly or via a wired connection, to complete data transmission and exchange.
[0074] Server 101 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0075] Additionally, server 101 can also be a node server in a blockchain network. Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms.
[0076] Terminal 102 can be a smartphone, tablet computer, laptop computer, desktop computer, smart speaker, smartwatch, etc., but is not limited to these. Terminal 102 and server 101 can be directly or indirectly connected via wired or wireless communication, and this embodiment of the invention does not impose any limitations.
[0077] Exemplary based on Figure 1 The implementation environment shown in this embodiment of the invention provides a method for constructing a private cloud network. The following description uses the application of this private cloud network construction method in terminal 102 as an example. It can be understood that this private cloud network construction method can also be applied to server 101.
[0078] Reference Figure 2 and Figure 3 , Figure 2 The flowchart illustrates a method for constructing a private cloud network for a terminal, as provided in an embodiment of the present invention. The executing entity of this private cloud network construction method can be any of the aforementioned computer devices (including servers or terminals). Figure 3 This is a schematic diagram illustrating a structural example of a private cloud network system provided in an embodiment of the present invention. (Refer to...) Figure 2 The method includes the following steps:
[0079] like Figure 2 and Figure 3 As shown, a method for constructing a private cloud network is applied to the security protection layer 105 in a private cloud network system. This method may include steps S101 to S103.
[0080] S101: In response to the received first information, extract multiple key configuration features of the first information. The first information is configuration information sent by the target layer. The target layer includes the hardware layer 101, virtualization layer 102, application layer 104, or management layer 103 in the private cloud network system.
[0081] In this embodiment, the first information may include configuration information sent by a layer (hardware layer 101, virtualization layer 102, application layer 104, or management layer 103) in the private cloud network system. Since each layer undertakes different functions and tasks, the configuration information they send is different. Upon receiving the first information, the security protection layer 105 can extract several key configuration features. These features may include at least one of IP address, port number, and protocol type.
[0082] For example, a large enterprise has deployed a private cloud network system to support its critical business processes. To ensure data security and business continuity, the enterprise decides to adopt the aforementioned private cloud network construction method. When deploying the hardware layer 101, virtualization layer 102, application layer 104, and management layer 103, each layer can send configuration information to the security protection layer 105 based on its own operational status and configuration requirements. For example, the hardware layer 101 can send information about the physical device status, and the application layer 104 can send information about application service ports and protocols. The security protection layer 105 can then extract key configuration characteristics from this information, such as at least one of the following: IP address range, open port numbers, and network protocols used.
[0083] For example, with the continuous improvement of educational informatization, the construction of smart campuses in universities has become an important development direction. In a smart campus, the private cloud network carries a large amount of information data related to teaching, research, and management; therefore, ensuring the security of the private cloud network is particularly important. In a certain university, the hardware layer 101 may include infrastructure such as servers, storage devices, and network devices. When these devices access the private cloud network, they can send configuration information to the security protection layer 105. The security protection layer 105 extracts key configuration characteristics based on this information, such as at least one of the device's Internet Protocol Address (IP), Media Access Control Address (MAC), and model number. Based on these characteristics, the security protection layer 105 can generate corresponding Access Control Lists (ACLs) to ensure that only authenticated and authorized devices can access the network.
[0084] For example, virtualization layer 102 can send virtual machine configuration information to security layer 105, which may include at least one of the virtual machine's IP address, operating system type, and application list. Based on these characteristics and the features of virtualization layer 102, security layer 105 can generate corresponding ACLs to control access permissions to the virtual machine.
[0085] S102: Generate a target access control list based on the target layer category and its corresponding key configuration features.
[0086] In this embodiment, the target layer may include a hardware layer 101, a virtualization layer 102, an application layer 104, and a management layer 103. Each layer may correspond to a specific category, and each category may correspond to its own key configuration features.
[0087] For example, a smart campus deploys numerous application systems, such as academic affairs systems, library systems, and student management systems. These systems can send application configuration information to security layer 105, including at least one of the application's Uniform Resource Locator (URL), port number, and user permissions. Based on the corresponding key configuration characteristics, the business requirements of application layer 104, and security requirements, security layer 105 can generate corresponding ACLs to restrict access permissions to the applications. This ensures that only users with the appropriate permissions can access and use these applications.
[0088] For example, the management layer 103 is a core component of the smart campus private cloud network, responsible for monitoring and managing the entire network. Management layer 103 can send management configuration information to security layer 105, including at least one of the administrator's IP address, login credentials, and management permissions. Based on the corresponding key configuration features, the characteristics of management layer 103, and security requirements, security layer 105 can generate corresponding ACLs to restrict user access to the management platform. This ensures that only administrators with management permissions can access and operate the management platform.
