Access authority management method and cloud management platform
By establishing a resource model and obtaining access logs on the cloud management platform, and automatically generating access permissions, the problem of inefficient access permission management in the cloud system is solved, and more efficient and secure access permission management is achieved.
Patent Information
- Application Number
- CN202410277946.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2024-03-11
- Publication Date
- 2025-05-16
AI Technical Summary
The existing technology is unable to effectively manage access rights in rapidly increasing cloud systems, resulting in inefficient management and insufficient security.
By establishing a resource model on the cloud management platform, obtaining access logs, and automatically generating access permissions based on this information, ensuring the automated management and accuracy of access permissions.
It realizes the automatic management of access rights of the cloud management platform, improves the efficiency of setting and customization of access rights, and enhances the security and rationality of the system.
Smart Images

Figure CN120017295A_ABST
Abstract
Description
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 15, 2023, with application number 202311524179.6 and application name “Access Policy Generation Method and Device”, all contents of which are incorporated by reference in this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to an access rights management method and a cloud management platform. Background Art
[0003] With the development of information technology such as mobile Internet, big data, and cloud computing, the accompanying network risks and threats are also increasing. In order to ensure the security of cloud resources, tenants usually use manual access rights to control user access behavior. However, the current access rights management method is not applicable to the rapidly growing cloud system. Summary of the invention
[0004] The present application provides an access rights management method and a cloud management platform, which can realize automated management of access rights in the cloud management platform.
[0005] In the first aspect, the present application provides a method for access rights management. The method is applied to a cloud management platform, which is used to manage the infrastructure that provides cloud services, and cloud resources are run on the infrastructure. The method includes: the cloud management platform establishes a resource model of cloud resources. Among them, the resource model includes the association between cloud resources and access operations. The cloud management platform obtains the access log of the cloud resources, and the access log includes user information of at least one user, resource information of the cloud resources, and historical access operations. The cloud management platform generates access rights based on the access log and the resource model, and the access rights include the permission of at least one user to access the cloud resources. In this way, the present application can facilitate the setting and management of access rights by establishing a unified resource model. Based on the access log in the cloud management platform, the access rights are generated, and the automatic generation of access rights of the cloud management platform can be realized, which effectively improves the efficiency of formulating access rights. Moreover, through this automatic generation method, it can be applied to large-scale, multi-user cluster systems to effectively improve the customization efficiency and rationality of access rights of large-scale, multi-user cluster systems. In addition, the present application generates access rights with appropriate granularity based on the user's access behavior (i.e., access requests to cloud resources) and the dependency relationship between access operations and resources, which can implement associated control on resources with associated relationships, improve the accuracy and rationality of access rights, and improve the security of the system.
[0006] For example, cloud resources may include, but are not limited to, hardware resources and software resources. Hardware resources include, but are not limited to, storage resources, network resources, etc. Software resources include, but are not limited to, business resources, data resources, etc.
[0007] Exemplarily, the access log includes at least one user log, which is used to indicate the user's access operation to the cloud resource.
[0008] Exemplarily, the access operations in the resource model are operations that users can perform on cloud resources, such as query, add, delete, etc. The operations that different cloud resources can perform can be the same or different. The historical access operations in the access log are access operations that users have performed on cloud resources. Exemplarily, the historical access operations in the access log are one or more of the access operations in the resource model.
[0009] Exemplarily, the user information includes, but is not limited to: user name, user ID, user identity information, etc. The user identity information includes, but is not limited to: the department to which the user belongs, the user project group, etc.
[0010] In one possible implementation, a cloud resource includes multiple sub-resources, and a resource model of the cloud resource is established based on the cloud resource, including: obtaining the dependency relationship between the multiple sub-resources. Based on the dependency relationship between the cloud resource and the multiple sub-resources, a resource model is established, and the resource model includes access operations, cloud resources, and the association relationship between the dependent sub-resources of the sub-resources. In this way, by sorting out the dependency relationship between resources, it is possible to avoid missing relevant access rights when formulating access rights, and effectively improve the accuracy of access rights. In addition, based on the dependency relationship between resources, resource access that does not appear in the log can be supplemented, so that the generated access rights have more comprehensive coverage, avoid missing access rights, and improve the accuracy of access rights.
[0011] Exemplarily, the dependency relationship in cloud resources can also be called a resource calling relationship, that is, when a user accesses a cloud resource, if the user accesses one of the sub-resources, the access request will also trigger the system to call at least one sub-resource that the sub-resource depends on.
[0012] In a possible implementation, the access rights also include the permission for at least one user to access a dependent sub-resource of a sub-resource. In this way, the access rights generated by this application can control access to resources accessed by users, and also control access to resources that the resource depends on, effectively improving the accuracy and rationality of access rights while improving the access security of cloud resources.
[0013] In a possible implementation, the cloud resource is provided with an access interface, and the access interface is used to respond to the target user's target access operation on the target sub-resource. The method also includes: based on the access permission and the target access operation, determining the target user's permission for the target access operation on the target sub-resource, and the target user's permission for the target access operation on the dependent sub-resource of the target sub-resource. In this way, the access permission generated by this application can control access to the resources accessed by the user, and also control access to the resources on which the resource depends, effectively improving the accuracy and rationality of the access permission, while improving the access security of cloud resources.
[0014] Exemplarily, the access interface is an API interface.
[0015] In a possible implementation, access rights are generated based on access logs and resource models, including: based on the access logs, at least one user is grouped with multiple sub-resources to obtain at least one user group and at least one cloud resource group; based on the resource model, at least one user group and at least one cloud resource group, access rights are generated; access rights include the right of at least one user group to access at least one cloud resource group. In this way, users and resources are grouped (only users can be grouped in the embodiment) to achieve automatic grouping of access rights, so that users with similar attributes can be divided into one group and have the same access rights, which is convenient for subsequent updating and optimization of access rights. Moreover, the present application can effectively improve the rationality of the granularity of access rights based on user groups and resource groups.
[0016] In a possible implementation, based on the resource model, at least one user group and at least one cloud resource group, generating access rights includes: generating initial access rights based on the resource model, at least one user group and at least one cloud resource group; wherein the initial access rights include the access rights of each user group to each resource group; in response to at least one user's access operation to the cloud resource, updating the initial access rights to obtain access rights. In this way, automatic updating of access rights can be achieved. Based on the user's access situation, access rights that fit the user's access situation and have appropriate granularity can be generated.
[0017] In one possible implementation, in response to at least one user's access operation to a cloud resource, the initial access permission is updated to obtain the access permission, including: in response to at least one user's access operation to a cloud resource, the initial access permission and the user's pre-set access permission are updated to obtain the access permission; wherein the user's pre-set access permission is used to indicate the permission of at least one user to access all or part of the cloud resources. . In this way, in a scenario where there are old access permissions (i.e., user-pre-set access permissions) in the system, the present application can further optimize the existing access permissions. For example, the access permissions set by the user may not include access permissions to some resources with dependencies. The method of the present application can avoid missing permissions and improve the rationality of access permissions.
[0018] In a possible implementation, in response to at least one user's access operation to a cloud resource, the initial access permission is updated, including: determining a weight value of the initial access permission based on a preset rule and at least one user's access operation to the cloud resource; and taking into effect access permissions with a weight value greater than a preset threshold. In this way, automatic updating of access permissions can be achieved. The granularity of access permissions can be updated in real time based on the user's access situation.
[0019] Exemplarily, the weight value may be a score in the embodiments of the present application.
[0020] Exemplarily, the preset rules include at least one of the following: setting a preset sample, wherein the weight value of the access rights that meet the preset sample is increased, and the weight value of the access rights that do not meet the preset sample is reduced; setting the access duration, wherein the weight value of the access rights that meet the access duration is increased, and the weight value of the access rights that do not meet the access duration is reduced; reducing the weight value of the access rights that trigger the access alarm; making each access right in the access rights effective one by one, and adjusting the weight value of the access rights based on the number of cloud resources accessible to the user under each access right. In this way, by setting different preset rules, the access rights can be updated in real time or periodically to reduce the granularity of the access rights to an appropriate granularity.
[0021] In a possible implementation, the method further includes: obtaining user information of the new user; based on the user information of the new user, adding the new user to a target user group, the target user group being included in at least one user group; and determining the new user's access rights to cloud resources based on the access rights corresponding to the target user group. In this way, after detecting that a new user has joined, the present application automatically optimizes the access rights so that the new user can have appropriate access rights, and the cloud management platform can perform permission control on the new user's access operations based on the access rights of the user group to which the new user belongs.
[0022] In a possible implementation, the method further includes: obtaining user information of the new user; based on the user information of the new user, querying at least one target user group similar to the new user; using the access rights corresponding to the at least one target user group as the access rights of the new user, and determining the access rights of the new user to access cloud resources. In this way, the present application grants the access rights of the user group similar to the new user to the new user, which can realize the automatic generation of the access rights of the new user, so that the technical solution of the present application can be applied to a dynamically changing environment.
[0023] Exemplarily, each user group in the at least one target user group may include one or more users.
[0024] In a possible implementation, the method further includes: in response to the access operation of the new user to access the cloud resources, updating the access rights of the new user. In this way, if the access rights of the new user may be inappropriate, the cloud management platform can update the access rights in real time according to the user's access behavior (i.e., the user's access operation to the resource), thereby retaining (or taking into effect) the appropriate access rights and removing (or invalidating) the inappropriate access rights.
[0025] In the second aspect, the present application provides a cloud management platform. The cloud management platform is used to manage the infrastructure that provides cloud services, and cloud resources are running on the infrastructure. The cloud management platform includes: a resource model creation module, which is used to establish a resource model of cloud resources, and the resource model includes the association between cloud resources and access operations; an acquisition module, which is used to obtain access logs of cloud resources, and the access logs include user information of at least one user, resource information of cloud resources, and historical access operations; an access permission generation module, which is used to generate access permissions based on the access logs and resource models, and the access permissions include the permission of at least one user to access cloud resources.
