Distributed access control system and method

By introducing data storage modules, event modules and policy processing modules into the distributed access control system, real-time effectiveness of policy changes and rapid response to access control is achieved, and the problem of access control policy adjustment in large-scale cluster service development is solved, which improves the availability of the system and reduces operation and maintenance pressure.

CN119945706AActive Publication Date: 2025-05-06CHINA TELECOM CLOUD TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411730397.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-05-06
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

When the existing technology faces large-scale cluster service development, it is impossible to quickly adjust the access control strategy, resulting in high operation and maintenance pressure and low availability.

Method used

A distributed access control system is designed, including data storage module, event module and policy processing module. Through real-time notification and caching mechanisms, policy decision-making and policy execution are decoupled to real-time effectiveness of policy changes.

Benefits of technology

It improves the availability of access control, reduces operation and maintenance pressure, and realizes a distributed access control system with low operation and maintenance costs and real-time fast response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945706A_ABST
    Figure CN119945706A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of distributed cluster control, and discloses a distributed access control system and method.Each access control instance in the distributed access control system comprises a complete data storage module, an event module and a strategy processing module, the data storage capacity, the event processing capacity and the strategy processing capacity can be met at a time, and the access control efficiency is improved. The complexity of the system is reduced, the communication overhead among the components is reduced, each instance is an independent and complete access control unit, the normal operation of other instances cannot be influenced by instance faults, instant notification and real-time enhancement of data change are realized through the event module, and the system is more suitable for deployment and expansion of a cloud computing environment; each access control instance in the distributed cluster is independent, so that the service availability of access control can be improved, and the operation and maintenance pressure can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of distributed cluster control, and in particular to a distributed access control system and method. Background Art

[0002] In the related art, instance access control is implemented through a layered architecture, in which the internal structure of the access control service layer is as follows: (1) The receiving module receives the access control verification request; (2) The processing module verifies the identity of the request, obtains the permission, resource and other information from the cache and database, and determines whether the authentication is passed; (3) The response module responds according to the authentication result.

[0003] However, in the existing technology, once the access policy or user permissions are changed, customized development is required to redeploy and start the update of the processing logic from beginning to end. The access control policy cannot be adjusted quickly. When faced with large-scale cluster service development, a lot of R&D and operation and maintenance time is consumed, which greatly increases the operation and maintenance pressure of access control and reduces the availability of access control. Summary of the invention

[0004] In view of this, the present invention provides a distributed access control system and method to solve the problem of how to improve the availability of access control and reduce operation and maintenance pressure when facing large-scale cluster service development.

[0005] In a first aspect, the present invention provides a distributed access control system, which is applied to access control of access control instances in a distributed cluster, and the system includes: a data storage module, an event module and a policy processing module;

[0006] The data storage module is used to store policy data and user authority data;

[0007] The event module is used to generate a policy data event change notification and / or a user authority data event change notification according to the policy data and / or user authority data changed in the data storage module;

[0008] The policy processing module includes a policy parsing unit, a policy execution unit and a cache area; the policy parsing unit is used to update the policy cache data in the cache area according to the policy data event change notification; the policy execution unit is used to update the user authority cache data in the cache area according to the user authority data event change notification;

[0009] Among them, when the policy processing module receives a target access request from any target access instance outside the distributed cluster, the policy execution unit is used to execute access control verification logic according to the policy cache data and the user authority cache data in the cache area, perform access control judgment on the target access request, and generate response information for the target access request.

[0010] In the distributed access control system provided by the embodiment of the present invention, the data storage module stores policies and permission data, the event module monitors data changes and generates notifications, and the combination of the data storage module and the event module realizes real-time notification of data changes without redeployment. The policy parsing unit processes policy changes, the policy execution unit processes permission changes, and the cache area stores the latest data, decoupling policy decisions and policy execution. Policy changes can take effect in real time without the need to redevelop and deploy the entire access control verification process, and the cache area can ensure a quick response to access requests. The modules of the embodiment of the present invention exchange data and decouple the modules at the same time, forming a distributed access control system with low operation and maintenance costs and real-time and fast response. When facing large-scale cluster service development, it effectively improves the availability of access control and reduces operation and maintenance pressure.

[0011] In an optional implementation, the distributed cluster includes at least three access control instances, and the system further includes a data synchronization module;

[0012] The data synchronization module is used to obtain the data synchronization instructions issued by the distributed cluster, and based on the instance identification information to be synchronized and the data to be synchronized in the data synchronization instructions, use the distributed cluster data synchronization algorithm to forward the data to be synchronized to the data storage modules of multiple access control instances to be synchronized, so as to synchronously change the policy data and user authority data in the data storage module.

