Login control method based on cloud technology, cloud management platform and cluster

By implementing a cloud-based login control method on the cloud management platform, the problem of single login control function in the existing technology is solved, and flexible and refined control of user login methods is achieved, meeting the personalized needs of different users and improving security.

CN120223347APending Publication Date: 2025-06-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410471670.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-25
Filing Date
2024-04-18
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing cloud management platform has a single login control solution function, making it difficult for administrators to flexibly configure users' login methods and cannot meet the personalized login needs of different users.

Method used

It provides a login control method based on cloud technology, obtains the login control policy configured by the administrator through the cloud management platform, and allows or denies users to log in to the cloud management platform based on their permission or prohibition. This method supports flexible configuration of multiple login methods and can be refined to control according to the specific needs of users.

Benefits of technology

It realizes flexible and refined control of the cloud management platform for users login in the organization, meets the personalized login needs of different users, and improves the administrator's management ability and security of login methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223347A_ABST
    Figure CN120223347A_ABST
Patent Text Reader

Abstract

The invention provides a login control method based on a cloud technology, a cloud management platform and a cluster. The method comprises the steps that a cloud management platform obtains a first login control strategy which is configured by an administrator of an organization and aims at a first user in the organization, the first login control strategy comprises first login indication information, and the first login indication information is used for indicating a login permission or prohibition mode of the first user; the cloud management platform obtains a first login request sent by a first user through the login interface, and the first login request is used for the first user to request to log in the cloud management platform; and the cloud management platform allows or rejects the first user to log in the cloud management platform through the first login request based on the first login indication information and a login mode adopted by the first login request. According to the method, the administrator of the organization can flexibly and finely control the login mode of the members in the organization.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application titled "A Login Control Method" with the application number 202311797687.1, filed with the China National Intellectual Property Administration on December 25, 2023. The entire content of this Chinese patent application is incorporated herein by reference. Technical Field

[0002] This application relates to the field of cloud computing technology, and in particular, to a login control method, a cloud management platform, and a cluster based on cloud technology. Background Art

[0003] With the development of cloud computing technology, enterprises and the like can utilize the cloud resources provided by the infrastructure through a cloud management platform. In this way, enterprises and the like can implement relevant services without building local infrastructure, thereby reducing their operating costs.

[0004] Members in an enterprise can act as users of cloud services and access cloud resources after logging in to the cloud management platform. Currently, the cloud management platform provides various login methods such as cloud account login, federated login, user-defined identity proxy login, IAM identity center login, and third-party account login through identity and access management (IAM) services. Administrators of enterprises, for security and other considerations, hope to restrict the login methods of users in the enterprise to log in to the cloud management platform.

[0005] In the current login control solution, the cloud account deletion function or single sign-on (SSO) shutdown function provided by the cloud management platform is used to restrict users from logging in to the cloud management platform through cloud accounts. This login control solution has a single function, and it is difficult for administrators to flexibly configure the login methods of users. Summary of the Invention

[0006] This application provides a login control method, a cloud management platform, and a cluster based on cloud technology, which can enable the administrator of an organization to flexibly and finely control the login methods of members in the organization.

[0007] In a first aspect, a login control method based on cloud technology is provided. This method is applied to a cloud management platform, which is used to manage cloud resources deployed in infrastructure. The infrastructure includes at least one cloud data center, and each cloud data center includes multiple servers. The cloud resources are deployed in at least one server in the infrastructure, and the cloud resources belong to an organization. The cloud management platform is used to provide a login interface for users in the organization to log in to the cloud management platform, and the cloud management platform is used to allow users who log in to the cloud management platform to access the cloud resources. The method includes: The cloud management platform obtains a first login control policy configured by the administrator of the organization for a first user in the organization. The first login control policy includes first login indication information, and the first login indication information is used to indicate the allowed or prohibited login method of the first user. The cloud management platform obtains, through the login interface, a first login request sent by the first user, and the first login request is used for the first user to request to log in to the cloud management platform. The cloud management platform allows or rejects the first user to log in to the cloud management platform through the first login request based on the first login indication information and the login method adopted by the first login request.

[0008] Exemplarily, the allowed or prohibited login methods of the first user include at least one of cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login. Exemplarily, the cloud resources include at least one of virtual machines, bare metal servers, containers, database instances, and data warehouse instances.