[0026] In a possible implementation, the cloud resource includes multiple sub-resources, and the resource model creation module is used to: obtain the dependency relationship between the multiple sub-resources. Based on the dependency relationship between the cloud resource and the multiple sub-resources, a resource model is established, and the resource model includes access operations, cloud resources, and association relationships between dependent sub-resources of the sub-resources.
[0027] In a possible implementation, the access permission also includes permission for at least one user to access a dependent sub-resource of the sub-resource.
[0028] In one possible implementation, the cloud management platform is provided with an access interface, which is used to respond to the target user's target access operation on the target sub-resource. The cloud management platform also includes: a permission control module, which is used to determine the target user's permission for the target access operation on the target sub-resource based on the access permission and the target access operation, as well as the target user's permission for the target access operation on the dependent sub-resource of the target sub-resource.
[0029] In one possible implementation, the access permission generation module includes: an access permission generation unit, which is used to group at least one user and multiple sub-resources based on access logs to obtain at least one user group and at least one cloud resource group; the access permission generation unit is also used to generate access permissions based on a resource model, at least one user group and at least one cloud resource group; the access permissions include permissions for at least one user group to access at least one cloud resource group.
[0030] In one possible implementation, the access permission generation module also includes an access permission optimization unit; the access permission generation unit is further used to generate initial access permissions based on a resource model, at least one user group and at least one resource group; wherein the initial access permissions include the permissions for each user group to access each resource group; the access permission optimization unit is used to update the initial access permissions in response to at least one user's access operation to a cloud resource to obtain access permissions.
[0031] In one possible implementation, the access permission optimization unit is specifically used to: in response to at least one user's access operation to cloud resources, update the initial access permission and the user's pre-set access permission to obtain the access permission; wherein the user's pre-set access permission is used to indicate the permission of at least one user to access all or part of the cloud resources.
[0032] In a possible implementation, the access permission optimization unit is specifically used to: determine the weight value of the initial access permission based on preset rules and at least one user's access operation to the cloud resource; and take into effect access permissions whose weight values are greater than a preset threshold.
[0033] In one possible implementation, the access permission generation module is also used to: obtain user information of the new user; based on the user information of the new user, add the new user to a target user group, and the target user group is included in at least one user group; the cloud management platform also includes a permission control module, which is used to: control the new user's access to cloud resources based on the access permissions corresponding to the target user group.
[0034] In one possible implementation, the access permission generation module is also used to: obtain user information of the new user; based on the user information of the new user, query at least one target user group similar to the new user; the cloud management platform also includes a permission control module, which is used to: use the access permissions corresponding to at least one target user group as the access permissions of the new user, and control the new user's access permissions to cloud resources.
[0035] In a possible implementation, the access permission optimization unit is further configured to: update the access permission of the new user in response to an access operation of the new user to access the cloud resources.
[0036] In a third aspect, an embodiment of the present application provides a computing device cluster, including at least one computing device, each computing device including a processor and a memory. The processor of at least one computing device is used to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation of the first aspect.
[0037] In a fourth aspect, an embodiment of the present application provides a computer program product comprising instructions, characterized in that when the instructions are executed by a computing device cluster, the computing device cluster executes the method in the first aspect or any possible implementation of the first aspect.
[0038] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, characterized in that it includes computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method in the first aspect or any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 This is a schematic diagram of the architecture of the cloud system in an embodiment of the present application;
[0040] Figure 2 A flowchart of an exemplary access rights management method;
[0041] Figure 3 The figure is a schematic diagram of a process of establishing a resource model for example;
[0042] Figure 4 is a schematic diagram of a resource structure shown as an example;
[0043] Figure 5 A schematic diagram of resources is shown as an example;
[0044] Figure 6 A schematic diagram of the structure of access rights shown as an example;
[0045] Figure 7 The structure diagram of the cloud management platform is shown as an example;
[0046] Figure 8 A schematic diagram of the structure of a computing device is shown as an example;
[0047] Fig. 9 A schematic diagram of the structure of a computing device is shown as an example;
[0048] Fig.10 The figure is a schematic diagram of the structure of a computing device cluster shown as an example. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0050] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0051] The terms "first" and "second" in the description and claims of the embodiments of the present application are used to distinguish different objects rather than to describe a specific order of objects. For example, a first target object and a second target object are used to distinguish different target objects rather than to describe a specific order of target objects.
[0052] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0053] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" refers to two or more than two. For example, multiple processing units refer to two or more processing units; multiple systems refer to two or more systems.
[0054] Before describing the technical solution of the embodiment of the present application, the background technology involved in the embodiment of the present application is briefly introduced:
[0055] Public cloud, also known as public cloud system, is a cloud platform provided by third-party public cloud providers for individuals or enterprises. In the public cloud, the hardware, software and other structures are owned and managed by the third-party public cloud providers. Figure 1 For an exemplary schematic diagram of the cloud system structure, please refer to Figure 1 , specifically including but not limited to: public cloud and client.
[0056] Exemplarily, a public cloud includes, but is not limited to, a cloud management platform and infrastructure.
[0057] Cloud infrastructure is the hardware equipment used to implement the public cloud system to provide various cloud services to the outside world. It can include multiple data centers (DC) located in different geographical areas. Each data center contains multiple physical servers, and each server can be used to support various cloud services such as virtual machines (VM), containers (Docker), bare metal servers, and cloud hard disks. In addition, the cloud management platform communicates with the cloud infrastructure equipment, so the cloud management platform can provide tenants with various cloud services supported by the cloud infrastructure.
[0058] A cloud management platform, also known as a cloud platform or simply a cloud management platform, is a software system for cloud technology (also known as cloud computing technology) services provided by a cloud provider, which is used to manage the infrastructure that provides cloud services. Specifically, the cloud management platform provides an interface related to cloud services for tenants to remotely access cloud services. Tenants can log in to the cloud management platform on the cloud service access page using a pre-registered account and password, and after a successful login, select and purchase the corresponding cloud service on the cloud service access page. In an embodiment of the present application, a tenant includes at least one user. The tenant has a main account, and the user has a sub-account. The following embodiments are all scenarios for user access to cloud resources, and access rights (also known as access policies) are formulated for scenarios in which users access cloud resources. In the embodiments of the present application, tenants and users can be replaced arbitrarily, and will not be repeated below.
[0059] Exemplarily, the cloud management platform may provide various interfaces such as a login interface and an access interface for access by the tenant's client (e.g., a terminal device used by the tenant or a browser on a terminal device used by the tenant, etc.). Exemplarily, the tenant's terminal may be referred to as an electronic device, a user device, or a terminal device, which is not limited in this application. Terminals include, but are not limited to: mobile phones, tablet computers, computers, personal computers (PCs), devices in the Internet of Things (IoT) system, etc.
[0060] Exemplarily, the cloud management platform may receive the account number and password input by the tenant through the client through the login interface to authenticate the tenant's client, and may allow the tenant's client to log in to the cloud management platform after the authentication is passed.
[0061] Exemplarily, the cloud management platform also provides an access interface. The access interface may be an API (Application Programming Interface). The cloud management platform may allow the tenant's client to send an access request to the cloud management platform through the access interface, and the access request is used to request to call a specified API. Exemplarily, the user's client accesses the cloud service on the cloud resource by calling the API, which essentially means that the user wants to complete a business action by performing a specific operation (i.e., an access operation) on a certain cloud resource. An application program interface is a collection of definitions, functions, programs, and / or protocols. For example, an application program interface of the cloud management platform includes one or more system calls (system calls), each of which is a program that can perform a specific function. Accordingly, in an embodiment of the present application, the cloud management platform calls the specified API in response to the access request sent by the tenant's client received by the access interface, which can also be understood as the cloud management platform performing an access operation on the corresponding cloud resource in response to the tenant's access request.
[0062] Cloud services include computing services, storage services, virtual machine services, network services, etc. Any device or function that a user device can access through the cloud management platform can be considered a service provided by the public cloud.
[0063] Cloud resources are hardware resources (also referred to as cloud infrastructure or infrastructure) and software resources (also referred to as public cloud services) used to provide services. For example, the hardware resources corresponding to software resources such as computing services, storage services or network services include computing resources, storage resources or network resources. Optionally, computing resources include central processing unit (CPU) resources, memory resources and / or hard disk resources. For example, a user (also referred to as a tenant) purchases a large number of virtual machine resources, and a large number of applications (also referred to as cloud applications) are deployed on the virtual machine resources. In this example, the virtual machine and the applications in the virtual machine belong to the cloud service (i.e., software resources), and the server and other devices to which the virtual machine belongs are the corresponding hardware resources.
[0064] In an embodiment of the present application, the cloud management platform may be deployed with an access rights management system (or may be referred to as an access rights control system, which is not limited in this application), and the access rights management system is used to generate access rights (which may also be referred to as access policies, which are not limited in this application) and perform rights management on the user's access behavior (or access request) based on the access rights. Among them, the user's access behavior (or access request) is used to indicate the user's access operation to the cloud resources. Rights management includes allowing users to access cloud resources or denying users access to cloud resources.
[0065] For example, taking the access permission design in ECS (Elastic Compute Service), suppose a user creates a cloud server to provide cloud services. The operation and maintenance personnel in the tenant (also understood as employees of the operation and maintenance department) need to have the permission to restart the cloud server, while other roles in the tenant (such as employees of the business department or employees of the personnel department) do not need to have the permission to restart the cloud server. Then, calling the API to restart the cloud server can also be understood as performing a restart access operation on the cloud server, which requires permission control. That is, in this example, the operation and maintenance personnel have the permission to call the API to restart the cloud server, and the cloud management platform allows the operation and maintenance personnel to restart the cloud server, while other employees do not have the permission to call the API, that is, the cloud management platform does not allow other employees to restart the server.
[0066] It should be noted that in the embodiments of the present application, the access permission management system is deployed in a cloud system (specifically a cloud management platform) as an example for description. In other embodiments, the technical solutions in the embodiments of the present application can also be applied to other system architectures, and the present application does not limit them.