[0013] In the embodiment of the present invention, the data synchronization module uses a distributed cluster data synchronization algorithm to achieve data consistency between multiple access control instances in a distributed cluster. When the policy data or user permission data of a certain instance changes, the data synchronization module can accurately and timely synchronize the changed data to other instances, avoiding access control errors caused by inconsistent data. Since each access control instance is decoupled from a separate data synchronization module, the data synchronization speed is faster in large-scale distributed cluster scenarios.

[0014] In an optional implementation, the system further includes a request receiving module and a response returning module;

[0015] The request receiving module is used to send a target access request of an access instance outside the distributed cluster to the policy processing module;

[0016] The response returning module is used to send the response information of the target access request returned by the policy processing module to the access instance outside the distributed cluster.

[0017] In the embodiment of the present invention, independent request receiving module and response returning module are set to realize the decoupling between the access control system and the external access instance. Among them, the request receiving module is specifically responsible for receiving and preprocessing external access requests, and the response returning module is specifically responsible for processing and returning response results, which improves the scalability of the system. When it is necessary to add new request processing logic or response format, only the request receiving module and the response returning module need to be modified, which will not affect the normal operation of other modules.

[0018] In an optional implementation, the policy cache data includes at least a first access condition control policy and a second access condition control policy, wherein the first access condition control policy is used to characterize whether an access instance outside the distributed cluster is allowed to access, and the second access condition control policy is used to characterize whether an access instance outside the distributed cluster is allowed to perform an operation;

[0019] The user permission cache data at least includes a preset access instance list and a corresponding preset access instance resource list and a preset access instance operation permission list, wherein each access instance corresponding to the identification information in the preset access instance list is allowed to be accessed;

[0020] The target access request includes target identification information, target access resources, and target access operations.

[0021] In the embodiment of the present invention, the policy cache data includes a first access condition control policy (i.e., access permission) and a second access condition control policy (i.e., operation permission), and the user permission cache data includes a preset access instance list and a corresponding resource list and an operation permission list; based on the target access request including target identification information, target access resources, and target access operations, the above-mentioned data structure division can provide a data basis for the subsequent hierarchical and rapid control and judgment of the access request process.

[0022] In an optional implementation, the system further includes a log module;

[0023] The log module is used to record the timestamp of the target access request, and store the target access request and the response information of the target access request based on the timestamp of the target access request;

[0024] When the response information of the target access request is a successful response, the number of target access instances is recorded.

[0025] The embodiment of the present invention sets a log module to record the entire process of access requests, including timestamps, request contents and response results, and analyzes system usage by counting the number of successful accesses, which helps to discover abnormal access behaviors during large-scale distributed cluster operation and maintenance, and further reduces the operation and maintenance pressure.

[0026] In a second aspect, the present invention provides a distributed access control method, the method comprising:

[0027] Generate a policy data event change notification and / or a user authority data event change notification according to the changed policy data and / or user authority data;

[0028] updating the policy cache data according to the policy data event change notification and / or updating the user authority cache data according to the user authority data event change notification;

[0029] When a target access request is received from any target access instance outside the distributed cluster, the access control verification logic is executed according to the policy cache data and the user authority cache data, an access control judgment is made on the target access request, and response information of the target access request is generated.

[0030] The distributed access control method provided by the embodiment of the present invention realizes real-time notification of data changes by monitoring data changes and generating notifications, and the combination of data storage modules and event modules, without the need for redeployment. Among them, policy changes and permission changes are processed separately, the latest data is stored, and the steps of policy decision-making and policy execution are decoupled. Policy changes can take effect in real time without the need to redevelop and deploy the entire access control verification process. Through policy cache data and user permission cache data, rapid response to access requests is guaranteed. The embodiment of the present invention decouples the steps of policy decision-making and policy execution to form a distributed access control method with low operation and maintenance costs and real-time rapid response. When facing large-scale cluster service development, it effectively improves the availability of access control and reduces operation and maintenance pressure.

[0031] In an optional implementation, when a target access request is received, access control verification logic is executed according to the policy cache data and the user authority cache data, access control judgment is performed on the target access request, and response information of the target access request is generated, specifically including:

[0032] Searching the preset access instance list according to the target identification information to obtain a first query result;

[0033] Searching the preset access instance resource list according to the target access resource to obtain a second query result;

[0034] Determining whether the target access instance is allowed to be accessed based on the first access condition control policy, the first query result, and the second query result;

[0035] When it is confirmed that the target access instance is allowed to be accessed, a preset access instance operation permission list is searched according to the target access operation to obtain a third query result; based on the second access condition control strategy and the third query result, it is determined whether the target access instance is allowed to perform the operation;

[0036] When confirming whether the target access instance is allowed to perform the operation, generating response success information of the target access request;

[0037] When it is confirmed that the target access instance is not allowed to be accessed, or when it is confirmed that the target access instance is not allowed to perform an operation, response failure information of the target access request is generated.