[0009] In this method, the administrator of the organization configures the allowed or prohibited login methods of the users in the organization. When a user logs in to the cloud management platform, the cloud management platform can allow or reject the user to log in to the cloud management platform by determining whether the login method used by the user to currently log in to the cloud management platform is consistent with the allowed or prohibited login method of the user. In this way, the administrator of the organization can achieve flexible and refined control over the login methods of users in the organization to log in to the cloud management platform by configuring the allowed or prohibited login methods of the users.

[0010] In a possible implementation manner, the method includes: The cloud management platform obtains a second login control policy configured by the administrator for a second user in the organization. The second login control policy includes second login indication information, and the second login indication information is used to indicate the allowed or prohibited login method of the second user. The allowed or prohibited login method of the second user is different from that of the first user. The cloud management platform obtains, through the login interface, a second login request sent by the second user, and the second login request is used for the second user to request to log in to the cloud management platform. The cloud management platform allows or rejects the second user to log in to the cloud management platform through the second login request based on the second login indication information and the login method adopted by the second login request.

[0011] In this method, the administrator of the organization can separately set the allowed or prohibited login methods for different users. That is to say, the allowed or prohibited login methods for each user can be independent of each other, and they can be the same or different. In this way, the administrator of the organization can more flexibly control the login methods of different users to the cloud management platform.

[0012] In a possible implementation, the first login control policy further includes preset login protection information for the first user; the method further includes: obtaining the current login protection information of the first user when the first login request is sent; the cloud management platform allows or rejects the first user to log in to the cloud management platform through the first login request based on the preset login protection information and the current login protection information. Wherein, the current login protection information includes at least one of the network environment information of the first login request, the user attribute information of the first user, the login setting information of the first user, and the login behavior information of the first user.

[0013] In this method, the administrator of the organization can also configure login protection information for the users in the organization. Through the login protection information, more refined control over the users' login to the cloud management platform can be achieved.

[0014] In a possible implementation, the first login control policy is configured at the root node of the organization or the leaf node corresponding to the first user.

[0015] When the login control policy is configured at the root node of the organization, the login control policy is effective for all users (including administrators) in the organization. That is, through this login control policy, the login of all users in the organization to the cloud management platform can be controlled.

[0016] When the login control policy is configured at the leaf node corresponding to the user, the login control policy is effective for the user. In this way, the administrator can configure a personalized login control policy for the user to achieve personalized control over the user's login to the cloud management platform.

[0017] Second aspect, a cloud management platform is provided. The cloud management platform is used to manage cloud resources deployed in the infrastructure. Among them, the infrastructure includes at least one cloud data center, and each cloud data center includes multiple servers. Among them, the cloud resources are deployed in at least one server in the infrastructure, and the cloud resources belong to the organization. The cloud management platform is used to provide a login interface for users in the organization to log in to the cloud management platform. The cloud management platform is used to allow users who log in to the cloud management platform to access the cloud resources. The cloud management platform includes: a first acquisition module, configured to acquire a first login control policy for a first user in the organization configured by the administrator of the organization. Among them, the first login control policy includes first login indication information, and the first login indication information is used to indicate the allowed or prohibited login method of the first user. A second acquisition module, configured to acquire, through the login interface, a first login request sent by the first user, where the first login request is used for the first user to request to log in to the cloud management platform. A control module, configured to allow or reject the first user to log in to the cloud management platform through the first login request based on the first login indication information and the login method adopted by the first login request.

[0018] In a possible implementation manner, the first acquisition module is further configured to: acquire a second login control policy for a second user in the organization configured by the administrator, where the second login control policy includes second login indication information, and the second login indication information is used to indicate the allowed or prohibited login method of the second user. Among them, the allowed or prohibited login method of the second user is different from that of the first user. The second acquisition module is further configured to: acquire, through the login interface, a second login request sent by the second user, where the second login request is used for the second user to request to log in to the cloud management platform. The control module is further configured to: allow or reject the second user to log in to the cloud management platform through the second login request based on the second login indication information and the login method adopted by the second login request.

[0019] In a possible implementation manner, the first login control policy further includes preset login protection information for the first user. The first acquisition module is further configured to: acquire the current login protection information of the first user when the first login request is sent. The control module is further configured to: allow or reject the first user to log in to the cloud management platform through the first login request based on the preset login protection information and the current login protection information.

[0020] In a possible implementation manner, the current login protection information includes at least one of the following: network environment information of the first login request, user attribute information of the first user, login setting information of the first user, and login behavior information of the first user.

