Cloud service authentication method and cloud service system

By introducing policy decision points and trust anchors into the cloud management platform, centrally managing user permissions, and generating temporary credentials through the temporary access permission management service, the security risk of user error assumption roles in cross-domain authentication services is solved, and strict access control of cloud resources is achieved.

CN120223341APending Publication Date: 2025-06-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410381417.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-03-29
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art poses security risks in cross-domain authentication services, and users may mistakenly assume that other users’ roles access cloud resources, violating the principles of single responsibilities and minimization of permissions.

Method used

By introducing policy decision points into the cloud management platform, centrally managing users to obtain the permissions configured by the application, and generating temporary credentials through trust anchors and temporary access rights management services, strictly limiting the roles that users can assume.

Benefits of technology

Reduces the risk of illegal applications invading cloud resources, ensures that users can only access their authorized application configurations and roles, and meets the principles of single responsibilities and minimization of permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223341A_ABST
    Figure CN120223341A_ABST
Patent Text Reader

Abstract

The invention provides a cloud service authentication method and a cloud service system, the method is applied to the cloud service system, and the cloud service system comprises at least one trust anchor and a plurality of application configurations; the method comprises the steps that a request of a first user for obtaining a temporary certificate is received, the request comprises a client certificate of the first user and information of a first role requested by the first user, and the client certificate of the first user comprises a subject identifier of the first user; determining that the first user accesses the cloud service system according to the client certificate of the first user and the root certificate in the first trust anchor; according to the main body identifier of the first user, determining the permission of the first user to obtain the first application configuration; acquiring the permission of the first user to use the first role in the first application configuration; acquiring a temporary voucher; and sending the temporary credential to the first user. According to the embodiment of the invention, the risk that illegal applications invade cloud resources can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application with the application number 202311823932.1 and the invention title "Method for Authenticating Cloud Service Resources" filed with the China National Intellectual Property Administration on December 27, 2023. The entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of cloud computing, and more particularly, to a method for authenticating cloud services and a cloud service system. Background Art

[0003] In a traditional identity and access management (IAM) system, authentication and access control are mainly applied to services and resources within a cloud environment. The main goal of a cross-domain identity authentication service (CDIAS) is to extend IAM functions outside the cloud environment, enabling organizations to uniformly manage and control the authentication and authorization processes across multiple devices, applications, and network environments.

[0004] Currently, in the related art, corresponding client certificates are specified in the application configuration, and a trust policy is set for each application configuration, that is, each application configuration configures for each user which roles in the application configuration the user is authorized to assume. If the configuration is incorrect, it may cause some users to be authorized to assume the roles corresponding to other users to access cloud resources, posing a security risk. Summary of the Invention

[0005] This application provides a method for authenticating cloud services and a cloud service system, in order to reduce the risk of illegal applications invading cloud resources.

[0006] In a first aspect, an embodiment of the present application provides a method for authenticating cloud services. The method is applied to a cloud management platform, which is used to manage the infrastructure that provides cloud services. The infrastructure includes multiple data centers, and each data center includes multiple servers. At least one of the servers stores at least one trust anchor and multiple application configurations. The trust anchor includes a root certificate, and each application configuration in the multiple application configurations includes at least one role and the permissions for a user to use the role. The method includes: receiving a request from a first user to obtain a temporary credential, the request including the client certificate of the first user and information about the first role requested by the first user. The client certificate of the first user includes the subject identifier of the first user; determining that the first user accesses the cloud management platform based on the client certificate of the first user and the root certificate in the first trust anchor, where the root certificate of the first trust anchor corresponds to the client certificate of the first user; determining the permission for the first user to obtain the first application configuration based on the subject identifier of the first user, where the first application configuration includes the first role; obtaining the permission for the first user to use the first role in the first application configuration when the first user has the right to obtain the first application configuration; obtaining the first temporary credential when the first user has the right to use the first role, the first temporary credential including the right to use the first role; and sending the first temporary credential to the first user.

[0007] The embodiment of the present application provides a method for authenticating cloud services, which centrally manages the permissions of multiple users to obtain application configurations, more strictly restricts the roles that users can use, and reduces the risk of illegal applications invading cloud resources.

[0008] In a possible implementation manner of the first aspect, at least one server runs at least one policy decision point. One policy decision point corresponds to one trust anchor among at least one trust anchor, and the policy decision point is configured with the permissions for a user associated with the root certificate in the corresponding trust anchor to obtain multiple application configurations. Determining the permission for the first user to obtain the first application configuration based on the subject identifier of the first user includes: sending an application configuration authentication request to the first policy decision point corresponding to the first trust anchor, the application configuration authentication request including the subject identifier of the first user; where the first policy decision point is used to determine the permission for the first user to obtain the first application configuration based on the subject identifier of the first user; and receiving an authorized response from the first policy decision point when the first user has the right to obtain the first application configuration, the authorized response being used to indicate that the first user has the right to obtain the first application configuration.

[0009] The policy decision point can conveniently manage the permissions of users associated with the corresponding trust anchor to obtain application configurations and reduce the cost of identity and access management.

[0010] In a possible implementation of the first aspect, the first policy decision point is configured with a service control policy, and the service control policy includes that a first group of users obtain a common permission for one application configuration among multiple application configurations; the first group of users are all users associated with the root certificate in the first trust anchor.