[0067] The access permission management method in the embodiment of the present application is described in detail below. Figure 2 For a flowchart of an exemplary access rights management method, please refer to Figure 2 , including but not limited to the following steps:
[0068] S201, the cloud management platform establishes a resource model of cloud resources.
[0069] For example, in a cloud system, access rights are usually controlled in a unified manner. If an API needs to be authenticated (i.e., whether to grant the user access to the API), it is necessary to sort out the resources corresponding to the API and the resources related to it (i.e., the resources on which the various resources in the embodiments of the present application depend).
[0070] For example, suppose a user needs to create a virtual machine, and the API he calls is the API corresponding to "Create Virtual Machine". Among them, "Create" is the access operation, and "Virtual Machine" is the access object. That is to say, the "Create Virtual Machine" API is used to perform the "Create" operation on the "Virtual Machine" resource. That is, the resource corresponding to the API is the virtual machine, and the corresponding access operation is "Create". The system needs to allocate network resources and storage resources for the virtual machine to create a virtual machine. Accordingly, calling the "Create Virtual Machine" API also depends on the "Create Network Resources" API and the "Create Storage Resources" API. In other words, in the scenario where a user needs to create a virtual machine, the user needs to have the "Create Virtual Machine" permission, and also needs to have the "Create Network Resources" permission and the "Create Storage Resources" permission. It can also be understood that the user needs to have the permission to call the "Create Virtual Machine" API, the permission to call the "Create Network Resources" API, and the permission to call the "Create Storage Resources" API. The cloud management platform authenticates all relevant resources one by one to confirm whether the API call operation is feasible, that is, to determine whether the user is allowed to call the "Create Virtual Machine" API to create a virtual machine.
[0071] Based on this, in the embodiments of the present application, cloud resources, the dependencies of each resource in the cloud resources, and the corresponding access operations are sorted out, and a unified resource model is established to improve the rationality of the access rights generated subsequently and avoid the omission of access rights. In addition, the cloud resources and corresponding access operations provided by the public cloud are standardized to facilitate setting access operations for the API, which can also standardize the access rights generated subsequently for unified management and authentication.
[0072] Figure 3 For an exemplary diagram of establishing a resource model, please refer to Figure 3 When establishing a resource model, the cloud management platform uses all cloud resources (including but not limited to business applications and data resources, etc.) in the public cloud that can be provided to tenants (i.e., users) as resources (Resource). The cloud management platform can obtain the resources that each resource depends on based on the dependency relationship between resources. Accordingly, the cloud management platform establishes a resource model based on the resources (i.e., cloud resources) and the resources that each resource in the cloud resource (which can be referred to as sub-resources in the embodiment of the present application) depends on. Among them, the resource model includes the association relationship between resources, dependent resources, and access operations.
[0073] Below Figure 3 The process is described in detail:
[0074] In an embodiment of the present application, the cloud resources in the cloud system (i.e., the public cloud) may include multiple sub-resources, and the sub-resources are business data or domain objects observed from the client. In an e-commerce system, it may be customers, orders, and order details. In a cloud infrastructure system, sub-resources may be resource objects such as computing, networking, and storage. The specific entities of sub-resources can be set according to actual needs. The types and quantities of resources provided by different scenarios and different services are different, and the corresponding resource models are also different. This application does not limit them.
[0075] In the embodiment of the present application, each sub-resource is used as a resource. The cloud management platform maps each resource to a standardized public vocabulary. Similarly, for the access operations that the cloud management platform allows users to perform on cloud resources (i.e., resources), the cloud management platform maps each access operation to a standardized public vocabulary, thereby achieving standardized naming of resources and access operations to establish a unified resource model.
[0076] Specifically, the cloud management platform can obtain the resources and resource information (such as name, type, etc.) existing in the public cloud based on methods such as traversing configuration files. Among them, the configuration file can be pre-configured by the operator. For example, the operator can configure the resources that require permission control (or access control) based on the cloud management platform interface described above. The cloud management platform generates a configuration file based on the received user instructions, and the configuration file records at least one resource that requires access control. Optionally, the at least one resource configured by the user can be all resources in the system or part of the resources, which is not limited in this application. In other words, in the embodiments of the present application, access control can be performed on all resources in the cloud management platform, or access control can be performed only on part of the resources indicated by the user, which is not limited in this application.
[0077] The cloud management platform further obtains the access operations corresponding to each resource based on the configuration file, etc., which can also be understood as the access operations that the cloud management platform allows tenants (or users) to perform on resources. For example: create (also called add) (Create), delete (Delete), update (Update) (also called modify), query (Show), list (List), etc. The resources, access operations, and the corresponding relationship between resources and access operations involved in the embodiments of the present application are only illustrative examples and can be set according to actual needs. This application does not limit them.
[0078] In the embodiments of the present application, the resource model is used to represent the correspondence between resources and access operations (it can also be understood as an association relationship, etc., which is not limited in the present application). It can also be understood that a resource in the resource model contains an authorization object (i.e., access resource) and a set of operations defined on this authorization object (i.e., at least one access operation). After the cloud management platform determines the resources and the access operations corresponding to each resource, it names the resources and access operations according to the preset standardized names and obtains the correspondence between the resources and the access operations.
[0079] For example, Table 1 is an exemplary standardized model of resources related to a general “Instance”.
[0080] Table 1
[0081] action List, Show, Create, Update, Delete Resource name Instance
[0082] Please refer to Table 1, the resource name is "Instance", and the access operations defined on the instance include but are not limited to: List, Show, Create, Update, Delete. It can be understood that the access operations allowed by the system to be performed on the Instance include but are not limited to: List, Show, Create, Update, Delete, etc. Optionally, the resource name of Instance is only an illustrative example. In other embodiments, it can be named according to a pre-set name. For example, the resource name can be "Address Book", and the corresponding access operations can be "Create, Update, Show, Delete", etc. This application does not limit it.
[0083] Next, the cloud management platform obtains the dependency relationship between each resource (also called sub-resource) to determine the resource that each resource depends on. The cloud management platform further establishes a resource model based on the dependent resources of the resource and the obtained standardized model.
[0084] Figure 4 For an exemplary resource structure diagram, please refer to Figure 4, the public cloud provides "Instance" resources, and the public cloud also provides APIs corresponding to the Instance resources, including but not limited to: CreateInstance, UpdateInstance, DeleteInstance, ShowInstance and ListInstance. The operation objects corresponding to these APIs are all Instances. The cloud management platform can characterize the API based on the resource model, that is, map the access objects and access operations in the API to obtain a standardized representation of the API. The standardized representation includes but is not limited to: API name, access operation, access resource, etc.
[0085] For example, Table 2 shows an exemplary API:
[0086] Table 2
[0087] name Resource (resource, i.e. access resource) Action (access operation) CreateInstace1 Instance 1 Create DeleteInstace1 Instance 1 Delete CreateInstace2 Instance 2 Create ShowInstace2 Instance 2 Show … … …
[0088] Please refer to Table 2. For example, the API name is usually named in the form of API resource + operation, or other naming methods, which are not limited in this application. Resource is the resource called by the API (i.e., access object or access resource), and operation is the access operation performed by the API on the resource.
[0089] Among them, Table 2 can be regarded as a part of the resource model, or the initial resource model. In the following process, the cloud management platform further queries the dependency relationship between each resource (also called sub-resource), and obtains the resource model based on the obtained dependency relationship. It can also be understood as supplementing the initial resource model to generate a resource model including the association relationship between resources, dependent resources and access operations, so that the access rights generated subsequently also include the permission of at least one user to access the dependent resources of the sub-resource.
[0090] Specifically, there is a mutual dependency between resources. As mentioned above, if a user calls the "create virtual machine" API, the system will perform the business action of "create virtual machine" and also need to call other resources, such as network resources and storage resources. Therefore, in the embodiment of the present application, after obtaining the resource model, the cloud management platform further clarifies the dependency between resources, and establishes a resource model based on the dependency between resources, so that when the user calls a certain API, the cloud management platform can perform association control on the associated API. In other words, the access permission also includes at least one user's permission to access the dependent resources of the sub-resource. Accordingly, when the cloud management platform responds to the target user's target access operation on a sub-resource (or can be called a target sub-resource), it can determine the target user's permission to the target access operation of the target sub-resource based on the access permission, as well as the target user's permission to the target access operation of the dependent sub-resource of the target sub-resource, so as to achieve association control on the access operation of the resource on which the sub-resource depends.
[0091] In the embodiment of the present application, the dependencies between different resources (i.e., sub-resources) will also cause the corresponding APIs to have dependencies. Accordingly, the cloud management platform can determine the dependencies between APIs based on the dependencies between resources, and obtain a resource model based on the dependencies between APIs. For example, Figure 5 For an exemplary resource diagram, please refer to Figure 5 The cloud management platform can sort out the dependencies between resources based on the configuration file. For example, there is a dependency between Instance1 (which can be a virtual machine or other resource, which is not limited in this application) and Resource1 and Resource2 (which can be a network disk, storage or other resource, which is not limited in this application). As shown in Table 3:
[0092] Table 3
[0093]
[0094] Please refer to Table 3. Based on the dependency relationship between resources, the cloud management platform can determine that the API of "CreateInstance1" depends on the API of "CreateResource1" and the API of "CreateResource2". In other words, if the cloud management platform needs to call the API of "CreateInstance1", it also needs to further call the API of "CreateResource1" and the API of "CreateResource2".
[0095] Optionally, in the embodiments of the present application, only one API corresponding to one resource and one access operation is used as an example for illustration. In other embodiments, the API may also correspond to one resource and multiple access operations, and the present application does not limit this.
[0096] In this way, the cloud management platform in this application can obtain a unified resource model to facilitate setting access control policies (i.e., access permissions) for APIs. It also clarifies the dependencies between resources, and further clarifies the dependencies between APIs, so as to achieve the associated control between APIs. In addition, in the embodiments of this application, by mapping resources with access operations to obtain corresponding standardized APIs (which can also be understood as characterizing the API), complex access permissions are converted into corresponding relationships between Resources and Actions.