[0021] In a possible implementation manner, the first login control policy is configured at the root node of the organization or the leaf node corresponding to the first user.

[0022] In a possible implementation, the permitted or prohibited login methods for the first user include at least one of cloud account login, federated login, user-defined identity proxy login, Identity and Access Management (IAM) identity center login, and third-party account login.

[0023] In a possible implementation, cloud resources include at least one of virtual machines, bare metal servers, containers, database instances, and data warehouse instances.

[0024] In a third aspect, a computing device cluster is provided, including at least one computing device, and each computing device includes a processor and a memory; the processor of at least one computing device is configured to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method provided in the first aspect.

[0025] In a fourth aspect, a computer-readable storage medium is provided, including computer program instructions, and when the computer program instructions are executed by the computing device cluster, the computing device cluster executes the method provided in the first aspect.

[0026] In a fifth aspect, a computer program product including instructions is provided, and when the instructions are run by a computer device cluster, the computer device cluster is caused to execute the method provided in the first aspect.

[0027] The beneficial effects of the second to fifth aspects can be referred to the introduction of the beneficial effects of the first aspect above, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 Shows a schematic diagram of a unified identity authentication service;

[0029] Figure 2 Shows a schematic structural diagram of a system architecture provided by an embodiment of the present application;

[0030] Figure 3 Shows a schematic structural diagram of a cloud management platform provided by an embodiment of the present application;

[0031] Figure 4 Shows a flowchart of a login control method provided by an embodiment of the present application;

[0032] Figure 5 Shows a schematic diagram of a login control policy provided by an embodiment of the present application;

[0033] Figure 6 Shows a schematic diagram of a login control policy provided by an embodiment of the present application;

[0034] Figure 7 Shows a schematic diagram of the binding between a login control policy and a user provided by an embodiment of the present application;

[0035] Figure 8 Shows a schematic diagram of a login control policy and user binding provided by an embodiment of the present application;

[0036] Figure 9 Is a schematic diagram of the structure of a cloud management platform provided by an embodiment of the present application;

[0037] Figure 10 Is a schematic diagram of the structure of a computing device provided by an embodiment of the present application;

[0038] Figure 11 Is a schematic diagram of the structure of a computing device cluster provided by an embodiment of the present application;

[0039] Figure 12 Is a schematic diagram of the structure of a computing device cluster connected through a network provided by an embodiment of the present application. Detailed implementation manners

[0040] The solutions provided by the embodiments of the present application will be described below with reference to the accompanying drawings. Among them, in the embodiments of the present application, "a plurality of" means two or more. "First", "second", etc. are only used to distinguish similar objects and do not have to be used to describe a specific order or the number of objects.

[0041] To facilitate understanding of the solutions provided by the embodiments of the present application, the technical terms that may be involved in the embodiments of the present application will be introduced first.

[0042] Cloud management platform: A platform provided by a cloud service provider for interacting with users. Users can register an account on the cloud management platform and rent cloud services with the account, thus becoming users of the cloud services. The cloud management platform is also used to manage the infrastructure and isolate the computing, network, and / or storage resources rented by different users according to the accounts of different users.

[0043] Cloud resources: Refer to the instances deployed in the infrastructure for running cloud services. The cloud instances are used to provide instances of computing, network, or storage resources. Cloud instances include, but are not limited to, virtual machines (VMs), elastic cloud servers (ECSs), containers, bare metal servers (BMSs), object storage service (OBS) buckets, elastic load balancers (ELBs), network address translation gateways, and cloud caches.

[0044] Infrastructure: Facilities that support cloud resources, including at least one data center. Each data center includes multiple servers, and cloud instances such as virtual machines, containers, and BMSs run on the servers to implement elastic cloud computing services, cloud network services, or cloud storage services. Exemplarily, in the case where the infrastructure includes multiple data centers, the multiple data centers can be distributed in different geographical regions and are remotely connected through a backbone network.

[0045] Organization (ORG): A hierarchical tree-structured entity created by the cloud management platform to uniformly manage multiple users. An organization has multiple members. Each of the multiple members is a user registered to the cloud management platform. Among them, multiple users within an organization usually belong to the same group, for example, the same enterprise.

[0046] Organization Unit (OU): A node in the organization's tree structure. Organization units are created by organization administrators and can be nested. Each organization unit is used to manage one or more users.