[0089] S103: Send the target access control list to the target layer.
[0090] In this embodiment, the target layer may include a hardware layer 101, a virtualization layer 102, an application layer 104, and a management layer 103, each with its corresponding access control list. The security protection layer 105 can generate a corresponding access control list based on the configuration information and characteristics of each layer, and send it to each layer.
[0091] For example, hardware layer 101 ACL is used to control access to hardware resources such as physical servers, storage devices, and network devices. Based on the sensitivity of the hardware resources and business needs, specific IP addresses, MAC addresses, or user groups can be defined to access specific hardware resources. The defined rules are configured on devices such as network switches, routers, or firewalls to ensure that only traffic conforming to the rules can pass through the network devices, thereby achieving access control over hardware resources.
[0092] For example, the security protection layer 105 can also periodically monitor the access records of the target layer ACL. When abnormal access is detected, it can make timely adjustments and optimizations, update the target layer ACL, and send it to the target layer.
[0093] For example, the virtualization layer 102 ACL is used to control access to virtual machines (VMs) and communication between VMs. Depending on business needs and security considerations, permissions for certain users or applications to access specific VMs can be defined, as well as communication rules between VMs. These defined rules are configured into network components of the virtualization platform, such as virtual switches or virtual firewalls. The virtualization layer 102 can monitor network traffic between VMs, and when abnormal behavior is detected, it can send alarm information to the security layer 105 for isolation and investigation.
[0094] As can be seen from the above, by acquiring the key configuration characteristics of each layer of the private cloud network, the core security elements of the hardware layer 101, virtualization layer 102, application layer 104, or management layer 103 can be accurately captured and access control lists can be automatically generated. This feature-based access control policy, compared to traditional single access control models or manually set static access control rules, can more specifically protect the security of each layer, ensuring the flexibility and adaptability of the access control policy. Different layers have different security needs and risk points; customized access control policies can more effectively prevent potential security threats. Simultaneously, sending the target access control list to the target layer enables the security policy to take effect immediately and be dynamically adjusted. This real-time security protection mechanism allows the private cloud network system to respond quickly to security threats, reducing security risks.
[0095] In some embodiments of the present invention, the target layer is the virtualization layer 102, and the first information includes resource configuration information and virtual device configuration information.
[0096] Extract several key configuration features from the first information, including:
[0097] The resource configuration information is matched with the first database to determine several key resource configuration features. The first database includes multiple standard key resource configuration information.
[0098] The virtual device configuration information is matched with the second database to determine several key virtual device configuration characteristics. The second database includes multiple standard virtual device configuration information.
[0099] Multiple key configuration features are determined based on multiple key resource configuration features and multiple key virtual device configuration features.
[0100] In this embodiment, the key configuration features include multiple key resource configuration features and multiple key virtual device configuration features.
[0101] For example, resource configuration information may include the allocation of hardware resources such as Data Processing Units (DPUs), memory, and storage, as well as the allocation of network resources such as network bandwidth and IP addresses. The resource configuration information is then matched with standard key resource configuration information in a first database. This first database stores numerous known standard resource configuration features, which can be formulated based on the operational experience and business requirements of the virtualization layer 102. Through similarity calculation, key configuration features in the current resource configuration information can be identified, such as high-load DPUs, insufficient memory, resource utilization levels, and whether there is resource waste or insufficiency.
[0102] For example, virtual device configuration information may include configuration details of virtual devices such as virtual machines, load balancers, and firewalls, including operating system versions, software installation status, and security policy settings. This virtual device configuration information is compared with standard virtual device configuration information in a second database. The second database stores standard configuration patterns for virtual devices, which can be customized based on best practices and security requirements. Through similarity matching, the system can identify key characteristics in the virtual device configuration, such as whether security settings are adequate and whether load balancing is appropriate.
[0103] For example, in the construction of a private cloud network in a university, the security protection layer 105 can periodically collect resource configuration information and virtual device configuration information from the virtualization layer 102 and extract key configuration features. For instance, in terms of teaching resource allocation, the security protection layer 105 can automatically adjust the allocation ratio of resources such as DPU and memory based on key resource configuration features to ensure the stable operation of various teaching applications. Simultaneously, the security protection layer 105 can also automatically optimize the configuration of virtual machines based on key virtual device configuration features, such as adjusting the operating system version and updating security patches, to improve the performance and security of virtual machines.
