Access control method based on cloud management platform and cloud management platform
By implementing an access control method based on credential acquisition request on the cloud management platform, allowing tenants to customize access relationships between multiple cloud instances, the problem that tenants cannot actively control access relationships in the prior art is solved, and the tenant experience and data security are improved.
Patent Information
- Application Number
- CN202410516416.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-04-26
- Publication Date
- 2025-06-24
AI Technical Summary
Existing cloud management platforms cannot allow tenants to actively control access relationships between multiple cloud instances, resulting in poor tenant experience and potentially data security risks.
By implementing an access control method based on credential acquisition request on the cloud management platform, tenants are allowed to specify access control policies, while the cloud management platform decides whether to provide credentials to cloud instances based on the policy, thereby realizing the tenant's custom control of access relationships between multiple cloud instances.
Improves tenants' management capabilities and experience of multiple cloud instances, ensures data security, and meets the specific needs of tenants for access control.
Smart Images

Figure CN120200770A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202311785301.5 and the invention title "A Cross-Service Forwarding Method and a Cloud Management Platform Based on a Cloud Management Platform" filed on December 22, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of cloud technologies, and in particular, to an access control method and a cloud management platform based on a cloud management platform. Background Art
[0003] With the rapid development of cloud technologies, more and more tenants choose cloud services deployed in the cloud to handle their own businesses. Generally, when a tenant often needs to invoke multiple cloud services to handle their own businesses, communications will occur between multiple cloud instances used to deploy multiple cloud services, thus forming a communication chain.
[0004] In related technologies, a cloud service system includes a cloud management platform and multiple cloud instances that provide cloud services for tenants. The cloud management platform can, according to the access control requirements of tenants, restrict the access relationships between multiple cloud instances by itself. For example, the cloud management platform can restrict that a first cloud instance among multiple cloud instances can access a second cloud instance among multiple cloud instances, while the first cloud instance cannot access a third cloud instance among multiple cloud instances. When a tenant has a data processing requirement, since data processing also needs to be jointly completed by the first cloud instance and the second cloud instance, after the tenant accesses the first cloud instance, the first cloud instance will query the cloud management platform to determine whether it can access the second cloud instance, and the cloud management platform can allow the first cloud instance to access the second cloud instance to complete the tenant's data processing requirement.
[0005] In the above process, since the access relationship is formulated by the cloud management platform, which is a black box to the tenant, the tenant cannot actively control the access relationship between multiple cloud instances, resulting in a poor tenant experience. Summary of the Invention
[0006] Embodiments of this application provide an access control method and a cloud management platform based on a cloud management platform, which can enable a tenant to manage the mutual access between multiple cloud instances, thereby improving the tenant experience.
[0007] A first aspect of embodiments of this application provides an access control method based on a cloud management platform. The cloud management platform used to implement this method can manage multiple cloud instances that provide cloud services for tenants, and these multiple cloud instances can communicate based on the tenant's credentials. The method includes:
[0008] Among multiple cloud instances serving a tenant, when a first cloud instance needs to access a second cloud instance, the first cloud instance may send a credential acquisition request to the cloud management platform. The credential acquisition request is used to indicate the access control policy of the tenant for the multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance and is used to indicate at least one cloud instance among the multiple cloud instances that can obtain credentials.
[0009] After receiving the credential acquisition request from the first cloud instance, the cloud management platform may parse the credential acquisition request to obtain the access control policy. Then, the cloud management platform may detect whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. If the first cloud instance is among the at least one cloud instance, the cloud management platform will send the tenant's credential to the first cloud instance so that the first cloud instance can access the second cloud instance based on the tenant's credential.
[0010] As can be seen from the above method: Among multiple cloud instances serving a tenant, at least one cloud instance that can be granted the tenant's credential is specified by the tenant. The at least one cloud instance that is authorized can obtain the tenant's credential from the cloud management platform to access the remaining cloud instances. That is to say, the access relationship between these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant and is completely set according to the tenant's access control intention. The tenant can actively control the first cloud instance, which is beneficial for the tenant to manage the mutual access between these multiple cloud instances, thereby improving the tenant's experience and ensuring the data security of the tenant on the cloud instance.
[0011] In a possible implementation, the access control policy is used to indicate the cloud instance whitelist set by the tenant. The cloud instance whitelist consists of at least one cloud instance among the multiple cloud instances. The cloud management platform detecting whether the first cloud instance is among the at least one cloud instance indicated by the access control policy based on the credential acquisition request includes: The cloud management platform detecting whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy based on the credential acquisition request. In the foregoing implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy formulated by the tenant for the multiple cloud instances from the request. When the access control policy includes the cloud instance whitelist set by the tenant, since the cloud instance whitelist includes at least one cloud instance selected by the tenant from these multiple cloud instances, the cloud management platform detects whether the first cloud instance is in the cloud instance whitelist. If the first cloud instance is in the cloud instance whitelist, the cloud management platform can provide the tenant's credential to the first cloud instance, so the first cloud instance can use the tenant's credential to access the second cloud instance.
[0012] In a possible implementation, each cloud instance includes at least one interface. The credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant. The access control policy is used to indicate the interface whitelist set by the tenant. The interface whitelist is composed of the interfaces of at least one cloud instance among multiple cloud instances. The cloud management platform, based on the credential acquisition request, detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy, including: The cloud management platform, based on the credential acquisition request, detects whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy. In the foregoing implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the interface of the first cloud instance called by the tenant and the access control policy formulated by the tenant for multiple cloud instances. When the access control policy includes the interface whitelist set by the tenant, since the interface whitelist includes the interfaces of at least one cloud instance selected by the tenant from the interfaces of these multiple cloud instances, the cloud management platform can detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist. If the interface of the first cloud instance called by the tenant is in the interface whitelist, the cloud management platform can provide the tenant's credential to the first cloud instance, so the first cloud instance can use the tenant's credential to access the second cloud instance.
[0013] In a possible implementation, the access control policy is used to indicate the identity of the tenant. There is a pre-set identity whitelist for the first cloud instance in the cloud management platform. The identity whitelist is composed of multiple pre-set identities. The cloud management platform, based on the credential acquisition request, detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy, including: The cloud management platform, based on the credential acquisition request, detects whether the identity indicated by the access control policy is in the identity whitelist. In the foregoing implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy includes the identity used by the tenant to access the first cloud instance, since there is a pre-set identity whitelist for the first cloud instance in the cloud management platform, the cloud management platform can detect whether the identity used by the tenant to access the first cloud instance is in the identity whitelist for the first cloud instance. If the identity used by the tenant to access the first cloud instance is in the identity whitelist for the first cloud instance, the cloud management platform can provide the tenant's credential to the first cloud instance, so the first cloud instance can use the tenant's credential to access the second cloud instance.