[0047] Root Organization Unit (ROU): Also known as the root OU, it is the root node in the organization's tree structure. Among them, other OUs in the organization besides the root OU are leaf nodes of the organization's tree structure, or leaf nodes of the root OU. Among them, leaf nodes can also be simply referred to as child nodes.

[0048] Member Account (Acct): The object managed by the organization. A member account represents a user. After the organization is created, the organization administrator invites existing accounts to join the organization, or creates new accounts through the organization, and the newly created accounts automatically join the organization.

[0049] Service Control Policy (SCP): A mandatory access control (MAC) policy in the organization's management service that acts on users within the organization. The service control policy describes a set of permissions. Among them, the service control policy is a constraint, not an authorization. The behavior of users to whom the service control policy is applied cannot exceed the set of permissions described by the service control policy.

[0050] Allowed Login Method: Refers to the login method that allows users to log in to the cloud management platform. That is, users are allowed to log in to the cloud management platform through the allowed login methods of the users.

[0051] Prohibited login method: It refers to the login method that prohibits users from logging in to the cloud management platform. That is, users are prohibited from logging in to the cloud management platform through the prohibited login method of the user.

[0052] Allowed or prohibited login method: It refers to the allowed login method or the prohibited login method.

[0053] Identity and Access Management (IAM): It is a web service that can help the cloud management platform control users' access to resources. Among them, it can control users' authentication and resource usage permissions. IAM has functions such as single sign-on, powerful authentication management, policy-based centralized authorization and auditing, dynamic authorization, and enterprise manageability.

[0054] The cloud management platform can provide a unified identity authentication service through IAM. The unified identity authentication service provides multiple ways to log in to the cloud management platform to meet the login needs of different users in different scenarios. For example, as Figure 1 shown, the unified identity authentication service can provide login methods such as cloud account login, federated login, custom identity proxy login, IAM identity center login, and third-party account login. Among them, cloud account login includes sub-login methods such as user password login, QR code login, mobile phone number login, email login, and application (APP) login. Federated login includes enterprise federated user login based on the Security Assertion Markup Language (SAML) protocol, enterprise federated user login based on the OIDC (OpenID-Connect) protocol, and enterprise federated user login based on the Open Authorization (OAuth) protocol. Custom identity proxy login includes sub-login methods such as logging in with a login token created by the entrusting party and logging in with a login token created in the token way. IAM identity center login includes sub-login methods such as single sign-on through integrating external identity providers by the IAM identity center. Third-party login includes sub-login methods such as single sign-on through integrating third-party systems.

[0055] Through the unified identity authentication service provided by the cloud management platform, the administrator of the organization can create or connect to an existing identity authentication system (such as the local identity authentication system of the corresponding enterprise of the organization), and centrally manage the ways for all users in the organization to log in to the cloud management platform.

[0056] For security reasons and to facilitate user logins, etc., the administrator of an organization hopes to be able to flexibly and finely control the login methods of users in the organization to log in to the cloud management platform. For example, control the login methods of users logging in to the cloud management platform according to the user's credit level, the user's common login methods, etc.

[0057] The embodiment of the present application provides a login control method based on cloud technology. In this method, the administrator of an organization can configure the allowed or prohibited login methods of users in the organization, and include the indication information of the allowed or prohibited login methods of the users into the login control policy of the users. The cloud management platform can use this login control policy to control the login of the users to the cloud management platform. Specifically, when the cloud management platform receives a login request sent by the user, it can allow or reject the user to log in to the cloud management platform through this login request based on the login method adopted by this login request and this login control policy.

[0058] Among them, when the indication information in the login control policy indicates the allowed login method of the user, then when the login method adopted by the login request is the same as the login method indicated by the indication information, allow the user to log in to the cloud management platform through this login request. Otherwise, reject the user to log in to the cloud management platform through this login request.

[0059] When the indication information in the login control policy indicates the prohibited login method of the user, then when the login method adopted by the login request is the same as the login method indicated by the indication information, reject the user to log in to the cloud management platform through this login request. Otherwise, allow the user to log in to the cloud management platform through this login request.

[0060] In this way, the administrator of the organization can flexibly control the login methods of users in the organization to log in to the cloud management platform, realizing flexible and fine control.

[0061] In addition, the administrator of the organization can separately set the allowed or prohibited login methods for different users. That is to say, the allowed or prohibited login methods of each user can be independent of each other, and they can be the same or different.