[0104] See Figure 4 , Figure 4 This is a flowchart illustrating another method for constructing a private cloud network disclosed herein, primarily used to describe the interaction process between the security protection layer 105 and the virtualization layer 102.
[0105] Specifically, the above-mentioned interaction process may include A101 to A106.
[0106] A101: Virtualization layer 102 sends virtualization layer 102 configuration information to the security protection slave. The virtualization layer 102 configuration information includes resource configuration information and virtual device configuration information.
[0107] A102: The first matching process includes the security protection layer 105 matching the resource configuration information with the first database to determine multiple key resource configuration features. The first database includes multiple standard key resource configuration information.
[0108] A103: The second matching process includes the security protection layer 105 matching the virtual device configuration information with the second database to determine multiple key virtual device configuration features. The second database includes multiple standard virtual device configuration information. Multiple key configuration features are determined based on these multiple key resource configuration features and multiple key virtual device configuration features.
[0109] A104: The vector calculation process includes the security protection layer 105 determining the first identifier corresponding to the virtualization layer 102 and generating the first vector corresponding to the first identifier. It also involves determining multiple second vectors corresponding to multiple key configuration features.
[0110] A105: Access control list generation includes security protection layer 105 determining multiple first data encryption rules corresponding to virtualization layer 102 based on a first vector and multiple second vectors. A target access control list corresponding to the virtualization layer is generated based on these multiple first data encryption rules.
[0111] A106: Security layer 105 sends a target access control list to virtualization layer 102.
[0112] This embodiment, by matching resource configuration information with standard critical resource configuration information, can quickly identify the rationality of resource allocation and optimization potential, thereby ensuring efficient utilization of computing resources and reducing resource waste. Comparing virtual device configuration information with standard configurations helps to identify potential security vulnerabilities and performance bottlenecks, enabling early warnings and interventions, and enhancing system stability and security.
[0113] In some embodiments of the present invention, the target layer is a virtualization layer 102. Based on the category of the target layer and the corresponding multiple key configuration features, a target access control list is generated, including:
[0114] Determine the first identifier corresponding to the virtualization layer 102, and generate the first vector corresponding to the first identifier.
[0115] Determine multiple second vectors corresponding to multiple key configuration features.
[0116] Multiple first data encryption rules corresponding to virtualization layer 102 are determined based on the first vector and multiple second vectors.
[0117] The target access control list corresponding to the virtualization layer 102 is generated based on multiple first data encryption rules.
[0118] For example, the security protection layer 105 can determine the first identifier corresponding to the virtualization layer 102 and generate a corresponding first vector, which represents the uniqueness and basic attributes of the virtualization layer 102. Multiple key configuration features are extracted and analyzed, generating a corresponding second vector for each feature. These second vectors can contain key information about the configuration of the virtualization layer 102, such as resource allocation and virtual device settings. By combining the first vector and multiple second vectors, and according to a preset algorithm or strategy (which can be set according to actual application needs, and this embodiment of the invention does not specifically limit it), multiple first data encryption rules for the virtualization layer 102 are determined. These rules can specify in detail the encryption method and key management security requirements for data in the virtualization layer 102. Based on these first data encryption rules, the system generates a target access control list corresponding to the virtualization layer 102. This list can not only contain which users or applications can access data in the virtualization layer 102, but also specify the encryption requirements and security policies for data during transmission and storage.
[0119] For example, the China Telecom Cloud Elastic Bare Metal Server can be deployed using the China Telecom Cloud Zijing DPU Smart NIC + Server approach. By deploying the China Telecom Cloud Elastic Bare Metal Server in the branch office's security stack private cloud test environment module, a cloud test platform can be built, constructing various cloud and security service deployment test scenarios. This provides strong support for deploying China Telecom Cloud Elastic Bare Metal Servers and better serving various private cloud and full-stack cloud customers.
[0120] This embodiment can automatically generate encryption rules and access control lists based on the configuration characteristics of the virtualization layer 102, improving the security and management efficiency of the private cloud network. Simultaneously, through granular data encryption and access control, it reduces the risk of data leakage and unauthorized access, providing strong protection for the stable operation of the private cloud network.
[0121] In some embodiments of the present invention, the target layer is the application layer 104, and the first information includes configuration information of multiple applications.
[0122] Extract several key configuration features from the first information, including:
[0123] Feature extraction is performed on the configuration information of multiple applications to obtain the key configuration features of multiple applications.
[0124] Accordingly, based on the target layer category and its corresponding multiple key configuration features, a target access control list is generated, including:
[0125] Determine the second identifier corresponding to hardware layer 101, and generate the third vector corresponding to the second identifier.