[0014] In a possible implementation manner, the access control policy is used to indicate the communication duration set by the tenant and the moment when the tenant accesses the first cloud instance. The cloud management platform, based on the credential acquisition request, detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy, including: The cloud management platform, based on the credential acquisition request, detects whether the difference between the moment indicated by the access control policy and the current moment is less than the communication duration indicated by the access control policy. In the foregoing implementation manner, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy includes the moment when the tenant accesses the first cloud instance and the communication duration of the entire communication chain set by the tenant, the cloud management platform can calculate the difference between the moment when the tenant accesses the first cloud instance and the current moment, and detect whether the difference is less than the communication duration of the entire communication chain set by the tenant. If the difference is less than the communication duration, the cloud management platform can provide the tenant's credential to the first cloud instance, so that the first cloud instance can use the tenant's credential to access the second cloud instance.
[0015] In a possible implementation manner, the access control policy is used to indicate the feasible communication path between the tenant and the first cloud instance set by the tenant. The cloud management platform, based on the credential acquisition request, detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy, including: The cloud management platform, based on the credential acquisition request, detects whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy. In the foregoing implementation manner, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy includes the feasible communication path between the tenant and the first cloud instance, the cloud management platform can detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path between the tenant and the first cloud instance. If the two match, the cloud management platform can provide the tenant's credential to the first cloud instance, so that the first cloud instance can use the tenant's credential to access the second cloud instance.
[0016] In a possible implementation, the access control policy is further used to indicate the signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The cloud management platform, based on the credential acquisition request, detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy, including: the cloud management platform, based on the credential acquisition request, performs a signature verification operation on the signature indicated by the access control policy; if the signature verification operation is successful, the cloud management platform detects whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. In the foregoing implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. The access control policy may include the signature of the access control policy, and the signature is obtained by the tenant performing a signature operation on the remaining fields included in the access control policy. Then, the cloud management platform can first perform a signature verification operation on the signature. If the signature verification operation is successful, the cloud management platform detects whether the tenant's credential can be provided to the first cloud instance.
[0017] In a possible implementation, the multiple cloud instances are any one of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0018] In a second aspect of the embodiments of the present application, a cloud management platform is provided. The cloud management platform is used to manage multiple cloud instances that provide cloud services for tenants. The multiple cloud instances can communicate based on the tenant's credential. The cloud management platform includes: a receiving module, configured to receive a credential acquisition request sent by a first cloud instance among the multiple cloud instances. The credential acquisition request is used to indicate an access control policy for the multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance, and the access control policy is used to indicate at least one cloud instance among the multiple cloud instances that can obtain the credential; a detection module, configured to detect, based on the credential acquisition request, whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
[0019] In a possible implementation, the access control policy is used to indicate a cloud instance whitelist set by the tenant. The cloud instance whitelist consists of at least one cloud instance among the multiple cloud instances. The detection module is configured to detect, based on the credential acquisition request, whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy.
[0020] In a possible implementation manner, each cloud instance includes at least one interface. The credential acquisition request is further used to indicate the interface of the first cloud instance called by the tenant. The access control policy is used to indicate the interface whitelist set by the tenant. The interface whitelist is composed of interfaces of at least one cloud instance among multiple cloud instances. The detection module is used to detect, based on the credential acquisition request, whether the interface of the first cloud instance called by the tenant is located in the interface whitelist indicated by the access control policy.
[0021] In a possible implementation manner, the access control policy is used to indicate the identity of the tenant. An identity whitelist for the first cloud instance is preset in the cloud management platform. The identity whitelist is composed of multiple preset identities. The detection module is used to detect, based on the credential acquisition request, whether the identity indicated by the access control policy is located in the identity whitelist.
[0022] In a possible implementation manner, the access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance. The detection module is used to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
[0023] In a possible implementation manner, the access control policy is used to indicate the feasible communication path between the tenant and the first cloud instance set by the tenant. The detection module is used to detect, based on the credential acquisition request, whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
[0024] In a possible implementation manner, the access control policy is further used to indicate the signature of the access control policy. The signature is obtained by the tenant performing a signature operation on the access control policy. The detection module is used to: perform a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; if the signature verification operation is successful, detect whether the first cloud instance is located in at least one cloud instance indicated by the access control policy.
[0025] In a possible implementation manner, the multiple cloud instances are any one of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0026] The third aspect of the embodiments of the present application provides a computing device cluster. The computing device cluster includes at least one computing device. Each computing device includes a processor and a memory: the memory is used to store instructions; the processor is used to execute the method described in the first aspect or any possible implementation manner in the first aspect according to the instructions.
[0027] The fourth aspect of the embodiments of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, cause the one or more computers to implement the method described in the first aspect or any possible implementation manner of the first aspect.
[0028] The fifth aspect of the embodiments of the present application provides a computer program product storing instructions, which, when executed by a computer, cause the computer to implement the method described in the first aspect or any possible implementation manner of the first aspect.
[0029] In the embodiments of the present application, among multiple cloud instances serving a tenant, when a first cloud instance needs to access a second cloud instance, the first cloud instance may send a credential acquisition request to the cloud management platform. The credential acquisition request carries an access control policy for multiple cloud instances, which is provided by the tenant to the first cloud instance and is used to indicate at least one cloud instance among the multiple cloud instances serving the tenant that can obtain the credential. Then, the cloud management platform can parse the credential acquisition request to obtain the access control policy. Therefore, the cloud management platform can detect whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. If so, the cloud management platform will send the tenant's credential to the first cloud instance so that the first cloud instance can access the second cloud instance based on the tenant's credential. In the foregoing process, among the multiple cloud instances serving the tenant, at least one cloud instance that can be granted the tenant's credential is specified by the tenant. The authorized at least one cloud instance can obtain the tenant's credential from the cloud management platform to access the remaining cloud instances. That is to say, the access relationship among these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant and is completely set according to the tenant's access control intention. The tenant can achieve active control of the first cloud instance, which is beneficial to the tenant's management of the mutual access among these multiple cloud instances, thereby improving the tenant's experience and ensuring the data security of the tenant on the cloud instance. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a schematic structural diagram of the cloud service system provided by the embodiments of the present application;
[0031] Figure 2 It is a schematic flowchart of the access control method based on the cloud management platform provided by the embodiments of the present application;
[0032] Figure 3 It is a schematic diagram of the payload provided by the embodiments of the present application;
[0033] Figure 4Another structural schematic diagram of the cloud service system provided by the embodiment of the present application;
[0034] Figure 5 Another structural schematic diagram of the cloud service system provided by the embodiment of the present application;
[0035] Figure 6 Another structural schematic diagram of the cloud service system provided by the embodiment of the present application;
[0036] Figure 7 Another structural schematic diagram of the cloud service system provided by the embodiment of the present application;
[0037] Figure 8 Another structural schematic diagram of the cloud service system provided by the embodiment of the present application;
[0038] Figure 9 A structural schematic diagram of the cloud management platform provided by the embodiment of the present application;
[0039] Figure 10 A structural schematic diagram of the computing device provided by the embodiment of the present application;
[0040] Figure 11 A structural schematic diagram of the computing device cluster provided by the embodiment of the present application;
[0041] Figure 12 A schematic diagram showing the connection of computing devices in the computer cluster provided by the embodiment of the present application through a network. Detailed implementation manners
[0042] The embodiment of the present application provides an access control method based on a cloud management platform and a cloud management platform, which can enable a tenant to manage the mutual access between multiple cloud instances, thereby improving the tenant experience.
