A Microservice Security Control Method in a Container Cloud Environment

By obtaining and synchronizing the registration center data in real time to the microservice security framework, combining policy databases and monitoring tools, the problem of traditional firewalls being difficult to monitor and control service communications in the microservice architecture is solved, and comprehensive security management and monitoring of the microservice environment is realized.

CN119652678BActive Publication Date: 2025-06-13TAIJI COMPUTER CORPORATION LIMITED
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510170037.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-06-13
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

Traditional firewalls are difficult to effectively monitor and control communication between services in microservice architectures, especially when the number of service instances and IP addresses are frequently changed, resulting in an increase in security threats at the application layer.

Method used

By obtaining the registration service and service change data of the registration center in real time, synchronizing it to the microservice security framework, combining preset policy databases for security policy configuration, reviewing service subscription information and performing security control, and monitoring and evaluating the security of service instances in real time through monitoring tools.

Benefits of technology

It realizes comprehensive security management and monitoring of the microservice environment, effectively ensures the security of the microservice system, improves the stability and reliability of the system, reduces security risks, and promptly detects and responds to potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652678B_ABST
    Figure CN119652678B_ABST
Patent Text Reader

Abstract

The present invention provides a microservice security control method in a container cloud environment, which relates to the technical field of microservice security and includes: obtaining in real time the registered services and service change data of each registry center, outputting a service instance list, and synchronizing it to the microservice security framework through corresponding interfaces in a preset interface group; combining with a preset policy database, and performing security policy configuration on each service instance through the microservice security framework to output a policy configuration table; auditing the received service subscription information and service content and configuring security control information; performing security control on the service calls of service consumers to output service results after service security control; capturing in real time the monitoring data of each service instance, and performing security auditing and risk assessment to output security auditing results. The present invention can ensure the security of the microservice system, improve the stability and reliability of the system, reduce security risks, and timely discover and respond to potential security threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of microservice security, and particularly to a microservice security control method in a container cloud environment. Background Art

[0002] The microservice architecture is a distributed system, and its communication process involves the interaction between multiple service instances. This complexity makes it difficult for application layer access control technologies to effectively monitor and control the communication between services.

[0003] Traditional firewalls rely on static signature libraries to identify and intercept attack data. Traditional firewalls mainly set access control lists (ACLs) based on network layer TCP and IP addresses, and have insufficient protection capabilities against application layer attacks. Due to the elastic scaling and IP masking characteristics of the microservice architecture, the number of service instances and IP addresses change frequently. This makes it difficult for the application layer access control technology of traditional firewalls to accurately identify and track service instances, increasing the difficulty of security control, and the security threats at the application layer are increasing day by day, and the limitations of traditional firewalls are becoming more and more obvious.

[0004] Therefore, the present invention provides a microservice security control method in a container cloud environment. Summary of the Invention

[0005] The present invention provides a microservice security control method in a container cloud environment, which effectively ensures the security of the microservice system, improves the stability and reliability of the system, reduces security risks, and timely discovers and responds to potential security threats, thereby protecting the information security of service providers and service consumers.

[0006] The present invention provides a microservice security control method in a container cloud environment, including:

[0007] Step 1: Real-time obtain the registered services and service change data of each registry, output a service instance list, and synchronize it to the microservice security framework through the corresponding interfaces in a preset interface group;

[0008] Step 2: Combine a preset policy database, and configure security policies for each service instance in the service instance list through the microservice security framework, and output a policy configuration table;

[0009] Step 3: Based on the policy configuration table, review the received service subscription information and the service content in the corresponding information and configure security control information;

[0010] Step 4: Perform security control on the service calls of service consumers based on the security control information, and output the service result after service security control;

[0011] Step 5: Real-time capture the monitoring data corresponding to each service instance in the microservice security framework through a preset monitoring tool, and conduct security auditing and risk assessment, and output the security auditing results.

[0012] Preferably, the real-time acquisition of the registered services and service change data of each registry, and output the service instance list, including:

[0013] Establish interactive communication with each registry through a preset service abstraction layer. At the same time, allocate corresponding adapters for each registry through a preset adapter pattern, establish a registry-adapter comparison table, and monitor the registered services and service change data in the corresponding registry in real time through the adapters in the registry-adapter comparison table, and output the service instance list.

[0014] Preferably, the synchronization to the microservice security framework through the corresponding interfaces in the preset interface group includes:

[0015] Obtain the service call information across applications and the corresponding service call requirements, match the corresponding interfaces in the preset interface group based on the service call requirements, and synchronously register each service in the service instance list to the microservice security framework in a preset registration manner for service management.

[0016] Preferably, the service management includes: service group management, service online, service offline, service and interface suspension, service and interface recovery, service and interface disablement, service and interface enablement capabilities.

[0017] Preferably, before configuring the security policies for each service instance in the service instance list through the microservice security framework, it includes:

[0018] Conduct feature recognition and extraction on the service instances in the service instance list, establish a service feature set, and select an appropriate security control policy from the preset policy database to construct a feature-policy mapping diagram.