[0126] Determine multiple third identifiers corresponding to each application, and generate multiple fourth vectors corresponding to these third identifiers.
[0127] Identify multiple fifth vectors corresponding to key configuration features of multiple applications.
[0128] Multiple second data encryption rules corresponding to application layer 104 are determined based on the third vector, multiple fourth vectors, and multiple fifth vectors.
[0129] A target access control list corresponding to application layer 104 is generated based on multiple second data encryption rules.
[0130] See Figure 5 , Figure 5 This is a flowchart illustrating another method for constructing a private cloud network disclosed herein, primarily used to describe the interaction process between the security protection layer 105 and the application layer 104.
[0131] Specifically, the above-mentioned interaction process may include B101 to B105.
[0132] B101: Application layer 104 sends application layer 104 configuration information to security protection layer 105, which includes configuration information for multiple applications.
[0133] B102: Key configuration feature extraction includes the security protection layer 105 performing feature extraction on the configuration information of multiple applications to obtain key configuration features of multiple applications.
[0134] B103: The vector calculation process includes the security protection layer 105 determining the second identifier corresponding to the application layer 104 and generating the third vector corresponding to the second identifier. Multiple third identifiers corresponding to each application are determined, and multiple fourth vectors corresponding to these third identifiers are generated.
[0135] B104: Access control list generation includes security protection layer 105 determining multiple second data encryption rules corresponding to application layer 104 based on third vectors, multiple fourth vectors, and multiple fifth vectors. A target access control list corresponding to application layer 104 is generated based on these multiple second data encryption rules.
[0136] B105: Security layer 105 sends an access control list to application layer 104.
[0137] This embodiment significantly improves the security and management efficiency of the private cloud network application layer 104 by automatically extracting key features of application configuration and generating data encryption rules and access control lists, and reduces potential security risks.
[0138] In some embodiments of the present invention, the target layer is the management layer 103. The first information includes configuration information for multiple management users.
[0139] Extract several key configuration features from the first information, including:
[0140] Feature extraction was performed on the configuration information of multiple management users to obtain the key configuration features of multiple management users.
[0141] Accordingly, based on the target layer category and its corresponding multiple key configuration features, a target access control list is generated, including:
[0142] Determine the fourth identifier corresponding to management level 103, and generate the sixth vector corresponding to the fourth identifier.
[0143] Determine the management permissions of each management user, generate multiple fifth identifiers based on the management permissions of each management user, and generate multiple seventh vectors corresponding to the multiple fifth identifiers.
[0144] Identify multiple eighth vectors for key configuration characteristics of multiple management users.
[0145] The security level of each management user is determined based on the sixth vector, multiple seventh vectors, and multiple eighth vectors.
[0146] Generate the target access control list corresponding to management layer 103 based on the security level of each management user.
[0147] See Figure 6 , Figure 6 This is a flowchart illustrating another method for constructing a private cloud network disclosed herein, primarily used to describe the interaction process between the security protection layer 105 and the management layer 103.
[0148] Specifically, the above-mentioned interaction process may include C101 to C106.
[0149] C101: The management layer 103 sends configuration information for multiple management users to the security protection layer 105.
[0150] C102: Key configuration feature extraction includes the security protection layer 105 performing feature extraction on the configuration information of multiple management users to obtain key configuration features of multiple management users.
[0151] C103: The vector calculation process includes: the security protection layer 105 determining the fourth identifier corresponding to the management layer 103, and generating the sixth vector corresponding to the fourth identifier; determining the management permissions of each management user, and based on the management permissions of each management user, determining multiple fifth identifiers, and generating multiple seventh vectors corresponding to the multiple fifth identifiers; and determining multiple eighth vectors corresponding to the key configuration features of the multiple management users.
[0152] C104: Determining the security level includes security protection layer 105. Based on the sixth vector, multiple seventh vectors, and multiple eighth vectors, the security level of each management user is determined.
[0153] C105: Access Control List Generation includes generating a target access control list corresponding to the management layer 103 based on the security level of each management user, using security layer 105.
[0154] C106: Security layer 105 sends an access control list to management layer 103.
[0155] This embodiment transforms the fourth identifier corresponding to the management layer 103 into a sixth vector and the management permissions of management users into multiple seventh vectors, enabling the system to quantitatively evaluate the permission level of each management user and providing data support for formulating access control policies.
[0156] In some embodiments of the present invention, the target layer is hardware layer 101. The first information includes hardware configuration information of multiple hardware components.
[0157] Extract several key configuration features from the first information, including:
[0158] Feature extraction is performed on the hardware configuration information of multiple hardware components to obtain key configuration features of the multiple hardware components.