[0043] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing when describing objects with the same attributes in the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these process, method, product or device.
[0044] With the rapid development of cloud technology, more and more tenants choose cloud services deployed in the cloud to handle their own businesses. Generally, when a tenant often needs to call multiple cloud services to handle their own businesses, communication will occur between multiple cloud instances used to deploy multiple cloud services, thus forming a communication chain.
[0045] In the related art, a cloud service system includes a cloud management platform and multiple cloud instances that provide cloud services for tenants. The cloud management platform can, according to the access control requirements of tenants, limit the access relationships of multiple cloud instances by itself. For example, the cloud management platform can limit that a first cloud instance among multiple cloud instances can access a second cloud instance among multiple cloud instances, while the first cloud instance cannot access a third cloud instance among multiple cloud instances. When a tenant has a data processing requirement, since the data processing also needs to be jointly completed by the first cloud instance and the second cloud instance, after the tenant accesses the first cloud instance, the first cloud instance will query the cloud management platform to determine whether it can access the second cloud instance, and the cloud management platform can allow the first cloud instance to access the second cloud instance to complete the tenant's data processing requirement. For example, assume that data storage services are deployed on cloud instance 1 and data encryption services are deployed on cloud instance 2. After the tenant's data is stored on cloud instance 1, since the cloud management platform stipulates that cloud instance 1 can call cloud instance 2 for data encryption, cloud instance 1 can call cloud instance 2 to encrypt the tenant's data to obtain encrypted data, so the tenant's data is stored on cloud instance 1 in an encrypted form.
[0046] In the above process, since the access relationship is formulated by the cloud management platform, which is a black box to the tenant, the tenant cannot actively control the access relationship between multiple cloud instances, resulting in a poor tenant experience and may also cause certain security problems with the tenant's data on the cloud instance.
[0047] To solve the above problems, an embodiment of the present application provides an access control method based on a cloud management platform, and this method can be implemented through a cloud service system (such as, a public cloud system, etc.). Figure 1 A schematic structural diagram of the cloud service system provided by an embodiment of the present application is as Figure 1 shown. The cloud service system includes an infrastructure that can provide cloud services and a cloud management platform that manages these infrastructures. The cloud management platform and the infrastructure will be introduced separately below:
[0048] A cloud management platform can overall manage the infrastructure in the entire cloud service system (for example, in the infrastructure, according to the instructions of the tenant, create multiple cloud instances for the tenant to serve the tenant, and these cloud instances can be used to run the cloud services specified by the tenant (such as data storage services, data encryption and decryption services, etc.) to provide remote data processing, etc. for the tenant), and can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as a login interface and a cloud instance purchase interface for the client of the tenant (such as the terminal device used by the tenant or the browser on the terminal device, etc.) to access. Among them, the cloud management platform can authenticate the client of the tenant through the login interface, and after successful authentication, allow the client of the tenant to log in to the cloud management platform. Also, for example, the cloud management platform can also allow the client of the tenant to send a purchase request for multiple cloud instances to the cloud management platform through the cloud instance purchase interface. This purchase request is usually used to indicate these multiple cloud instances and the cloud services required to be deployed for each cloud instance. Therefore, the cloud management platform can create exclusive multiple cloud instances for the tenant based on this purchase request and deploy the corresponding cloud services on each cloud instance so that these multiple cloud instances meet the data processing needs of the tenant.
[0049] The infrastructure includes multiple cloud instances serving the tenant, and each cloud instance runs a kind of cloud service. Since the data processing needs of the tenant may require the assistance of different cloud services to complete, communication will occur between different cloud services, which is equivalent to communication occurring between different cloud instances, and will not be elaborated hereinafter. It should be noted that these multiple cloud instances serving the tenant communicate based on the (identity) credentials of the tenant, and the credentials of the tenant are usually preset in the cloud management platform. When the tenant has data processing needs, it can send a data processing request to a certain cloud instance. This data processing request not only includes the data to be processed, but also includes the access control policy customized by the tenant for these multiple cloud instances. This access control policy can be used to indicate a certain part of the cloud instances selected by the tenant among these multiple cloud instances, and this part of the cloud instances can be granted the credentials of the tenant by the cloud management platform. Then, after receiving this data processing request, this cloud instance can parse this data processing request, generate a credential acquisition request carrying this access control policy, and send this credential acquisition request to the cloud management platform. Then, the cloud management platform can parse this credential acquisition request to obtain this access control policy. Subsequently, the cloud management platform can determine whether this cloud instance is located in this part of the cloud instances indicated by this access control policy. If so, the cloud management platform can provide the credentials of the tenant to this cloud instance so that this cloud instance can access the remaining cloud instances based on the credentials of the tenant, thereby meeting the data processing needs of the tenant.
[0050] Furthermore, the tenant's credentials can be understood as the account password pair generated by the cloud management platform based on the tenant's identity information. It can be understood that for any cloud instance, the cloud management platform can generate the account password pair exclusive to this cloud instance for this cloud instance, so that this cloud instance can access other cloud instances in the tenant's identity.
[0051] Furthermore, the access control policy formulated by the tenant can be presented as a special data structure (payload), which can contain multiple fields. Some of these fields can be used to describe the access control conditions, and some other fields can be used to describe the access control information. The access control conditions and the access control information can be combined and used by the cloud management platform to perform authorization detection on any cloud instance (that is, whether this cloud instance can be granted the tenant's credentials), or can be used separately by the cloud management platform to perform authorization detection on any cloud instance. This will not be elaborated here.