[0097] S202, the cloud management platform obtains access logs of cloud resources.
[0098] In an embodiment of the present application, the cloud management platform collects access logs. Among them, the access log includes the user's user information, the resource information of the cloud resources, and the access operation. Specifically, the cloud management platform responds to the user's access request, obtains the user information, access object, access operation and other information included in the access request, and generates a corresponding access log. It can be understood that each access log (also referred to as a log entry) in the access log is used to describe a user's access behavior to a cloud resource. Optionally, the logs cached by the cloud management platform may include multiple types of log information, such as access logs, alarm logs, etc., which are not limited in this application. In an embodiment of the present application, the cloud management platform only obtains access logs.
[0099] S203, the cloud management platform generates access rights based on the access log and resource model.
[0100] In an embodiment of the present application, the cloud management platform may group the users, resources, access operations (also referred to as historical access operations or user access operations) involved in the access log based on the access log. Optionally, the set of access operations on resources included in the access log may be less than or equal to the set of access operations corresponding to the resource in the resource model. For example, in the resource model, the access operations on resource 1 include access operations A to D, while only access operations A and C on resource 1 may appear in the access log, that is, in the access log counted by the cloud management platform, the user did not perform access operations B and D on resource 1.
[0101] The cloud management platform can generate access rights based on the grouping results (such as user groups and resource groups) and resource models. Correspondingly, the access rights include the rights of the user group to access the resource group. In the embodiment of the present application, the access rights are generated with "group" as the granularity, and the rights of users and resources with the same attributes can be uniformly managed to provide access rights with appropriate granularity.
[0102] Specifically, the generation process of access rights can be divided into two parts: the first part is to generate initial access rights according to the access log and resource model, and the second part is to update (also called optimization) the initial access rights to obtain access rights (also called access policy).
[0103] The following is an introduction to the above two parts:
[0104] Part 1: Generate initial access permissions based on access logs and resource models.
[0105] Exemplarily, the cloud management platform extracts key information from the access log based on the access log obtained. It can be understood that the access log includes some key information and some non-key information, wherein the key information is defined as information used to generate access rights in the embodiment of the present application, and conversely, non-key information is some information that is not used to generate access rights. Exemplarily, the key information includes, but is not limited to: user information, access operations, access objects, access time and other information.
[0106] Optionally, the user information is used to identify the user, and the user information of each user is different and unique. The user information includes but is not limited to at least one of the following: user identification information, user address information, user identity information, etc.
[0107] User identification information may include, but is not limited to, at least one of the following: user name, user ID, device ID, and other information.
[0108] The user address information may include but is not limited to at least one of the following: device IP address, device MAC address and other information.
[0109] The user identity information may include but is not limited to at least one of the following: the user's department, the user's project group, the virtual private cloud (VPC) ID, etc. Optionally, the user identity information may be obtained from the log or from other user files, which is not limited in this application.
[0110] The access object is used to indicate the resource object corresponding to the user behavior (also referred to as access behavior) represented by the access log. Optionally, in a system with a Restful interface, the access object may be a URL in the API information, etc., which is not limited in this application.
[0111] The access operation is used to indicate the access operation corresponding to the user behavior represented by the access log, which is the Action mentioned above.
[0112] Access time is used to indicate the access time or access duration. This information is mainly used to filter some accidental traffic in the subsequent stage to avoid misjudgment of access rights by such accidental traffic.
[0113] Optionally, the access log may also include condition information to indicate access conditions. It can be understood that only users who meet certain conditions (i.e., specific users) can access a certain resource. For example, some resources can only be accessed by specific users under specific IPs (specific IPs are Conditions). In other words, if the same user is not under a specific IP, he cannot access the resource. In this example, a Condition information is included, i.e., {IP == ${IP}}. Optionally, the Condition information is usually some keywords pre-set by the cloud management platform.
[0114] Exemplarily, the cloud management platform constructs a user feature vector based on the acquired user information. The feature vector is as follows:
[0115] (user_name, user_id, devise_id, ip, dept_no, project_id, vpc_id)
[0116] Among them, user_name is used to indicate the user name, user_id is used to indicate the user ID, devide_id is used to indicate the device ID, dept_no is used to indicate the department to which the user belongs, project_id is used to indicate the project group to which the user belongs, and vpc_id is used to indicate the VPC ID.
[0117] Exemplarily, the cloud management platform maps key information to access vectors based on the resource model. Among them, the access vector represents the correspondence between users, resources, and access operations. It can be understood that the resource model is used to represent the relationship between resources (here refers to the access resources that appear in the log, which may not include dependent resources involved in the access process) and access operations. Based on the access log and resource model, the cloud management platform can map the information in the access log to the same form as the resource model to obtain the relationship between users, resources, and access operations.
[0118] Specifically, the cloud management platform may map the user feature vector to a user identifier, such as U1, U2, etc. For example, the cloud management platform may map the feature vector (user_name, user_id, devide_id, ip, dept_no, project_id, vpc_id) to U (or other identifiers, which are not limited in this application) to characterize a user through a standardized user identifier.
[0119] Accordingly, the cloud management platform maps the key information according to the standardized definition of the resource model, and obtains the vector corresponding to each key information (also called the access vector), which is used to represent the corresponding relationship between users, access operations and resources, and other information (such as Condition). The vector can be expressed as:
[0120] <User,Action,Condition,Resource>
[0121] That is, the mapped vector can be used to represent the association relationship between users, access operations (Action), resources (Resource) and conditions (Condition).
[0122] Exemplarily, as described above, the resource model also includes the association relationship between the dependent resources of the sub-resources and the access operation, which can also be understood as the association relationship between each API and the dependent API. The cloud management platform can further generate an access vector based on the dependency relationship between the APIs in the resource model, and the access vector has been completed. It can be understood that the access vector generated by the cloud management platform based on the access log represents the association relationship between the user, the resources accessed by the user, and the access operation performed. As described above, there is a dependency relationship between resources. Assuming that the user expects to access Resource1, and Resource1 depends on Resource2, the user needs to have the permission to call the API of Resource1 and the permission to call the API of Resource2. However, in some scenarios, the access log may only record the relevant records of the user's access to Resource1, and will not record the records of other APIs called in the process of calling the API of Resource1. Therefore, in order to ensure the integrity and coverage of the generated access rights, the cloud management platform can further generate an access vector based on the dependency relationship between the APIs in the resource model to obtain a complete access vector including the association relationship between the resource, the dependent resources of the resource, and the access operation.
[0123] Specifically, after the cloud management platform obtains the access vector corresponding to each access log (i.e., key information), it can query whether the access vector is missing the vector corresponding to the API with dependency relationship based on the dependency relationship of the API in the resource model (i.e., the association relationship between the dependent resources of the resource and the access operation). If missing, the corresponding access vector is supplemented.
[0124] For example, taking the API dependency in Table 3 as an example, it is assumed that the access vectors currently obtained by the cloud management platform include:
[0125] <U1,Create,Instance1>
[0126] <U1,Delete,Instance1>
[0127] …
[0128] The cloud management platform is based on the resource model<U1,Create,Instance1> , determine that the API "CreateInstance1" depends on the APIs "CreateResour1" and "CreateResource2". The cloud management platform traverses the generated access vectors to detect whether it includes<Create,Resource1> and<Create,Resource2> If not included, the corresponding vector is added to the access vector. Optionally, the user corresponding to the supplemented access vector can be any user. This supplementation step is mainly to avoid missing the relevant API access rights in the access rights generated subsequently.
[0129] In one possible implementation, the cloud management platform may further improve the obtained access vector based on the resource model. As mentioned above, the set of resources and access operations in the access log may be less than or less than or equal to the set of resources and access operations in the resource model. For example, the resource model includes the corresponding relationship of {R3, Delete}, that is, the cloud management platform allows users to perform the Delete operation on R3. Assume that only administrators in the tenant can perform the "Delete" operation on the R3 resource, and in the access log obtained by the cloud management platform, the administrator did not perform the "Delete" operation on the R3 resource. In other words, the access vector generated by the cloud management platform based on the access log does not include<Delete,R3> In this example, the cloud management platform can determine the missing<Delete,R3> The cloud management platform can generate corresponding vectors, such as<U1,Delete,R3> Here we only take the vector assigned to U1 as an example. It can be assigned to any user. The purpose is to make the initial access rights generated later exist.<Delete,R3> The relevant access rights.
[0130] Exemplarily, the cloud management platform groups at least one user in the tenant and multiple sub-resources in the cloud resources based on the access log, and obtains at least one user group and at least one cloud resource group (which may be referred to as a resource group). Specifically, the cloud management platform performs cluster analysis on the access vectors based on the access log to obtain user groups and resource groups. Exemplarily, the cloud management platform may perform cluster analysis on the access vectors that have been obtained based on the access log (which may also be key information) to determine whether there are common characteristics between users and whether there are common characteristics between resources. The cloud management platform may divide users with common characteristics into one group, and divide resources with common characteristics into one group, to obtain at least one user group and at least one resource group.
[0131] In one example, the method of finding common characteristics between users can be based on the user information of the users, that is, the common characteristics are user attributes. For example, users in the same department can be divided into one group, users in the same project group can be divided into one group, and users in the same IP address can be divided into one group.
[0132] In another example, the method of finding common characteristics between users can be based on access behavior, that is, the common characteristics are the same or similar access behaviors. For example, the access behaviors of multiple users are highly similar, for example, the access records of U1 and U2 both indicate the execution of the "Create" operation on Resource1, and U1 and U2 can be grouped together.
[0133] In one example, the method of finding common characteristics between resources may be based on the dependency relationship of the resources, that is, the common characteristics are the dependency relationship. For example, resources with dependency relationships may be divided into a group.
[0134] In another example, the method of finding common characteristics between resources can be based on the access situation of the resources, that is, the common characteristics are access behaviors. For example, the same user (or user group) always accesses the same multiple resources, and these resources can be divided into one group.
