Virtual instance identity authentication method based on cloud technology and cloud management platform

By configuring virtual instances to authenticate identity at startup on the cloud management platform, the problem that cloud system does not support virtual instance identity authentication is solved, and the authentication of virtual instances and network security is guaranteed.

CN120223345APending Publication Date: 2025-06-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410382648.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-03-29
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Existing cloud systems do not support identity authentication when virtual instances access the cloud system, making it difficult to ensure network security.

Method used

Provide a virtual instance identity authentication method based on cloud technology, obtain the tenant's identity authentication settings through the cloud management platform, configure the virtual instance to connect to the identity authentication service node for identity authentication at startup, and use the 802.1x protocol to ensure the security of identity authentication.

Benefits of technology

The cloud system has realized the identity authentication of virtual instances, ensures network security, prevents network attacks, and grants network access to virtual instances with successful authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223345A_ABST
    Figure CN120223345A_ABST
Patent Text Reader

Abstract

The invention discloses a virtual instance identity authentication method based on a cloud technology and a cloud management platform, and relates to the technical field of cloud computing. The method comprises the following steps: acquiring settings related to identity authentication and input by a tenant in a cloud management platform, wherein the settings comprise a VPC creation request, identity authentication configuration information used for indicating identity authentication for a virtual instance set in a VPC in the future, a network address of an identity authentication service node, a virtual instance specification and an identifier of the VPC; and after the virtual instance arranged in the subnet of the VPC is created, configuring the virtual instance according to the identity authentication configuration information to be connected to the identity authentication service node for identity authentication under the condition of starting. Therefore, on the public cloud infrastructure, a set of interfaces related to identity authentication of the virtual instances is provided, and the tenants can set identity authentication of the virtual instances on the public cloud through the interfaces on the cloud management platform, so that the cloud system can support identity authentication of the virtual instances to ensure network security and prevent network attacks.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of the Chinese patent application with the application number 202311839470.2 and the application title "Network Authentication Method, Device, Network Equipment and Communication System" submitted to the National Intellectual Property Administration on December 27, 2023, the entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of cloud computing technology, and in particular to a virtual instance identity authentication method and a cloud management platform based on cloud technology. Background Art

[0003] With the development of cloud computing technology, enterprise services can be deployed to the cloud to achieve the consensus of cost reduction, efficiency improvement, IT capability enhancement, and customer experience improvement. When a virtual instance accesses resources in a cloud system, it is necessary to ensure network security and prevent network attacks. However, currently, the cloud system does not support the identity authentication of virtual instances when accessing the cloud system. Summary of the Invention

[0004] This application provides a virtual instance identity authentication method and a cloud management platform based on cloud technology, which can enable the cloud system to support the identity authentication of virtual instances when accessing the cloud system.

[0005] In a first aspect, a virtual instance identity authentication method based on cloud technology is provided. This method is applied to a cloud management platform, which is used to manage the infrastructure that provides cloud services. The infrastructure may include multiple servers. The method includes: obtaining settings related to identity authentication input by a tenant in the cloud management platform, such as obtaining a VPC creation request input by the tenant, creating a VPC in the infrastructure, where the VPC includes at least one subnet; obtaining identity authentication configuration information input by the tenant, where the identity authentication configuration information is used to indicate identity authentication for virtual instances to be set in the VPC in the future; obtaining the network address of the identity authentication service node input by the tenant; obtaining the virtual instance specification and the identifier of the VPC input by the tenant, selecting a target server that can provide the virtual instance specification from multiple servers, and creating a virtual instance in the subnet of the VPC in the target server; configuring the virtual instance to connect to the identity authentication service node for identity authentication when the virtual instance is started according to the identity authentication configuration information.

[0006] In this way, on the public cloud infrastructure, a set of interfaces related to virtual instance identity authentication is provided, so that a tenant can set the identity authentication of virtual instances on the public cloud through this interface in the cloud management platform, enabling the cloud system to support the authentication of the identity of virtual instances, granting network access permissions to virtual instances with successful authentication, and ensuring network security and preventing network attacks.

[0007] In a possible implementation, the above virtual switch is set in the target server, and the virtual switch is used to instruct the identity authentication service node to authenticate the identity of the virtual instance according to the identity identifier of the virtual instance.

[0008] As a communication connection bridge, the virtual switch carries the message transmission related to the identity authentication of the virtual instance between the virtual instance and the identity authentication service node. The interaction among the virtual instance, the virtual switch, and the identity authentication service node can provide a secure authentication method, that is, the identity authentication service node grants the virtual instance that has successfully passed the identity authentication the permission to access network resources to ensure network security.

[0009] In another possible implementation, the above identity authentication service node is set in the VPC or in the external network of the infrastructure. The identity authentication service node can be a virtual device in the VPC or a physical device in the external network, so that the type of the identity authentication node can be selected according to the business requirements of the tenant.

[0010] In another possible implementation, after the virtual instance is configured to connect to the identity authentication service node for identity authentication when starting up according to the identity authentication configuration information, the above method further includes: when the virtual instance is successfully authenticated, instructing the cloud management platform to allow the virtual instance to access the network resources in the VPC.

[0011] In another possible implementation, after the virtual instance is configured to connect to the identity authentication service node for identity authentication when starting up according to the identity authentication configuration information, the above method further includes: when the virtual instance fails to be authenticated, instructing the cloud management platform to deny the virtual instance access to the network resources in the VPC.

[0012] The virtual instance that fails to be authenticated may attack the VPC, posing a security threat to the cloud system. Prohibiting the virtual instance from accessing the network resources in the VPC and closing the access permission to protect network security.

[0013] In another possible implementation, when the virtual instance is configured to connect to the identity authentication service node for identity authentication when starting up according to the identity authentication configuration information, it specifically is used for: configuring the virtual instance to connect to the identity authentication service node when starting up according to the identity authentication configuration information, and performing identity authentication based on the 802.1x protocol.

[0014] The 802.1x protocol belongs to the Endpoint Admission Defense (EAD) security defense system. The network access control mechanism under this system strengthens the centralized management of the security of virtual instances, improves the defense ability of network resources, and ensures network security.

[0015] In another possible implementation, the above virtual instance includes at least one of a virtual machine or a container, so that a VM or a container can be created in the VPC according to the business requirements of the tenant.