[0011] Setting the service control policy in the policy decision point can uniformly manage the permissions of all users in an organization to obtain application configurations, making the cross-domain authentication service comply with the principle of single responsibility.

[0012] In a possible implementation of the first aspect, the first policy decision point is configured with a resource policy, and the resource policy includes the permissions for a first user to obtain each of the multiple application configurations.

[0013] Setting the resource policy in the policy decision point can limit the permissions of specific users to obtain specific application configurations, making the cross-domain authentication service comply with the principle of least privilege.

[0014] In a possible implementation of the first aspect, the resource policy includes the permissions for a first user to obtain each of the multiple application configurations under the first environmental attribute conditions, and the first environmental attribute conditions include the source IP address of the first user accessing the cloud management platform and / or the media access control (MAC) address of the network adapter.

[0015] In a possible implementation of the first aspect, the application configuration authentication request includes the first environmental attribute conditions, and the first policy decision point determines the permission for the first user to obtain the first application configuration according to the principal identity of the first user, including:

[0016] Determine the permission for the first user to obtain the first application configuration according to the principal identity of the first user and the first environmental attribute conditions.

[0017] Setting the environmental attribute conditions when a user accesses the cross-domain authentication service can verify the user's identity in a strict manner.

[0018] In a possible implementation of the first aspect, at least one server runs a temporary access rights management service (STS), and the STS is used to generate a temporary credential according to the information of the role. When the first user has the right to use the first role, obtaining the first temporary credential includes:

[0019] Request the first temporary credential from the STS;

[0020] Receive the first temporary credential sent by the STS.

[0021] Second aspect, an embodiment of the present application provides a cloud service system. The cloud service system includes a cloud management platform and an infrastructure for managing the provision of cloud services. The infrastructure includes multiple data centers, and each data center includes multiple servers. At least one server stores at least one trust anchor and multiple application configurations. Among them, the trust anchor includes a root certificate, and each application configuration among the multiple application configurations includes at least one role and the permissions for a user to use the role. The cloud management platform is configured to: receive a request from a first user to obtain a temporary credential, the request including the client certificate of the first user and information about the first role requested by the first user, and the client certificate of the first user including the subject identifier of the first user; determine the access of the first user to the cloud management platform based on the client certificate of the first user and the root certificate in the first trust anchor, where the root certificate of the first trust anchor corresponds to the client certificate of the first user; determine the permission for the first user to obtain the first application configuration based on the subject identifier of the first user, where the first application configuration includes the first role; when the first user has the right to obtain the first application configuration, obtain the permission for the first user to use the first role in the first application configuration; when the first user has the right to use the first role, obtain the first temporary credential, the first temporary credential including the right to use the first role; and send the first temporary credential to the first user.

[0022] In a possible implementation manner of the second aspect, at least one server runs at least one policy decision point. Among them, one policy decision point corresponds to one trust anchor among at least one trust anchor, and the policy decision point is configured with the permissions for a user associated with the root certificate in the corresponding trust anchor to obtain multiple application configurations. The cloud management platform is configured to: initiate an application configuration authentication request to the first policy decision point corresponding to the first trust anchor, the application configuration authentication request including the subject identifier of the first user; where the first policy decision point is configured to determine the permission for the first user to obtain the first application configuration based on the subject identifier of the first user; when the first user has the right to obtain the first application configuration, receive an authorized response from the first policy decision point, and the authorized response is used to indicate that the first user has the right to obtain the first application configuration.

[0023] In a possible implementation manner of the second aspect, the first policy decision point is configured with a service control policy, and the service control policy includes the common permissions for a first group of users to obtain one application configuration among multiple application configurations; the first group of users are all users associated with the root certificate in the first trust anchor.

[0024] In a possible implementation manner of the second aspect, the first policy decision point is configured with a resource policy, and the resource policy includes the permissions for the first user to obtain each application configuration among multiple application configurations.

[0025] In a possible implementation of the second aspect, the resource policy includes the permission for the first user to obtain each application configuration under the first environmental attribute condition, and the first environmental attribute condition includes the source IP address of the first user accessing the cloud management platform and / or the media access control (MAC) address of the network adapter.

[0026] In a possible implementation of the second aspect, the application configuration authentication request includes the first environmental attribute condition, and the first policy decision point is used to: determine the permission for the first user to obtain the first application configuration according to the subject identifier of the first user and the first environmental attribute condition.

[0027] In a possible implementation of the second aspect, at least one server runs a temporary access rights management service (STS), and the STS is used to generate a temporary credential according to the role information. The cloud management platform is used to: request the first temporary credential from the STS; receive the first temporary credential sent by the STS.

[0028] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, including computer program instructions. When the computer program instructions are executed by a cloud service system, the cloud service system executes the method described in any implementation of the first aspect.

[0029] In a fourth aspect, an embodiment of the present application provides a computer program product, characterized in that when the computer program product runs on a cloud service system, the cloud service system is caused to execute the method described in any implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is a schematic diagram of an application scenario of an embodiment of the present application.

[0031] Figure 2 is a process of obtaining an IAM credential for an external-cloud load in an embodiment of the present application.

[0032] Figure 3 is a schematic block diagram of an authentication process of a policy decision point in an embodiment of the present application.

[0033] Figure 4 is a schematic block diagram of an authentication process of a policy decision point in an embodiment of the present application.