[0052] Furthermore, for the access control policy formulated by the tenant, another part of the fields is the signature of the entire access control policy, and this signature is obtained by the tenant performing a signature operation on the above two parts of the fields. Then, after obtaining this access control policy, the cloud management platform can first perform a signature verification operation on this signature. If the signature verification is successful, it means that the above two parts of the fields are both trustworthy (or in other words, these two parts of the fields are complete, etc.). Therefore, the cloud management platform can use the above two parts of the fields to perform authorization detection on the cloud instance.
[0053] Furthermore, among the multiple cloud instances serving the tenant, the cloud service running on any cloud instance can be an application, microservice, or plugin developed by the tenant, etc., or can be an application, microservice, or plugin provided by the cloud vendor (the developer of the cloud service system) to the tenant, etc. There is no restriction here.
[0054] Furthermore, among the multiple cloud instances serving the tenant, these cloud instances can be presented in multiple ways. For example, these cloud instances can be physical servers selected by the cloud management platform, or these cloud instances can be bare metal servers selected by the cloud management platform. Also, these cloud instances can be virtual machines (VMs) created by the cloud management platform on physical servers through virtualization technology, or these cloud instances can also be containers (docker) created by the cloud management platform on physical servers through virtualization technology. Additionally, these cloud instances can also be micro virtual machines (microVMs) created by the cloud management platform on physical servers through virtualization technology, etc.
[0055] Further, for multiple cloud instances serving a tenant, these multiple cloud instances can be deployed in the same site or different sites. A site can be presented in various forms. For example, a site can be a region in the infrastructure, or a site can be an availability zone in the infrastructure, or a site can be a data center (DC) in the infrastructure, or a site can be a room in the infrastructure, or a site can be a cabinet in the infrastructure, and so on.
[0056] Based on the above cloud service system, after a certain cloud instance serving a tenant receives a data processing request from the tenant, the cloud instance can generate a credential acquisition request containing the access control policy based on the access control policy included in the data processing request, and send the credential acquisition request to the cloud management platform. Then, the cloud management platform can parse the credential acquisition request to obtain the access control policy. Since the access control policy can be used to indicate a certain part of the cloud instances among these multiple cloud instances that can be granted to the tenant with credentials, the cloud management platform can determine whether the cloud instance is located in this part of the cloud instances indicated by the access control policy. If so, the cloud management platform can provide the tenant's credentials to the cloud instance so that the cloud instance can access the remaining cloud instances based on the tenant's credentials, thereby meeting the tenant's data processing requirements. Thus, among the multiple cloud instances serving a tenant, which specific part of the cloud instances can be granted the tenant's credentials is specified by the tenant. This part of the authorized cloud instances can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. That is to say, the access relationship between these multiple cloud instances is defined by the tenant himself. Therefore, for any one of these multiple cloud instances, whether it can access the remaining cloud instances is completely set according to the tenant's access control intention. The tenant can achieve active control of the cloud instance, which is beneficial for the tenant to manage the mutual access between these multiple cloud instances, thereby improving the tenant's experience. To further understand this process, the following will combine Figure 2 to further introduce this process. Figure 2 is a schematic flowchart of an access control method based on a cloud management platform provided by an embodiment of the present application. As Figure 2 shown, this method can be implemented through the cloud service system shown in Figure 1 . The cloud management platform includes the infrastructure that provides cloud services for tenants and the cloud management platform that manages these infrastructures. These infrastructures include multiple cloud instances serving tenants. These multiple cloud instances communicate based on the tenant's credentials. The method includes:
[0057] 201. The cloud management platform receives a credential acquisition request sent by a first cloud instance among multiple cloud instances. The credential acquisition request is used to indicate an access control policy for the multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance and is used to indicate at least one cloud instance among the multiple cloud instances that can acquire credentials.
[0058] In this embodiment, among multiple cloud instances serving a tenant, when the tenant has a data processing requirement, the tenant can send a data processing request to the first cloud instance among the multiple cloud instances. The data processing request carries the tenant's data to be processed and the access control policy customized by the tenant for these multiple cloud instances. Then, the first cloud instance can parse the data processing request, determine that the tenant has a data processing requirement, and obtain the access control policy from the data processing request. Since the tenant's data processing requirement needs to be realized by the first cloud instance in combination with the second cloud instance, the first cloud instance can generate a credential acquisition request carrying the access control policy and send the credential acquisition request to the cloud management platform.
[0059] It should be noted that the access control policy is used to indicate at least one cloud instance selected by the tenant from these multiple cloud instances that can obtain the tenant's credentials.
[0060] Specifically, the access control policy is usually a special data structure (payload), and this data structure can include at least one of the following fields. These fields will be introduced separately below:
[0061] (1) Cloud instance (or cloud service) control policy (service control policy) field. This field describes the cloud instance whitelist set by the tenant. The cloud instance whitelist includes at least one cloud instance selected by the tenant from these multiple cloud instances, indicating that these at least one cloud instances can directly grant the tenant's credentials. That is to say, these at least one cloud instances are cloud instances directly authorized by the tenant.
[0062] For example, as Figure 3 shown ( Figure 3 is a schematic diagram of the payload provided by the embodiment of the present application), assume that the cloud instances serving the tenant are cloud instance 1, cloud instance 2, and cloud instance 3. Cloud service 1 runs on cloud instance 1, cloud service 2 runs on cloud instance 2, and cloud service 3 runs on cloud instance 3. For these 3 cloud instances, the tenant can define a payload. The payload includes a service control policy field, and this field is used to describe a cloud instance whitelist. The cloud instance whitelist includes cloud instance 1 and cloud instance 3, indicating that these 2 cloud instances are cloud instances directly authorized by the tenant.
[0063] (2) API permission field, which describes the interface whitelist set by the tenant. It should be noted that among multiple cloud instances serving the tenant, each cloud instance provides at least one interface externally (it can also be understood that each cloud instance provides at least one type of interface externally). The interface whitelist contains the interfaces of at least one cloud instance selected by the tenant from the interfaces of these multiple cloud instances, indicating that once the interfaces of these at least one cloud instance are called, the credentials that can be directly granted to the tenant by these at least one cloud instance.
[0064] For example, as Figure 3 shown, assume there are cloud instance 1, cloud instance 2, and cloud instance 3 serving the tenant. These three cloud instances can provide one or more different types of interfaces externally, such as upload interfaces, download interfaces, encryption interfaces, and decryption interfaces. The tenant can define a payload that contains an API permission field, which is used to describe an interface whitelist. The interface whitelist can include the upload interface and download interface of cloud instance 1, and the encryption interface and decryption interface of cloud instance 2.