[0159] Accordingly, based on the target layer category and its corresponding multiple key configuration features, a target access control list is generated, including:
[0160] Determine the sixth identifier corresponding to hardware layer 101, and generate the ninth vector corresponding to the sixth identifier.
[0161] Determine multiple seventh identifiers corresponding to each hardware component, and generate multiple tenth vectors corresponding to the seventh identifiers.
[0162] Determine multiple eleventh vectors for key configuration features of multiple hardware components.
[0163] The access level of each piece of hardware is determined based on the ninth vector and multiple tenth vectors.
[0164] The target access control list for hardware layer 101 is determined based on the access levels of each hardware component and multiple eleventh vectors.
[0165] For example, security layer 105 can receive hardware configuration information from multiple hardware devices and perform feature extraction on this hardware configuration information to obtain key configuration features for each hardware device. These features may include the hardware model, performance parameters, and security settings. A target access control list is generated based on the category of hardware layer 101 (i.e., hardware layer 101 itself) and these key configuration features. A sixth identifier corresponding to hardware layer 101 is determined, and a corresponding ninth vector is generated. Simultaneously, a seventh identifier is determined for each hardware device, and a corresponding tenth vector is generated. These vectors can be seen as unique identifiers for hardware layer 101 and each hardware device in the access control list. By combining the ninth vector, multiple tenth vectors, and the eleventh vector of the key configuration features of multiple hardware devices, the access level of each hardware device can be comprehensively evaluated. The determination of the access level includes considerations of hardware security and importance. Based on the access level and key configuration features of each hardware device, the system can generate a target access control list for hardware layer 101. This list specifies in detail which hardware devices have what access permissions, thereby ensuring the security of hardware layer 101 and the effectiveness of access control.
[0166] See Figure 7 , Figure 7 This is a flowchart illustrating another method for constructing a private cloud network disclosed herein, primarily used to describe the interaction process between the security protection layer 105 and the hardware layer 101.
[0167] Specifically, the above-mentioned interaction process may include D101 to D105.
[0168] D101: Hardware layer 101 sends hardware layer 101 configuration information to security protection layer 105.
[0169] D102: Key configuration feature extraction includes the security protection layer 105 performing feature extraction on the hardware configuration information of multiple hardware components to obtain key configuration features of multiple hardware components.
[0170] D103: The vector calculation process includes: security layer 105 determining the sixth identifier corresponding to hardware layer 101 and generating the ninth vector corresponding to the sixth identifier; determining multiple seventh identifiers corresponding to each hardware component and generating multiple tenth vectors corresponding to the multiple seventh identifiers; and determining multiple eleventh vectors corresponding to the key configuration features of multiple hardware components in hardware layer 101.
[0171] D104: Access control list generation includes security protection layer 105 determining the access level of each hardware component based on the ninth vector and multiple tenth vectors. The target access control list for hardware layer 101 is determined based on the access level of each hardware component and multiple eleventh vectors.
[0172] D105: Security layer 105 sends an access control list to hardware layer 101.
[0173] This embodiment enables fine-grained control over access permissions at hardware layer 101, ensuring that only qualified hardware can obtain the corresponding access permissions. Determining access levels based on key hardware configuration characteristics ensures that only hardware with sufficient security and reliability can obtain higher-level access permissions, thereby improving the security of the entire private cloud network.
[0174] In some embodiments of the present invention, a method for constructing a private cloud network further includes:
[0175] In response to receiving the second information, the security coefficient of the target layer is determined based on the second information, which includes log information and event information of the target layer.
[0176] The security strategy for the target layer is determined based on the security factor.
[0177] Send the security policy to the target layer.
[0178] In this embodiment, the target layer may include a hardware layer 101, a virtualization layer 102, an application layer 104, or a management layer 103. The second information may include security information of the target layer.
[0179] For example, security layer 105 can receive security information from application layer 104. This security information may include user behavior information, business transaction information, performance metrics information, log information, and business rules and policies information. A security coefficient is determined based on the analysis and evaluation results of the security information. A corresponding security policy is matched based on the security coefficient. The security policy may include deploying application firewalls, attack behavior detection, and security scanning.
[0180] For example, security policies may also include physical alarms, hardware encryption, virtual machine isolation, virtual machine security monitoring, virtual device migration policies, automated troubleshooting and recovery, access control, data encryption, identity authentication, access control, firewall rules, and intrusion detection rules.
[0181] For example, security policies can be automatically updated based on security logs, event information, and security protection data for the hardware, virtualization, management, and application layers. Security protection data includes security protection types, the number of security protection attempts, and the number of risks.