[0019] Preferably, in step 2, it also includes:

[0020] Based on the preset policy database and the feature-policy mapping diagram, and configure the security policies for each service instance in the service instance list through the microservice security framework, and output a policy configuration table, where the security policies include black and white lists, time period restrictions, traffic restrictions, domain name restrictions, namespace restrictions.

[0021] Preferably, in step 3, it includes:

[0022] Determine the service requirements that the service consumer needs to call, where the service requirements include service type, service group, specific service content, and the corresponding interface information;

[0023] Based on the service requirements, the service consumer submits a service subscription request through the microservice security framework. The service subscription request includes the authentication information of the service consumer and the details of the service to be subscribed.

[0024] Obtain service provider information that matches the service subscription request through the microservice security framework, and send the service subscription request to the corresponding service provider for review.

[0025] The service provider reviews the received service subscription request through the microservice security framework, conducts a comparative analysis with the service scope and service requirements corresponding to the service provider, and determines the service subscription requests whose comparison results meet the preset conditions as qualified subscription requests.

[0026] Based on the service requirements and security requirements of the service consumer, and based on the policy configuration table, determine and set the access security policies corresponding to each service instance. Among them, the access security policies include function permission control methods based on users, roles, identities, and organizational structures, as well as time limit, access frequency limit, transmission encryption policies, and data permission scope limit methods.

[0027] Preferably, in step 4, it includes:

[0028] Combined with the preset application access control method, conduct security verification and analysis on the access security policies and data scope review results, and perform security control on the service call information and the corresponding service content based on the verification and analysis results. Among them, the preset application access control method includes function permission control methods and data permission control methods.

[0029] Determine the access data content scope of the service consumer corresponding to each service instance, dynamically configure the access data content scope of each service consumer in real time based on the preset dynamic feature library, and conduct a comparative analysis with the actual data content scope corresponding to each service subscription request, and output the service content that meets the data scope review.

[0030] Preferably, in step 5, it includes:

[0031] Obtain the monitoring requirements of the user, output the monitoring requirement information, select a monitoring tool that matches the monitoring requirement information from the preset monitoring tool library. At the same time, determine the data type of the data to be monitored and the corresponding monitoring content based on the monitoring requirement information, and output the information of the data to be monitored.

[0032] Obtain the data corresponding to the information of the data to be monitored in real time through the monitoring tool, and output the real-time monitoring data.

[0033] Perform type analysis on the real-time monitoring data to obtain performance monitoring data, status monitoring data, and security monitoring data respectively;

[0034] Meanwhile, combine the dynamic feature library to perform feature recognition, extraction, and matching on the real-time monitoring data, and output the real-time feature set of the monitoring data;

[0035] Select historical monitoring data that matches the real-time feature set of the monitoring data in the historical database, and input it into a preset prediction and early warning model for model training and optimization, and output a service prediction and early warning analysis model;

[0036] Based on the prediction and early warning analysis model, and combine a preset abnormal database to perform early warning analysis on the real-time monitoring data, annotate and collect information on service instances that meet the preset early warning trigger conditions, and output the early warning analysis result;

[0037] Meanwhile, based on the prediction and early warning analysis model, perform comparative analysis on the historical monitoring data and the real-time monitoring data to determine the operation trend of each service instance, and output the prediction analysis result;

[0038] Select audit indicators and risk analysis indicators that match the monitoring requirement information in the indicator database, and output an audit-risk indicator set;

[0039] Based on the audit-risk indicator set, and combine the early warning analysis result and the prediction analysis result to perform audit and risk analysis on the security policy, access control, and data security in the microservice security framework, and output the security audit result.

[0040] A microservice security control method in a container cloud environment provided by the present invention realizes comprehensive security management and monitoring of the microservice environment by obtaining service data from the registration center in real time and synchronizing it to the microservice security framework, configuring security policies in combination with a preset policy database, auditing service subscription information and performing security control, and monitoring and evaluating the security of service instances in real time through a monitoring tool. The present invention can effectively ensure the security of the microservice system, improve the stability and reliability of the system, reduce security risks, and timely discover and respond to potential security threats, thereby protecting enterprise information security and business continuous operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0042] Figure 1It is a schematic flowchart of a microservice security control method in a container cloud environment provided by an embodiment of the present invention. Detailed implementation manners

[0043] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0044] As Figure 1 shown, a microservice security control method in a container cloud environment provided by an embodiment of the present invention includes:

[0045] Step 1: Real-time obtain the registered services and service change data of each registry, output a service instance list, and synchronize it to the microservice security framework through the corresponding interfaces in a preset interface group;

[0046] Step 2: Combine a preset policy database, and configure security policies for each service instance in the service instance list through the microservice security framework, and output a policy configuration table;

[0047] Step 3: Audit the received service subscription information and the service content in the corresponding information based on the policy configuration table and configure security control information;

[0048] Step 4: Perform security control on the service calls of service consumers based on the security control information, and output a service result after service security control;

[0049] Step 5: Real-time capture the monitoring data corresponding to each service instance in the microservice security framework through a preset monitoring tool, and perform security auditing and risk assessment, and output a security auditing result.