[0135] It should be noted that the division rules (ie, common characteristics) of user groups and resource groups in the embodiments of the present application are only illustrative examples. In other embodiments, they can be set according to actual needs and are not limited in the present application.
[0136] Optionally, the cloud management platform may also group access operations and other information such as Condition, and the grouping conditions (ie, common characteristics) may be set according to actual needs, and this application does not limit this.
[0137] Optionally, each user corresponds to a separate user group, and each resource also corresponds to a separate resource group. For example, U1 and U2 are divided into the same user group G1, and U1 and U2 correspond to separate user groups respectively, that is, user groups include but are not limited to: {U1}, {U2}, G1 = {U1, U2}.
[0138] Exemplarily, the cloud management platform generates access rights based on the resource model, at least one user group and at least one resource group. Specifically, the cloud management platform first generates initial access rights (which may also be referred to as alternative access rights, etc., which are not limited in this application) based on the resource model, at least one user group and at least one resource. Among them, the initial access rights are used to indicate the permissions of each user group to access operations on each cloud resource group. It can be understood that the initial access rights can cover the permissions corresponding to all possible combinations of user groups, cloud resource groups and access operations (which may also include other parameters such as conditions).
[0139] The permission control scope of the initial access rights in the embodiment of the present application is relatively large, and the main purpose is to cover the APIs that may need permission control in the system as comprehensively as possible. When the permission control scope of the initial access rights is large and the coverage is wide, the initial access rights are updated (or optimized) to reduce unnecessary access rights, thereby avoiding missing access rights while reducing the granularity of the access rights. It can be understood that the initial access rights generated in the embodiment of the present application can formulate corresponding access rights for all resources that each user may access and all access operations that may be performed, that is, the user formulates access rights for each API that may be called, especially including the access rights of the API corresponding to the dependent resources. Then the initial access rights are updated (or optimized) to eliminate unnecessary access rights. Access rights with appropriate granularity can enable the system to accurately control the user's access behavior based on the access rights, and the comprehensiveness of the access rights can reduce the attack area and improve the security of the system.
[0140] Exemplarily, access rights can be divided into identity-based access rights and resource-based access rights. Identity-based access rights are used to control what operations visitors (such as user groups, project teams, and other role identities) can perform on those resources under what conditions. Resource-based access rights are used to grant specified visitors the authority to perform specific access operations on specified resources, and define the conditions under which this authority is used. The above two types of access rights are only illustrative examples, and other access rights modes may be used in other embodiments, which are not limited in this application.
[0141] In the embodiment of the present application, taking resource-based access rights as an example, it is assumed that the access rights are defined as follows:
[0142]
[0143] This access permission means: the user with UserID o-xxxxxxxxxxx is allowed to perform the "ShowInstance" and "ListInstance" operations on the resource (ecs:cn-north-1:instance).
[0144] In a possible implementation, the cloud management platform can obtain initial access rights based on user groups and resource groups by means of Cartesian product. Each access right in the initial access rights is used to represent the correspondence between user groups, resource groups, and access operations. For example, assume that UserGroup includes U1 and U2, and Action includes Create and Show. Condition includes g:DomainId and g:DomainName, and Resource Group includes R1 and R2. Effect includes Allow and Deny. Based on the above set, a Cartesian product is generated, and the initial access rights obtained include but are not limited to:
[0145] (U1,Create,g:DomainId,R1,Allow)
[0146] (U1,Create,g:DomainId,R1,Deny)
[0147] (U1,Create,g:DomainId,R2,Allow)
[0148] (U1,Create,g:DomainId,R2,Deny)
[0149] (U1,Create,g:DomainId,R1,Allow)
[0150] (U1,Create,g:DomainId,R1,Deny)
[0151] (U1,Create,g:DomainId,R2,Allow)
[0152] (U1,Create,g:DomainId,R2,Deny)
[0153] (U1,Create,g:DomainName,R1,Allow)
[0154] (U1,Create,g:DomainName,R1,Deny)
[0155] (U1,Create,g:DomainName,R2,Allow)
[0156] (U1,Create,g:DomainName,R2,Deny)
[0157] …
[0158] In another possible implementation, the cloud management platform can generate initial access permissions based on the access log (i.e., key information) and the resource model. Specifically, the cloud management platform can extract users based on key information and map users to specified user identifiers, such as U1, U2, etc. The cloud management platform can generate corresponding access vectors based on users, combined with each resource in the resource model and the corresponding access operations. For example, assuming that there is a U1 user and the resource model is shown in Table 1, the cloud management platform can generate the following access vectors accordingly:
[0159] <U1,List,Instance>
[0160] <U1,Show,Instance>
[0161] <U1,Create,Instance>
[0162] <U1,Delete,Instance>
[0163] <U1,Update,Instance>
[0164] The cloud management platform can group users and resources based on access logs. The grouping method can refer to the above and will not be repeated here. This access permission generation method does not refer to API dependencies, that is, all possible APIs are covered in the vector generated based on resources. The other processing steps are the same as in the above embodiment and will not be repeated here.
[0165] In another possible implementation, if access rights already exist in the cloud management platform, for example, the existing access rights are set by the user and are used to control the access rights of at least one user to all or part of the cloud resources (i.e., sub-resources) in the cloud resources. The cloud management platform can obtain the access rights that have been generated, and perform subsequent optimization steps on the access rights that have been generated together with the initial access rights newly generated based on the above method. Optionally, the cloud management platform can also skip the generation step of the above access rights and directly perform subsequent optimization processes on the access rights pre-set by the user to improve the accuracy of the preset access rights.
[0166] Part 2: Update (or optimize) the initial access permissions to obtain access permissions (also called access policies).
[0167] During the access rights optimization phase, the cloud management platform optimizes the initial access rights in real time or periodically to reduce the granularity of access rights and obtain fine-grained access rights.
[0168] Specifically, the cloud management platform optimizes the initial access rights in response to the user's access operation to cloud resources (which can also be understood as the user's access behavior) to obtain access rights. Specifically, the cloud management platform evaluates each access right based on the user's access behavior, and eliminates unnecessary access rights based on the evaluation results, narrows the scope of coarse-grained access rights, and obtains a fine-grained scope of rights to improve system security and reduce system risks. Moreover, this optimization method is an automated method and can be applied to large-scale, multi-user cluster scenarios to effectively improve the configuration efficiency of access rights. In addition, during the optimization process, the cloud management platform optimizes and adjusts access rights in real time based on the user's access behavior, so that access rights can be dynamically adjusted according to the changing environment and threats, effectively improving the security of the system.
[0169] Specifically, the cloud management platform can obtain the user's access log in real time or periodically, which can also be understood as monitoring the access behavior of at least one user in the tenant. Optionally, based on different optimization methods, the cloud management platform can set different monitoring conditions to extract access logs that meet the monitoring conditions. After the cloud management platform extracts the access logs that meet the monitoring conditions, it can extract the corresponding key information based on the resource model in the manner described above, including but not limited to: user information, access operations, access resources, access time, etc.
[0170] The cloud management platform is pre-set with optimization conditions (also known as optimization rules or preset rules, which are not limited in this application). The optimization conditions are used to indicate that the access rights that meet the conditions are retained and the access rights that do not meet the conditions are eliminated. The cloud management platform can obtain the weight value of each access right in the initial access rights based on the optimization conditions and user access behavior (i.e., at least one user's access operation on cloud resources), and optimize the initial access rights based on the weight value. Optionally, the cloud management platform can set a scoring standard, add 1 point to the weight value (i.e., score) of the access rights that meet the optimization conditions (it can also be other values, which are not limited in this application), and subtract 1 point from the weight value (i.e., score) of the access rights that do not meet the optimization conditions. Then, the cloud management platform evaluates each access right based on the scoring result (i.e., weight value) of each access right.
[0171] In the embodiment of the present application, the cloud management platform validates (or can be understood as retaining) access rights whose scoring results (i.e., weight values) are greater than or equal to a preset threshold, and invalidates (or can be understood as removing) access rights whose scoring results are less than or equal to the preset threshold. Optionally, in the embodiment of the present application, "retaining" access rights can be understood as validating the access rights, and "removing" access rights can be understood as invalidating the corresponding access rights. The "removed" access rights can still exist in the access rights, and can be understood as invalid (or ineffective) alternative access rights. In the process of real-time optimization of the present application, the "removed" access rights may still be effective, and the present application does not limit this.
[0172] Several optimization methods are provided below. It should be understood that the optimization methods in the embodiments of the present application are only illustrative examples. In other embodiments, different optimization conditions can be set according to actual needs, and this application does not limit them.
[0173] Optimization method 1)
[0174] Exemplarily, the optimization condition in this method can be based on an evaluation sample. For example, there are currently 100 users, and the operator can set an evaluation sample. The evaluation sample can optionally set corresponding access rights for 10 of the users (in the embodiment of the present application, 10% of the total number of users is taken, which is only an illustrative example and is not limited in this application). For example, A1 can perform a Create operation on R1, but cannot perform a Delete operation on R1. The access rights contained in the corresponding evaluation sample are:<A1,Create,R1,Allow> ,<A1,Delete,R1,Deny> The cloud management platform can score each access right in the current access rights based on the evaluation sample. If the access right is consistent with the permissions required by the access right in the evaluation sample, 1 point can be added to the access right (for illustrative purposes only). If the access right is inconsistent with the permissions required by the access right in the evaluation sample, 1 point can be subtracted from the access right (for illustrative purposes only). In other words, if a user who was originally prohibited from access has access rights under the new access rights, 1 point will be subtracted from the access right.