[0182] See Figure 8 , Figure 8 This is a flowchart illustrating another method for constructing a private cloud network disclosed herein, primarily used to describe the interaction process between the security protection layer 105 and the target layer.
[0183] Specifically, the above-mentioned interaction process may include E101 to E104.
[0184] E101: The target layer sends target layer information to the security protection layer 105.
[0185] E102: Security factor calculation includes the security protection layer 105 responding to the received target layer information and determining the security factor of the target layer based on the target layer information, which includes the target layer's log information and event information.
[0186] E103: Matching security strategies includes security protection layer 105, which determines the security strategy of the target layer based on the security coefficient.
[0187] E104: Security protection layer 105 sends security policies to the target layer.
[0188] This embodiment, by monitoring the target layer's log and event information in real time, can promptly detect and respond to potential security risks, ensuring the real-time security of the private cloud network. Security policies based on security coefficients can formulate effective defenses against specific security risks, improving the effectiveness of the security strategy. This embodiment can dynamically adjust the security policy according to the security status of the target layer, achieving automation, reducing the need for manual intervention, and lowering management costs and error rates.
[0189] Corresponding to the above embodiment of a private cloud network construction method, Figure 9 This is a structural block diagram of a private cloud network construction apparatus according to an embodiment of this disclosure. For ease of explanation, only the parts relevant to the embodiment of this disclosure are shown. References Figure 9 A private cloud network construction method apparatus 20, applied to the security protection layer of a private cloud network system, includes:
[0190] The first data processing module 21 is used to extract multiple key configuration features of the first information in response to receiving the first information. The first information is configuration information sent by the target layer, which is the hardware layer 101, virtualization layer 102, application layer 104, or management layer 103 in the private cloud network system.
[0191] The second data processing module 22 is used to generate a target access control list based on the target layer's category and corresponding multiple key configuration features.
[0192] The third data processing module 23 is used to send the target access control list to the target layer.
[0193] In some embodiments of the present invention, the target layer is the virtualization layer 102, and the first information includes resource configuration information and virtual device configuration information.
[0194] The first data processing module 21 is specifically used to match resource configuration information with the first database to determine multiple key resource configuration features. The first database includes multiple standard key resource configuration information.
[0195] The virtual device configuration information is matched with the second database to determine several key virtual device configuration characteristics. The second database includes multiple standard virtual device configuration information.
[0196] Multiple key configuration features are determined based on multiple key resource configuration features and multiple key virtual device configuration features.
[0197] In some embodiments of the present invention, the target layer is virtualization layer 102.
[0198] The second data processing module 22 is specifically used to determine the first identifier corresponding to the virtualization layer 102 and generate the first vector corresponding to the first identifier.
[0199] Determine multiple second vectors corresponding to multiple key configuration features.
[0200] Multiple first data encryption rules corresponding to virtualization layer 102 are determined based on the first vector and multiple second vectors.
[0201] The target access control list corresponding to the virtualization layer 102 is generated based on multiple first data encryption rules.
[0202] In some embodiments of the present invention, the target layer is the application layer 104, and the first information includes configuration information of multiple applications.
[0203] The first data processing module 21 is specifically used to extract features from the configuration information of multiple applications to obtain the key configuration features of multiple applications.
[0204] The second data processing module 22 is specifically used to determine the second identifier corresponding to the hardware layer 101 and generate the third vector corresponding to the second identifier.
[0205] Determine multiple third identifiers corresponding to each application, and generate multiple fourth vectors corresponding to these third identifiers.
[0206] Identify multiple fifth vectors corresponding to key configuration features of multiple applications.
[0207] Multiple second data encryption rules corresponding to application layer 104 are determined based on the third vector, multiple fourth vectors, and multiple fifth vectors.
[0208] A target access control list corresponding to application layer 104 is generated based on multiple second data encryption rules.
[0209] In some embodiments of the present invention, the target layer is the management layer 103. The first information includes configuration information for multiple management users.
[0210] The first data processing module 21 is specifically used to extract features from the configuration information of multiple management users to obtain the key configuration features of multiple management users.
[0211] The second data processing module 22 is specifically used to determine the fourth identifier corresponding to the management layer 103 and generate the sixth vector corresponding to the fourth identifier.
[0212] Determine the management permissions of each management user, generate multiple fifth identifiers based on the management permissions of each management user, and generate multiple seventh vectors corresponding to the multiple fifth identifiers.
[0213] Identify multiple eighth vectors for key configuration characteristics of multiple management users.
[0214] The security level of each management user is determined based on the sixth vector, multiple seventh vectors, and multiple eighth vectors.