[0050] In this embodiment, the registry: a core component in the microservice architecture, used to register and discover the locations and network information of each microservice instance, acting as a service registry, allowing microservices to discover and communicate with each other, such as Nacos, Consul, Eureka, and Kubernetes, etc.;

[0051] In this embodiment, the registered service: the process of registering a microservice instance to the registry so that other microservices or clients can discover and access the service;

[0052] In this embodiment, the service change data: the state change of the microservice instance in the registry, such as the registration of a new service, the offline of a service instance, etc.;

[0053] In this embodiment, the service instance list: a list containing all microservice instances registered in the registry, usually including information such as service name, IP address, port number, etc.;

[0054] In this embodiment, the preset interface group: a logical grouping composed of multiple predefined interfaces, used to synchronize service data in the registry in the microservice security framework, facilitating unified management of multiple interfaces with similar management methods;

[0055] In this embodiment, the microservice security framework: a tool or platform for managing and protecting the security of microservices, including functions such as security policy configuration, security control, and security auditing;

[0056] In this embodiment, the preset policy database: contains predefined security policies and rules, used for security policy configuration of microservice instances;

[0057] In this embodiment, security policy configuration: according to the rules in the preset policy database, perform security configuration on microservice instances to ensure the security and compliance of the services;

[0058] In this embodiment, the policy configuration table: a table or data structure containing microservice instance security policy configuration information, used to record and manage the security configuration of each service instance;

[0059] In this embodiment, service subscription information: the subscription relationship between microservices or between the client and microservices, including information such as the subscribed service name, version, interface, etc.;

[0060] In this embodiment, service content: the specific service content included in the service subscription information, such as the function of the service, data format, access rights, etc.;

[0061] In this embodiment, security control information: review and security control of the received service subscription information to ensure that the subscribed service content complies with security policies and regulations;

[0062] In this embodiment, the preset monitoring tool: a pre-configured tool or software for monitoring service instances in the microservice security framework, used to capture monitoring data in real time and perform security auditing and risk assessment. For example, log monitoring tools, Metrics monitoring tools, and call chain monitoring tools;

[0063] In this embodiment, monitoring data: data such as the running status, performance metrics, and abnormal conditions of each service instance in the microservice security framework captured in real time by the preset monitoring tool;

[0064] In this embodiment, security audit: review and evaluate the security of service instances in the microservice security framework to confirm compliance with security standards and policy requirements;

[0065] In this embodiment, risk assessment: assess and analyze potential security risks in the microservice environment to determine potential security threats and the degree of impact;

[0066] In this embodiment, security audit results: the evaluation results and audit reports on the security of service instances in the microservice security framework, including discovered security issues, recommended improvement measures, etc.

[0067] Implementation principle and beneficial effects of this embodiment: The present invention realizes comprehensive security management and monitoring of the microservice environment by obtaining service data from the registry in real time and synchronizing it to the microservice security framework, configuring security policies for service instances in combination with a preset policy database, auditing service subscription information and performing security control, and monitoring and evaluating the security of service instances in real time through monitoring tools. The present invention can effectively ensure the security of the microservice system, improve the stability and reliability of the system, reduce security risks, and timely detect and respond to potential security threats. Through continuously updated registry data and preset policy databases, combined with the security policy configuration of the microservice security framework and the real-time monitoring of the monitoring tools, dynamic security management and control are performed on microservice instances. Furthermore, through security audit and risk assessment of service instances, security audit results can be output to help enterprises timely discover security issues and take corresponding measures, thereby ensuring enterprise information security and business continuous operation.

[0068] A microservice security control method in a container cloud environment provided by an embodiment of the present invention obtains the registered services and service change data of each registry in real time and outputs a list of service instances, including:

[0069] Establish interactive communication with each registry through a preset service abstraction layer. At the same time, assign corresponding adapters to each registry through a preset adapter pattern, establish a registry - adapter comparison table, and monitor the registered services and service change data in the corresponding registry in real time through the adapters in the registry - adapter comparison table, and output a list of service instances.

[0070] In this embodiment, the preset service abstraction layer: a predefined abstract interface layer for interactive communication with each registry, hiding the implementation details of specific registries, making the system easier to expand and maintain;

[0071] In this embodiment, a preset adapter pattern is a design pattern used to unify the functions of different interfaces or classes into a common interface. In this case, the preset adapter pattern is used to assign corresponding adapters to each registry so as to uniformly process the data of different registries;

[0072] In this embodiment, an adapter is a specific implementation in the preset adapter pattern and is responsible for converting the data of different registries into a unified format so that the system can uniformly process it;

[0073] In this embodiment, a registry-adapter correspondence table is a table or data structure that records the adapters corresponding to each registry and is used by the system to find the corresponding adapter according to the identifier of the registry for data processing.

[0074] The implementation principle and beneficial effects of this embodiment: The present invention establishes interactive communication with each registry through a preset service abstraction layer, and assigns an adapter to each registry through a preset adapter pattern, and establishes a registry-adapter correspondence table, realizing real-time monitoring of the registration services and service change data of the registry, and outputting a service instance list. The present invention simplifies the interaction process with different registries, makes the system more flexible and extensible. Through the application of the adapter pattern, the data of different registries can be uniformly processed, improving the maintainability and extensibility of the system. At the same time, real-time monitoring of the data changes in the registry can help the system update the service instance list in a timely manner, maintaining the accuracy and timeliness of the data.