[0062] In this way, the administrator of the organization can more flexibly control the login methods of different users to log in to the cloud management platform, realizing flexible and fine control.

[0063] Next, a specific introduction to the login control method provided by the embodiment of the present application will be given.

[0064] Figure 2 Shows a system architecture that can implement this method. As Figure 2 shown, this system architecture includes a cloud management platform 100 and a cloud infrastructure 200.

[0065] Among them, the infrastructure 200 may include at least one cloud data center. Each cloud data center in the at least one cloud data center includes a plurality of servers. Cloud resources 210 are deployed in at least one of the servers in the infrastructure 200. Among them, different servers in the at least one server may belong to the same data center or different data centers. The cloud resources 210 belong to the organization 300, and the cloud resources 210 are managed by the cloud management platform 100. In some embodiments, the cloud resources 210 may be any one or a combination of virtual machines, bare metal servers, containers, database instances, data warehouse instances, etc.

[0066] The organization 300 includes a plurality of users, such as user 310 and user 320. At least one of the plurality of users may be an administrator of the organization 300 for managing the users in the organization, for example, configuring a login control policy for the users. Each user in the organization 200 may send a login request to the cloud management platform 100 to request to log in to the cloud management platform 200. The cloud management platform 100 includes a login interface 110. The login interface 110 may receive the login request sent by the user and, based on the user's login control policy, reject or allow the user to log in to the cloud management platform 100 through the login request. When the user logs in to the cloud management platform 100, the cloud management platform 100 may allow the user to access the cloud resources 210.

[0067] In some embodiments, as Figure 3 shown, the cloud management platform 100 includes a policy management module 120, a user management module 130, an authentication module 140, and an access module 150.

[0068] Among them, the policy management module 120 records the login control policy. The login control policy may include a basic policy and a custom policy. The basic policy is a policy for controlling the configuration of the login control policy by the administrator of the organization. For example, the basic policy includes that the administrator has the ability to configure the login control policy only when the administrator logs in to the cloud management platform in the form of federated login. The custom policy refers to the login control policy configured by the administrator of the organization for the users in the organization.

[0069] The administrator of the organization 300 may log in to the cloud management system 100 through the login interface 110. Then, the administrator may configure the login control policy. Among them, the allowed or prohibited login method may be configured, and login indication information for indicating the configured login method may be generated. The login indication information may be used as or included in the login control policy. The administrator may store the configured login control policy in the policy management module 120.

[0070] The user management module 130 is used to record information of users in the organization, such as the identity information of the users, the login control policies of the users, etc.

[0071] Among them, the administrator of the organization can bind the login control policy in the policy management module 120 to the users in the organization to obtain a binding relationship. Then, the user management module 130 can obtain this binding relationship and record the login control policy of the users by recording this binding relationship.

[0072] In some embodiments, binding the login control policy to the user may specifically be to only bind the login control policy to the user, that is, the login control policy is only applicable to this user. In some embodiments, binding the login control policy to the user may specifically be to only bind the login control policy to the user group to which the user belongs, that is, the login control policy is applicable to all users in this user group. Among them, the user group to which the user belongs can be the entire organization or a specific user group under the organization.

[0073] The authentication module 140 is used to authenticate the login request sent by the user to determine whether the login request matches the login control policy of the user to obtain an authentication result. As Figure 3 shown, when the login interface 110 receives the login request sent by the user, the login interface 110 sends an authentication request to the authentication module 140. Among them, the authentication request may include the login method adopted by the login request and the login control policy of the user. The authentication request module 140 can obtain the login indication information from the login control policy. Then, it is determined whether the login method adopted by the login request is consistent with the login method indicated by the login indication information. If they are consistent, an authentication result that the login request matches the login control policy is obtained. If they are inconsistent, an authentication result that the login request does not match the login control policy is obtained. Then, the authentication module 140 can send the authentication result to the login interface 110.

[0074] In some embodiments, when it is confirmed that the login request passes authentication, the request authentication module 140 authenticates the login request. Specifically, the login interface 110 records the user's identity information, and the login request also includes the identity information of the user who issues the login request. The login interface 110 can authenticate the login request based on the user's identity information recorded by itself and the identity information included in the login request, and obtain an authentication result. Among them, if the user's identity information recorded by the login interface 110 itself is consistent with the identity information included in the login request, it is confirmed that the login request passes authentication, and an authentication result indicating that the login request passes authentication is obtained. If the user's identity information recorded by the login interface 110 itself is inconsistent with the identity information included in the login request, it is confirmed that the login request does not pass authentication, and an authentication result indicating that the login request does not pass authentication is obtained. When an authentication result indicating that the login request passes authentication is obtained, the login interface 110 sends an authentication request to the authentication module 140.