[0215] Generate the target access control list corresponding to management layer 103 based on the security level of each management user.
[0216] In some embodiments of the present invention, the target layer is hardware layer 101. The first information includes hardware configuration information of multiple hardware components.
[0217] The first data processing module 21 is specifically used to extract features from the hardware configuration information of multiple hardware devices to obtain key configuration features of the multiple hardware devices.
[0218] The second data processing module 22 is specifically used to determine the sixth identifier corresponding to the hardware layer 101 and generate the ninth vector corresponding to the sixth identifier.
[0219] Determine multiple seventh identifiers corresponding to each hardware component, and generate multiple tenth vectors corresponding to the seventh identifiers.
[0220] Determine multiple eleventh vectors for key configuration features of multiple hardware components.
[0221] The access level of each piece of hardware is determined based on the ninth vector and multiple tenth vectors.
[0222] The target access control list for hardware layer 101 is determined based on the access levels of each hardware component and multiple eleventh vectors.
[0223] In some embodiments of the present invention, a private cloud network construction method apparatus 20, applied to a security protection layer in a private cloud network system, further includes:
[0224] The fourth data processing module is used to respond to the received second information and determine the security coefficient of the target layer based on the second information, which includes log information and event information of the target layer.
[0225] The fifth data processing module is used to determine the security strategy of the target layer based on the security factor.
[0226] The sixth data processing module is used to send security policies to the target layer.
[0227] The content of the method embodiments of the present invention is applicable to the device embodiments. The specific functions implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.
[0228] On the other hand, embodiments of the present invention also provide an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned sensitive information method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0229] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0230] like Figure 10 As shown, Figure 10 This illustration shows a specific example of the hardware structure of an electronic device 1000 according to one embodiment. The electronic device 1000 includes:
[0231] The processor 1001 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present invention.
[0232] The memory 1002 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 1002 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1002 and is called and executed by the processor 1001 to execute the network node population optimization method of the embodiments of this invention.
[0233] Input / output interface 1003 is used to implement information input and output;
[0234] The communication interface 1004 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0235] Bus 1005 transmits information between various components of the device (e.g., processor 1001, memory 1002, input / output interface 1003, and communication interface 1004);
[0236] The processor 1001, memory 1002, input / output interface 1003 and communication interface 1004 are connected to each other within the device via bus 1005.
[0237] The electronic device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0238] The content of the method embodiments of the present invention is applicable to the embodiments of the present electronic device. The specific functions implemented by the embodiments of the present electronic device are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.
[0239] Another aspect of this invention provides a computer-readable storage medium storing a program that is executed by a processor to implement the aforementioned method.
[0240] It should be noted that the computer-readable medium shown in the embodiments of the present invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD to ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the present invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, wherein computer-readable program code is carried. Such transmitted data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0241] The content of the method embodiments of the present invention is applicable to the computer-readable storage medium embodiments. The specific functions implemented by the computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.
[0242] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions, causing the computer device to perform the aforementioned method.
[0243] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0244] It should be noted that although several modules for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0245] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, portable hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the method according to the embodiments of the present invention.
[0246] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this invention are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is changed and sub-operations described as part of a larger operation are executed independently.
[0247] Furthermore, although the invention has been described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the invention. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional skill of an engineer. Therefore, those skilled in the art can implement the invention as set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of the invention, which is determined by the full scope of the appended claims and their equivalents.
[0248] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0249] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution means, apparatus, or device (such as a computer-based device, a processor-including device, or other means that can fetch and execute instructions from, or in conjunction with, an instruction execution means, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution means, apparatus, or device.
[0250] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0251] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution device. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0252] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0253] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
[0254] The above is a detailed description of the preferred embodiments of the present invention. However, the present invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the present invention. All such equivalent modifications or substitutions are included within the scope defined by the claims of the present invention.
Claims
1. A method for constructing a private cloud network, characterized in that, A security protection layer applied to a private cloud network system, the method comprising the following steps: In response to the received first information, extract multiple key configuration features that obtained the first information; The first information includes configuration information sent by the target layer; the target layer includes the hardware layer, virtualization layer, application layer, or management layer in the private cloud network system. Based on the target layer's specific categories and key configuration features, a target access control list is compiled. Send the target access control list to the target layer.
2. The method for constructing a private cloud network according to claim 1, characterized in that, When the target layer is the virtualization layer, the first information includes resource configuration information and virtual device configuration information; the extraction of multiple key configuration features to obtain the first information includes the following steps: The resource configuration information is matched with a first database to determine multiple key resource configuration features; the first database includes multiple standard key resource configuration information. The virtual device configuration information is matched with a second database to determine several key virtual device configuration features; the second database includes several standard virtual device configuration information. The key configuration features are obtained by organizing the key resource configuration features and the key virtual device configuration features.