[0075] A microservice security control method in a container cloud environment provided by an embodiment of the present invention synchronizes corresponding interfaces in a preset interface group to a microservice security framework, including:

[0076] Obtain cross-application service call information and corresponding service call requirements, match corresponding interfaces in the preset interface group based on the service call requirements, and synchronously register each service in the service instance list to the microservice security framework in a preset registration manner for service management.

[0077] In this embodiment, service call information is relevant information about cross-application service calls in a container cloud environment, including the source, target, parameters, etc. of the service call;

[0078] In this embodiment, service call requirements are specific requirements or conditions for service calls, such as security requirements, performance requirements, data format requirements, etc.;

[0079] In this embodiment, the interface: the interface defined in the preset interface group, which is used to communicate with the microservice security framework and synchronize the service instance list, is the smallest control unit of the microservice security framework. In the microservice architecture, the interface is the bridge for interaction between services, which defines the communication protocol, data format, and request and response methods between services;

[0080] In this embodiment, the preset registration method: the predefined service registration method, which is used to register service instances into the microservice security framework for management, including registering one by one for each interface or registering in batches through swagger;

[0081] In this embodiment, service management: the process of managing and monitoring service instances, including operations such as registering, updating, and deleting service instances.

[0082] The implementation principle and beneficial effects of this embodiment: According to the obtained cross-application service call information and the corresponding service call requirements, the present invention matches the corresponding interfaces in the preset interface group, and synchronously registers each service in the service instance list to the microservice security framework in the preset registration method, so as to realize the management and monitoring of services. The present invention can help to achieve the unified management and monitoring of service instances, improve the maintainability and security of the system. By matching the service call requirements with the interfaces in the preset interface group, it can ensure that the service calls meet the corresponding requirement conditions. At the same time, the application of the preset registration method can simplify the registration process of service instances, improve the efficiency and accuracy of registration, and then through the service management process, it can help the system to monitor and manage service instances in real time, ensuring the stability and security of the system operation.

[0083] A microservice security control method in a container cloud environment provided by an embodiment of the present invention, where service management includes: service group management, service online, service offline, service and interface suspension, service and interface recovery, service and interface disablement, and service and interface enablement capabilities.

[0084] In this embodiment, service group management: the process of centrally managing and monitoring a group of related services, and the services can be classified and grouped according to business requirements;

[0085] In this embodiment, service online: the process of officially releasing a service instance or service function and making it available for other systems or applications to call and use;

[0086] In this embodiment, service offline: removing a service instance or service function from the system so that it no longer provides services externally;

[0087] In this embodiment, service and interface suspension: temporarily stopping the operation and service provision of a certain service or interface, usually because maintenance or repair is required;

[0088] In this embodiment, service and interface recovery: After a service or interface is paused, it is restarted and restored to its normal operating state.

[0089] In this embodiment, service and interface disabling: Permanently stop the operation and service provision of a certain service or interface, usually because of security or other reasons that require the service or interface to be deactivated.

[0090] In this embodiment, service and interface enabling: Re-enable a previously disabled or paused service or interface so that it can continue to provide services.

[0091] The implementation principle and beneficial effects of this embodiment: Through the organizational management of services, the present invention realizes the classification and grouping management of services; the online and offline of services realizes the control of the service life cycle; the capabilities of service and interface suspension, recovery, disabling, and enabling can flexibly control the operating states of services and interfaces. The present invention can help system administrators better manage and control the operating states of microservices, improving the stability and security of the system. Through service group management, relevant services can be better organized and managed, improving management efficiency.

[0092] A microservice security control method in a container cloud environment provided by an embodiment of the present invention, before performing security policy configuration on each service instance in the service instance list through a microservice security framework, includes:

[0093] Perform feature recognition and extraction on the service instances in the service instance list, establish a service feature set, and select an appropriate security control policy from a preset policy database to construct a feature-policy mapping graph.

[0094] In this embodiment, feature recognition and extraction: By analyzing the attributes and features of service instances, key information is extracted for subsequent security policy configuration, including the functions of services, data processing methods, access control requirements, etc.

[0095] In this embodiment, service feature set: A set of features extracted from service instances, used to describe and identify the characteristics and attributes of each service instance, which can help distinguish different service instances.

[0096] In this embodiment, security control policy: Security rules and control policies defined in a preset policy database, used to ensure the security of service instances, such as access control, data encryption, auditing, etc.

[0097] In this embodiment, feature-policy mapping graph: A chart that maps and associates the features of service instances with appropriate security control policies, so as to select appropriate security policies according to the features of service instances.