[0016] In a second aspect, a cloud management platform is provided. The cloud management platform is used to manage the infrastructure that provides cloud services, and the infrastructure includes multiple servers. The cloud management platform includes: a VPC creation request acquisition module, an identity authentication configuration information acquisition module, a network address acquisition module, a specification and identifier acquisition module, and an authentication module.

[0017] Among them, the VPC creation request acquisition module is used to acquire the VPC creation request input by the tenant and create the tenant's VPC in the infrastructure. The VPC includes at least one subnet.

[0018] The identity authentication configuration information acquisition module is used to acquire the identity authentication configuration information input by the tenant, and the identity authentication configuration information is used to indicate identity authentication for virtual instances to be set in the VPC in the future;

[0019] The network address acquisition module is used to acquire the network address of the identity authentication service node input by the tenant;

[0020] The specification and identifier acquisition module is used to acquire the virtual instance specification and the identifier of the VPC input by the tenant, select a target server that can provide the virtual instance specification among multiple servers, and create a virtual instance in the subnet of the VPC in the target server;

[0021] The authentication module is used to configure the virtual instance to connect to the identity authentication service node for identity authentication when the virtual instance is started according to the identity authentication configuration information.

[0022] In a possible implementation, the above virtual switch is set in the target server, and the virtual switch is used to instruct the identity authentication service node to authenticate the identity of the virtual instance according to the identity identifier of the virtual instance.

[0023] In another possible implementation, the above identity authentication service node is set in the VPC or in the external network of the infrastructure.

[0024] In another possible implementation, after the authentication module configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information, it is further used to, when the virtual instance authentication is successful, instruct the cloud management platform to allow the virtual instance to access the network resources in the VPC.

[0025] In another possible implementation, after the authentication module configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information when the virtual instance is started, it is further used to instruct the cloud management platform to reject the virtual instance's access to the network resources in the VPC when the virtual instance authentication fails.

[0026] In another possible implementation, when the authentication module configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information when the virtual instance is started, it is specifically used to: configure the virtual instance to connect to the identity authentication service node according to the identity authentication configuration information, and perform identity authentication based on the 802.1x protocol.

[0027] In another possible implementation, the above virtual instance includes at least one of a virtual machine or a container.

[0028] In a third aspect, a computing device cluster is provided, and the computing device cluster includes at least one computing device. The computing device includes a processor and a memory, and the memory is used to store a set of computer instructions; when the processor, as the execution device in the first aspect or any possible implementation manner of the first aspect, executes the set of computer instructions, it executes the operation steps of the virtual instance identity authentication method based on cloud technology in the first aspect or any possible implementation manner of the first aspect.

[0029] In a fourth aspect, a computer-readable storage medium is provided, including: computer software instructions; when the computer software instructions run in the authentication device, the authentication device is caused to execute the operation steps of the virtual instance identity authentication method based on cloud technology in the first aspect or any possible implementation manner of the first aspect.

[0030] In a fifth aspect, a computer program product is provided, and when the computer program product runs on the authentication device, the authentication device is caused to execute the operation steps of the virtual instance identity authentication method based on cloud technology in the first aspect or any possible implementation manner of the first aspect.

[0031] The technical effects brought by any of the design manners in the second aspect to the fifth aspect can refer to the technical effects brought by the first aspect or different design manners in the first aspect, which will not be elaborated here.

[0032] Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 It is a schematic diagram of the basic framework of an 802.1x protocol provided by the present application;

[0034] Figure 2A structural schematic diagram of a cloud system provided by this application;

[0035] Figure 3 A flowchart of a virtual instance identity authentication method based on cloud technology provided by this application;

[0036] Figure 4 A flowchart of an authentication process executed among a virtual instance, a virtual switch, and an identity authentication node provided by this application;

[0037] Figure 5 A schematic diagram of the application of a security group and an ACL in a VPC provided by this application;

[0038] Figure 6 An interaction schematic diagram for implementing virtual instance identity authentication provided by this application;

[0039] Figure 7 A structural schematic diagram of a cloud management platform provided by this application;

[0040] Figure 8 A structural schematic diagram of a computing device provided by this application;

[0041] Figure 9 A structural schematic diagram of a computing device cluster provided by this application;

[0042] Figure 10 Another structural schematic diagram of a computing device cluster provided by this application. Detailed implementation manners

[0043] For the sake of clear and concise description of the following embodiments, the terms related to this application are briefly introduced first:

[0044] The 802.1x protocol is a port-based network access control protocol, which can refer to an authentication device verifying the identity of a client connected to the port of a local area network access device (such as a switch) and controlling the client's permission to access the network. For example, the authentication device grants the permission to access the network to the client with successful authentication; and closes the permission to access the network to the client with failed authentication.

[0045] The 802.1x protocol adopts a client / server structure, and its constituent entities can include: a client, an access device, and an authentication server. Figure 1 A schematic diagram of the basic framework of the 802.1x protocol provided by this application. As Figure 1 shown, the access device can be connected to at least one client, and the authentication server is connected to the access device.

[0046] Among them, the client can be a user terminal device on a local area network. The user can initiate 802.1x authentication by starting the 802.1x software installed on the client device. Here, the client needs to support the Extensible Authentication Protocol (EAP) to allow the identity of the client to be authenticated based on the local area network.

[0047] The access device can be a network device (such as a switch) that supports the 802.1x protocol. The access device can provide a port for the client to access the local area network. Here, the port can be a physical port or a logical port (such as an Eth-Trunk interface).

[0048] The authentication server can be an authentication device that provides identity authentication services for the client, and is used to implement identity authentication of the client, authorization for accessing the network, and charging, etc. The authentication server can include a Remote Authentication Dial In User Service (RADIUS) server.

[0049] Using the 802.1x protocol provides a relatively secure authentication method for traditional local area networks, effectively ensuring the network security of traditional networks. However, enterprise services are not limited to being deployed on traditional local area networks. With the development of cloud computing technology, enterprise services can be deployed to the cloud. When virtual instances processing services access resources in the cloud system, it is also necessary to ensure network security and prevent network attacks. However, currently, the cloud system does not support identity authentication when virtual instances access the cloud system.