[0038] In the embodiment of the present invention, a preset access instance list is searched according to target identification information to obtain a first query result, the legitimacy of the identity of the visitor is firstly verified, and a preset access instance resource list is searched according to the target access resource to obtain a second query result, and the legitimacy of the access resource is verified. Both steps use the preset list for fast matching; based on the first access condition control policy, the first query result and the second query result, it is judged whether the target access instance is allowed to access, and the two conditions of identity and resource are combined for judgment. When it is confirmed that the target access instance is allowed to access, the preset access instance operation permission list is searched according to the target access operation to obtain a third query result, and based on the second access condition control policy and the third query result, it is judged whether the target access instance is allowed to perform the operation, that is, the operation permission verification is performed only after the basic access permission verification is passed, and the permission control of the specific operation level is further judged; when it is confirmed whether the target access instance is allowed to perform the operation, the response success information of the target access request is generated, and when it is confirmed that the target access instance is not allowed to access, or when it is confirmed that the target access instance is not allowed to perform the operation, the response failure information of the target access request is generated, and corresponding response information is returned for different judgment results, so that the target access request can be responded to quickly in real time.

[0039] In an optional embodiment, the method further includes:

[0040] Get the data synchronization instructions issued by the distributed cluster;

[0041] Based on the identification information of the instance to be synchronized and the data to be synchronized in the data synchronization instruction, the data to be synchronized is forwarded to multiple access control instances to be synchronized using a distributed cluster data synchronization algorithm to synchronize the change policy data and user authority data.

[0042] In the embodiment of the present invention, a distributed cluster data synchronization algorithm is used to achieve data consistency between multiple access control instances in a distributed cluster. When the policy data or user permission data of a certain instance changes, the changed data can be synchronized to other instances accurately and timely, avoiding access control errors caused by inconsistent data. Since each access control instance is decoupled from a separate data synchronization process, the data synchronization speed is faster in large-scale distributed cluster scenarios.

[0043] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the distributed access control method of the above-mentioned second aspect or any corresponding embodiment thereof by executing the computer instructions.

[0044] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the distributed access control method of the second aspect or any corresponding embodiment thereof.

[0045] In a fifth aspect, the present invention provides a computer program product, including computer instructions, which are used to enable a computer to execute the distributed access control method of the second aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0047] Figure 1 is a schematic diagram of the structure of a distributed access control system in a related art according to an embodiment of the present invention;

[0048] Figure 2 is a schematic diagram of the structure of another distributed access control system in the related art according to an embodiment of the present invention;

[0049] Figure 3 is a first structural diagram of a distributed access control system according to an embodiment of the present invention;

[0050] Figure 4 is a second structural schematic diagram of a distributed access control system according to an embodiment of the present invention;

[0051] Figure 5is a flow chart of a distributed access control method according to an embodiment of the present invention;

[0052] Figure 6 is a third structural schematic diagram of a distributed access control system according to an embodiment of the present invention;

[0053] Figure 7 is a fourth structural schematic diagram of a distributed access control system according to an embodiment of the present invention;

[0054] Figure 8 is a fifth structural diagram of a distributed access control system according to an embodiment of the present invention;

[0055] Fig. 9 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0057] In the new information technology cloud computing field, access control is a basic element in the security field, which is used to determine who can access specific data, applications and resources under what circumstances. Similar to keys and visitor lists in physical space, access control policies ensure legitimate user access and block illegal access through technologies such as identity authentication and authorization.

[0058] The current mainstream access control high availability solution in the industry adopts a layered architecture, which can be referred to Figure 1 , including the data layer (used for persistent storage of access control policies, user data, resource data, and permission relationships), the cache layer (using memory databases such as Redis to accelerate data access, and using a master-slave architecture to ensure high availability), and the service layer (implementing the core logic of access control). The service layer includes multiple access control service replicas, each of which includes three modules. Figure 2 ,Receiving module: processes access control verification requests; processing module: performs identity authentication, obtains permission information, and performs authentication judgment; response module: returns authentication results.

[0059] The existing technology layered architecture introduces multiple middlewares in layers, which increases system complexity and operation and maintenance pressure. When expanding horizontally, it is necessary to deeply locate the bottleneck level, and it is impossible to quickly expand the capacity to respond to emergencies. When updating policies, customized development is required, and the update processing logic must be redeployed and started. Access control policies cannot be adjusted quickly, and the timeliness of policy changes is not high.