[0098] Implementation principle and beneficial effects of this embodiment: By identifying and extracting the characteristics of service instances, the present invention establishes a service feature set, and then matches and adapts security control policies in a preset policy database to construct a feature-policy mapping graph, so as to select appropriate security policies according to the characteristics of service instances. The present invention can help system administrators select suitable security control policies according to the characteristics of service instances, improving the security and protection capabilities of the system. Through feature identification and extraction, the characteristics of each service instance can be more accurately understood, and security policies can be configured in a targeted manner. Establishing a feature-policy mapping graph can make the configuration of security policies more systematic and standardized, improving the efficiency and accuracy of security management.

[0099] In the method for micro-service security control in a container cloud environment provided by an embodiment of the present invention, step 2 further includes:

[0100] Based on a preset policy database and a feature-policy mapping graph, and through a micro-service security framework, security policies are configured for each service instance in the service instance list, and a policy configuration table is output, where the security policies include black and white lists, time period restrictions, traffic restrictions, domain name restrictions, and namespace restrictions.

[0101] In this embodiment, the black and white lists: are used to restrict service instances from allowing or denying interactions with specific resources. The blacklist usually lists resources that are prohibited from being accessed, a list of users or IP addresses that are blocked from accessing. By setting the blacklist, enterprises can quickly block known attack sources and respond to potential threats in a timely manner, while the white list lists resources, IP addresses, or user lists that are allowed to access. Only users in these lists can access the service, and the service only allows trusted sources to access through the white list, which can significantly reduce the risk of being maliciously attacked;

[0102] In this embodiment, the time period restriction: is used to specify the time range during which a service instance can perform specific operations. During the specified time period, the service instance can perform corresponding operations; during other time periods, the operations may be restricted or prohibited;

[0103] In this embodiment, the traffic restriction: restricts the data transmission volume of a service instance to control the network traffic of the service instance, including measures such as restricting the number of requests and bandwidth restrictions, to ensure the effective utilization and security of system resources;

[0104] In this embodiment, the domain name restriction: is used to restrict the range of domain names or host addresses that a micro-service instance can access. By configuring the domain name restriction, it can be ensured that the micro-service instance can only communicate with specified domain names or hosts, preventing unauthorized access or communication from occurring;

[0105] In this embodiment, namespace restriction: a restriction measure in the security policy, used to control the access permissions of microservice instances in a specific namespace. It is a container for organizing and managing objects, usually used to isolate different resources or services to ensure their operation and access within a specific scope.

[0106] Implementation principle and beneficial effects of this embodiment: The present invention configures security policies for each service instance in the service instance list through the microservice security framework and outputs a policy configuration table. The present invention can help system administrators flexibly configure security policies according to the characteristics and security requirements of service instances, thereby strengthening the security protection of service instances. At the same time, through these security control policies, access can be restricted, traffic can be controlled, operation time can be specified, and access permissions can be managed according to user roles, improving the security and controllability of the system.

[0107] A microservice security control method in a container cloud environment provided by an embodiment of the present invention, in step 3, includes:

[0108] Determine the service requirements that the service consumer needs to call, where the service requirements include service type, service group, specific service content, and corresponding interface information;

[0109] Based on the service requirements, the service consumer submits a service subscription request through the microservice security framework. The service subscription request includes the authentication information of the service consumer and the details of the service to be subscribed;

[0110] Obtain the service provider information that matches the service subscription request through the microservice security framework, and send the service subscription request to the corresponding service provider for review;

[0111] The service provider reviews the received service subscription request through the microservice security framework, and conducts a comparative analysis with the service scope and service requirements corresponding to the service provider. The service subscription requests whose comparison results meet the preset conditions are determined as qualified subscription requests;

[0112] Based on the service requirements and security requirements of the service consumer, and based on the policy configuration table, determine and set the access security policies corresponding to each service instance. The access security policies include function permission control methods based on users, roles, identities, and organizational structures, as well as time limit, access frequency limit, transmission encryption policy, and data permission scope limit methods.

[0113] In this embodiment, service consumer: an entity that uses services in the microservice architecture, and they implement their own business logic by calling services;

[0114] In this embodiment, service requirement: the specific requirements of the service consumer for the service, including service type, service group, specific service content, and corresponding interface information;

[0115] In this embodiment, authentication information: data used to confirm the identity of the service consumer to ensure that only legitimate users can access the service;

[0116] In this embodiment, service details: specific information about the service, such as the functions, interfaces, parameters, etc. of the service;

[0117] In this embodiment, service provider information: relevant information about the entity providing the service, including the identity of the service provider, service scope, service requirements, etc.;

[0118] In this embodiment, service scope and service requirements: the coverage of the service provided by the service provider, and the service requirements refer to the specific requirements and restrictions of the service provider for the service;

[0119] In this embodiment, preset conditions: pre-set conditions or rules used to determine whether a service subscription request meets the requirements;

[0120] In this embodiment, qualified request: a service subscription request that has been reviewed and meets the preset conditions;

[0121] In this embodiment, security requirements: security requirements for service subscription requests and access data content, including access time limits, access frequency limits, and transmission encryption policies, etc.;

[0122] In this embodiment, access security policy: a set of rules used to control the access rights and security of service consumers to the service;

[0123] In this embodiment, the function permission control method based on users, roles, identities, and organizational structures: based on the relationships between users, roles, identities, and organizational structures, by assigning users to specific roles and then associating the roles with specific permissions, access control of system resources is achieved. Specifically, a user can be assigned to one or more roles, and each role has specific permissions, and these permissions can be finely controlled and managed based on the user's identity and the organizational structure to which the user belongs;

[0124] In this embodiment, access time limit: the time range during which service consumers can access the service is restricted;

[0125] In this embodiment, access frequency limit: the number of times or frequency of service consumers' access to the service is restricted;

[0126] In this embodiment, transmission encryption policy: the encryption method adopted during data transmission, used to protect the confidentiality and integrity of data.