[0065] (3) Session policy field, which describes the broader permission control policy set by the tenant. The permission control policy can be the communication duration of the entire communication chain set by the tenant, or the feasible communication paths between the tenant and each cloud instance set by the tenant, etc. Among them, the communication duration of the entire communication chain refers to the total duration from when the tenant accesses the first cloud instance, then the first cloud instance accesses the second cloud instance, until the last cloud instance is accessed, which should not exceed this communication duration. The feasible communication path between the tenant and a certain cloud instance refers to which cloud instances the tenant can pass through when communicating with this cloud instance. It can be seen that both the communication duration and the feasible communication path can be used to determine whether a certain cloud instance can grant the tenant's credentials.
[0066] For example, as Figure 3 shown, assume there are cloud instance 1, cloud instance 2, and cloud instance 3 serving the tenant. For these 3 cloud instances, the tenant can define a payload that contains a session policy field. This field is used to describe that the communication duration of the communication chain set by the tenant is 3 minutes, or this field is used to describe the feasible communication path between the tenant and cloud instance 1. The feasible communication path is that the tenant can directly access cloud instance 1, and the tenant cannot access cloud instance 1 through other cloud instances (for example, cloud instance 2 and / or cloud instance 3).
[0067] (4) A "properties" field, which can be used to describe information such as the identity used by a tenant to access a cloud instance or the time when the tenant accesses a cloud instance (i.e., the initial time when the tenant sends a data processing request to the cloud instance). Among them, for the identity used by a tenant to access a cloud instance, if the identity used by the tenant to access the cloud instance is in the preset identity whitelist, the cloud instance can grant the tenant a credential. For the time when a tenant accesses a cloud instance, if the difference between this time and the current time is less than the aforementioned communication duration, the cloud instance can grant the tenant a credential.
[0068] For example, as Figure 3 shown, assume there are cloud instance 1, cloud instance 2, and cloud instance 3 serving a tenant. Suppose the tenant directly accesses cloud instance 1. For cloud instance 1, the tenant can define a payload that contains a "properties" field. This field is used to describe that the identity used by the tenant to access cloud instance 1 is X, or this field is used to describe that the time when the tenant directly accesses cloud instance 1 is 10:00.
[0069] (5) A "service appenders" field of the cloud instance (or cloud service), which is used to record the intermediate nodes and the termination node passed by the current communication chain. This communication chain usually takes the tenant as the initial node. Once the tenant accesses a cloud instance, this cloud instance is recorded by this field as an intermediate node. It can be seen that this field can describe the current communication path between the tenant and the cloud instance accessed by the tenant (for example, the initial node of the current communication path is the tenant, the first intermediate node is the cloud instance directly accessed by the tenant, the second intermediate node is the cloud instance directly accessed by the first intermediate node, etc.). It should be noted that since the content of this field is updated, the entire data structure will also be updated, that is, the entire access control policy will also be updated.
[0070] For example, as Figure 3 shown, assume there are cloud instance 1, cloud instance 2, and cloud instance 3 serving a tenant. Suppose the tenant directly accesses cloud instance 1. For cloud instance 1, the tenant can define a payload that contains a "service appenders" field. Since the tenant needs to access cloud instance 1, this field can record the initial node - tenant. Of course, this field can also not record the initial node and be blank, with the default initial node being the tenant. That is to say, the current communication path between the tenant and cloud instance 1 described by this field can be understood as the tenant directly accessing cloud instance 1.
[0071] (6) Cryptographic message field, which is used to describe the signature of the entire data structure. This signature is obtained by the tenant performing a signature operation on the remaining fields of the data structure (for example, one or more of the aforementioned five fields (1) to (5)). This signature can be used to ensure the credibility of the remaining fields, that is, to ensure that these fields have not been tampered with.
[0072] 202. Based on the credential acquisition request, the cloud management platform detects whether the first cloud instance is among at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access the second cloud instance among multiple cloud instances.
[0073] After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the credential acquisition request to obtain the access control policy formulated by the tenant for multiple cloud instances. Therefore, the cloud management platform can, based on this access control policy, determine at least one cloud instance among these multiple cloud instances for which the tenant's credential can be granted. Thus, the cloud management platform can detect whether the first cloud instance is among these at least one cloud instance. If the first cloud instance is among these at least one cloud instance, the cloud management platform provides the tenant's credential to the first cloud instance. Thereafter, the first cloud instance processes the tenant's pending data to obtain processed data (the processing performed by the first cloud instance on the pending data has nothing to do with the tenant's credential. That is, even if the first cloud instance does not obtain the tenant's credential, the first cloud instance can still process the pending data). Since the processed data still requires further processing by the second cloud instance, a new data processing request can be generated. The new data processing request includes the processed data, the tenant's credential, and the access control policy formulated by the tenant for multiple cloud instances, and the new data processing request is sent to the second cloud instance. Since the new data processing request carries the tenant's credential, the second cloud instance will parse the new data processing request to obtain the access control policy and the processed data. Then, the second cloud instance can determine whether a third cloud instance is needed to assist in fulfilling the tenant's data processing requirements. If not, the second cloud instance can directly process the processed data to obtain a data processing result and return it to the tenant through the first cloud instance. If so, the second cloud instance can perform the operations performed by the aforementioned first cloud instance, which will not be elaborated here.
[0074] Specifically, the cloud management platform can detect whether the first cloud instance is among at least one cloud instance indicated by the access control policy in the following multiple ways:
[0075] (1) After receiving a credential acquisition request sent by a first cloud instance, the cloud management platform can parse from this request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy includes a cloud instance control policy field, since this field is used to describe the cloud instance whitelist set by the tenant, and the cloud instance whitelist includes at least one cloud instance selected by the tenant from these multiple cloud instances, the cloud management platform detects whether the first cloud instance is in the cloud instance whitelist. If the first cloud instance is in the cloud instance whitelist, the cloud management platform can provide the tenant's credential to the first cloud instance, so the first cloud instance can use the tenant's credential to access the second cloud instance. If the first cloud instance is not in the cloud instance whitelist, the cloud management platform refuses to provide the tenant's credential to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0076] Still as in the above example, as Figure 4 shown ( Figure 4 which is another structural schematic diagram of the cloud service system provided by an embodiment of this application), after the tenant sends a data processing request carrying a payload to cloud instance 1, cloud instance 1 can parse the data processing request to obtain the payload, and send a credential acquisition request carrying the payload to the cloud management platform. After parsing the credential acquisition request, the cloud management platform can obtain the payload. Since the payload includes a service control policy field, and the cloud instance whitelist described by this field includes cloud instance 1 (cloud service 1) and cloud instance 3 (cloud service 3), the cloud management platform can determine that cloud instance 1 is in the cloud instance whitelist, then the cloud management platform can provide the tenant's credential to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if cloud instance 2 also needs to obtain the tenant's credential, it will also send a credential acquisition request to the cloud management platform. However, since cloud instance 2 is not in the cloud instance whitelist, the cloud management platform will not provide the tenant's credential to cloud instance 2, so cloud instance 2 cannot access the other cloud instances.