[0034] Figure 5 is a schematic block diagram of a cloud service authentication device in an embodiment of the present application.

[0035] Figure 6 is a schematic block diagram of a controller in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] Aspects, embodiments or features of the present application will be presented in the context of a system including multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in connection with the figures. In addition, combinations of these solutions may also be used.

[0037] In addition, in the embodiments of the present application, words such as "exemplary", "for example", etc. are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" in the present application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of the word "exemplary" is intended to present concepts in a specific manner.

[0038] In the embodiments of the present application, "corresponding" and "corresponding" may sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they convey are the same.

[0039] The business scenarios described in the embodiments of the present application are for the purpose of more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. As is known to those of ordinary skill in the art, with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0040] A brief introduction to commonly used technical terms in this field is given below.

[0041] Cloud service infrastructure refers to the hardware and software resources used to provide cloud services, including multiple data centers. Each data center is an independent physical facility, usually including multiple servers, storage devices, network devices, etc. In a typical cloud service infrastructure, there are multiple data centers distributed in different geographical locations to provide better disaster tolerance and load balancing capabilities. Each data center includes multiple servers, which are usually virtualized and can run multiple virtual machine instances.

[0042] The cloud management platform is a configuration page or application programming interface for cloud service tenants, which can receive tenant requests and set the cloud services provided by servers in the infrastructure according to the requests. Specifically, the resource management function enables users to easily create, delete, adjust, and monitor cloud resources through the cloud management platform; the automation function can help users automate some repetitive tasks, improve efficiency, and reduce labor costs; the security management function can help users manage cloud security policies, including access control, identity authentication, data encryption, etc., to ensure the security of the cloud infrastructure; the performance monitoring function can monitor the performance of the cloud infrastructure, including CPU utilization, memory utilization, network traffic, etc., to help users promptly discover and solve performance problems. For example, the cloud management platform can be used to manage elastic container services (ECS). The cloud management platform receives the user's virtual machine creation request, selects a suitable server in the infrastructure according to the virtual machine creation request, and creates a virtual machine on the server.

[0043] In a cloud computing environment, the network of the infrastructure is usually divided into two parts: outside the cloud and inside the cloud. Outside the cloud (public cloud) refers to the external network of the infrastructure, also known as the public cloud. The public cloud is a cloud service provided by a third-party cloud service provider. Users can access and use various cloud services, such as computing, storage, databases, etc., through the public cloud. The public cloud is usually multi-tenant, and multiple users share the same set of hardware resources, but are isolated through virtualization technology to ensure data security and privacy protection between users. Inside the cloud (private cloud) refers to the internal network of the infrastructure, also known as the private cloud. The private cloud is a cloud service independently owned and managed by a single organization or enterprise, usually deployed in its own data center or hosted in a third-party data center.

[0044] In a traditional identity and access management (IAM) system, identity authentication and access control are mainly applied to services and resources within the cloud environment. Users, groups, and roles are created and assigned policies that define their access rights to cloud environment resources. When an entity (such as an EC2 instance, lambda function, or API call) needs to access a cloud resource such as an S3 storage service bucket, it can obtain temporary security credentials through the security token service (STS).

[0045] STS is a cloud service mainly used to provide temporary security credentials for secure access to and authentication of cloud service resources. The STS service can provide short-term, limited-permission access credentials for authenticated users. These temporary credentials usually include an access key, a secret key, and a security token. The validity period of these credentials is shorter than that of traditional long-term access keys and can be set from a few minutes to several hours. Using STS can reduce the management and distribution of long-term access keys because users no longer need to directly hold long-term keys but obtain temporary credentials through the STS service for access.

[0046] STS allows an entity (such as a user, application, or service) to assume another IAM role for a specific period of time. This is achieved through the AssumeRole API or other related APIs, enabling users to dynamically obtain the permissions of different roles as needed. Using the STS service can implement the principle of least privilege because users only obtain the corresponding permissions when they need to access specific resources, and these permissions are only valid for a limited time. Since the credentials provided by STS are temporary, even if the credentials are stolen, attackers can only use these credentials within a limited time. In addition, since the credentials are different from the user's long-term access key, even if the temporary credentials are leaked, the user's long-term access permissions will not be compromised. Through STS, administrators can finely control the access permissions of users or applications to cloud service resources, and can dynamically adjust policies according to needs to ensure that only authorized operations can be executed.

[0047] The main goal of the cross-domain identity authentication service (CDIAS) is to extend IAM capabilities beyond the cloud environment, enabling organizations to uniformly manage and control the authentication and authorization processes across multiple devices, applications, and network environments. CDIAS extends traditional IAM capabilities, allowing the use of IAM roles for authentication and authorization in devices and applications outside the cloud environment. Specifically, the authentication and authorization policies of CDIAS are called IAM policies, including identity policies, resource policies, trust policies, and service control policies.

[0048] It should be understood that the cloud management platform can also be used to manage STS or cross - domain authentication services. The cloud management platform receives various types of requests from users and performs corresponding functions in the corresponding services. The cloud management platform and the services it manages, such as STS, ECS, storage services, network services, etc., together constitute a complete cloud service system. Users can interact with the cross - domain authentication service or other services in the cloud service system by sending requests to the cloud management platform.

[0049] The following further introduces the IAM function and the specific components of the IAM service.

