Identity management in multi-cloud infrastructure
Through the multi-cloud control plane framework, the problem of closedness of the cloud environment is solved, service access and management across cloud environments is realized, and native user experience and data plane capabilities are provided.
Patent Information
- Application Number
- CN202380072781.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-07
- Filing Date
- 2023-10-13
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, the closedness of the cloud environment makes it impossible for customers to conveniently use the services provided by different cloud service providers, and lacks effective cross-cloud environment resource access and management methods.
The multi-cloud control plane (MCCP) framework is adopted, allowing users to manage services in another cloud environment through one cloud environment, provide native user experience, and realize resource deployment across cloud environments through identity system migration and authorization mechanisms.
It realizes service access and management across cloud environments, provides a user experience close to the native cloud environment, and enhances users' data plane capabilities for external cloud services.
Smart Images

Figure CN120035958A_ABST
Abstract
Claims
1. A method, include: receiving, by a multi-cloud console of the multi-cloud infrastructure, a request for a service from a user, the request comprising a first token generated by a first identity system associated with a first cloud environment; authorizing, by the platform, the user based on the first token, the authorization comprising verifying identity information associated with the user, wherein the identity information was previously migrated from a second identity system associated with the second cloud environment to a first identity system of the first cloud environment; as well as In response to the user being successfully authenticated, resources associated with the service are deployed, by a multi-cloud control plane of the multi-cloud infrastructure, in a tenancy associated with the user in the first cloud environment.
2. The method according to claim 1, further comprising: include: Credentials of a user are received at a login portal of the first cloud environment, wherein a first token is generated by the first identity system in response to successfully authenticating the credentials, and wherein the login portal is distinct from a multi-cloud console of the multi-cloud infrastructure.
3. The method of claim 1 or 2, wherein the request is received at a GUI of a multi-cloud console, the GUI listing a plurality of services provided by a multi-cloud infrastructure.
4. The method of claim 1 , 2 or 3 , wherein the multi-cloud control plane hosts cloud link adapters, network link adapters, and adapter pools, each of the cloud link adapters, network link adapters, and adapter pools corresponding to a specific service in a set of one or more cloud services provided by the multi-cloud infrastructure.
5. The method according to any one of the preceding claims, further comprising: include: The first token is converted into a second token by the multi-cloud control plane, the second token being associated with the service and used to access the service.
6. The method according to any one of the preceding claims, further comprising: include: Instantiating, by the multi-cloud control plane, a service account in the second cloud environment, the service account being associated with a cloud service provider of the first cloud environment; as well as Access to the user account in the second cloud environment is obtained by the multi-cloud control plane via the service account.
7. The method of claim 6, wherein the user's identity information is migrated from a second identity system associated with the second cloud environment to a first identity system of the first cloud environment based on a trust configured between the service account and the user account in the second cloud environment.
8. The method according to any one of the preceding claims, further comprising: include: A mapping / link is created using the multi-cloud infrastructure between the user's account in the second cloud environment and the tenancy associated with the user in the first cloud environment.
9. The method according to any one of the preceding claims, further comprising: include: A network link is established between the first cloud environment and the second cloud environment, the network link facilitating access from the second cloud environment to resources deployed in a lease associated with the user in the first cloud environment.
10. One or more computer-readable non-transitory media storing computer-executable instructions that, when executed by one or more processors, cause: receiving, by a multi-cloud console of the multi-cloud infrastructure, a request for a service from a user, the request comprising a first token generated by a first identity system associated with a first cloud environment; authorizing, by the platform, the user based on the first token, the authorization comprising verifying identity information associated with the user, wherein the identity information was previously migrated from a second identity system associated with the second cloud environment to a first identity system of the first cloud environment; as well as In response to the user being successfully authenticated, resources associated with the service are deployed, by a multi-cloud control plane of the multi-cloud infrastructure, in a tenancy associated with the user in the first cloud environment.
11. One or more computer-readable non-transitory media storing computer-executable instructions as claimed in claim 10, further comprising: include: Credentials of a user are received at a login portal of the first cloud environment, wherein a first token is generated by the first identity system in response to successfully authenticating the credentials, and wherein the login portal is distinct from a multi-cloud console of the multi-cloud infrastructure.
12. One or more computer-readable non-transitory media storing computer-executable instructions as described in claim 10 or 11, wherein the request is received at a GUI of a multi-cloud console, the GUI listing a plurality of services provided by a multi-cloud infrastructure.
13. One or more computer-readable non-transitory media storing computer-executable instructions as described in claims 10, 11 or 12, wherein the multi-cloud control plane hosts cloud link adapters, network link adapters, and adapter pools, each of the cloud link adapters, network link adapters, and adapter pools corresponding to a specific service in a set of one or more cloud services provided by the multi-cloud infrastructure.
14. One or more computer-readable non-transitory media storing computer-executable instructions as claimed in any one of claims 10 to 13, further comprising: include: The first token is converted into a second token by the multi-cloud control plane, the second token being associated with the service and used to access the service.
15. One or more computer-readable non-transitory media storing computer-executable instructions as claimed in any one of claims 10 to 14, further comprising: include: Instantiating, by the multi-cloud control plane, a service account in the second cloud environment, the service account being associated with a cloud service provider of the first cloud environment; as well as Access to the user account in the second cloud environment is obtained by the multi-cloud control plane via the service account.
16. One or more computer-readable non-transitory media storing computer-executable instructions as described in claim 15, wherein based on the trust configured between the service account and the user account in the second cloud environment, the user's identity information is migrated from a second identity system associated with the second cloud environment to a first identity system of the first cloud environment.
17. One or more computer-readable non-transitory media storing computer-executable instructions as claimed in any one of claims 10 to 16, further comprising: include: A mapping / link is created using the multi-cloud infrastructure between the user's account in the second cloud environment and the tenancy associated with the user in the first cloud environment.
18. One or more computer-readable non-transitory media storing computer-executable instructions as claimed in any one of claims 10 to 17, further comprising: include: A network link is established between the first cloud environment and the second cloud environment, the network link facilitating access from the second cloud environment to resources deployed in a lease associated with the user in the first cloud environment.
19. A computing device, include: one or more processors; as well as a memory including instructions that, when executed by the one or more processors, cause the computing device to at least: receiving, by a multi-cloud console of the multi-cloud infrastructure, a request for a service from a user, the request comprising a first token generated by a first identity system associated with a first cloud environment; authorizing, by the platform, the user based on the first token, including verifying identity information associated with the user, wherein the identity information was previously migrated from a second identity system associated with the second cloud environment to a first identity system of the first cloud environment; In response to the user being successfully authenticated, resources associated with the service are deployed, by a multi-cloud control plane of the multi-cloud infrastructure, in a tenancy associated with the user in the first cloud environment.
20. The computing device of claim 19, wherein the request is received at a GUI of a multi-cloud console, the GUI listing a plurality of services provided by a multi-cloud infrastructure.