[0175] For example, let's take the evaluation sample above as an example. Assume that in the initial access rights generated by the cloud management platform, A1 belongs to group G1, group G2, and group G3. The initial access rights include but are not limited to:
[0176] <G1,Create,R1,Allow>
[0177] <G1,Create,R1,Deny>
[0178] <G1,Delete,R1,Allow>
[0179] <G1,Delete,R1,Deny>
[0180] <G2,Create,{R1,R2},Allow>
[0181] <G2,Create,{R1,R2},Deny>
[0182] <G2,Delete,{R1,R2},Allow>
[0183] <G2,Delete,{R1,R2},Deny>
[0184] <G3,Create,R1,Allow>
[0185] <G3,Create,R1,Deny>
[0186] <G3,Delete,R1,Allow>
[0187] <G3,Delete,R1,Deny>
[0188] Accordingly, the cloud management platform determines based on the evaluation samples<G1,Create,R1,Allow> ,<G1,Delete,R1,Deny> ,<G2,Create,{R1,R2},Allow> ,<G2,Delete,{R1,R2},Deny> ,<G3,Create,R1,Allow> ,<G3,Delete,R1,Deny> If the evaluation conditions are met, the score (i.e., weight value) of each of the above initial access rights is increased by 1. And,<G1,Create,R1,Deny> ,<G1,Delete,R1,Allow> ,<G2,Create,{R1,R2},Deny> ,<G2,Delete,{R1,R2},Allow> ,<G3,Create,R1,Deny> ,<G3,Delete,R1,Allow> If the evaluation conditions are not met, the score (i.e., weight value) of each of the above initial access rights will be reduced by 1.
[0189] Optimization method 2)
[0190] Exemplarily, the optimization condition in this method may be based on the access duration. For example, the optimization condition includes a preset access duration (e.g., 1 day, 1 week, not limited in this application). If no access behavior corresponding to a certain initial access right is detected within the preset access duration, the access right is removed (or the Deny right may be retained, and the ALLOW right may be removed). It can also be understood that the access right is redundant.
[0191] For example, initial access rights include but are not limited to:
[0192] <G1,Create,R1,Allow>
[0193] <G1,Create,R1,Deny>
[0194] The cloud management platform responds to the tenant's (i.e., at least one user's) access to cloud resources and determines that the Create request from G1 to R1 has not been detected within the preset access duration. This can also be understood as not detecting the user in G1 calling the "CreateR1" API. Accordingly, the cloud management platform may consider the above two initial access permissions to be redundant. Optionally, the cloud management platform may reduce the score (i.e., weight value) of the access permission that has not been hit for a long time by 1.
[0195] In some instances, the cloud management platform can remove (i.e., invalidate) the two initial access permissions. In other examples, the cloud management platform can retain (i.e., make them effective)<G1,Create,R1,Deny> Initial access rights are removed (i.e. invalidated)<G1,Create,R1,Allow> Initial access rights.
[0196] Optimization method 3)
[0197] Exemplarily, the optimization condition of this method can be based on the attack area. The attack area can be optionally the number of resources accessible to the user. The more resources the user can access, the larger the attack area of the system is subject to, and the cloud management platform will reduce the score (i.e., weight value) of the corresponding access rights by 1. Conversely, the fewer resources the user can access, the smaller the attack area of the cloud management platform is subject to, and the cloud management platform will increase the score (i.e., weight value) of the corresponding access rights by 1. Specifically, the cloud management platform implements the initial access rights one by one to detect the impact of the initial access rights on the user's access behavior.
[0198] For example, assume that the initial access rights include but are not limited to:
[0199] <G1,Create,R1,Allow>
[0200] <G1,Create,R1,Deny>
[0201] Cloud management platform takes effect<G1,Create,R1,Allow> Access rights are invalid<G1,Create,R1,Deny> During the process of taking effect of the access rights (the duration of effect can be set according to actual needs and is not limited in this application), the cloud management platform obtains the key information corresponding to the access log in real time or periodically. The key information is used to describe the user's access operations to cloud resources. The cloud management platform can determine the current<G1,Create,R1,Allow> During the process of the access rights taking effect, the access behaviors performed by all users in the G1 user group, including which access operations were performed on which resources. The cloud management platform can count the number of resources accessed by the G1 user group, for example, including 10 resources. Then, the cloud management platform fails.<G1,Create,R1,Allow> Access rights, effective<G1,Create,R1,Deny> Access rights. During the process of taking effect of the access rights (the effective duration can be set according to actual needs and is not limited by this application), the cloud management platform obtains the key information corresponding to the access log in real time or periodically. The cloud management platform can determine the current<G1,Create,R1,Deny> During the process of the access rights taking effect, the access behaviors performed by all users in the G1 user group, including which access operations were performed on which resources. The cloud management platform can count the number of resources accessed by the G1 user group, for example, including 4 resources.<G1,Create,R1,Allow> In this case, the number of resources accessed by the G1 user group is greater than<G1,Create,R1,Deny> In other words,<G1,Create,R1,Allow> When it takes effect, the corresponding attack surface is larger. Therefore, the cloud management platform will<G1,Create,R1,Allow> The score (i.e. weight) of the access permission is reduced by 1.<G1,Create,R1,Deny> The score (ie, weight value) of the access permission is increased by 1.
[0202] In a possible implementation, if an alarm message is generated in the access log during the process of the access right taking effect, the score corresponding to the access right is reduced by 1. For example, in some examples, if the attack surface corresponding to the access right is small but an alarm is triggered, that is, the access log includes an alarm message, the score corresponding to the access right is reduced by 1.
[0203] Exemplarily, the cloud management platform may retain (or enable) access rights whose scores are greater than or equal to a preset threshold (which can be set according to actual needs and is not limited in this application) based on the scoring results (i.e., the weight value of each access right), and eliminate (or invalidate) access rights whose scores are less than or equal to the preset threshold, thereby obtaining access rights of appropriate granularity.
[0204] Optionally, the cloud management platform may perform weighted processing based on the scores of each access right to obtain a corresponding score result (which may also be referred to as an evaluation result or assessment result, which is not limited in this application). For example, the cloud management platform may obtain the score result of the access right based on the following formula to determine whether the access right is reasonable:
[0205]
[0206] Among them, α i is the harmonic coefficient, S threshold The threshold for determining sensitive information can be set according to actual needs and is not limited in this application.
[0207] After the cloud management platform obtains the access rights, it saves the access rights. In addition, based on the access rights, the cloud management platform performs permission control on each received user's API call, that is, it performs permission control on each user's access operation to access cloud resources to detect whether the user is allowed to access the corresponding cloud resources, which can also be understood as whether the user is allowed to call the corresponding API.
[0208] In an embodiment of the present application, the cloud management platform can optimize the access rights in real time or periodically based on the access log to achieve dynamic adjustment of the access rights so that the access rights can cope with the changing environment. The optimization method can refer to any of the above, or the operator can also set other optimized access rights or optimization conditions, which can be set according to actual needs, and this application does not limit it. In a possible implementation method, the cloud management platform can adjust the score (i.e. weight value) of the access rights (including effective and invalid access rights) based on the alarm information. For example, due to changes in environmental factors such as resource adjustment, the originally accessible resources become sensitive resources. In this scenario, when the cloud management platform performs permission control based on the current access rights, an alarm message may be generated (i.e., the originally accessible resources are currently inaccessible resources). The cloud management platform can adjust the access rights score in time based on the alarm information. For example, the score of the invalid access rights after adjustment may be greater than the score of the effective access rights (referring to the Allow and Deny permissions for the same API). The cloud management platform can re-determine the effectiveness of the access rights based on the adjusted weight value. In another possible implementation, the cloud management platform may update the score of the access permission based on the number of times a user accesses a certain resource in the access log. For example, due to environmental changes such as department adjustments, the current access permission of the G1 user group may indicate that the G1 user group cannot access the R1 resource. However, after the department adjustment, the G1 user group needs to access the R1 resource. Accordingly, each time a user of the G1 user group accesses the R1 resource, it will be denied. Optionally, the user group may request the administrator to grant access to R1. The cloud management platform may adjust the score of the access permission based on the number of times the G1 user group is denied access to the R1 resource and the number of times the G1 group continues to access R1 after being denied, so as to achieve dynamic optimization of the access permission.
[0209] In an embodiment of the present application, for a newly added user, the cloud management platform can determine that there is a new user in the system based on the access log obtained on an implementation or periodic basis. The cloud management platform can obtain the corresponding user information based on the access log. The specific acquisition method can refer to the above and will not be repeated here. In one example, the cloud management platform can add the new user to the existing user group based on the obtained user information. For example, if the new user and at least one existing user group belong to the same project group, the new user is added to at least one user group. The access rights corresponding to the corresponding at least one user group are also effective for the new user. In another example, after the cloud management platform adds the new user to at least one group, it detects that there is an alarm information corresponding to the new user in the access log. The cloud management platform determines that the group to which the new user belongs is inaccurate. The cloud management platform can create a separate group for the new user, and generate new access rights for the new user based on the above-mentioned access right generation process. The specific generation method can refer to the above and will not be repeated here. In another example, the cloud management platform may also group the new user into a separate group, and based on the user information of the new user, search for at least one user group in the existing user groups that has similar user information to the new user. The cloud management platform may grant access rights corresponding to at least one user group to the new user group to which the new user belongs. The cloud management platform may evaluate the new access rights corresponding to the new user group based on the above-mentioned optimization method, and update (or optimize) the access rights based on the evaluation results. The specific implementation method may refer to the above and will not be described here. In another example, the cloud management platform does not find a user group that is the same or similar to the new user based on the user information. The cloud management platform may obtain the access log of the new user, and generate corresponding new access rights for the new user based on the above-mentioned access right generation method.