[0060] A distributed access control system provided by an embodiment of the present invention integrates the data layer, cache layer, and service layer in the layered architecture of the prior art into a single system, that is, each access control instance in the distributed cluster includes complete data storage, event processing, and policy processing capabilities, which reduces system complexity and communication overhead between components. Each instance is an independent and complete access control unit, and instance failure will not affect the normal operation of other instances. Instant notification of data changes is achieved through the event module, and real-time performance is enhanced, which is more suitable for deployment and expansion in a cloud computing environment. Since each access control instance in the distributed cluster is independent, the service availability of access control can be improved and the operation and maintenance pressure can be reduced.

[0061] It should be noted that "improving the service availability of access control" refers to "high availability" in cloud computing, which is one of the factors that must be considered in the design of distributed system architecture, that is, how to reduce the time that the system cannot provide services and ensure continuous availability of services.

[0062] In this embodiment, a distributed access control system is provided, which is applied to the access control of the access control instance in the distributed cluster. Figure 3 , the system includes a data storage module 10, an event module 20 and a policy processing module 30;

[0063] A data storage module 10, used to store policy data and user authority data;

[0064] An event module 20, configured to generate a policy data event change notification and / or a user authority data event change notification according to the policy data and / or user authority data changed in the data storage module;

[0065] The policy processing module 30 includes a policy parsing unit 301, a policy execution unit 302 and a cache area 303; the policy parsing unit 301 is used to update the policy cache data in the cache area 303 according to the policy data event change notification; the policy execution unit 302 is used to update the user permission cache data in the cache area 303 according to the user permission data event change notification; wherein, when the policy processing module 30 receives a target access request from any target access instance outside the distributed cluster, the policy execution unit 302 is used to execute access control verification logic based on the policy cache data and the user permission cache data in the cache area 303, perform access control judgment on the target access request, and generate response information for the target access request.

[0066] It should be noted that an access control instance refers to an independent node in a distributed system, which contains complete access control functions. For example, there is an overall cloud service architecture, which includes multiple functional systems, and each functional system has a corresponding access control instance (used to limit the access of other instances to the functional system). The data stored in the data storage module in different access control instances can be the same or different.

[0067] For example, there is a cloud storage service, and user A wants to access file X. The access control instance will quickly determine whether user A has the authority to access file X from the policy processing module based on the cached policy data and user permission data. If the administrator changes the "user A's permissions" or "control policy for accessing file X" in the data storage module during this period, the event module will immediately notify the policy processing module to update the cache based on the event change notification.

[0068] In the embodiment of the present invention, a data storage module stores policies and permission data, an event module monitors data changes and generates notifications, and a combination of the data storage module and the event module is used to realize real-time notification of data changes without redeployment. The policy parsing unit processes policy changes, the policy execution unit processes permission changes, and the cache area stores the latest data, decoupling policy decisions and policy execution. Policy changes can take effect in real time without the need to redevelop and deploy the entire access control verification process, and the cache area can ensure a quick response to access requests. In the embodiment of the present invention, the modules exchange data and decouple the modules at the same time, forming a distributed access control system with low operation and maintenance costs and real-time and fast response. When facing large-scale cluster service development, the availability of access control is effectively improved and the operation and maintenance pressure is reduced.

[0069] In a specific embodiment, reference may be made to Figure 4The distributed cluster includes at least three access control instances. The system also includes a data synchronization module 40, which is used to obtain the data synchronization instruction issued by the distributed cluster. Based on the identification information of the instance to be synchronized and the data to be synchronized in the data synchronization instruction, the distributed cluster data synchronization algorithm is used to forward the data to be synchronized to the data storage modules 10 of multiple access control instances to be synchronized, so as to synchronously change the policy data and user authority data in the data storage module.

[0070] It is understandable that the data synchronization module is introduced in this embodiment to ensure data consistency between multiple instances in a distributed environment. Even if an instance fails, other instances can still work normally, which further ensures the "high availability" of the access control instance.

[0071] Specifically, the distributed cluster data synchronization algorithm can adopt a distributed consistency algorithm such as Raft or Paxos to achieve incremental synchronization to reduce network transmission.

[0072] For example, there are three access control instances A, B, and C in the cluster. The administrator updates an access policy on instance A. The data synchronization module of instance A receives the synchronization instruction, and the module uses the Raft algorithm to synchronize the new policy to B and C. B and C receive and apply the update to ensure that the policies of the three instances are consistent.