[0050] IAM identity policies are associated with specific IAM identities (such as users, user groups, or roles). These policies define the actions that the identity can perform, the resources that it has access to, and the conditions under which access can be granted.

[0051] IAM trust policies define which entities can assume the permissions of an IAM role. Trust policies are associated with IAM roles, not directly with users or resources. When an entity (such as another account, service, or authenticated user) needs to temporarily obtain and use the permissions of a specific role, it must first obtain temporary credentials through the AssumeRole API. The trust policy plays a role in this process and determines which entities are trusted and allowed to perform this role assumption.

[0052] IAM resource policies define which identities can perform which actions on specific resources (such as S3 buckets).

[0053] IAM service control policies (SCPs) are a type of policy used to centrally manage and enforce a set of account - level permission policies. The main purpose of SCPs is to set and implement unified access control rules and compliance requirements for multiple accounts in an organization. SCPs allow organizational administrators to set policies at the root level of the organization or at the organizational unit (OU) level. These policies are automatically applied to all member accounts under the organization or accounts under a specific OU. SCPs are mandatory. Once applied to an account, even if there are more permissive permission policies at the account level, the permissions of users, roles, and groups in that account will be restricted by the SCP. This helps ensure that all accounts within an organization follow consistent security and compliance standards, meet various regulatory and compliance requirements, simplify the auditing process, and reduce the risk of misconfiguration by centrally defining and implementing access control policies.

[0054] An IAM application configuration is an IAM entity used to centrally manage users' identities and access permissions to cloud resources. Specifically, an application configuration includes one or more pre-configured roles. After a user obtains the application configuration, the user can assume the pre-configured roles in the application configuration to perform specific operations. Among them, the permission for a user to obtain an application configuration is restricted by a resource policy, and the permission for a user to assume a role in the application configuration is restricted by a trust policy.

[0055] Through the above various policies, CDIAS can manage IAM roles used on devices and applications outside the cloud environment. Devices and applications outside the cloud environment are abbreviated as off-cloud applications, off-cloud workloads, or off-cloud loads, including Internet of Things (IoT) devices, edge devices, servers in data centers, or resources in other cloud platforms. It can be considered that an off-cloud load is also a user, and the user in subsequent embodiments can refer to an off-cloud load.

[0056] A trust anchor is an IAM entity used to verify and confirm the authenticity of other certificates or identities based on the root certificate issued by a user authentication center (certificate authority, CA). Specifically, each user has a client certificate respectively. A trust anchor includes a root certificate, and there is a corresponding relationship between a root certificate and multiple client certificates. A trust anchor can determine the authenticity of a user's identity and whether to allow access through the client certificate.

[0057] In the context of IAM, an identity provider (IdP) refers to a service, application, or system responsible for providing and managing identities. They issue a unique identifier for a user, usually a string, called a subject identifier. This identifier is passed to the cloud service through a token or other authentication mechanism during user authentication to identify the user's identity.

[0058] The Policy Decision Point (PDP) is a core component in an access control architecture. In complex systems, especially those that need to handle a large number of users, roles, resources, and permissions, the role of the PDP is to centrally evaluate and decide whether to allow a subject (such as a user, application, or service) to perform a specific operation on a specific resource. The PDP is usually integrated with a policy repository that contains all applicable access control policies, such as IAM policies. Specifically, the IdP is responsible for authenticating users and generating an identity token containing the user's identity information after successful authentication. Based on the information in the identity token obtained from the identity provider, the PDP can combine pre-defined access policies to determine whether the user is granted access to a specific resource.

[0059] In the related art, CDIAS includes a set of application configurations, and an off-cloud workload can assume a specific role in the application configuration to access cloud resources. CDIAS can restrict the permissions of users to access the cloud service system through an identity policy, but cannot restrict the permissions of authenticated users to obtain application configurations through a resource policy and SCP. That is, all off-cloud workloads have the right to access all application configurations in CDIAS. Assuming that there are roles in these application configurations that are not correctly configured with permissions, CDIAS violates the single responsibility principle. Therefore, currently, a corresponding client certificate is specified in the application configuration, and a trust policy is set for each application configuration. That is, each application configuration separately configures which roles in the application configuration a user has the right to assume. If the configuration is incorrect, it will cause some users to have the right to assume the roles corresponding to other users to access cloud resources, that is, CDIAS violates the principle of least privilege and there are security risks.

[0060] In view of this, an embodiment of the present application provides a method for authenticating cloud services, which centrally manages the permissions of multiple users to obtain application configurations, more strictly restricts the roles that users can assume, and reduces the risk of illegal applications invading cloud resources.

[0061] An embodiment of the present application illustrates the method for authenticating cloud services provided by the embodiment of the present application through a cloud service system including a cloud management platform, a trust anchor, CDIAS, and a policy decision point. A possible application scenario is as Figure 1 shown. A user carrying a client certificate sends a request to obtain an IAM temporary credential to CDIAS in the cloud service system. After CDIAS verifies the validity of the certificate through the trust anchor, it obtains the IAM temporary credential in the STS according to the user's identity policy and sends the temporary credential to the user.

[0062] It should be understood that the user referred to in this embodiment may be an off-cloud workload.

[0063] A process for a user of the present application to obtain an IAM temporary credential is asFigure 2 as shown

[0064] S210, the user sends a request to the cloud management platform to obtain IAM temporary credentials.