[0050] To solve the problem that the current cloud system does not support identity authentication when virtual instances access the cloud system and enable identity authentication on the cloud system, this application provides a virtual instance identity authentication method based on cloud technology. This method is applied to a cloud management platform, which is used to manage the infrastructure that provides cloud services. The infrastructure can include multiple servers. The method includes: obtaining settings related to identity authentication input by the tenant in the cloud management platform, such as obtaining a VPC creation request input by the tenant, creating a VPC in the infrastructure, where the VPC includes at least one subnet; obtaining identity authentication configuration information input by the tenant, where the identity authentication configuration information is used to indicate identity authentication for virtual instances to be set in the VPC in the future; obtaining the network address of the identity authentication service node input by the tenant; obtaining the virtual instance specification and the identifier of the VPC input by the tenant, selecting a target server that can provide the virtual instance specification from multiple servers, and creating a virtual instance in the subnet of the VPC in the target server; configuring the virtual instance to connect to the identity authentication service node for identity authentication when the virtual instance is started according to the identity authentication configuration information.

[0051] In this way, on the public cloud infrastructure, a set of interfaces related to virtual instance identity authentication is provided. Tenants can, through this interface on the cloud management platform, set the identity authentication of virtual instances on the public cloud, enabling the cloud system to support the authentication of the identities of virtual instances, granting network access permissions to the virtual instances that pass the identity verification, so as to ensure network security and prevent network attacks.

[0052] The following will introduce in detail the virtual instance identity authentication method provided by this application based on cloud technology with reference to the accompanying drawings.

[0053] Figure 2 It is a schematic structural diagram of a cloud system provided by this application. As Figure 2 shown, the cloud system 200 includes a cloud resource pool 210 and a computing cluster 220.

[0054] Among them, the cloud resource pool 210 includes but is not limited to computing resources (such as virtual machine resources and container resources, etc.), storage resources, and network resources, etc. These resources are provided to tenants in the form of services, and tenants can access and utilize these resources through the cloud network without managing and maintaining computing devices.

[0055] Exemplarily, the cloud network can be a Virtual Private Cloud (VPC) network. The VPC allows, on the public cloud infrastructure, to create an isolated, private, and custom-configured virtual network environment for computing resources such as virtual instances, and divide subnets and configure network parameters according to the needs of tenants. The VPC is applicable to enterprise tenants with high requirements for data security and custom planning of network topologies.

[0056] The computing cluster 220, as the public cloud infrastructure, can provide cloud services for users based on the cloud resource pool 210 in the cloud system 200. The computing cluster 220 that provides cloud services can be managed by the cloud management platform in the cloud system, so as to allocate cloud resources to tenants as needed according to resource usage requirements. The computing cluster 220 managed by the cloud management platform is the center for the cloud system 200 to process authentication tasks, and multiple computing devices in the computing cluster 220 can cooperate to process the identity authentication of virtual instances.

[0057] The computing cluster 220 includes multiple servers, such as Figure 2 the shown servers 221, 222, and 223, etc. Based on virtualization technology, the servers can virtualize multiple virtual instances, such as virtual machines or containers, and the virtual instances can be used as business nodes for processing enterprise business in the cloud. Figure 2Taking the server 221 as an example, at least one virtual instance (such as virtual instance 1, virtual instance 2, …, and virtual instance N) can be deployed on the server 221. The virtual instances access the resources of the cloud network. To ensure network security, identity authentication is required.

[0058] In some embodiments, the server further includes an access node and an identity authentication service node. The access node and the identity authentication service node can be deployed on the same server as the service node, or can be deployed on a server different from the service node. The embodiments of the present application do not limit this.

[0059] The functions of the access node and the identity authentication service node can be implemented by the virtual instance. For example, the access node can be a virtual switch that provides a cloud network port for the virtual instance, such as a Distributed Virtual Switch (DVS). The identity authentication service node can be a virtualized authentication server that provides identity authentication services for the virtual instance, such as a virtual RADIUS authentication server.

[0060] When a virtual instance needs to access network resources in a cloud network (such as a VPC), the virtual switch can instruct the virtualized authentication server to verify the identity of the virtual instance. The virtualized authentication server grants the virtual instance with successful authentication the permission to access resources, allowing the virtual machine with access permission to access network resources. In this authentication process, the EAP protocol can be used for communication between the virtual machine and the virtual switch, and the RADIUS protocol can be used for communication between the virtual switch and the virtualized authentication server. The implementation process of the specific authentication method can refer to the content described in the subsequent method embodiments.

[0061] Next, in combination with Figures 3 to 6 , a detailed description of the virtual instance identity authentication method provided by the present application will be given. Figure 3 It is a schematic flowchart of a virtual instance identity authentication method provided by the present application. As Figure 3 shown, the virtual instance identity authentication method can include the following steps.

[0062] Step 310: Obtain a VPC creation request input by a tenant, and create the tenant's VPC in the infrastructure.

[0063] After an individual or an enterprise registers an account on the cloud management platform, the cloud management platform regards the user with the account information as a tenant, and distributes resources in units of tenants according to the tenant's resource usage requirements. In the embodiments of the present application, the form of the tenant is not limited. For example, the tenant can be a large individual tenant or a tenant group composed of multiple small tenants.

[0064] After obtaining the VPC creation request input by the tenant in the cloud management platform, create the tenant's VPC in the infrastructure (such as a public cloud server). The VPC includes at least one subnet. In some embodiments, the tenant's VPC can be created first, and then at least one subnet can be created in the VPC.

[0065] In some embodiments, there is a cloud product running in the cloud management platform that can provide virtualized network configuration. When creating the tenant's VPC, enter the VPC creation page in the cloud product and configure the VPC parameters according to the tenant's requirements based on the page prompts. The VPC parameters include but are not limited to the available zone, name, network segment, and enterprise business description of the VPC, etc.

[0066] When creating a subnet in the VPC, enter the subnet creation page and configure the subnet parameters according to the tenant's requirements based on the page prompts. The subnet parameters include but are not limited to the available zone, name, subnet network segment (subnet IPv4 network segment or subnet IPv6 network segment), associated route table, and advanced configuration (such as gateway, DNS server address, and domain name), etc. As an IP address block in the VPC, the subnet can divide the network segment of the VPC into multiple subnet network segments according to the tenant's requirements, so as to create at least one subnet in the VPC. Subnet division is beneficial to reasonably planning IP address resources.

[0067] Step 320: Obtain the identity configuration information input by the tenant.

[0068] Obtain the identity configuration information input by the tenant in the cloud management platform. The identity authentication configuration information is used to indicate the identity authentication for virtual instances to be set in the VPC in the future.

[0069] In some embodiments, the identity configuration information includes an authentication identifier. The authentication identifier can be used as an authentication switch to enable the cloud system to support virtual instance identity authentication. The value of the authentication identifier can be 0 or 1.