[0073] In the embodiment of the present invention, the data synchronization module uses a distributed cluster data synchronization algorithm to achieve data consistency between multiple access control instances in a distributed cluster. When the policy data or user permission data of a certain instance changes, the data synchronization module can accurately and timely synchronize the changed data to other instances, avoiding access control errors caused by inconsistent data. Since each access control instance is decoupled from a separate data synchronization module, the data synchronization speed is faster in large-scale distributed cluster scenarios.

[0074] In a specific embodiment, reference may be made to Figure 4 The system also includes a request receiving module 50 and a response returning module 60; wherein the request receiving module 50 is used to send the target access request of the access instance outside the distributed cluster to the policy processing module 30; the response returning module 60 is used to send the response information of the target access request returned by the policy processing module 30 to the access instance outside the distributed cluster.

[0075] It is understandable that the request receiving module and the response returning module realize the decoupling of the access control system from the external system, thereby improving the scalability of the system.

[0076] For example, a user device instance (an access instance outside a distributed cluster) wants to verify user access rights and sends an HTTP request to the access control instance. The request receiving module parses the HTTP request and extracts key information (user ID, resources, and operations). The policy processing module performs permission verification. The response returning module encapsulates the result in JSON format and returns it to the user device instance.

[0077] In the embodiment of the present invention, independent request receiving module and response returning module are set to realize the decoupling between the access control system and the external access instance. Among them, the request receiving module is specifically responsible for receiving and preprocessing external access requests, and the response returning module is specifically responsible for processing and returning response results, which improves the scalability of the system. When it is necessary to add new request processing logic or response format, only the request receiving module and the response returning module need to be modified, which will not affect the normal operation of other modules.

[0078] In a specific embodiment, the policy cache data includes at least a first access condition control policy and a second access condition control policy, wherein the first access condition control policy is used to characterize whether access instances outside the distributed cluster are allowed to be accessed, and the second access condition control policy is used to characterize whether access instances outside the distributed cluster are allowed to perform operations; the user permission cache data includes at least a preset access instance list and a corresponding preset access instance resource list, and a preset access instance operation permission list, wherein each access instance corresponding to the identification information in the preset access instance list is allowed to be accessed; the target access request includes target identification information, target access resources, and target access operations.

[0079] Exemplarily, the policy cache data stores a policy file (policy.rego), which includes a first access condition control policy that denies access by default, and a second access condition control policy based on role permissions. The user permission cache data stores the content of the data.json file, which includes a list of preset access instances (such as inspector-alice, maker-bob), a list of preset access instance resources (such as widgets), and a list of preset access instance operation permissions (such as read, write). When a target access request is received, the request includes target identification information (such as inspector-alice), target access resources (such as widgets), and target access operations (such as read).

[0080] Exemplarily, when a target access request is received, the policy execution unit first obtains the user's role information from the user permission cache data (for example, inspector-alice's role is widget-reader), and then determines whether the role has the corresponding resource operation permission (for example, having read permission for widgets resources) based on the policy rules in the policy cache data, thereby achieving hierarchical and fast access control judgment.

[0081] In the embodiment of the present invention, the policy cache data includes a first access condition control policy (i.e., access permission) and a second access condition control policy (i.e., operation permission), and the user permission cache data includes a preset access instance list and a corresponding resource list and an operation permission list; based on the target access request including target identification information, target access resources, and target access operations, the above-mentioned data structure division can provide a data basis for the subsequent hierarchical and rapid control and judgment of the access request process.

[0082] In a specific embodiment, reference may be made to Figure 4 The system also includes a log module 70, which is used to record the timestamp of the target access request, and store the target access request and the response information of the target access request based on the timestamp of the target access request; wherein, when the response information of the target access request is a successful response, the number of target access instances is recorded.

[0083] It should be noted that the log module records an accurate timestamp for each target access request to mark the specific time point when the request occurs, wherein the timestamp serves as a unique identifier for the target access instance that associates the request and the response.

[0084] Specifically, the content of the target access request is stored based on the timestamp, including: target identification information, target access resources, and target access operations; the corresponding response information is stored, including: whether access is allowed (yes or no), and the response result (success or failure). When the response information is successful, the number of access instances is recorded to analyze the usage frequency of different access instances, so as to determine unsafe access or abnormal access control instances.

[0085] The embodiment of the present invention sets a log module to record the entire process of access requests, including timestamps, request contents and response results, and analyzes system usage by counting the number of successful accesses, which helps to discover abnormal access behaviors during large-scale distributed cluster operation and maintenance, and further reduces the operation and maintenance pressure.

[0086] According to an embodiment of the present invention, an embodiment of a distributed access control method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0087] In this embodiment, a distributed access control method is provided, which can be used for the above-mentioned computer. Figure 5 is a flow chart of a distributed access control method according to an embodiment of the present invention. Figure 5 As shown, the process includes the following steps:

[0088] Step S501: Generate a policy data event change notification and / or a user authority data event change notification based on the changed policy data and / or user authority data. Figure 3 The description of the related embodiments of the distributed access control system shown will not be repeated here.