[0210] The technical solution above is described in detail with specific embodiments below:
[0211] Exemplarily, the cloud management platform establishes an initial resource model based on cloud resources, which may include but is not limited to:
[0212] {Instance, {Create,Delete,query}}
[0213] {VPC, {Create, Delete}}
[0214] Next, the cloud management platform obtains the dependencies between sub-resources and builds a resource model based on the dependencies between cloud resources and sub-resources. The resource model includes the association between cloud resources, sub-resource dependencies, and access operations. See Table 4:
[0215] Table 4
[0216]
[0217] Next, the cloud management platform obtains user groups and resource groups based on the resource model and access logs. Specifically, the cloud management platform extracts key information based on the access logs. The cloud management platform collects access logs and<UserId,IP,Action,Time,resource> , extract the key information corresponding to each access log. For example, the key information extracted by the cloud management platform includes but is not limited to:
[0218] c607e3b-c1c4-42ae-8b52-62f31e5578b1,10.173.140.3,create,2021-10-0110:23:45.123,instance
[0219] 263a38a5-6fb2-453d-b265-12722f6d7a00,10.173.140.3,create,2021-10-0110:23:45.123,instance
[0220] 263a38a5-6fb2-453d-b265-12722f6d7a00, 10.173.140.3, query, 2021-10-0110:23:45.123, instance
[0221] …
[0222] In this example, 10.173.140.3 is the IP address information, that is, the Condition information described above. In some examples, the IP address may also be a network resource, which is not limited in this application.
[0223] Exemplarily, the cloud management platform can filter out sporadic traffic based on access time or access duration, such as access behavior that only occurs once, or key information corresponding to access logs whose access duration is less than a threshold (which can be set according to actual needs and is not limited in this application).
[0224] Based on the resource model, the cloud management platform maps key information into access vectors to represent the corresponding relationship between users, resources, and access operations. Specifically, the cloud management platform obtains key information. Based on the resource model, the cloud management platform maps the key information corresponding to the access log into a standardized API structure.
[0225] For example, the cloud management platform maps 9c607e3b-c1c4-42ae-8b52-62f31e5578b1 to U1 and 263a38a5-6fb2-453d-b265-12722f6d7a00 to U2. The access vectors obtained based on key information include but are not limited to:
[0226] <U1,Create,Instance,10.173.140.3>
[0227] <U1,Delete,Instance,10.173.140.3>
[0228] <U1,Create,Instance,10.173.140.16>
[0229] <U1,Delete,Instance,10.173.140.16>
[0230] <U2,Query,Instance,10.173.140.13>
[0231] <U3,Create,Instance,10.173.140.3>
[0232] <U3,Delete,Instance,10.173.140.3>
[0233] <U3,Create,Instance,10.173.140.16>
[0234] <U3,Delete,Instance,10.173.140.16>
[0235] …
[0236] Exemplarily, assuming that the key information corresponding to the access log does not include the access operations corresponding to "create VPC" and "DeleteVPC", the access vector generated by the cloud management platform accordingly does not include the vectors corresponding to the above access operations. The cloud management platform can determine that the resource Instance and the resource VPC have a dependency relationship based on the API dependencies included in the resource model (i.e., resource dependencies), as shown in Table 4, and that the "CreateInstance" API depends on the "CreateVPC" API. The "DeleteInstance" API depends on the "DeleteVPC" API. Accordingly, the cloud management platform supplements the corresponding access vectors, and the supplemented vectors include but are not limited to:
[0237] <U1,Create,VPC,10.173.140.3>
[0238] <U1,Delete,VPC,10.173.140.3>
[0239] <U1,Create,VPC,10.173.140.16>
[0240] <U1,Delete,VPC,10.173.140.16>
[0241] <U3,Create,VPC,10.173.140.3>
[0242] <U3,Delete,VPC,10.173.140.3>
[0243] <U3,Create,VPC 10.173.140.16>
[0244] <U3,Delete,VPC,10.173.140.16>
[0245] …
[0246] The cloud management platform performs cluster analysis on the access vectors based on the access logs to obtain user groups and resource groups. Based on the classification conditions described above, the cloud management platform groups users, condition information (i.e., IP addresses), and resources based on the vectors described above to obtain user groups, resource groups, and condition groups, including but not limited to:
[0247] User Group:
[0248] G1={U1,U3}
[0249] G2={U2}
[0250] G3={U1}
[0251] G4={U3}
[0252] Resource Group:
[0253] R1={Instance,VPC}
[0254] R2={Instance}
[0255] R3={VPC}
[0256] Condition groups are:
[0257] {10.173.140.13} and {10.173.140.3, 10.173.140.16}
[0258] Execute S404 to obtain initial access permissions based on the user group and the resource group.
[0259] Specifically, the cloud management platform obtains initial access permissions based on the above grouping using a Cartesian product method.
[0260] Assuming that the cloud management platform generates initial access permissions by means of Cartesian product, the data is as follows:
[0261] (G1,{Create,Delete},{g:IP,StringEquals{10.173.140.3, 10.173.140.16}},{Instance,VPC},Allow)
[0262] (G1,{query},{g:IP,StringEquals{10.173.140.3, 10.173.140.16}},{Instance,VPC},Deny)
[0263] (G2,{query},{g:IP,StringEquals{10.173.140.13}},{Instance,},Allow)
[0264] (G2,{Create,Delete},{g:IP,StringEquals{10.173.140.13}},{Instance,},Deny)
[0265] …
[0266] Next, the cloud management platform may update (or optimize) the initial access rights based on the optimization method described above to reduce the scope of control of the access rights.
[0267] For example, Figure 6 For an exemplary structural diagram of access rights, please refer to Figure 6In this access right, there is an access right that indicates the user group to which UserA and UserB belong has the permission to specify access operations on Resource1 and Resource2 (specific access operations are not given as examples). There is an access right that indicates the user group to which UserC, UserD, UserE, and UserF belong has the permission to specify access operations (i.e., Action) on Resource2 (i.e., a sub-resource in the cloud resource). There is an access right that indicates the user group to which UserE and UserF belong has the permission to specify access operations on Resource2 and Resource3. There is an access right that indicates the user group to which UserF belongs has the permission to specify access operations on Resource3.
[0268] In the access rights generated in the embodiment of the present application, the user information of the user is indirectly obtained through the access log, so as to obtain appropriate user grouping and resource grouping based on the user information and access behavior, etc. In this way, the cloud management platform can obtain user information in real time or periodically through the access log to adjust the access rights.
[0269] The present application provides a cloud management platform. The cloud management platform is used to manage an infrastructure that provides cloud services, on which cloud resources of tenants run, and the tenants include at least one user. Figure 7 The schematic diagram of the structure of the cloud management platform 700 is shown as an example. Figure 7 The cloud management platform includes: a resource model creation module 701, an acquisition module 702 and an access permission generation module 703. The resource model creation module 701 is used to establish a resource model of cloud resources, and the resource model includes access operations and associations between cloud resources. The acquisition module 702 is used to obtain access logs of cloud resources, and the access logs include user information of at least one user, resource information of cloud resources, and historical access operations. The access permission generation module 703 is used to generate access permissions based on the access logs and the resource model, and the access permissions are used to indicate the permissions of at least one user to access cloud resources.
[0270] In a possible implementation, the cloud resource includes multiple sub-resources, and the resource model creation module 701 is used to: obtain the dependency relationship between the multiple sub-resources. Based on the dependency relationship between the cloud resource and the multiple sub-resources, establish the resource model, and the resource model includes the access operation, the cloud resource, and the association relationship between the sub-resource and the dependent sub-resources of the sub-resource.
[0271] In one possible implementation, the cloud management platform is provided with an access interface, which is used to respond to the target user's target access operation on the target sub-resource. The cloud management platform also includes: a permission control module 704, which is used to determine the target user's permission for the target access operation on the target sub-resource based on the access permission and the target access operation, and the target user's permission for the target access operation on the dependent sub-resource of the target sub-resource.
[0272] In one possible implementation, the access permission generation module 703 includes: an access permission generation unit, which is used to group at least one user and multiple sub-resources based on the access log to obtain at least one user group and at least one cloud resource group; the access permission generation unit is also used to generate access permissions based on the resource model, at least one user group and at least one cloud resource group; the access permissions include permissions for at least one user group to access at least one cloud resource group.
[0273] In one possible implementation, the access permission generation module 703 also includes an access permission optimization unit; the access permission generation unit is further used to generate initial access permissions based on a resource model, at least one user group and at least one resource group; wherein the initial access permissions include the permissions for each user group to access each resource group; the access permission optimization unit is used to optimize the initial access permissions in response to at least one user's access operation to a cloud resource to obtain access permissions.
[0274] In one possible implementation, the access permission optimization unit is specifically used to: in response to at least one user's access operation to cloud resources, update the initial access permission and the user's pre-set access permission to obtain the access permission; wherein the user's pre-set access permission is used to indicate the permission of at least one user to access all or part of the cloud resources.
[0275] In a possible implementation, the access permission optimization unit is specifically used to: determine the weight value of the initial access permission based on preset rules and at least one user's access operation to the cloud resource; and take into effect access permissions whose weight values are greater than a preset threshold.
[0276] In one possible implementation, the access permission generation module 703 is also used to: obtain user information of the new user; based on the user information of the new user, add the new user to a target user group, and the target user group is included in at least one user group; the cloud management platform also includes a permission control module, which is used to: control the new user's access to cloud resources based on the access permissions corresponding to the target user group.
[0277] In one possible implementation, the access permission generation module 703 is also used to: obtain user information of the new user; based on the user information of the new user, query at least one target user group similar to the new user; the cloud management platform also includes a permission control module, which is used to: use the access permissions corresponding to at least one target user group as the access permissions of the new user, and control the new user's access permissions to cloud resources.
[0278] In a possible implementation, the access permission optimization unit is further configured to: update the access permission of the new user in response to an access operation of the new user to access the cloud resources.
[0279] Among them, the above modules can all be implemented by software, or can be implemented by hardware. Among them, the module is an example of a software functional unit, and the above module may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the detection task sending module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region (region) or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Among them, usually a region may include multiple AZs.
[0280] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0281] As an example of a hardware functional unit, the module may include at least one computing device, such as a server, etc. Alternatively, the module may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0282] The multiple computing devices included in the above modules can be distributed in the same region or in different regions. The multiple computing devices included in the above modules can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the above modules can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0283] It should be noted that, in other embodiments, the above modules can be used to execute Figure 2 To realize the full functions of the cloud management platform, follow the corresponding steps in
[0284] The present application also provides a computing device 800. Figure 8 As shown, the computing device 800 includes: a bus 802, a processor 804, a memory 806, and a communication interface 808. The processor 804, the memory 806, and the communication interface 808 communicate through the bus 802. The computing device 800 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the computing device 800.