[0070] For example, if the value of the authentication identifier of the VPC is 0, it can indicate that all virtual instances in the VPC do not execute the identity authentication process.

[0071] If the value of the authentication identifier of the VPC is 1, it can indicate that all virtual instances in the VPC execute the authentication process.

[0072] For another example, if the value of the authentication identifier of the subnet is 0, it can indicate that all virtual nodes in the subnet do not execute the authentication process. If the value of the authentication identifier of the subnet is 1, it can indicate that all virtual instances in the subnet execute the authentication process.

[0073] For yet another example, if the value of the authentication identifier of the virtual instance is 0, it can indicate that this virtual instance does not execute the authentication process. If the value of the authentication identifier of the virtual instance is 1, it can indicate that this virtual instance executes the authentication process.

[0074] Set the authentication identifiers for the VPC, subnet, and virtual instance respectively. Different authentication scopes are represented by different values of the authentication identifiers, and it is possible to indicate that the authentication process is executed according to different authentication granularities to meet the diversity of authentication requirements.

[0075] The virtual instances in the embodiments of the present application include at least one of a virtual machine (VM) or a container. Among them, the advantage of a VM is that it can be isolated from the operating system of the server and has relatively high security. A container is a virtualization technology that can enable different application programs to run in a relatively isolated environment. The advantage of a container is that it is lightweight and has a fast startup speed, and it is more convenient to deploy services inside the container. VMs or containers can be created in the VPC according to the business requirements of the tenant.

[0076] Step 330: Obtain the network address of the identity authentication service node input by the tenant.

[0077] Obtain the network address of the identity authentication service node input by the tenant in the cloud management platform. The network address can be the IP address of the identity authentication service node. Here, the identity authentication service node can be set in the VPC, such as any virtual instance in the VPC or any virtual instance in the subnet included in the VPC. It can also be set in the external network of the infrastructure (such as a public cloud server), such as a virtual instance or a physical device from the external network. When the identity authentication service node is a physical device, it is necessary to further obtain the VPC routing table address input by the tenant in order to access this physical device through the VPC.

[0078] Step 340: Obtain the virtual instance specification and the identifier of the VPC input by the tenant, select a target server that can provide the virtual instance specification from multiple servers, and create a virtual instance in the subnet of the VPC in the target server.

[0079] Obtain the virtual instance specification and the identifier of the VPC input by the tenant in the cloud management platform. Among them, the identifier can be used to uniquely indicate the VPC, such as the VPC ID. The tenant inputs the virtual instance specification according to the business requirements, and the obtained virtual instance specification includes the number of virtual processors, the size of virtual memory, and the number and capacity of virtual devices (such as virtual disks, virtual network cards, and virtual graphics cards, etc.).

[0080] Select a target server that can provide the virtual instance specification from multiple servers. The virtualization resources in the target server need to be greater than the virtualization resources indicated by the virtual instance specification to be able to meet the business requirements of the tenant.

[0081] After selecting the target server, create a virtual instance in the subnet of the VPC configured in the target server. Based on the creation of the tenant's VPC in the server and the creation of subnets in the VPC completed in step 310 above, a virtual instance can be directly created in the subnet configured in the target server according to the virtual instance specifications, and the virtual instance can be managed through the tenant's VPC or subnet in the target server.

[0082] The created virtual instance includes a virtual machine or a container. Among them, the virtual machine can be created by a virtual machine monitor (such as a hypervisor) responsible for creating and managing the virtual machine. The container can be created by Kubernetes (K8S) responsible for creating, orchestrating, and managing the container.

[0083] According to the above steps 310 to 340, the settings related to identity authentication input by the tenant in the cloud management platform are obtained. Based on the tenant's settings, a set of interfaces related to the identity authentication of virtual instances are provided on the public cloud infrastructure, so that the tenant can set the identity authentication of virtual instances on the public cloud through this interface in the cloud management platform. The specific method of identity authentication is described in the following content of step 350.

[0084] Step 350: Configure the virtual instance to connect to the identity authentication service node for identity authentication when the virtual instance is started according to the identity authentication configuration information.

[0085] When the virtual instance in the subnet of the VPC is started, according to the indication of the identity authentication configuration information, the virtual instance in the VPC will be authenticated. Configure the virtual instance to connect to the identity authentication service node, and based on the 802.1x protocol, the identity authentication service node authenticates the identity of the virtual instance and controls the permission of the virtual instance to access the network resources in the VPC.

[0086] In some embodiments, a virtual switch can be set in the target server, and the virtual switch can instruct the identity authentication service node to authenticate the identity of the virtual instance according to the identity identifier of the virtual instance. As a communication connection bridge, the virtual switch carries the message transmission related to the identity authentication of the virtual instance between the virtual instance and the identity authentication service node. The identity authentication service node grants the permission to access network resources to the virtual instance with successful authentication, and the cloud management platform allows the virtual instance with access permission to access the resources in the VPC to ensure network security.

[0087] Next, in combination with the accompanying drawings, an authentication process between a virtual instance, a virtual switch, and an identity authentication node based on the 802.1x protocol is exemplarily introduced to implement the identity authentication of the virtual instance. Figure 4 It is a schematic flow diagram of an authentication process executed between a virtual instance, a virtual switch, and an identity authentication node provided by this application, asFigure 4 As shown, the process includes the following steps:

[0088] Step 410: The virtual switch receives an authentication request sent by a virtual instance.

[0089] The virtual instance can process enterprise services on the cloud management platform. When the virtual instance is started, the identity authentication service node needs to verify the identity of the virtual instance.

[0090] In a possible implementation, the virtual instance can initiate identity authentication actively, send an authentication request to the virtual switch, and the authentication request is used to indicate the identity information for authenticating the virtual instance. In this way, the virtual switch receives the authentication request sent by the virtual instance.

[0091] In another possible implementation, the virtual switch can instruct the virtual instance to trigger identity authentication and send an authentication indication to the virtual instance. After receiving the authentication indication, the virtual instance sends an authentication request to the virtual switch. In this way, the virtual switch receives the authentication request sent by the virtual instance.

[0092] Step 420: The virtual switch instructs the identity authentication service node to authenticate the identity of the virtual instance according to the identity identifier of the virtual instance.