[0089] Step S502: Update the policy cache data according to the policy data event change notification and / or update the user authority cache data according to the user authority data event change notification. Figure 3 The description of the related embodiments of the distributed access control system shown will not be repeated here.

[0090] Step S503, when a target access request is received from any target access instance outside the distributed cluster, the access control verification logic is executed according to the policy cache data and the user authority cache data, the access control judgment is performed on the target access request, and the response information of the target access request is generated.

[0091] Specifically, the above step S503 includes:

[0092] Step S5031, searching a preset access instance list according to the target identification information to obtain a first query result;

[0093] For example, an access control request is received, and the input content in the example is as follows:

[0094]

[0095] In this request, the target identification information is "user":"inspector-alice". First, the information of user inspector-alice is searched from the cache. If there is no user information in the cache, it will continue to search from the data module. The role information of user inspector-alice is obtained through the following steps:

[0096] Step a1: Look up the role information of user inspector-alice from the cache.

[0097] Step a2: Similarly, if there is no data in the cache, the data of user inspector-alice will continue to be obtained from the data module. The result is as follows:

[0098] {

[0099] "user":"inspector-alice",

[0100] "role":"widget-reader"

[0101] }

[0102] Finally, the first query result is the role widget-reader of the user inspector-alice.

[0103] Step S5032, searching the preset access instance resource list according to the target access resource to obtain a second query result;

[0104] For example, according to the target access resource "resource":"widgets" in the request, the cache will be searched for related resource information, that is, to find out whether the role widget-reader has access rights to the widgets resource. If the cache contains the permissions of the role widget-reader as follows:

[0105] {

[0106] "operation":"read",

[0107] "resource":"widgets",

[0108] "name":"widget-reader"

[0109] }

[0110] Finally, the second query result shows that the role widget-reader has the read permission for the resource widgets.

[0111] Step S5033, judging whether the target access instance is allowed to be accessed based on the first access condition control policy, the first query result and the second query result;

[0112] Exemplarily, the first query result (user role information) and the second query result (resource permission information) are combined to determine whether the target access instance is allowed to access. The permissions of the role widget-reader clearly include the read permission for the widgets resource. Therefore, according to the access control rules in the policy file, the target user inspector-alice is allowed to access the widgets resource.

[0113] Step S5034: when it is confirmed that the target access instance is allowed to be accessed, a preset access instance operation permission list is searched according to the target access operation to obtain a third query result; based on the second access condition control policy and the third query result, it is determined whether the target access instance is allowed to perform the operation;

[0114] Exemplarily, it is further checked whether the target access operation "operation": "read" in the request is within the permission scope of the user role widget-reader. It is found that the role widget-reader has read permission for the resource widgets, so the third query result confirms that inspector-alice is allowed to perform the read operation.

[0115] Step S5035, when confirming whether the target access instance is allowed to perform the operation, generating a response success message of the target access request;

[0116] Exemplarily, it is confirmed that all conditions are met and a successful response message is generated. In other words, inspector-alice has the read permission and is allowed to access the widgets resource, and a successful response is returned, indicating that the access request is allowed.

[0117] Step S5036: When it is confirmed that the target access instance is not allowed to be accessed, or when it is confirmed that the target access instance is not allowed to perform an operation, a response failure message of the target access request is generated.

[0118] For example, if the user is found to have no permission in any step, a response message of access denied will be generated. That is, if inspector-alice does not have read permission or does not have permission to access widgets, a failure message will be directly returned.

[0119] In addition, in the embodiment of the present invention, the first access condition control policy and the second access condition control policy are stored in the policy file in the form of rego language. In different service architectures, a suitable programming language can be selected for writing according to the actual application scenario. However, the code logic written in different languages ​​is the same as the principle of steps S5031 to S5036 in this embodiment. The sample code is as follows:

[0120] #Access is not allowed by default

[0121] default allow=false

[0122] #Access is allowed only when the user has a certain role and the role has relevant resource permissions (steps S5031 to S5036 are in the programming format of the rego language)

[0123] allow{

[0124] some role_name

[0125] user_has_role[role_name]

[0126] role_has_permission[role_name]

[0127] }

[0128] #Check user role (first access condition control strategy)

[0129] user_has_role[role_name]{

[0130] role_binding=data.bindings[_]

[0131] role_binding.role = role_name

[0132] role_binding.user==input.subject.user

[0133] }

[0134] #Check if the role has permissions (second access condition control strategy)