[0065] Specifically, the request may include information about the application configuration specified by the user, and may also include information about the role that the user wants to assume in the specified application configuration. Optionally, the user can also specify the role to be assumed after successfully obtaining the application configuration.

[0066] Correspondingly, the cloud management platform receives the user's request to obtain temporary credentials.

[0067] S220, the cloud management platform determines that the user accesses the cloud service system based on the user's client certificate and the root certificate of the corresponding trust anchor.

[0068] For the user, the user's access to the cloud service system means that the user obtains certain permissions to interact with each service in the cloud service system through the cloud management platform. The entity that specifically interacts with each entity in the cloud service system can be CDIAS.

[0069] In one embodiment, CDIAS authenticates using the user's client certificate. Specifically, a trust anchor includes a root certificate, which corresponds to the client certificates of at least one user. All users corresponding to a trust anchor belong to the same organization, and the client certificates of users in an organization are issued by the trust anchor CA. In this embodiment, CDIAS verifies whether the client certificate is issued by the pre-configured trust anchor CA. If the client certificate is issued by the pre-configured trust anchor CA, the user is allowed to access the cloud service system.

[0070] In the related art, if the client certificate passes the verification, the user's permission to obtain the application configuration is not restricted by the organization's SCP and resource policies, that is, the user can obtain any application configuration. The organization in this embodiment can uniformly manage the user's IAM policy. Specifically, this embodiment sets the subject identifier and custom IAM system stipulated by the organization for the user, and authenticates the SCP and resource policies.

[0071] S230, the cloud management platform sends an application configuration authentication request to the policy decision point.

[0072] In one embodiment, an identity provider (IdP) with CDIAS as the identity subject is created, called the external application IdP. The external application IdP uses the unique identifier of each user's client certificate as the subject identifier of the user, and this subject identifier is used to configure the user's IAM policy in the organization.

[0073] Further, in the cloud service system, a corresponding policy decision point is set for each trust anchor. The policy decision point is used for the permission policy of the users of an organization. Among them, all the users corresponding to a trust anchor form an organization, and the user permissions in this organization can be restricted by the SCP of this organization. In the resource authentication request initiated by CDIAS to the policy decision point, the identity information of the user is the newly set principal identifier.

[0074] Correspondingly, the policy decision point receives the application configuration authentication request initiated by the cloud management platform.

[0075] S240, the policy decision point determines the user's permission to obtain the application configuration according to the principal identifier of the user.

[0076] In this embodiment, the cloud resources mainly refer to the application configurations in CDIAS. After the user obtains the application configuration, the user can assume the roles in it according to the trust policies set in the application configuration, so as to obtain the temporary credentials containing the roles. Among them, one of the multiple application configurations in CDIAS includes the permissions for all users in CDIAS to assume the roles in this application configuration.

[0077] Specifically, IAM policies corresponding to the organization are configured on the policy decision point, such as SCP and resource policies. Specifically, SCP can limit the maximum permissions of the resource policies of all users in the organization. The resource policy can be set separately for each user. Authenticating the user can include SCP authentication and resource policy authentication.

[0078] The policy decision point can determine whether the user has the right to access the application configuration specified by the user according to the IAM policy configured by the administrator of the policy decision point, and send an unauthorized response or an authorized response to the user. Among them, the IAM policy configured by the administrator can be the IAM policy set for all organization users, or the IAM policy set for one of the organization users. The specific form will be described in detail in the subsequent embodiments.

[0079] It should be understood that the user's permission to obtain the application configuration is restricted by the resource policy, and the user's permission to assume the roles in the application configuration is restricted by the trust policy set in the application configuration. The policy decision point set in this embodiment does not involve the specific content in the application configuration or the method of setting the trust policy for the application configuration in the related technology.

[0080] It should be understood that the policy decision point can also set IAM policies for other cloud resources such as S3 buckets. Setting the IAM policy for the application configuration in this embodiment should not be construed as a limitation to the technical solution of this application.

[0081] The policy decision point can conveniently manage the permission of the users associated with the corresponding trust anchor to obtain the application configuration, and reduce the cost of identity and access management.

[0082] S241, the Policy Decision Point sends an unauthorized response to the user.

[0083] The following combines Figure 3 with the schematic block diagram of the authentication process of the Policy Decision Point shown in the figure to illustrate the process of sending an unauthorized response to the user.

[0084] In one embodiment, according to the common permissions for an organizational user to obtain application configurations configured in the SCP of the Policy Decision Point, it is determined whether the user has the right to access the application configuration specified by the user. For example, in CDIAS, there are application configurations 301, 302, and 303. Since there are errors in the configuration processes of application configurations 302 and 303, user 11 has the right to obtain application configurations 301, 302, and 303. The SCP of the organization to which the user belongs is configured in the Policy Decision Point 41, and the resource policy of the SCP stipulates that all users in this organization have no right to obtain application configuration 302 or application configuration 303. When user 11 attempts to obtain application configuration 303, the Policy Decision Point 41 determines according to the configured IAM policy that user 11 has no right to obtain application configuration 303, and thus sends an unauthorized response to user 11.

[0085] By setting a service control policy in the Policy Decision Point, the permissions for all users in an organization to obtain application configurations can be uniformly managed, enabling the cross-domain authentication service to comply with the principle of single responsibility.