[0093] The identity identifier (such as the user name ID of the virtual instance) can be used as the only credential to prove the identity of the virtual instance, and the identity identifier of each virtual instance is different. The virtual switch can instruct the identity authentication service node to encrypt the identity identifier of the virtual instance for facilitating the authentication of the virtual instance. The specific implementation can include the following steps.

[0094] Step 421: The virtual switch sends an encryption request to the identity authentication service node.

[0095] The encryption request can include the identity identifier of the virtual instance. For example, the virtual switch can encapsulate the identity identifier of the virtual instance in a RADIUS message and send this message to the identity authentication service node (such as a virtualized RADIUS server).

[0096] Step 422: The identity authentication service node encrypts the identity identifier of the virtual instance according to the key algorithm to obtain a first encrypted password.

[0097] After receiving the encryption request sent by the virtual switch, the identity authentication service node parses the encryption request to obtain the identity identifier of the virtual instance. Encrypt the identity identifier according to the key algorithm to obtain the first encrypted password. The key algorithms here include, but are not limited to, Message-Digest Algorithm 5 (MD5), Security Hash Algorithm 1 (SHA1), and Hash-based Message Authentication Code (HMAC), etc.

[0098] For example, the identity authentication service node randomly generates an encryption word (MD5 Challenge) using the MD5 algorithm, encrypts the identity identifier with this encryption word to obtain the first encrypted password, and stores the first encrypted password.

[0099] Step 423: The virtual switch receives the encryption response sent by the identity authentication service node.

[0100] After the identity authentication service node finishes encrypting the identity identifier of the virtual instance, it sends an encryption response to the virtual switch. The encryption response can include the key algorithm used by the identity authentication service node. For example, the identity authentication service node can also encapsulate the key algorithm in a RADIUS message and send this message to the virtual switch. In this way, the virtual switch receives the encryption response sent by the identity authentication service node.

[0101] Step 430: The virtual instance authenticates with the identity authentication service node.

[0102] The virtual instance and the identity authentication service node can authenticate the identity of the virtual instance based on the same encryption method. During this authentication process, the virtual switch can carry the transmission of messages related to the identity authentication of the virtual instance. The specific implementation method can include the following steps.

[0103] Step 431: The virtual instance receives the authentication response sent by the virtual switch.

[0104] The virtual switch has obtained the key algorithm used by the identity authentication service node when encrypting the identity identifier in the above step 423. In order for the virtual instance to encrypt the identity identifier using the same key algorithm, the virtual switch needs to transmit the key algorithm to the virtual instance.

[0105] The virtual switch can send an authentication response to the virtual instance, and the authentication response includes the key algorithm used by the identity authentication service node. For example, the virtual switch can encapsulate this key algorithm in the authentication response message (EAP-Response / Challenge message) and send this message to the virtual instance. In this way, the virtual instance receives the authentication response sent by the virtual switch.

[0106] Step 432: The virtual instance encrypts the identity identifier of the virtual instance according to the key algorithm to obtain a second encrypted password.

[0107] The virtual instance can parse the authentication response to obtain the key algorithm used by the identity authentication service node. The virtual instance encrypts the identity identifier according to the same key algorithm to obtain a second encrypted password.

[0108] Step 433: The virtual instance sends the second encrypted password to the identity authentication service node.

[0109] In a possible implementation, the virtual instance can first send the second encrypted password to the virtual switch, and then the virtual switch forwards the second encrypted password to the identity authentication service node.

[0110] In another possible implementation, the virtual instance can directly send the second encrypted password to the identity authentication service node without being forwarded by the virtual switch.

[0111] Step 434: The identity authentication service node receives the second encrypted password sent by the virtual instance and verifies the second encrypted password according to the first encrypted password; when the verification of the second encrypted password is successful, the virtual instance authentication is successful.

[0112] The identity authentication service node verifies the second encrypted password according to the first encrypted password. For example, it can determine whether the virtual instance has passed the identity authentication by comparing the first encrypted password and the second encrypted password. If the comparison results are the same, it indicates that the identity authentication service node and the virtual instance use the same encryption method to encrypt the identity identifier of the virtual instance, the verification of the second encrypted password by the first encrypted password is successful, and the virtual instance authentication is successful. If the comparison results are different, the virtual instance authentication fails.

[0113] Step 440: When the virtual instance authentication is successful, the cloud management platform allows the virtual instance to access the network resources in the VPC.

[0114] When the virtual instance authentication is successful, the virtual switch can receive the permission indication sent by the identity authentication service node. The permission indication is used to allow the virtual instance to access the network resources in the VPC, and the identity authentication service node grants the virtual instance the permission to access the resources.

[0115] Step 450: When the virtual instance authentication fails, the cloud management platform prohibits the virtual instance from accessing the network resources in the VPC.

[0116] When the virtual instance authentication fails, the virtual switch can receive the revocation instruction sent by the identity authentication service node. The revocation instruction is used to prohibit the virtual instance from accessing the network resources in the VPC. The identity authentication service node closes the access permission of the virtual instance to the resources to protect network security.

[0117] In some embodiments, when the virtual instance passes the identity authentication, the virtual switch can allow the virtual instance to access the network resources in the VPC according to the network traffic in the VPC. The network traffic in the VPC includes the network traffic of the virtual instance or the network traffic of the subnet where the virtual instance is located.

[0118] Among them, the network traffic of the virtual instance can be controlled by a security group. A security group is a virtual firewall used to control the network traffic of the virtual instance accessing the VPC. A security group is a logical grouping. After creating a security group, the security rules of the security group can be defined. The security rules are used to restrict the network traffic entering and leaving the virtual instance, allow the network traffic that matches the security rules to pass through the virtual instance, so that the virtual instance can access the network resources in the VPC. Intercept the network traffic that does not match the security rules and prohibit the network traffic that does not match the security rules from passing through the virtual instance to protect network security.

[0119] The network traffic of the subnet where the virtual instance is located can be controlled by an access control list (ACL). The ACL is also a virtual firewall used to control the network traffic of the virtual instances included in the subnet accessing the cloud network. The ACL rules are used to restrict the network traffic entering and leaving the subnet, allow the network traffic that matches the ACL rules to pass through the subnet, so that the virtual instances under the subnet can access the network resources in the VPC. Intercept the network traffic that does not match the ACL rules and prohibit the network traffic that does not match the ACL rules from passing through the subnet to protect network security.