[0075] Based on the authentication request received from the authentication module 140, the login interface 110 determines whether to allow the user to log in to the cloud management platform 100 through the login request. Specifically, it can be set that the login indication information in the login control policy indicates the allowed login method of the user. If the authentication result is that the login request does not match the login control policy, the login interface 110 rejects the user from logging in to the cloud management platform 100 through this login request. If the authentication result is that the login request matches the login control policy, the login interface 110 allows the user to log in to the cloud management platform 100 through this login request. It can be set that the login indication information in the login control policy indicates the prohibited login method of the user. If the authentication result is that the login request does not match the login control policy, the login interface 110 allows the user to log in to the cloud management platform 100 through this login request. If the authentication result is that the login request matches the login control policy, the login interface 110 rejects the user from logging in to the cloud management platform 100 through this login request.

[0076] If the login interface 110 allows the user to log in to the cloud management platform 100 through this login request, the user can log in to the cloud management platform 100. If the login interface 110 rejects the user from logging in to the cloud management platform 100 through this login request, the user cannot log in to the cloud management platform 100.

[0077] When the user logs in to the cloud management platform 100, the user sends an access request to the login interface 110 to request access to the cloud resource 210. The login interface 110 can send the access request to the access module 150, and the access module 150 can initiate an access to the cloud resource 210 based on the access request, thereby realizing the user's access to the cloud resource 210.

[0078] The above examples introduced the system architecture provided by the embodiments of the present application. Next, in combination with this system architecture, the login control method provided by the embodiments of the present application will be introduced.

[0079] This method can be executed by the cloud management platform 100 introduced above. As Figure 4 shown, this method includes the following steps.

[0080] Step 401, the cloud management platform 100 obtains the login control policy A1 configured by the administrator of the organization 300 for the user 310 in the organization 300. Among them, the login control policy A1 includes login indication information A11, and the login indication information A11 is used to indicate the allowed or prohibited login methods of the user 310.

[0081] In some embodiments, the administrator can configure the prohibited login method of the user 310. The login methods supported by the cloud management platform 100 other than the prohibited login method of the user 310 are the allowed login methods of the user 310. For example, the cloud management platform 100 supports login methods such as cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login. If the prohibited login method of the user 310 configured by the administrator is cloud account login, then login methods such as federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login are the allowed login methods of the user 310.

[0082] In some embodiments, as described above, login methods such as cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login each have sub-login methods. The prohibited login method of the user 310 that the administrator can configure can be one or more sub-login methods. In one example, as Figure 5 shown, the prohibited login methods of the user 310 are user password login and QR code login, and other sub-login methods are the allowed login methods of the user 310. Among them, Figure 5 "Effect: Deny" in the shown login indication information indicates that the configured login method is a prohibited login method, "UserPassword" indicates user password login, and "qrCode" indicates QR code login. In addition, Figure 5 The login based on the SAML protocol is specifically the enterprise federated user login based on the SAML protocol, and the login based on the OIDC protocol is specifically the enterprise federated user login based on the OIDC protocol.

[0083] In some embodiments, an administrator may configure the allowed login methods for user 310. Login methods supported by the cloud management platform 100 other than the allowed login methods for user 310 are prohibited login methods for user 310. In one example, the login control policy configured for user 310 is as follows.

[0084]

[0085] Among them, "Effect: allow" indicates that the configured login method is an allowed login method, "UserPassword" indicates user password login, and "qrCode" indicates QR code login. The allowed login methods for user 310 indicated by the login indication information included in the above login control policy are user password login and QR code, etc. Login methods other than user password login and QR code are prohibited login methods for user 310. In cloud account login, sub-login methods such as mobile phone number login, email login, and App login, as well as login methods such as federated login, custom identity proxy login, IAM identity center login, and third-party account login, are all prohibited login methods for user 310.

[0086] In some embodiments, the login control policy A1 further includes preset login protection information for user 310. The login protection information may be information that can be obtained by the cloud management platform 100 during the user's login to the cloud management platform 100 and is related to the user's login to the cloud platform 100. Exemplarily, the login protection information includes any one or a combination of network environment information, user attribute information, login setting information, and login behavior information.