[0086] In another embodiment, according to the permissions for a user to obtain application configurations configured in the resource policy of the Policy Decision Point, it is determined whether the user has the right to access the application configuration specified by the user. For example, in CDIAS, there are application configurations 304 and 305. The organization to which user 12 belongs has not set an SCP in the Policy Decision Point 42, but a resource policy is set for user 12. The resource policy stipulates that user 12 can only obtain application configuration 304. When user 12 attempts to obtain application configuration 305, the Policy Decision Point 42 determines according to the configured IAM policy that user 12 has no right to obtain application configuration 305, and thus sends an unauthorized response to user 12.

[0087] By setting a resource policy in the Policy Decision Point, the permissions for a specific user to obtain specific application configurations can be restricted, enabling the cross-domain authentication service to comply with the principle of least privilege.

[0088] It should be understood that the SCP or resource policy configured in the Policy Decision Point can specify that a specific user has the right to access a specific application configuration, or can also specify that a specific user has no right to access a specific application configuration. In the above embodiment, user 12 can only obtain application configuration 304, which means that user 12 has the right to obtain application configuration 304 and at the same time has no right to obtain application configuration 305.

[0089] S242, the policy decision point sends an authorization response to the user.

[0090] In one embodiment, when user 12 attempts to obtain application configuration 304, policy decision point 42 determines, based on the configured IAM policy, that user 12 is authorized to obtain application configuration 304, and thus sends an authorization response to user 12.

[0091] The following Figure 4 illustrates the process of sending an authorization response to the user with reference to the schematic block diagram of the authentication process of the policy decision point shown below.

[0092] In another embodiment, based on multiple environmental attribute conditions configured in the resource policy of the policy decision point when the user accesses the cloud management platform, it is determined whether the user is authorized to access the application configuration specified by the user. For example, there are application configurations 306 and 307 in CDIAS, and the resource policy in policy decision point 43 can also include environmental attribute conditions when the user accesses the cloud management platform. The environmental attribute conditions include the source IP address of the user, or information such as the media access control (MAC) address of the user's network adapter. For example, it can be restricted that user 13 can only access trust anchor 53 under the network segment 10.50.13.0 / 24 and can only obtain application configuration 306. It should be understood that the application configuration authentication request initiated by CDIAS to the policy decision point can include the environmental attribute conditions when the user accesses the cloud management platform.

[0093] In yet another embodiment, the client certificates of user 14 and user 13 are both issued by the root certificate of trust anchor 53 corresponding to policy decision point 43. Policy decision point 43 can also restrict that user 14 must be a device installed with an Intel network card with a MAC address of 00:1E:68:88:88:88, and can only access trust anchor 53 under the network segment 10.50.14.0 / 24 and can only obtain application configuration 307.

[0094] It should be understood that the environmental attribute conditions can include the source IP address of the user and / or the MAC address of the user's network adapter, and this embodiment does not limit this. In addition, the interaction process between the user or the policy decision point and the trust anchor is omitted in the foregoing embodiments, which should not be construed as a limitation to the technical solution of this application.

[0095] For the user, the policy decision point sending an authorization response to the user means that the cloud management platform receives the authorization response from the policy decision point, and the user can obtain the content of this response through the cloud management platform. Similarly, the user obtaining an application configuration means that the cloud management platform obtains the user-specified user configuration, or the cloud management platform obtains all application configurations and only allows the user to interact with the permitted partial application configurations.

[0096] Setting the environmental attribute conditions when a user accesses the cross - domain identity authentication service can verify the user's identity in a strict manner.

[0097] It should be understood that after S241 is completed, the subsequent steps are no longer executed, and after S242 is completed, S250 is continued to be executed.

[0098] S250, the cloud management platform obtains the permissions of the user's assumed role in the application configuration.

[0099] Specifically, each application configuration includes at least one role and the permissions for all users in the cloud service system to use these roles. In one embodiment, CDIAS can directly obtain this information in the application configuration to determine that the user has the right to assume the role the user wants to assume. Optionally, after the user obtains the application configuration, the required role is specified in this step.

[0100] S260, the cloud management platform requests IAM temporary credentials from the STS.

[0101] In some embodiments, CDIAS requests temporary credentials from the STS according to the specified role.

[0102] S270, the STS sends the IAM temporary credentials to the cloud management platform.

[0103] This step is similar to the prior art and will not be elaborated here. Correspondingly, the cloud management platform receives the IAM temporary credentials sent by the STS.

[0104] S280, the cloud management platform sends the IAM temporary credentials to the user.

[0105] This step is similar to the prior art and will not be elaborated here.

[0106] It should be understood that the CDIAS adopted in the method of this application can be implemented by various CDIASs, such as CDIASs built based on Security Assertion Markup Language (SAML) or OpenID Connect (OIDC), or by expanding functional modules outside a mature CDIAS. This application does not make any limitations in this regard. Specifically, for a CDIAS with a high degree of customization, the policy decision point can be a functional module of the CDIAS or an externally expanded functional module set in the cloud service system. This application does not make any limitations in this regard.

[0107] It should be understood that the cloud service infrastructure includes multiple data centers, and each data center includes multiple servers. The aforementioned application configuration and trust anchor can be stored on at least one server, and the aforementioned policy decision point and STS can be stored and run on at least one server.