[0120] Generally speaking, both the security group and the ACL can be used to control network traffic and protect network security. Figure 5 The figure shows a schematic diagram of the application of a security group and an ACL in the VPC provided by this application. As Figure 5 shown, the security group is more suitable for controlling the network traffic entering and leaving the virtual instance. The security group can be applied to at least one virtual instance, but one virtual instance is associated with one security group. For example, security group 1 is applied to virtual instance 1, security group 2 is applied to virtual instance 2, and security group 3 is applied to virtual instances 3 and 4. The ACL is more suitable for controlling the network traffic entering and leaving the subnet. The ACL can be applied to one subnet. For example, ACL1 is applied to subnet 1 and ACL2 is applied to subnet 2.

[0121] The above steps 410 to 450 introduce the authentication process of the interaction between the virtual instance, the virtual switch, and the identity authentication service node to achieve the identity authentication of the virtual instance. After the virtual instance passes the authentication, the virtual switch can also detect whether the virtual instance is in the state of accessing the network resources in the VPC, take the virtual instance that has not accessed the network resources offline, so as to release the network bandwidth in time and save network resources.

[0122] The virtual switch can send a handshake message to the virtual instance, and the handshake message is used to detect the connection status between the virtual instance and the VPC. For example, the virtual switch periodically sends a handshake message to the virtual instance by starting a timer.

[0123] After receiving the handshake message, if the virtual instance still needs to continue accessing resources, it sends a response message to the virtual switch. The response message indicates that the virtual instance is connected to the VPC and is accessing the network resources in the VPC online, keeping alive the state of accessing the network resources. The virtual switch receives the response message sent by the virtual instance and allows the virtual instance to continue accessing the network resources in the VPC.

[0124] After receiving the handshake message, if the virtual instance no longer continues to access resources, the virtual switch can prohibit the virtual instance from continuing to access the network resources in the VPC.

[0125] In a possible implementation, the virtual instance actively sends a logout message to the virtual switch, and the logout message is used to indicate the revocation of the identity authentication of the virtual instance. The virtual switch receives the logout message sent by the virtual instance and closes the permission for the virtual instance to access the network resources in the VPC.

[0126] In another possible implementation, if the virtual instance does not respond to the handshake message sent by the virtual switch and the virtual switch does not receive the response message, it can actively close the permission for the virtual instance to access the network resources in the VPC, triggering the virtual instance to go offline.

[0127] To facilitate understanding of the complete process of identity authentication described in the above embodiments, Figure 6 This is an interaction schematic diagram for implementing the identity authentication of a virtual instance provided by this application. During the process of identity authentication based on the 802.1x protocol, the virtual instance and the virtual switch can interact through relevant messages of the Extensible Authentication Protocol over LAN (EAPoL), and the virtual switch and the identity authentication service node can interact through relevant messages of the RADIUS protocol to achieve communication of information related to identity authentication. As Figure 6 shown, this process may include the following steps:

[0128] Step 601: The virtual instance sends an authentication request (EAPoL-Start message) to the virtual switch to trigger identity authentication.

[0129] Step 602: The virtual switch receives the authentication request sent by the virtual instance and sends an Identity request (EAP-Request / Identity message) to the virtual instance to obtain the identity of the virtual instance.

[0130] Step 603: The virtual instance receives the request sent by the virtual switch and sends an Identity response (EAP-Response / Identity message) to the virtual switch.

[0131] Step 604: The virtual switch encapsulates the identity sent by the virtual instance into a RADIUS authentication message (RADIUS Access-Request message) and sends an encryption request containing the RADIUS authentication message to the identity authentication service node.

[0132] Step 605: The identity authentication service node receives the encryption request sent by the virtual switch, parses out the identity contained in the encryption request, encrypts the identity using a secret key algorithm, for example, randomly generates an encryption word (MD5 Challenge) using the MD5 algorithm to encrypt this identity to obtain a first encrypted password, encapsulates the encryption word into a RADIUS encryption message (RADIUS Access-Challenge message), and sends an encryption response containing the RADIUS encryption message to the virtual switch.

[0133] Step 606: The virtual switch receives the encryption response, parses out the encryption word contained in the encryption response, encapsulates the encryption word into an authentication response message (EAP-Response / Challenge message), and sends an authentication response containing the authentication response message to the virtual instance.

[0134] Step 607: The virtual instance receives the authentication response, parses out the encryption word contained in the authentication response, encrypts the identity with this encryption word to obtain a second encrypted password, and sends the second encrypted password obtained after encryption to the virtual switch.

[0135] Step 608: The virtual switch receives the second encrypted password and sends the second encrypted password to the identity authentication service node.

[0136] Step 609: The identity authentication service node receives the second encrypted password sent by the virtual switch, and compares the first encrypted password with the second encrypted password. If the comparison results are the same, the virtual instance passes the authentication and sends an authorization indication (RADIUS Access-Accept message) to the virtual switch.

[0137] Step 610: The virtual switch receives the authorization indication, allows the virtual instance to access the network resources in the VPC, sends an authentication success message (EAP-Success message) to the virtual instance, and the virtual instance starts to access the network resources.

[0138] Step 611: The virtual switch periodically sends a handshake message to the virtual instance, and the handshake message is used to indicate the status of the virtual instance accessing the network resources in the VPC.

[0139] Step 612: The virtual instance receives the handshake message. If it still needs to continue accessing the resources, it sends a response message to the virtual switch to keep the status of accessing the network resources alive.

[0140] Step 613: The virtual instance receives the handshake message. If it no longer needs to continue accessing the resources, it can actively send a logout message (EAPoL-Logoff) to the virtual switch, and the logout message is used to indicate the revocation of the identity authentication of the virtual instance.

[0141] Step 614: The virtual switch receives the logout message (EAPoL-Logoff) sent by the virtual instance, closes the permission of the virtual instance to access the network resources in the VPC, and prohibits the virtual instance from continuing to access the network resources.

[0142] Alternatively, after step 611, step 614 is executed. That is, if the virtual switch does not receive the response message sent by the virtual instance, it can actively close the permission of the virtual instance to access the network resources in the VPC, triggering the virtual instance to go offline.

[0143] According to the above virtual instance identity authentication method based on cloud technology provided by the embodiments of the present application, on the public cloud infrastructure, a set of interfaces related to virtual instance identity authentication is provided. Tenants can set the virtual instance identity authentication on the public cloud through this interface in the cloud management platform, enabling the cloud system to support the authentication of the identity of the virtual instance, granting network access permissions to the virtual instances with successful identity verification, so as to ensure network security and prevent network attacks.