[0077] (2) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the interface of the first cloud instance called by the tenant and the access control policy formulated by the tenant for multiple cloud instances from the request. When the access control policy contains an interface permission field, since this field describes the interface whitelist set by the tenant, and the interface whitelist contains at least one interface of the cloud instances selected by the tenant from the interfaces of these multiple cloud instances, the cloud management platform can detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist. If the interface of the first cloud instance called by the tenant is in the interface whitelist, the cloud management platform can provide the tenant's credential to the first cloud instance, so that the first cloud instance can use the tenant's credential to access the second cloud instance. If the interface of the first cloud instance called by the tenant is not in the interface whitelist, the cloud management platform refuses to provide the tenant's credential to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0078] Still as in the above example, such as Figure 5 shown ( Figure 5 which is another structural schematic diagram of the cloud service system provided by the embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request, thereby obtaining the payload and determining that the tenant has called the upload interface of cloud instance 1 (the upload interface of cloud instance 1 can be presented in the request with the identifier of the upload interface of cloud instance 1, so based on this identifier, it can be determined that the tenant has called the upload interface of cloud instance 1). Since the payload contains an API permission field, this field is used to describe an interface whitelist, and this interface whitelist can contain the upload interface and the download interface of cloud instance 1, the encryption interface and the decryption interface of cloud instance 2. Since the tenant calls the upload interface of cloud instance 1 and the upload interface of cloud instance 1 is in the interface whitelist, the cloud management platform can provide the tenant's credential to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if cloud instance 1 calls the upload interface of cloud instance 2 later and cloud instance 2 also needs to obtain the tenant's credential, it will also send a credential acquisition request to the cloud management platform. However, since the upload interface of cloud instance 2 is not in the interface whitelist, the cloud management platform will not provide the tenant's credential to cloud instance 2, so cloud instance 2 cannot access the other cloud instances.
[0079] (3) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy contains a characteristic field, since this field can describe the identity used by the tenant when accessing the first cloud instance, and there is a pre-set identity whitelist for the first cloud instance in the cloud management platform, the cloud management platform can detect whether the identity used by the tenant when accessing the first cloud instance is in the identity whitelist for the first cloud instance. If the identity used by the tenant when accessing the first cloud instance is in the identity whitelist for the first cloud instance, the cloud management platform can provide the tenant's credential to the first cloud instance. Therefore, the first cloud instance can use the tenant's credential to access the second cloud instance. If the identity used by the tenant when accessing the first cloud instance is not in the identity whitelist for the first cloud instance, the cloud management platform refuses to provide the tenant's credential to the first cloud instance. Therefore, the first cloud instance cannot access the second cloud instance.
[0080] Still as in the above example, such as Figure 6 shown ( Figure 6 which is another structural schematic diagram of the cloud service system provided by the embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload. Since the payload contains a properties field which is used to describe that the identity used by the tenant when accessing cloud instance 1 is X, the cloud management platform can obtain the identity whitelist for cloud instance 1. This identity whitelist contains identities such as X, Y, and Z, and determines that the identity used by the tenant when accessing cloud instance 1 is in this identity whitelist. Then the cloud management platform can provide the tenant's credential to cloud instance 1 for cloud instance 1 to access cloud instance 2.
[0081] (4) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse from the request the access control policy formulated by the tenant for multiple cloud instances. When the access control policy contains a session policy field and a characteristic field, since the session policy field can describe the communication duration of the entire communication chain set by the tenant, and the characteristic field can describe the moment when the tenant accesses the first cloud instance, the cloud management platform can calculate the difference between the moment when the tenant accesses the first cloud instance and the current moment, and detect whether this difference is less than the communication duration of the entire communication chain set by the tenant. If this difference is less than the communication duration, the cloud management platform can provide the tenant's credential to the first cloud instance. Therefore, the first cloud instance can use the tenant's credential to access the second cloud instance. If this difference is greater than or equal to the communication duration, the cloud management platform refuses to provide the tenant's credential to the first cloud instance. Therefore, the first cloud instance cannot access the second cloud instance.
[0082] Still as in the above example, such as Figure 7 shown ( Figure 7Another schematic diagram of the cloud service system provided by the embodiment of the present application. After the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload. Since the payload includes a session policy field and a properties field, the session policy field is used to describe that the communication duration of the communication link set by the tenant is 3 minutes, and the properties field is used to describe that the time when the tenant directly accesses cloud instance 1 is 10:00. Since the current time is 10:01, the cloud management platform can calculate that the difference between the time when the tenant directly accesses cloud instance 1 and the current time is 1 minute, which is less than the communication duration of the communication link set by the tenant. Then the cloud management platform can provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if cloud instance 2 also needs to obtain the tenant's credentials later, it will also send a credential acquisition request to the cloud management platform. At this time, the current time has been updated to 10:04, and the difference between the two is 4 minutes, which is greater than the communication duration of the communication link set by the tenant. Therefore, the cloud management platform will not provide the tenant's credentials to cloud instance 2, so cloud instance 2 cannot access other cloud instances.
[0083] (5) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse out the access control policy formulated by the tenant for multiple cloud instances from the request. When the access control policy includes a session policy field and a cloud instance record field, since the cloud instance record field can describe the current communication path between the tenant and the first cloud instance, and the session policy field can describe the feasible communication path between the tenant and the first cloud instance, the cloud management platform can detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path between the tenant and the first cloud instance (for example, whether the two are the same or similar). If the two match, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the two do not match, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0084] Still as the above example, such as Figure 8 shown ( Figure 8 Another schematic diagram of the cloud service system provided by the embodiment of the present application. After the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload. Since the payload includes a session policy field and service appenders fields, the session policy field is used to describe that the feasible communication path between the tenant and cloud instance 1 (cloud service 1) is that the tenant can directly access cloud instance 1, and the service appenders fields (such asFigure 8 As shown, this field is empty and the starting node is not recorded), which is used to describe that the current communication path between the tenant and Cloud Instance 1 is that the tenant directly accesses Cloud Instance 1, and the two are matched. Therefore, the cloud management platform can provide the tenant's credentials to Cloud Instance 1 for Cloud Instance 1 to access Cloud Instance 2.