[0127] Implementation principle and beneficial effects of this embodiment: The microservice security control method in the container cloud environment provided by the present invention realizes fine-grained control over microservice subscription and access through steps such as service requirement determination, subscription request submission and review, and security policy configuration. Based on the function permission control method and other security policies of users, roles, identities, and organizational structures, it ensures that service consumers can only access services within their authorized scope, and at the same time realizes time limit, access frequency limit, transmission encryption, and data permission scope control, thereby improving security and controllability. The present invention realizes the matching and review of subscription requests through the microservice security framework, and combines the security policy configuration table to conduct refined management of the access permissions of service instances, thereby ensuring system security and data protection, reducing security risks, preventing unauthorized access, protecting data privacy, and improving the security and stability of the overall system.

[0128] A microservice security control method in the container cloud environment provided by an embodiment of the present invention, in step 4, includes:

[0129] Combined with a preset application access control method, conduct security verification and analysis on the access security policy and the data scope review result, and based on the verification and analysis result, conduct security control on the service call information and the corresponding service content, where the preset application access control method includes a function permission control method and a data permission control method;

[0130] Determine the access data content scope of the service consumers corresponding to each service instance, and based on the preset dynamic feature library, dynamically configure the access data content scope of each service consumer in real time, and conduct comparative analysis with the actual data content scope corresponding to each service subscription request, and output the service content that meets the data scope review.

[0131] In this embodiment, the access data content scope: the data scope that the service consumer can access, including data type, data volume, etc.;

[0132] In this embodiment, the preset dynamic feature library: a pre-defined set of dynamic features, used for real-time dynamic configuration and analysis of the access data content of service consumers;

[0133] In this embodiment, the actual data content scope: the data scope that the service consumer actually accesses, and conduct comparative analysis with the preset dynamic feature library;

[0134] In this embodiment, the data scope review result: the conclusion obtained after comparative analysis of the access data content scope of the service consumer, used to determine the legality of data access;

[0135] In this embodiment, the preset application access control method: a pre-defined control method for verifying the access security policy and the data scope review result, including a function permission control method and a data permission control method;

[0136] In this embodiment, security verification analysis: combining and analyzing the access security policy and the data scope audit result to ensure the security and compliance of the service;

[0137] In this embodiment, the functional permission control method: a method for controlling and restricting service functions according to the user role or identity, mainly restricting the user's access to and use of system functions, usually based on the user's role and identity, and implemented by assigning different permission sets;

[0138] In this embodiment, the data permission control method: a method for controlling and restricting data access according to the user role or identity, used to restrict the user's access to and use of system data, including data access levels, data classification, and more fine-grained row-level and column-level permission controls.

[0139] The implementation principle and beneficial effects of this embodiment: The present invention uses a preset application access control method to verify and analyze the access security policy and data scope, realizing the security control of service call information and service content. At the same time, by dynamically configuring the access data content scope corresponding to the service instance and combining it with a real-time dynamic feature library for comparative analysis, it effectively ensures that the access data content of service consumers meets security requirements. The present invention combines the functional permission control and data permission control methods, dynamically configures the access data content scope, improves security and flexibility, and at the same time strengthens the security control of service content through real-time comparative analysis, thus realizing more efficient microservice security management and control.

[0140] A microservice security control method in a container cloud environment provided by an embodiment of the present invention, in step 5, includes:

[0141] Obtain the monitoring requirements of the user, output monitoring requirement information, select a monitoring tool that matches the monitoring requirement information from a preset monitoring tool library, and at the same time, determine the data type and corresponding monitoring content of the data to be monitored based on the monitoring requirement information, and output the data information to be monitored;

[0142] Obtain the data corresponding to the data information to be monitored in real time through the monitoring tool, and output the real-time monitoring data;

[0143] Conduct type analysis on the real-time monitoring data to obtain performance monitoring data, status monitoring data, and security monitoring data respectively;

[0144] At the same time, combine the real-time monitoring data with the dynamic feature library for feature recognition, extraction, and matching, and output the real-time feature set of the monitoring data;

[0145] Select historical monitoring data that matches the real-time feature set of the monitoring data from the historical database, and input it into a preset prediction and early warning model for model training and optimization, and output a service prediction and early warning analysis model;

[0146] Based on the prediction and early warning analysis model, and combined with a preset abnormal database, conduct early warning analysis on the real-time monitoring data, label and collect information on service instances that meet the preset early warning trigger conditions, and output the early warning analysis results;

[0147] At the same time, based on the prediction and early warning analysis model, conduct a comparative analysis of the historical monitoring data and the real-time monitoring data to determine the operation trends of each service instance, and output the prediction analysis results;

[0148] Select audit indicators and risk analysis indicators that match the monitoring requirement information from the indicator database, and output an audit-risk indicator set;

[0149] Based on the audit-risk indicator set, and combined with the early warning analysis results and the prediction analysis results, conduct an audit and risk analysis on the security policies, access control, and data security in the microservice security framework, and output the security audit results.