[0144] The above mainly introduced the solution provided by the embodiments of the present application from the perspective of methods. It can be understood that, in order to implement the above functions, the server includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0145] In the above, in combination with Figures 2 to 6 , the virtual instance identity authentication method provided according to the embodiments of the present application was described in detail. Next, in combination with Figure 7 , a cloud management platform capable of implementing the virtual instance identity authentication function provided according to the embodiments of the present application will be described. The cloud management platform is used to manage the infrastructure that provides cloud services, and the infrastructure includes multiple servers.

[0146] Figure 7 It is a schematic structural diagram of a cloud management platform provided by the present application.

[0147] As Figure 7 shown, the cloud management platform 700 includes a VPC creation request acquisition module 710, an identity authentication configuration information acquisition module 720, a network address acquisition module 730, a specification and identification acquisition module 740, and an authentication module 750.

[0148] Among them, the VPC creation request acquisition module 710 is used to acquire the VPC creation request input by the tenant and create the tenant's VPC in the infrastructure. The VPC includes at least one subnet. For example, the VPC creation request acquisition module 710 is used to execute Figure 3 the steps in 310.

[0149] The identity authentication configuration information acquisition module 720 is used to acquire the identity authentication configuration information input by the tenant, and the identity authentication configuration information is used to indicate identity authentication for virtual instances to be set in the VPC in the future. For example, the identity authentication configuration information acquisition module 720 is used to execute Figure 3 the steps in 320.

[0150] The network address acquisition module 730 is used to acquire the network address of the identity authentication service node input by the tenant. For example, the network address acquisition module 730 is used to execute Figure 3 the steps in 330.

[0151] The specification and identification acquisition module 740 is used to obtain the virtual instance specification and the identification of the VPC input by the tenant, select a target server that can provide the virtual instance specification from multiple servers, and create a virtual instance in the subnet of the VPC in the target server. For example, the specification and identification acquisition module 740 is used to execute Figure 3 step 340 in

[0152] The authentication module 750 is used to configure the virtual instance to connect to the identity authentication service node for identity authentication when the virtual instance is started according to the identity authentication configuration information. For example, the authentication module 750 is used to execute Figure 3 step 350 in

[0153] Optionally, the above virtual switch is set in the target server, and the virtual switch is used to instruct the identity authentication service node to authenticate the identity of the virtual instance according to the identity identification of the virtual instance.

[0154] Optionally, the above identity authentication service node is set in the VPC or in the external network of the infrastructure.

[0155] Optionally, after the authentication module 750 configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information when the virtual instance is started, it is further used to instruct the cloud management platform to allow the virtual instance to access the network resources in the VPC when the virtual instance authentication is successful.

[0156] Optionally, after the authentication module 750 configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information when the virtual instance is started, it is further used to instruct the cloud management platform to deny the virtual instance access to the network resources in the VPC when the virtual instance authentication fails.

[0157] Optionally, when the authentication module 750 configures the virtual instance to connect to the identity authentication service node for identity authentication according to the identity authentication configuration information when the virtual instance is started, it is specifically used to: configure the virtual instance to connect to the identity authentication service node when the virtual instance is started according to the identity authentication configuration information, and perform identity authentication based on the 802.1x protocol.

[0158] Optionally, the above virtual instance includes at least one of a virtual machine or a container.

[0159] It should be understood that the cloud management platform 700 capable of implementing the virtual instance identity authentication function according to the embodiments of the present application may correspond to executing the methods described in the embodiments of the present application, and the above and other operations and / or functions of each unit in the cloud management platform 700 are for implementing Figure 3 the corresponding processes of the methods, and for the sake of brevity, they will not be described in detail here.

[0160] The authentication method provided by the embodiments of this application can be applied to a computing device cluster, which includes at least one computing device. Figure 8 It is a schematic structural diagram of a computing device provided by this application. As Figure 8 shown, the computing device 800 includes a processor 810, a bus 820, a memory 830, a memory 850 (which can also be referred to as the main memory), and a communication interface 840. The processor 810, the memory 830, the memory 850, and the communication interface 840 are connected through the bus 820.

[0161] It should be understood that in this embodiment, the processor 810 can be a CPU, and the processor 810 can also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0162] The communication interface 840 is used to implement the communication between the computing device 800 and external devices or components. In this embodiment, the communication interface 840 is used to perform data interaction with other computing devices.

[0163] The bus 820 can include a path for transmitting information between the above components (such as the processor 810, the memory 850, and the memory 830). In addition to the data bus, the bus 820 can also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity, in Figure 8 all kinds of buses are labeled as the bus 820. The bus 820 can be a Peripheral Component Interconnect Express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), etc.

[0164] As an example, the computing device 800 may include multiple processors. The processor may be a multi-CPU processor. Here, the processor may refer to one or more devices, circuits, and / or computing units for processing data (such as computer program instructions). The processor 810 may obtain the authentication-related settings input by the tenant in the cloud management platform, and configure the virtual instance to connect to the authentication service node for authentication when the virtual instance is started according to the authentication configuration information.

[0165] It is worth noting that Figure 8 only the example where the computing device 800 includes 1 processor 810 and 1 memory 830 is taken here. Here, the processor 810 and the memory 830 are respectively used to indicate a type of device or equipment. In specific embodiments, the quantity of each type of device or equipment can be determined according to service requirements.

[0166] The memory 850 may correspond to storing authentication configuration information and the like in the above method embodiments. The memory 850 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0167] The memory 830 is used to store VPC creation requests, authentication configuration information, network addresses, specifications, identifiers, etc., and may be a solid-state drive or a mechanical hard drive.

[0168] It should be understood that the computing device 800 according to this embodiment may correspond to the cloud management platform 700 in this embodiment that can implement the virtual instance identity authentication function, and the above and other operations and / or functions of each module of the cloud management platform 700 can be respectively implemented for Figure 3 the corresponding processes in, and for the sake of brevity, will not be elaborated here.

[0169] The method steps in this embodiment can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in the computing device. Of course, the processor and the storage medium can also exist as discrete components in a network device or a terminal device.

[0170] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer or a laptop computer.

[0171] As Figure 9 shown, the computing device cluster includes at least one computing device 900. The same instructions for executing the authentication method can be stored in the memory 906 in one or more of the computing devices 800 in the computing device cluster. The functions of the bus 902, the processor 904, the memory 906, and the communication interface 908 can refer to the introduction of the corresponding content in Figure 8 and will not be elaborated here.