[0085] It should be noted that the cloud management platform can also update the content of the service appenders field to Cloud Instance 1. Therefore, the updated service appenders field records the intermediate node Cloud Instance 1. At this time, the payload is also updated to new payload. The cloud management platform can provide new payload and the tenant's credentials to Cloud Instance 1 so that Cloud Instance 1 can use new payload and the tenant's credentials to access Cloud Instance 2. At this time, the updated service appenders field in new payload is used to describe that the current communication path between the tenant and Cloud Instance 2 is that the tenant indirectly accesses Cloud Instance 2 through Cloud Instance 1. Similarly, if Cloud Instance 2 applies to the cloud management platform for the tenant's credentials, since the sessionpolicy field also describes that the feasible communication path between the tenant and Cloud Instance 2 is that Cloud Instance 2 (Cloud Service 2) must access after passing through Cloud Instance 1 (Cloud Service 1), the cloud management platform can provide the tenant's credentials to Cloud Instance 2.
[0086] More specifically, to ensure the credibility of the access control policy, the following operations can also be performed:
[0087] After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse out the access control policy formulated by the tenant for multiple cloud instances from the request. When the access control policy contains an encrypted information field, the encrypted information field is usually the signature of the access control policy, and this signature is obtained by the tenant performing a signature operation on the remaining fields included in the access control policy. Then, the cloud management platform can first perform a signature verification operation on this signature. If the signature verification operation is successful, the cloud management platform then uses the remaining fields (reference can be made to the aforementioned (1) to (5), which will not be elaborated here) to detect whether the first cloud instance can be authorized, that is, whether the tenant's credentials can be provided to the first cloud instance.
[0088] It should be understood that in this embodiment, among the various fields in the access control policy, only the cloud instance record field can be modified by the cloud management platform, while the remaining fields generally cannot be modified by the cloud management platform.
[0089] It should also be understood that in this embodiment, only the above five independent detection methods (1) to (5) are introduced schematically. In actual applications, these five methods can also be used in combination. For example, in the case of (1)+(2), the cloud management platform will provide the tenant's credentials to the first cloud instance only when it determines that the first cloud instance is in the cloud instance whitelist and the interface called by the tenant for the first cloud instance is in the interface whitelist. Details are not elaborated here.
[0090] In the embodiment of the present application, among multiple cloud instances serving a tenant, when the first cloud instance needs to access the second cloud instance, the first cloud instance can send a credential acquisition request to the cloud management platform. The credential acquisition request carries an access control policy for multiple cloud instances, which is provided by the tenant to the first cloud instance, and the access control policy is used to indicate at least one cloud instance among the multiple cloud instances serving the tenant that can acquire credentials. Then, the cloud management platform can parse the credential acquisition request to obtain the access control policy. Therefore, the cloud management platform can detect whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. If so, the cloud management platform will send the tenant's credentials to the first cloud instance so that the first cloud instance can access the second cloud instance based on the tenant's credentials. In the foregoing process, among the multiple cloud instances serving the tenant, at least one cloud instance that can be granted the tenant's credentials is specified by the tenant. The authorized at least one cloud instance can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. That is to say, the access relationship among these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant, and it is completely set according to the tenant's access control intention. The tenant can actively control the first cloud instance, which is beneficial to the tenant's management of the mutual access among these multiple cloud instances, thereby improving the tenant's experience and ensuring the data security of the tenant on the cloud instance.
[0091] The above is a detailed description of the access control method based on the cloud management platform provided by the embodiment of the present application. The cloud management platform provided by the embodiment of the present application will be introduced below. Figure 9 A structural schematic diagram of the cloud management platform provided by the embodiment of the present application is as Figure 9 shown. The cloud management platform is used to manage multiple cloud instances that provide cloud services for tenants. The multiple cloud instances can communicate based on the tenant's credentials. The cloud management platform includes:
[0092] A receiving module 901, configured to receive a credential acquisition request sent by a first cloud instance among multiple cloud instances, where the credential acquisition request is used to indicate an access control policy for the multiple cloud instances, the access control policy is provided by a tenant to the first cloud instance, and the access control policy is used to indicate at least one cloud instance among the multiple cloud instances that can acquire credentials; for example, the receiving module 901 can be used to implement Figure 2 step 201 in the illustrated embodiment.
[0093] A detection module 902, configured to detect, based on the credential acquisition request, whether the first cloud instance is among the at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends a credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances. For example, the detection module 902 can be used to implement Figure 2 step 202 in the illustrated embodiment.
[0094] In a possible implementation manner, the access control policy is used to indicate a cloud instance whitelist set by the tenant, the cloud instance whitelist consists of at least one cloud instance among the multiple cloud instances, and the detection module 902 is configured to detect, based on the credential acquisition request, whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy.
[0095] In a possible implementation manner, each cloud instance includes at least one interface, the credential acquisition request is further used to indicate an interface of the first cloud instance called by the tenant, the access control policy is used to indicate an interface whitelist set by the tenant, the interface whitelist consists of at least one interface of the multiple cloud instances, and the detection module 902 is configured to detect, based on the credential acquisition request, whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy.
[0096] In a possible implementation manner, the access control policy is used to indicate the identity of the tenant, an identity whitelist for the first cloud instance is preset in the cloud management platform, the identity whitelist consists of multiple preset identities, and the detection module 902 is configured to detect, based on the credential acquisition request, whether the identity indicated by the access control policy is in the identity whitelist.
[0097] In a possible implementation manner, the access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance, and the detection module 902 is configured to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
[0098] In a possible implementation manner, the access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant. The detection module 902 is configured to detect, based on a credential acquisition request, whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
[0099] In a possible implementation manner, the access control policy is further used to indicate a signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The detection module 902 is configured to: perform a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; if the signature verification operation is successful, detect whether the first cloud instance is located in at least one cloud instance indicated by the access control policy.
[0100] In a possible implementation manner, the multiple cloud instances are any one of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0101] It should be noted that for the information interaction, implementation process, etc. between the above-mentioned device modules / units, since they are based on the same concept as the method embodiments of the present application, the technical effects brought by them are the same as those of the method embodiments of the present application. For the specific content, reference can be made to the description in the method embodiments shown in the foregoing of the embodiments of the present application, and details are not described herein again.
[0102] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 10 shown, the computing device 1000 (which can be used to present the foregoing cloud management platform) includes: a processor 1001, a memory 1002, a communication interface 1003, and a bus 1004. The processor 1001, the memory 1002, and the communication interface 1003 are coupled through a bus (not marked in the figure). The memory 1002 stores instructions. When the execution instructions in the memory 1002 are executed, the computing device 1000 executes the method performed by the cloud management platform in the above-mentioned method embodiments.
[0103] The computing device 1000 may be one or more integrated circuits configured to implement the above methods. For example, one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. Again, when the units in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call programs. Again, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0104] The processor 1001 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0105] The memory 1002 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0106] The executable program code is stored in the memory 1002, and the processor 1001 executes the executable program code to respectively implement the functions of the foregoing receiving module, detection module, and other modules, so as to implement the above access control method based on the cloud management platform. That is to say, the memory 1002 stores instructions for executing the above access control method based on the cloud management platform.