[0150] In this embodiment, the monitoring requirement information: the requirements and demands of users for system monitoring, including information such as monitoring tool selection, data type, and monitoring content;

[0151] In this embodiment, the preset monitoring tool library: a pre-defined set of monitoring tools used to select an adapted monitoring tool according to the user's monitoring requirements and capture monitoring data in real time;

[0152] In this embodiment, the data type: the type of data to be monitored, which may include performance data, status data, security data, etc.;

[0153] In this embodiment, the monitoring content: the specific content in the monitoring data that needs to be concerned about and recorded, such as request response time, system load, abnormal logs, etc.;

[0154] In this embodiment, the data information to be monitored: the relevant information of the data to be monitored determined according to the monitoring requirement information, including the data type and the monitoring content;

[0155] In this embodiment, the real-time monitoring data: the data corresponding to the data information to be monitored obtained in real time through the monitoring tool;

[0156] In this embodiment, the type analysis: analyze the real-time monitoring data to obtain different types of data such as performance monitoring data, status monitoring data, and security monitoring data;

[0157] In this embodiment, the real-time feature set of the monitoring data: the feature set extracted from the real-time monitoring data through feature recognition, extraction, and matching;

[0158] In this embodiment, the historical database: a database that stores historical monitoring data and is used for comparative analysis and model training with real-time monitoring data;

[0159] In this embodiment, the historical monitoring data: the monitoring data recorded in the past and is used for analyzing the system operation trend and model training;

[0160] In this embodiment, the preset prediction and early warning model: a model established in advance for predicting system anomalies and issuing alerts;

[0161] In this embodiment, the service prediction and early warning analysis model: a model trained based on historical monitoring data and real-time monitoring data and is used for predicting the service operation status and issuing early warnings;

[0162] In this embodiment, the preset anomaly database: a database that stores system anomalies defined in advance and is used for comparison with real-time monitoring data and anomaly detection;

[0163] In this embodiment, the preset early warning trigger condition: a set condition that triggers early warning analysis. Once the monitoring data meets the condition, the early warning will be triggered;

[0164] In this embodiment, the early warning analysis result: the early warning information obtained based on the prediction and early warning model and real-time monitoring data, including the detected anomalies and the measures to be taken;

[0165] In this embodiment, the operation trend: the change trend of the operation status of the system or service over a period of time, which can help predict future operations;

[0166] In this embodiment, the prediction analysis result: the prediction result of the future operation status of the system or service obtained based on historical data and the prediction model;

[0167] In this embodiment, the indicator database: a database that stores audit indicators and risk analysis indicators and is used for system auditing and risk assessment;

[0168] In this embodiment, the audit indicator: an indicator used to evaluate system security and compliance, which can include access log records, permission management situations, etc.;

[0169] In this embodiment, the risk analysis indicator: an indicator used to evaluate the system risk level, which can include the number of vulnerabilities, the number of attacks, etc.;

[0170] In this embodiment, the audit-risk indicator set: an indicator set obtained by comprehensively considering audit and risk analysis indicators and is used for auditing and risk assessment of system security policies and access control.

[0171] Implementation principle and beneficial effects of this embodiment: The present invention obtains the monitoring requirements of users and selects matching monitoring tools, obtains monitoring data in real time and conducts type analysis, identifies features in combination with a dynamic feature library and conducts comparative analysis. Utilizes a historical database to train and optimize the real-time monitoring data, and outputs a prediction and early warning analysis model. Through early warning analysis and prediction analysis, audits and risk analyzes the security policies, access control, and data security in the microservice security framework. The present invention can help users obtain and analyze monitoring data in real time according to monitoring requirements, identify problems in system performance, status, and security. Through historical data and model training, it can predict the system operation trend and discover potential problems in advance. Combining audits and risk analysis, it can timely evaluate the system security and take corresponding measures to improve the security control ability and stability of microservices in the container cloud environment.