[0172] In some possible implementations, the memory 906 of one or more computing devices 900 in the computing device cluster may also store some instructions for executing the authentication method respectively. In other words, the combination of one or more computing devices 900 may jointly execute the instructions for executing the authentication method.

[0173] It should be noted that the memories 906 in different computing devices 900 in the computing device cluster may store different instructions for respectively executing the functions of the various modules of the cloud management platform 700. That is, the instructions stored in the memories 906 of different computing devices 900 can implement the functions of one or more modules in the acquisition module (the acquisition module includes a VPC creation request acquisition module, an identity authentication configuration information acquisition module, a network address acquisition module, a specification and identification acquisition module) and the authentication module.

[0174] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network. Among them, the network may be a wide area network or a local area network, etc. Figure 10 A possible implementation is shown. As Figure 10 shown, two computing devices 1000A and 1000B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the memory 1006 in the computing device 1000A stores instructions for executing the functions of the acquisition module. At the same time, the memory 1006 in the computing device 1000B stores instructions for executing the functions of the deployment module. The functions of the bus 1002, the processor 1004, the memory 1006, and the communication interface 1008 may refer to the introduction of the corresponding content in Figure 8 and will not be elaborated here.

[0175] Figure 10 The connection method between the computing device clusters shown may be considered that since the authentication method provided in this application needs to store a large amount of VPC creation requests, identity authentication configuration information, network addresses, specifications and identifications, etc., it is therefore considered to hand over the functions implemented by the acquisition module to the computing device 1000A for execution. The functions implemented by the authentication module are handed over to the computing device 1000B for execution.

[0176] It should be understood that Figure 10 the functions of the computing device 1000A shown in

[0177] The embodiments of the present application also provide a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, at least one computing device is caused to execute the authentication method.

[0178] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium may be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute the authentication method.

[0179] The present application also provides a chip system, which includes a processor for implementing the functions of the authentication method in the above embodiments. In a possible design, the chip system further includes a memory for storing program instructions and / or data. The chip system may be composed of chips or may include chips and other discrete devices.

[0180] The chip integrates a control circuit for implementing the functions of the above computing device and one or more ports. Optionally, the functions supported by the chip may refer to the above, which will not be elaborated here. Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The storage medium mentioned above may be a read-only memory, a random access memory, etc. The above processing unit or processor may be a central processing unit, a general-purpose processor, an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.

[0181] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center integrating one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disc (DVD); or it may be a semiconductor medium, such as a solid state drive (SSD).

[0182] It should be noted that the devices for storing computer instructions or computer programs provided in the embodiments of the present application, such as but not limited to, the above-mentioned memory, computer-readable storage medium, and communication chip, etc., are all non-transitory.

[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; without departing from the essence of the corresponding technical solutions from the scope of protection.

Claims

1. A virtual instance identity authentication method based on cloud technology, characterized in that: The method is applied to a cloud management platform, the cloud management platform is used to manage an infrastructure for providing cloud services, the infrastructure includes a plurality of servers, and the method includes: Obtaining a virtual private cloud (VPC) creation request input by a tenant, and creating a VPC of the tenant in the infrastructure, wherein the VPC includes at least one subnet; Obtaining identity authentication configuration information input by the tenant, where the identity authentication configuration information is used to instruct to perform identity authentication on a virtual instance to be set up in the VPC in the future; Obtain the network address of the identity authentication service node input by the tenant; Obtaining the virtual instance specification input by the tenant and the identifier of the VPC, selecting a target server that can provide the virtual instance specification from the multiple servers, and creating a virtual instance set in a subnet of the VPC in the target server; The virtual instance is configured according to the identity authentication configuration information to connect to the identity authentication service node for identity authentication when it is started.

2. The method according to claim 1, characterized in that The virtual switch is set on the target server, and the virtual switch is used to instruct the identity authentication service node to authenticate the identity of the virtual instance according to the identity identifier of the virtual instance.

3. The method according to claim 1 or 2, characterized in that: The identity authentication service node is set in the VPC or in an external network of the infrastructure.

4. The method according to any one of claims 1 to 3, characterized in that After configuring the virtual instance according to the identity authentication configuration information to connect to the identity authentication service node for identity authentication when started, the method further includes: When the virtual instance is successfully authenticated, the cloud management platform is instructed to allow the virtual instance to access network resources in the VPC.

5. The method according to any one of claims 1 to 3, characterized in that: After configuring the virtual instance according to the identity authentication configuration information to connect to the identity authentication service node for identity authentication when started, the method further includes: When the virtual instance authentication fails, the cloud management platform is instructed to deny the virtual instance access to network resources in the VPC.

6. The method according to any one of claims 1 to 5, characterized in that Configuring the virtual instance to connect to the identity authentication service node for identity authentication when started according to the identity authentication configuration information includes: The virtual instance is configured according to the identity authentication configuration information to connect to the identity authentication service node when started, and perform identity authentication based on the 802.1x protocol.

7. The method according to any one of claims 1 to 6, characterized in that The virtual instance includes at least one of a virtual machine or a container.

8. A cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure for providing cloud services, the infrastructure includes multiple servers, and the cloud management platform includes: A virtual private cloud (VPC) creation request acquisition module, used to acquire a VPC creation request input by a tenant, and create a VPC of the tenant in the infrastructure, wherein the VPC includes at least one subnet; An identity authentication configuration information acquisition module, used to acquire identity authentication configuration information input by the tenant, wherein the identity authentication configuration information is used to instruct to perform identity authentication for a virtual instance to be set in the VPC in the future; A network address acquisition module, used to acquire the network address of the identity authentication service node input by the tenant; A specification and identification acquisition module, used to acquire the virtual instance specification input by the tenant and the identification of the VPC, select a target server that can provide the virtual instance specification from the multiple servers, and create a virtual instance set in the subnet of the VPC in the target server; The authentication module is used to configure the virtual instance to connect to the identity authentication service node for identity authentication when it is started according to the identity authentication configuration information.

9. A computing device cluster, characterized in that: It includes at least one computing device, each computing device includes a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device, the computing device performs the operation steps of the method according to any one of claims 1 to 7.

11. A computer program product comprising instructions, characterized in that When the instruction is executed by a computing device, the computing device performs the operation steps of the method according to any one of claims 1 to 7.