[0108] The cloud service authentication method provided by this application sets a policy decision point corresponding to a trust anchor, sets the permissions for a specific user to obtain a specific application configuration, and the common permissions for multiple users to obtain a specific application configuration, more strictly restricts the roles that can be assumed by off-cloud loads, enables the mechanism for off-cloud loads to access cloud services to meet the principles of single responsibility and minimum permissions, and reduces the risk of illegal applications invading cloud resources.

[0109] Figure 5 It is a schematic block diagram of the cloud service authentication device according to an embodiment of this application. Figure 5 The illustrated device 600 can be used to execute the cloud service authentication method according to an embodiment of this application.

[0110] As Figure 5 shown, the device includes an acquisition unit 610, a processing unit 620, and an output unit 630. The term "unit" here can be implemented in the form of software and / or hardware, and no specific limitation is made thereto.

[0111] For example, the "unit" can be a software program, a hardware circuit, or a combination of the two that implements the above functions, and can include code running on a computing instance. Exemplarily, taking the processing unit as an example, the implementation manner of the processing unit will be introduced next. Similarly, the implementation manners of the acquisition unit and the output unit can refer to the implementation manner of the processing unit.

[0112] Specifically, the processing unit can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code can be distributed in the same region, or can be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code can be distributed in the same availability zone (AZ), or can be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region can include multiple AZs.

[0113] Similarly, the multiple hosts / virtual machines / containers for running this code can be distributed in the same virtual private cloud (VPC), or can be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0114] As an example of a hardware functional unit, the processing unit may include at least one computing device, such as a server. Alternatively, the processing unit may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0115] The multiple computing devices included in the processing unit may be distributed in the same region or in different regions. The multiple computing devices included in the processing unit may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the processing unit may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0116] Therefore, the modules of the various examples described in the embodiments of the present application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0117] The present application also provides a controller 700. As Figure 6 shown, the controller 700 includes: a processor 704 and a communication interface 708. Further, the controller 700 may also include a bus 702 and a memory 706. It should be understood that the bus 702 and the memory 706 are optional. The processor 704, the memory 706, and the communication interface 708 communicate through the bus 702. Exemplarily, the controller 700 may be a computing device or a device in a computing device for implementing the method of the embodiments of the present application. The controller 700 may be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the controller 700.

[0118] The bus 702 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 only one line is used in Figure 6 , but it does not mean that there is only one bus or one type of bus. The bus 704 can include a path for transmitting information between various components of the controller 700 (for example, the memory 706, the processor 704, and the communication interface 708).

[0119] The processor 704 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0120] The memory 706 can include volatile memory, such as random access memory (RAM). The memory 706 can also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0121] The memory 706 stores executable program code, and the processor 704 executes the executable program code to respectively implement the functions of the foregoing acquisition unit and processing unit, thereby implementing the method for cloud service authentication. That is, the memory 706 stores instructions for the method for cloud service authentication.

[0122] The communication interface 708 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the controller 700 and other devices or a communication network (for example, multiple servers). The communication interface can also be referred to as an interface circuit.

[0123] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes a controller 700 and multiple computing devices. The computing devices can be servers, such as central servers, edge servers, or local servers in a local data center. In some embodiments, the computing devices can also be terminal devices such as desktop computers, laptop computers, or smart phones. The multiple computing devices can be the multiple servers described above. The computing device cluster can be used to implement a cloud service system.

[0124] In a possible implementation, the controller 700 is one of the multiple computing devices or a device in the computing devices for implementing the method described above.

[0125] In another possible implementation, the controller 700 is a computing device other than the multiple computing devices or a device in other computing devices for implementing the method described above.

[0126] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the method in the embodiments of the present application.

[0127] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available mediums. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute the method in the embodiments of the present application, or instruct the computing device to execute the method in the embodiments of the present application.

[0128] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0129] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0130] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0131] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0132] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0133] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0134] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0135] As described above, it is only the specific implementation manner of the present application. However, the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.

Claims

1. A cloud service authentication method, characterized in that: The method is applied to a cloud management platform, the cloud management platform is used to manage an infrastructure for providing cloud services, the infrastructure includes multiple data centers, the data centers include multiple servers, at least one of the servers stores at least one trust anchor and multiple application configurations, wherein the trust anchor includes a root certificate, and each of the multiple application configurations includes at least one role and a user's permission to use the role; The method comprises: receiving a request from a first user to obtain temporary credentials, the request including a client certificate of the first user and information of a first role requested by the first user, the client certificate of the first user including a subject identifier of the first user; determining, based on the client certificate of the first user and a root certificate in a first trust anchor, that the first user accesses the cloud management platform, wherein the root certificate of the first trust anchor corresponds to the client certificate of the first user; Determining, according to the subject identifier of the first user, permission for the first user to obtain a first application configuration, wherein the first application configuration includes the first role; If the first user has the right to obtain the first application configuration, obtaining the permission of the first user in the first application configuration to use the first role; If the first user has the right to use the first role, obtaining a first temporary credential, where the first temporary credential includes the right to use the first role; The first temporary credentials are sent to the first user.