[0107] The communication interface 1003 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement the communication between the computing device 1000 and other devices or communication networks.
[0108] In addition to including a data bus, the bus 1004 may also include a power bus, a control bus, a status signal bus, etc. The bus may be a peripheral component interconnect express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus may be divided into an address bus, a data bus, a control bus, etc.
[0109] Please refer to Figure 11 , Figure 11 which is a schematic structural diagram of a computing device cluster provided by an embodiment of this application. As Figure 11 shown, the computing device cluster 1100 includes at least one computing device 1000.
[0110] As Figure 11 shown, the computing device cluster 1100 includes at least one computing device 1000. In the memory 1002 of one or more of the computing devices 1000 in the computing device cluster 1100, there may be stored the same instructions for executing the above-mentioned access control method based on the cloud management platform.
[0111] In some possible implementation manners, in the memory 1002 of one or more of the computing devices 1000 in the computing device cluster 1100, there may also be respectively stored partial instructions for executing the above-mentioned access control method based on the cloud management platform. In other words, a combination of one or more computing devices 1000 can jointly execute the access control method based on the cloud management platform.
[0112] It should be noted that the memories 1002 in different computing devices 1000 in the computing device cluster 1100 may store different instructions, which are respectively used to execute some functions of the above-mentioned cloud management platform. That is, the instructions stored in the memories 1002 of different computing devices 1000 can implement the functions of one or more modules such as the receiving module and the detection module.
[0113] In some possible implementation manners, one or more of the computing devices 1000 in the computing device cluster 1100 may be connected through a network. Among them, the network may be a wide area network or a local area network, etc.
[0114] Please refer toFigure 12 , Figure 12 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application connected through a network. As Figure 12 shown, two computing devices 1000A and 1000B are connected through a network. Specifically, they are connected to the network through communication interfaces in each computing device.
[0115] In a possible implementation, instructions for executing functions of modules such as a receiving module are stored in the memory of computing device 1000A. At the same time, instructions for executing functions of modules such as a detection module are stored in the memory of computing device 1000B.
[0116] It should be understood that Figure 12 the functions of computing device 1000A shown in
[0117] can also be completed by multiple computing devices. Similarly, the functions of computing device 1000B can also be completed by multiple computing devices. Figure 4 An embodiment of the present application also relates to a computer storage medium, in which a program for signal processing is stored. When it runs on a computer, it causes the computer to execute the steps performed by the cloud management platform in the embodiment as
[0118] shown. An embodiment of the present application also relates to a computer program product, which stores instructions. When the instructions are executed by a computer, they cause the computer to execute the steps performed by the cloud management platform in the embodiment as Figure 4 shown.
[0119] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0120] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, indirect couplings or communication connections of devices or units, and can be in electrical, mechanical, or other forms.
[0121] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0122] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0123] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
Claims
1. An access control method based on a cloud management platform, characterized in that: The cloud management platform is used to manage multiple cloud instances that provide cloud services to tenants, and the multiple cloud instances can communicate with each other based on the credentials of the tenants. The method includes: The cloud management platform receives a credential acquisition request sent by a first cloud instance among the multiple cloud instances, where the credential acquisition request is used to indicate an access control policy for the multiple cloud instances, where the access control policy is provided by the tenant to the first cloud instance, and where the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be acquired; Based on the credential acquisition request, the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
2. The method according to claim 1, characterized in that: The access control policy is used to indicate a cloud instance whitelist set by the tenant, the cloud instance whitelist is composed of at least one cloud instance among the multiple cloud instances, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy.
3. The method according to claim 1, characterized in that Each cloud instance includes at least one interface, the credential acquisition request is further used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, the interface whitelist is composed of the interface of at least one cloud instance among the multiple cloud instances, and the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: The cloud management platform detects, based on the credential acquisition request, whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy.
4. The method according to claim 1, characterized in that: The access control policy is used to indicate the identity of the tenant, the cloud management platform is pre-set with an identity whitelist for the first cloud instance, the identity whitelist is composed of a plurality of pre-set identities, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether the identity indicated by the access control policy is in the identity whitelist.
5. The method according to claim 1, characterized in that The access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance, and the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: The cloud management platform detects, based on the credential acquisition request, whether a difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
6. The method according to claim 1, characterized in that The access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether a current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
7. The method according to any one of claims 1 to 6, characterized in that: The access control policy is further used to indicate a signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform performs a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; If the signature verification operation is successful, the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy.
8. The method according to any one of claims 1 to 7, characterized in that: The multiple cloud instances are any of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.
9. A cloud management platform, characterized in that: The cloud management platform is used to manage multiple cloud instances that provide cloud services to tenants. The multiple cloud instances can communicate with each other based on the credentials of the tenants. The cloud management platform includes: a receiving module, configured to receive a credential acquisition request sent by a first cloud instance among the multiple cloud instances, wherein the credential acquisition request is used to indicate an access control policy for the multiple cloud instances, wherein the access control policy is provided by the tenant to the first cloud instance, and wherein the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be acquired; A detection module is used to detect whether the first cloud instance is located in at least one of the cloud instances indicated by the access control policy based on the credential acquisition request. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
10. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate a cloud instance whitelist set by the tenant, and the cloud instance whitelist is composed of at least one cloud instance among the multiple cloud instances. The detection module is used to detect whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy based on the credential acquisition request.
11. The cloud management platform according to claim 9, characterized in that: Each cloud instance includes at least one interface, the credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, and the interface whitelist is composed of the interface of at least one cloud instance among the multiple cloud instances. The detection module is used to detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy based on the credential acquisition request.
12. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate the identity of the tenant. The cloud management platform is pre-set with an identity whitelist for the first cloud instance, and the identity whitelist is composed of multiple pre-set identities. The detection module is used to detect whether the identity indicated by the access control policy is in the identity whitelist based on the credential acquisition request.
13. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance. The detection module is used to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
14. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the detection module is used to detect, based on the credential acquisition request, whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
15. The cloud management platform according to any one of claims 9 to 14, characterized in that: The access control policy is further used to indicate a signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The detection module is used to: Based on the credential acquisition request, performing a signature verification operation on the signature indicated by the access control policy; If the signature verification operation is successful, it is detected whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy.
16. The cloud management platform according to any one of claims 9 to 15, characterized in that: The multiple cloud instances are any of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.
17. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 8 according to the instructions.
18. A computer storage medium, characterized in that: The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 8.
19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 8.