[0135] role_has_permission[role_name]{

[0136] role = data.roles[_]

[0137] role.name = role_name

[0138] role.operation==input.action.operation

[0139] role.resource==input.action.resource

[0140] }

[0141] Furthermore, the data is applied in the above policy file. The data.json content of users, roles, and permissions is as follows:

[0142]

[0143] The embodiment of the present invention searches for a preset access instance list according to target identification information to obtain a first query result, first verifies the legitimacy of the identity of the visitor, searches for a preset access instance resource list according to the target access resource to obtain a second query result, verifies the legitimacy of the access resource, and both steps use the preset list for fast matching; based on the first access condition control policy, the first query result and the second query result, it is determined whether the target access instance is allowed to access, and the two conditions of identity and resource are combined for determination. When it is confirmed that the target access instance is allowed to access, the preset access instance operation permission list is searched according to the target access operation to obtain a third query result, and based on the second access condition control policy and the third query result, it is determined whether the target access instance is allowed to perform the operation, that is, the operation permission verification is performed only after the basic access permission verification is passed, and the permission control of the specific operation level is further determined; when it is confirmed that the target access instance is allowed to perform the operation, a response success message of the target access request is generated, and when it is confirmed that the target access instance is not allowed to access, or when it is confirmed that the target access instance is not allowed to perform the operation, a response failure message of the target access request is generated, and corresponding response information is returned for different determination results, so that the target access request can be responded to quickly in real time.

[0144] Step S504, obtain the data synchronization instruction issued by the distributed cluster; for details, please refer to Figure 4 The description of the related embodiments of the distributed access control system shown will not be repeated here.

[0145] Step S505: Based on the identification information of the to-be-synchronized instance and the data to be synchronized in the data synchronization instruction, the distributed cluster data synchronization algorithm is used to forward the data to be synchronized to multiple to-be-synchronized access control instances to synchronize the change policy data and user authority data. Figure 4 The description of the embodiment related to the distributed access control system shown is not repeated here.

[0146] In the embodiment of the present invention, a distributed cluster data synchronization algorithm is used to achieve data consistency between multiple access control instances in a distributed cluster. When the policy data or user permission data of a certain instance changes, the changed data can be synchronized to other instances accurately and timely, avoiding access control errors caused by inconsistent data. Since each access control instance is decoupled from a separate data synchronization process, the data synchronization speed is faster in large-scale distributed cluster scenarios.

[0147] The embodiment of the present invention realizes real-time notification of data changes by monitoring data changes and generating notifications, a combination of data storage modules and event modules, without the need for redeployment. Among them, policy changes and permission changes are processed separately, the latest data is stored, and the steps of policy decision-making and policy execution are decoupled. Policy changes can take effect in real time without the need to redevelop and deploy the entire access control verification process. Through policy cache data and user permission cache data, rapid response to access requests is guaranteed. The embodiment of the present invention decouples the steps of policy decision-making and policy execution to form a distributed access control method with low operation and maintenance costs and real-time rapid response. When facing large-scale cluster service development, it effectively improves the availability of access control and reduces operation and maintenance pressure.

[0148] In actual application, the high-availability deployment architecture corresponding to a distributed access control system in this example can be referred to Figure 6 , including three access control instances, corresponding to device 1, device 2, and device 3, wherein high availability is implemented through at least three copies, and the data consistency is ensured by the data synchronization module inside the device, in order to ensure that more than half of the devices in the entire cluster are available. Subsequently, whenever there is a data change, all devices are synchronized in real time, and a distributed access control method of this example is applied in the access control process.

[0149] During real-time synchronization, you can refer to Figure 7 , the data synchronization module of device 1 synchronizes all data to devices 2 and 3. The data storage modules of devices 1, 2, and 3 trigger the [Policy Change] event in real time, which is pushed by the event module to the policy parsing unit for parsing and taking effect. The data storage modules of devices 1, 2, and 3 trigger the [Data Change] event in real time, which is pushed by the event module to the policy execution unit for data cache update. If there are subsequent changes to policies, users, roles, and permission data, the above process will also be followed to synchronize and update policies and caches in real time to achieve high real-time performance and high availability.

[0150] Further, when there is an input request, you can refer to Figure 8 ,The request receiving module receives the access control verification request, the policy execution unit obtains the execution flow of the latest parsed policy, starts to process the access control request, and the response return module outputs the result of the effective policy execution flow.

[0151] The embodiment of the present invention also provides a computer device, see Fig. 9 , Fig. 9 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Fig. 9As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Fig. 9 A processor 10 is taken as an example.

[0152] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0153] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.

[0154] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0155] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0156] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0157] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0158] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0159] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the defined scope.