2. The method according to claim 1, characterized in that at least one of the servers runs at least one policy decision point, wherein one policy decision point corresponds to one of the at least one trust anchors, and the policy decision point is configured with permission for a user associated with a root certificate in the corresponding trust anchor to obtain the plurality of application configurations; The determining, according to the subject identifier of the first user, the permission of the first user to obtain the first application configuration includes: Initiating an application configuration authentication request to a first policy decision point corresponding to the first trust anchor, the application configuration authentication request including a subject identifier of the first user; wherein the first policy decision point is used to determine the first user's permission to obtain the first application configuration according to the subject identifier of the first user; In a case where the first user has the right to obtain the first application configuration, an authorization response is received from the first policy decision point, where the authorization response is used to indicate that the first user has the right to obtain the first application configuration.

3. The method according to claim 2, characterized in that The first policy decision point is configured with a service control policy, wherein the service control policy includes a common permission for a first group of users to obtain one of the multiple application configurations; the first group of users is all users associated with a root certificate in the first trust anchor.

4. The method according to claim 2 or 3, characterized in that: The first policy decision point is configured with a resource policy, and the resource policy includes the permission of the first user to obtain each application configuration of the multiple application configurations.

5. The method according to claim 4, characterized in that The resource policy includes the first user's permission to obtain each of the multiple application configurations under a first environmental attribute condition, and the first environmental attribute condition includes the source IP address of the first user accessing the cloud management platform and / or the media access control MAC address of the network adapter.

6. The method according to claim 5, characterized in that The application configuration authentication request includes a first environment attribute condition, and the first policy decision point determines, according to the subject identifier of the first user, the permission of the first user to obtain the first application configuration, including: According to the subject identifier of the first user and the first environmental attribute condition, the permission of the first user to obtain the first application configuration is determined.

7. The method according to any one of claims 1 to 6, characterized in that At least one of the servers runs a temporary access permission management service STS, the STS is used to generate a temporary credential according to the role information, and the obtaining of the first temporary credential when the first user has the right to use the first role includes: Requesting the first temporary credential from the STS; Receive the first temporary credential sent by the STS.

8. A cloud service system, characterized in that: The cloud service system includes a cloud management platform and an infrastructure for managing and providing cloud services, wherein the infrastructure includes multiple data centers, the data centers include multiple servers, at least one of the servers stores at least one trust anchor and multiple application configurations, wherein the trust anchor includes a root certificate, and each of the multiple application configurations includes at least one role and a user's permission to use the role; The cloud management platform is used for: receiving a request from a first user to obtain temporary credentials, the request including a client certificate of the first user and information of a first role requested by the first user, the client certificate of the first user including a subject identifier of the first user; determining, based on the client certificate of the first user and a root certificate in a first trust anchor, that the first user accesses the cloud management platform, wherein the root certificate of the first trust anchor corresponds to the client certificate of the first user; Determining, according to the subject identifier of the first user, permission for the first user to obtain a first application configuration, wherein the first application configuration includes the first role; If the first user has the right to obtain the first application configuration, obtaining the permission of the first user in the first application configuration to use the first role; If the first user has the right to use the first role, obtaining a first temporary credential, where the first temporary credential includes the right to use the first role; The first temporary credentials are sent to the first user.

9. The cloud service system according to claim 8, characterized in that: At least one of the servers runs at least one policy decision point, wherein one policy decision point corresponds to one of the at least one trust anchors, and the policy decision point is configured with permission for a user associated with a root certificate in the corresponding trust anchor to obtain the plurality of application configurations; and the cloud management platform is used to: Initiating an application configuration authentication request to a first policy decision point corresponding to the first trust anchor, the application configuration authentication request including a subject identifier of the first user; wherein the first policy decision point is used to determine the first user's permission to obtain the first application configuration according to the subject identifier of the first user; In a case where the first user has the right to obtain the first application configuration, an authorization response is received from the first policy decision point, where the authorization response is used to indicate that the first user has the right to obtain the first application configuration.

10. The cloud service system according to claim 9, characterized in that: The first policy decision point is configured with a service control policy, wherein the service control policy includes a common permission for a first group of users to obtain one of the multiple application configurations; the first group of users is all users associated with a root certificate in the first trust anchor.

11. The cloud service system according to claim 9 or 10, characterized in that: The first policy decision point is configured with a resource policy, and the resource policy includes the permission of the first user to obtain each application configuration of the multiple application configurations.

12. The cloud service system according to claim 11, characterized in that: The resource policy includes the first user's permission to obtain each of the multiple application configurations under a first environmental attribute condition, and the first environmental attribute condition includes the source IP address of the first user accessing the cloud management platform and / or the media access control MAC address of the network adapter.

13. The cloud service system according to claim 12, characterized in that: The application configuration authentication request includes a first environment attribute condition, and the first policy decision point is used to: According to the subject identifier of the first user and the first environmental attribute condition, the permission of the first user to obtain the first application configuration is determined.

14. The cloud service system according to any one of claims 8 to 13, characterized in that: At least one of the servers runs a temporary access permission management service STS, the STS is used to generate temporary credentials according to the role information, and the cloud management platform is used to: Requesting the first temporary credential from the STS; Receive the first temporary credential sent by the STS.

15. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a cloud service system, the cloud service system executes the method as claimed in any one of claims 1 to 7.

16. A computer program product, characterized in that When the computer program product is run on a cloud service system, the cloud service system is caused to execute the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Permission data management method, device and system, medium, equipment and product

    CN121530703A