[0285] The bus 802 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8The bus 802 may include a path for transmitting information between various components of the computing device 800 (eg, the memory 806, the processor 804, and the communication interface 808).
[0286] The processor 804 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0287] The memory 806 may include a volatile memory, such as a random access memory (RAM). The processor 804 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0288] The memory 806 stores executable program codes, and the processor 804 executes the executable program codes to respectively implement the functions of the resource model creation module, the acquisition module, the access authority generation module, and the authority control module, thereby implementing Figure 2 That is, the memory 806 stores instructions for executing the access permission management method.
[0289] The communication interface 808 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 800 and other devices or communication networks.
[0290] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0291] like Fig. 9 As shown, the computing device cluster includes at least one computing device 900. The memory 906 in one or more computing devices 900 in the computing device cluster may store the same Fig. 9Instructions for the access rights management method shown.
[0292] In some possible implementations, the memory 906 of one or more computing devices 900 in the computing device cluster may also store partial instructions for executing access rights management. In other words, the combination of one or more computing devices 900 may jointly execute instructions for executing the access rights management method.
[0293] It should be noted that the memory 906 in different computing devices 900 in the computing device cluster can store different instructions, which are respectively used to execute part of the functions of the cloud management platform device. That is, the instructions stored in the memory 906 in different computing devices 900 can implement the functions of one or more modules of the resource model creation module, the acquisition module, the access permission generation module and the permission control module.
[0294] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network, which may be a wide area network or a local area network. Fig.10 A possible implementation is shown. Fig.10 As shown, two computing devices 1000A and 1000B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 1006 in the computing device 1000A stores instructions for executing the functions of the resource model creation module and the acquisition module. At the same time, the memory 1006 in the computing device 1000B stores instructions for executing the functions of the access permission generation module and the permission control module.
[0295] It should be understood that Fig.10 The functions of the computing device 1000A shown in FIG. 1000A may also be completed by multiple computing devices 1000. Similarly, the functions of the computing device 1000B may also be completed by multiple computing devices 1000.
[0296] The present application embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to that of Fig. 9 and Fig.10 The connection mode of the computing device cluster is different in that the memory 1006 in one or more computing devices 1000 in the computing device cluster may store the same instructions for executing the measurement method.
[0297] In some possible implementations, the memory 1006 of one or more computing devices 1000 in the computing device cluster may also store partial instructions for executing the measurement method. In other words, the combination of one or more computing devices 1000 may jointly execute instructions for executing the measurement method.
[0298] It should be noted that the memory 1006 in different computing devices 1000 in the computing device cluster may store different instructions for executing some functions of the cloud management platform. That is, the instructions stored in the memory 1006 in different computing devices 1000 may implement the functions of one or more devices in the cloud management platform.
[0299] The present application also provides a computer program product including instructions. The computer program product may be a software or program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the access policy formulation method in the above embodiment.
[0300] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute the access policy formulation method in the above embodiment.
[0301] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for managing access rights, characterized in that: The method is applied to a cloud management platform, the cloud management platform is used to manage an infrastructure that provides cloud services, and cloud resources are running on the infrastructure. The method includes: Establishing a resource model of the cloud resources, wherein the resource model includes an association relationship between the cloud resources and access operations; Obtaining an access log of the cloud resource, wherein the access log includes user information of at least one user, resource information of the cloud resource, and historical access operations; An access permission is generated according to the access log and the resource model, where the access permission includes permission for the at least one user to access the cloud resource.
2. The method according to claim 1, characterized in that The cloud resource includes a plurality of sub-resources, and the establishing of the resource model of the cloud resource includes: Obtaining dependency relationships between the multiple sub-resources; Based on the dependency relationship between the cloud resource and the multiple sub-resources, the resource model is established, and the resource model includes the access operation, the cloud resource, and the association relationship between the sub-resources and the dependent sub-resources of the sub-resource.
3. The method according to claim 2, characterized in that The access rights also include the permission of the at least one user to access dependent sub-resources of the sub-resource.
4. The method according to claim 3, characterized in that: The cloud management platform is provided with an access interface, and the access interface is used to respond to a target access operation of a target user on a target sub-resource. The method further includes: Based on the access permission and the target access operation, the target user's permission for the target access operation of the target sub-resource and the target user's permission for the target access operation of a dependent sub-resource of the target sub-resource are determined.
5. The method according to claim 2, characterized in that: Generating access rights according to the access log and the resource model includes: Based on the access log, grouping the at least one user and the multiple sub-resources to obtain at least one user group and at least one cloud resource group; The access permission is generated based on the resource model, the at least one user group and the at least one cloud resource group; the access permission includes permission for the at least one user group to access the at least one cloud resource group.
6. The method according to claim 5, characterized in that The generating the access permission based on the resource model, the at least one user group and the at least one resource group includes: Based on the resource model, the at least one user group and the at least one cloud resource group, generating initial access permissions; wherein the initial access permissions include permissions for each user group to access the operations of each cloud resource group; In response to the at least one user's access operation to the cloud resource, the initial access permission is updated to obtain the access permission.
7. The method according to claim 6, characterized in that The updating of the initial access permission in response to the at least one user's access operation to the cloud resource to obtain the access permission includes: In response to the access operation of the at least one user to the cloud resources, the initial access permission and the access permission pre-set by the user are updated to obtain the access permission; wherein the access permission pre-set by the user is used to indicate the permission of the at least one user to access all or part of the cloud resources.
8. The method according to claim 6, characterized in that The updating of the initial access permission in response to the at least one user's access operation to the cloud resource to obtain the access permission includes: Determining a weight value of the initial access permission based on a preset rule and an access operation of the at least one user to the cloud resource; Access rights whose weight value is greater than the preset threshold take effect.
9. The method according to claim 5, characterized in that The method further comprises: Get user information of new user; Based on the user information of the new user, adding the new user to a target user group, wherein the target user group is included in the at least one user group; Based on the access rights corresponding to the target user group, the access rights of the new user to the cloud resources are determined.
10. The method according to claim 5, characterized in that The method further comprises: Get user information of new user; Based on the user information of the new user, query at least one target user group similar to the new user; The access permission corresponding to the at least one target user group is used as the access permission of the new user to determine the permission of the new user to access the cloud resource.
11. A cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure that provides cloud services, on which cloud resources run, and the cloud management platform includes: A resource model creation module, used to establish a resource model of the cloud resource, wherein the resource model includes an association relationship between the cloud resource and the access operation; an acquisition module, configured to acquire an access log of the cloud resource, wherein the access log includes user information of the at least one user, resource information of the cloud resource, and historical access operations; The access permission generation module is used to generate access permissions according to the access log and the resource model, where the access permissions include permissions for the at least one user to access the cloud resource.
12. The cloud management platform according to claim 11, characterized in that: The cloud resource includes multiple sub-resources, and the resource model creation module is specifically used to: Obtain the dependency relationship between the multiple sub-resources. Based on the dependency relationship between the cloud resource and the multiple sub-resources, the resource model is established, and the resource model includes the access operation, the cloud resource, and the association relationship between the sub-resources and the dependent sub-resources of the sub-resource.
13. The cloud management platform according to claim 12, characterized in that: The access rights also include the permission of the at least one user to access dependent sub-resources of the sub-resource.
14. The cloud management platform according to claim 13, characterized in that: The cloud management platform is provided with an access interface, and the access interface is used to respond to a target access operation of a target user to a target sub-resource. The cloud management platform further includes: The permission control module is used to determine the permission of the target user to the target access operation of the target sub-resource and the permission of the target user to the target access operation of the dependent sub-resource of the target sub-resource based on the access permission and the target access operation.
15. The cloud management platform according to claim 12, characterized in that: The access authority generation module includes: an access permission generating unit, configured to group the at least one user and the plurality of sub-resources based on the access log to obtain at least one user group and at least one cloud resource group; The access permission generating unit is further used to generate the access permission based on the resource model, the at least one user group and the at least one cloud resource group; the access permission includes the permission for the at least one user group to access the at least one cloud resource group.
16. The cloud management platform according to claim 15, characterized in that: The access authority generation module further includes an access authority optimization unit; The access permission generating unit is further configured to generate initial access permissions based on the resource model, the at least one user group and the at least one cloud resource group; wherein the initial access permissions include permissions for each user group to access the operations of each cloud resource group; The access permission optimization unit is used to update the initial access permission in response to the access operation of the at least one user on the cloud resource to obtain the access permission.
17. The cloud management platform according to claim 16, characterized in that: The access permission optimization unit is specifically used to: In response to the access operation of the at least one user to the cloud resources, the initial access permission and the access permission pre-set by the user are updated to obtain the access permission; wherein the access permission pre-set by the user is used to indicate the permission of the at least one user to access all or part of the cloud resources.
18. The cloud management platform according to claim 16, characterized in that: The access permission optimization unit is specifically used to: Determining a weight value of the initial access permission based on a preset rule and an access operation of the at least one user to the cloud resource; Access rights whose weight value is greater than the preset threshold take effect.
19. The cloud management platform according to claim 15, characterized in that: The access authority generation module is further used to: Obtaining user information of the new user; Based on the user information of the new user, adding the new user to a target user group, wherein the target user group is included in the at least one user group; The cloud management platform also includes a permission control module, which is used to: Based on the access rights corresponding to the target user group, the access rights of the new user to the cloud resources are controlled.
20. The cloud management platform according to claim 15, characterized in that: The access authority generation module is further used to: Obtaining user information of the new user; Based on the user information of the new user, query at least one target user group similar to the new user; The cloud management platform also includes a permission control module, which is used to: The access permission corresponding to the at least one target user group is used as the access permission of the new user to control the access permission of the new user to the cloud resources.
21. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 10.
22. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 10.
23. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method according to any one of claims 1 to 10.