3. The method for constructing a private cloud network according to claim 1, characterized in that, When the target layer is the virtualization layer; the process of compiling a target access control list based on the target layer's specific category and key configuration features includes the following steps: The first identifier corresponding to the virtualization layer is determined according to the specific category of the virtualization layer, and the first identifier is vectorized to obtain the first vector; Each of the key configuration features is vectorized to obtain multiple second vectors; Based on the first vector and multiple second vectors, multiple first data encryption rules corresponding to the virtualization layer are determined; The target access control list corresponding to the virtualization layer is generated based on multiple of the first data encryption rules.
4. The method for constructing a private cloud network according to claim 1, characterized in that, When the target layer is the application layer, the first information includes application configuration information of multiple target applications, and the multiple key configuration features are obtained by feature extraction based on the application configuration information of each target application; The process of compiling a target access control list based on the target layer's specific categories and key configuration features includes the following steps: The second identifier corresponding to the application layer is determined according to the specific category of the application layer, and the second identifier is vectorized to obtain the third vector; Obtain the third identifier corresponding to each target application, and perform vectorization processing on each third identifier to obtain multiple fourth vectors; The key configuration features corresponding to each target application are vectorized to obtain multiple fifth vectors; Based on the third vector, multiple fourth vectors, and multiple fifth vectors, multiple second data encryption rules corresponding to the application layer are determined; The target access control list corresponding to the application layer is generated based on multiple of the second data encryption rules.
5. The method for constructing a private cloud network according to claim 1, characterized in that, When the target layer is the management layer, the first information includes user configuration information of multiple management users, and the multiple key configuration features are obtained by feature extraction based on the user configuration information of each management user. The process of compiling a target access control list based on the target layer's specific categories and key configuration features includes the following steps: The fourth identifier corresponding to the management level is determined based on the exclusive category of the management level, and the fourth identifier is vectorized to obtain the sixth vector. Obtain the fifth identifier corresponding to each of the management users, and perform vectorization processing on each of the fifth identifiers to obtain multiple seventh vectors; The key configuration features corresponding to each management user are vectorized to obtain multiple eighth vectors; The security level of each management user is determined based on the sixth vector, multiple seventh vectors, and multiple eighth vectors. The target access control list corresponding to the management layer is generated based on the security level of each management user.
6. The method for constructing a private cloud network according to claim 1, characterized in that, When the target layer is the hardware layer, the first information includes hardware configuration information of multiple target hardwares, and the multiple key configuration features are obtained by feature extraction based on the hardware configuration information of each target hardware. The process of compiling a target access control list based on the target layer's specific categories and key configuration features includes the following steps: The sixth identifier corresponding to the hardware layer is determined according to the exclusive category of the hardware layer, and the sixth identifier is vectorized to obtain the ninth vector; Obtain the seventh identifier corresponding to each of the target hardware devices, and perform vectorization processing on each of the seventh identifiers to obtain multiple tenth vectors; The key configuration features corresponding to each target hardware are vectorized to obtain multiple eleventh vectors; The access level of each target hardware is determined based on the ninth vector and multiple tenth vectors; The target access control list corresponding to the hardware layer is determined based on the access level of each of the target hardware and the plurality of eleventh vectors.
7. The method for constructing a private cloud network according to claim 1, characterized in that, The method further includes the following steps: In response to the received second information, the security factor of the target layer is determined based on the second information; The second information includes the log information and event information of the target layer; The security strategy for the target layer is determined based on the security factor. The security policy is sent to the target layer.
8. A private cloud network construction device, characterized in that, Security layers applied to private cloud network systems include: The first data processing module is used to extract multiple key configuration features of the first information in response to the received first information. The first information includes configuration information sent by the target layer; the target layer includes the hardware layer, virtualization layer, application layer, or management layer in the private cloud network system. The second data processing module is used to compile a target access control list based on the target layer's exclusive category and the key configuration features. The third data processing module is used to send the target access control list to the target layer.
9. An electronic device, characterized in that, Including the processor and memory; The memory is used to store programs; The processor executes the program to implement the method as described in any one of claims 1 to 7.
10. A computer storage medium storing a processor-executable program, characterized in that, The processor-executable program, when executed by the processor, is used to implement the method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network security management method and electronic equipment
CN114679290A
Cloud side-end collaborative zero-trust access control method and system based on trusted label
CN115118465A