[0172] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A microservice security control method in a container cloud environment, characterized in that: include: Step 1: Obtain the registration services and service change data of each registration center in real time, output the service instance list, and synchronize it to the microservice security framework through the corresponding interface in the preset interface group; Step 2: Combine the preset policy database and configure the security policy for each service instance in the service instance list through the microservice security framework, and output the policy configuration table; Step 3: Review the received service subscription information and the service content in the corresponding information based on the policy configuration table and configure security control information; Step 4: Perform security control on the service call of the service consumer based on the security control information, and output the service result after the service security control; Step 5: Use a preset monitoring tool to capture the monitoring data corresponding to each service instance in the microservice security framework in real time, perform security audits and risk assessments, and output security audit results; Wherein, step 5 includes: Obtain the user's monitoring needs, output monitoring need information, select a monitoring tool that matches the monitoring need information from a preset monitoring tool library, and at the same time, determine the data type of the data to be monitored and the corresponding monitoring content based on the monitoring need information, and output the data information to be monitored; Acquire data corresponding to the data information to be monitored in real time through the monitoring tool, and output real-time monitoring data; Performing type analysis on the real-time monitoring data to obtain performance monitoring data, status monitoring data and safety monitoring data respectively; At the same time, the real-time monitoring data is identified, extracted and matched with the dynamic feature library, and a real-time feature set of the monitoring data is output; Select historical monitoring data that matches the real-time feature set of the monitoring data from the historical database, input it into a preset prediction and early warning model for model training and optimization, and output a service prediction and early warning analysis model; Based on the prediction and warning analysis model, and in combination with the preset abnormal database, the real-time monitoring data is subjected to warning analysis, information of the service instances that meet the preset warning trigger conditions is annotated and collected, and the warning analysis results are output; At the same time, based on the prediction and early warning analysis model, the historical monitoring data and the real-time monitoring data are compared and analyzed to determine the operation trend of each service instance and output the prediction analysis results; Selecting audit indicators and risk analysis indicators that match the monitoring demand information from the indicator database, and outputting an audit-risk indicator set; Based on the audit-risk indicator set, and in combination with the early warning analysis results and the predictive analysis results, the security policies, access controls and data security in the microservice security framework are audited and risk analyzed, and the security audit results are output.

2. According to a microservice security control method in a container cloud environment according to claim 1, it is characterized in that: The real-time acquisition of the registration services and service change data of each registration center and the output of the service instance list include: Interactive communication with each registration center is established through the preset service abstraction layer. At the same time, a corresponding adapter is assigned to each registration center through the preset adapter mode, and a registration center-adapter comparison table is established. The registration services and service change data in the corresponding registration center are monitored in real time through the adapters in the registration center-adapter comparison table, and a service instance list is output.

3. According to a microservice security control method in a container cloud environment according to claim 1, it is characterized in that: The synchronization to the microservice security framework through the corresponding interface in the preset interface group includes: Obtain cross-application service call information and corresponding service call requirements, and match the corresponding interface in the preset interface group based on the service call requirements. Through the interface, each service in the service instance list is synchronously registered to the microservice security framework in a preset registration method for service management.

4. According to a microservice security control method in a container cloud environment according to claim 3, it is characterized in that: The service management includes: service group management, service launch, service offline, service and interface suspension, service and interface recovery, service and interface disabling, and service and interface enabling capabilities.

5. According to a microservice security control method in a container cloud environment according to claim 1, it is characterized in that: Before configuring the security policy for each service instance in the service instance list through the microservice security framework, the method includes: Feature identification and extraction are performed on the service instances in the service instance list to establish a service feature set, and adapted security control strategies are selected from the preset strategy database to construct a feature-strategy mapping diagram.

6. A microservice security control method in a container cloud environment according to claim 5, characterized in that: Step 2 also includes: Based on the preset policy database and the feature-policy mapping diagram, security policies are configured for each service instance in the service instance list through the microservice security framework, and a policy configuration table is output, wherein the security policies include black and white lists, time period restrictions, traffic restrictions, domain name restrictions, and namespace restrictions.

7. According to a microservice security control method in a container cloud environment according to claim 1, it is characterized in that: Step 3 includes: Determine the service requirements that the service consumer needs to call, wherein the service requirements include service type, service group, specific service content and corresponding interface information; Based on the service demand, the service consumer submits a service subscription request through the microservice security framework, where the service subscription request includes the service consumer's authentication information and details of the service to be subscribed; Acquire service provider information matching the service subscription request through the microservice security framework, and send the service subscription request to the corresponding service provider for review; The service provider reviews the received service subscription request through the microservice security framework, and compares and analyzes the service scope and service requirements corresponding to the service provider, and determines the service subscription request whose comparison result meets the preset conditions as a qualified subscription request; Based on the service requirements and security requirements of the service consumer, and based on the policy configuration table, the access security policy corresponding to each service instance is determined and set, wherein the access security policy includes a function authority control method based on users, roles, identities, and organizations, as well as time limits, access frequency limits, transmission encryption policies, and data authority range limitation methods.

8. A microservice security control method in a container cloud environment according to claim 7, characterized in that: Step 4 includes: Perform security verification analysis on the access security policy and data range audit results in combination with a preset application access control method, and perform security control on the service call information and the corresponding service content based on the verification analysis results, wherein the preset application access control method includes a function permission control method and a data permission control method; Determine the access data content range of the service consumer corresponding to each service instance, and dynamically configure the access data content range of each service consumer in real time based on the preset dynamic feature library, and compare and analyze it with the actual data content range corresponding to each service subscription request, and output the service content that meets the data range review.

Citation Information

Patent Citations

  • Safety management and control method for micro-service gateway request

    CN117675282A

  • Microservice architecture for identity and access management

    US20190273746A1