Claims

1. A distributed access control system, characterized in that: Access control applied to access control instances in a distributed cluster, the system includes a data storage module, an event module and a policy processing module; The data storage module is used to store policy data and user authority data; The event module is used to generate a policy data event change notification and / or a user authority data event change notification according to the policy data and / or user authority data changed in the data storage module; The policy processing module includes a policy parsing unit, a policy execution unit and a cache area; the policy parsing unit is used to update the policy cache data in the cache area according to the policy data event change notification; The policy execution unit is used to update the user authority cache data in the cache area according to the user authority data event change notification; Among them, when the policy processing module receives a target access request from any target access instance outside the distributed cluster, the policy execution unit is used to execute access control verification logic according to the policy cache data and the user authority cache data in the cache area, perform access control judgment on the target access request, and generate response information for the target access request.

2. The system according to claim 1, characterized in that The distributed cluster includes at least three access control instances, and the system also includes a data synchronization module; The data synchronization module is used to obtain the data synchronization instructions issued by the distributed cluster, and based on the instance identification information to be synchronized and the data to be synchronized in the data synchronization instructions, use the distributed cluster data synchronization algorithm to forward the data to be synchronized to the data storage modules of multiple access control instances to be synchronized, so as to synchronously change the policy data and user authority data in the data storage module.

3. The system according to claim 1 or 2, characterized in that: The system also includes a request receiving module and a response returning module; The request receiving module is used to send a target access request of an access instance outside the distributed cluster to the policy processing module; The response returning module is used to send the response information of the target access request returned by the policy processing module to the access instance outside the distributed cluster.

4. The system according to claim 3, characterized in that The policy cache data includes at least a first access condition control policy and a second access condition control policy, wherein the first access condition control policy is used to indicate whether an access instance outside the distributed cluster is allowed to access, and the second access condition control policy is used to indicate whether an access instance outside the distributed cluster is allowed to perform an operation; The user permission cache data at least includes a preset access instance list and a corresponding preset access instance resource list and a preset access instance operation permission list, wherein each access instance corresponding to the identification information in the preset access instance list is allowed to be accessed; The target access request includes target identification information, target access resources, and target access operations.

5. The system according to claim 4, characterized in that The system also includes a log module; The log module is used to record the timestamp of the target access request, and store the target access request and the response information of the target access request based on the timestamp of the target access request; When the response information of the target access request is a successful response, the number of target access instances is recorded.

6. A distributed access control method, characterized in that: An access control instance applied to a distributed cluster, the method comprising: Generate a policy data event change notification and / or a user authority data event change notification according to the changed policy data and / or user authority data; updating the policy cache data according to the policy data event change notification and / or updating the user authority cache data according to the user authority data event change notification; When a target access request is received from any target access instance outside the distributed cluster, the access control verification logic is executed according to the policy cache data and the user authority cache data, an access control judgment is made on the target access request, and response information of the target access request is generated.

7. The method according to claim 6, characterized in that When receiving a target access request, executing access control verification logic according to the policy cache data and the user authority cache data, performing access control judgment on the target access request, and generating response information of the target access request specifically includes: Searching the preset access instance list according to the target identification information to obtain a first query result; Searching the preset access instance resource list according to the target access resource to obtain a second query result; Determining whether access to the target access instance is allowed based on the first access condition control policy, the first query result, and the second query result; When it is confirmed that the target access instance is allowed to be accessed, a preset access instance operation permission list is searched according to the target access operation to obtain a third query result; based on the second access condition control strategy and the third query result, it is determined whether the target access instance is allowed to perform the operation; When confirming whether the target access instance is allowed to perform the operation, generating response success information of the target access request; When it is confirmed that the target access instance is not allowed to be accessed, or when it is confirmed that the target access instance is not allowed to perform an operation, response failure information of the target access request is generated.

8. The method according to claim 6 or 7, characterized in that: The method further comprises: Get the data synchronization instructions issued by the distributed cluster; Based on the identification information of the instance to be synchronized and the data to be synchronized in the data synchronization instruction, the data to be synchronized is forwarded to multiple access control instances to be synchronized using a distributed cluster data synchronization algorithm to synchronize the change policy data and user authority data.

9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the distributed access control method according to any one of claims 6 to 8 by executing the computer instructions.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the distributed access control method according to any one of claims 6 to 8.

Citation Information

Patent Citations

  • Two-level policy decision-based access control method and system

    CN102006297A

  • Access request processing method, system and equipment and readable storage medium

    CN111339507A

  • PDP configuration method and device, electronic equipment and storage medium

    CN111988284A

  • Access control system and method

    US10375071B1

  • Access rights monitoring device and local access rights management module

    WO2007096558A2