[0087] Among them, the network environment information may include: virtual path connection endpoint (VPCE), source internet protocol (IP) address of the login request, device that issues the login request (i.e., the login device), client agent, request region, access region, access time (the time when the login device issues the login request or the reception time when the cloud management platform receives the login request), etc.

[0088] User attribute information may include: user name, user group to which the user belongs, the user's resource access permissions, the user's account type (e.g., the user is an administrator or an ordinary user of the organization), the name of the user's identity provider (IDP), the federated identity authentication protocol and version, the federated identity authentication interaction scenario, etc. Among them, the federated identity authentication protocols include the SSO protocol, the SAML protocol, etc. The federated identity authentication interaction scenario refers to the relevant scenarios of federated login, which can be divided into the scenario where the user identity is verified by the identity provider and the scenario where the user identity is verified by the service provider (SP).

[0089] User login setting information may include: session duration when accessing cloud resources, lock duration after user identity authentication fails, password setting conditions, password validity conditions, account deactivation conditions, login protection policies, verification policies for the electronic key (USB key) to log in to the cloud management platform, etc.

[0090] Login behavior information may include: number of login failures, geographical location of the login terminal when the login request is sent, the time when the user last logged in to the cloud management platform, the common login devices used by the user to log in to the cloud management platform, etc.

[0091] Any one or more of the above information can be used as login protection information. The administrator of the organization can select one or more types of information when configuring the login control policy, so as to achieve fine-grained control over the user's login to the cloud management platform.

[0092] The login control policy includes preset login protection information. When controlling the user's login to the cloud management platform based on the login control policy, if the login protection information when the user logs in to the cloud management platform is consistent with the preset login protection information, the user is allowed or refused to log in to the cloud management platform. Among them, the login protection information is divided into allowed login protection information and prohibited login protection information. When the login protection information is allowed login protection information, if the login protection information when logging in to the cloud management platform is consistent with the preset login protection information, the user is allowed to log in to the cloud management platform; if not, the user is refused to log in to the cloud management platform. When the login protection information is prohibited login protection information, if the login protection information when logging in to the cloud management platform is inconsistent with the preset login protection information, the user is allowed to log in to the cloud management platform; if consistent, the user is refused to log in to the cloud management platform.

[0093] In one example, the login control policy may include, for example Figure 6The login protection information shown. "Effect: allow" indicates that the login protection information is allowed login protection information. The login protection information in this login control policy is specifically VPCE B1. If the VPCE when the user logs in to the cloud management platform is VPCE B1, then login is allowed. If the VPCE when the user logs in to the cloud management platform is empty, or is not VPCE B1 (for example, it is VPCE B2), then login is rejected.

[0094] In one example, the login control policy may include the login protection information shown below.

[0095]

[0096]

[0097] The login control policy including the above login protection information allows users to log in by means of federated login using the OIDC protocol. And, when all the conditions of multi-factor authentication (MFA), the login device is a browser, the VPCE at the time of login is VPCE B1, the source IP address is in the 10.0.0.1 / 25 network segment, the identity provider name is "OIDC_IDP_TEST", and the number of login failures is less than 2 times are met, login is allowed. If any one of the conditions is not met, login will be rejected.

[0098] In some embodiments, the organization 300 has a Figure 7 tree-like structure as shown. Among them, the administrator corresponds to the root node, and the users 310 and 320 respectively correspond to different leaf nodes. The login control policy A1 can be configured to the leaf node corresponding to the user 310. In this way, the login control policy A1 can be bound to the user 310. When the user 310 requests to log in to the cloud management platform 100, the cloud management platform 100 can control the login request of the user 310 based on the login control policy A1.

[0099] In some embodiments, as Figure 8 shown, the login control policy A1 can be configured to the root node, that is, the node corresponding to the administrator. Configuring the login control policy A1 to the root node is equivalent to binding the login control policy A1 to all users (including the administrator) in the organization 300, and the login control policy A1 takes effect for all users in the organization 300. In this way, the cloud management platform 100 can use the login control policy A1 to control the login of the users corresponding to the leaf nodes in the organization, and can also control the login of the user corresponding to the root node of the organization (that is, the administrator). Thus, the permissions of the user corresponding to the root node can be restricted, and the security risk caused by the leakage of the account of the user corresponding to the root node can be reduced.

[0100] In one example, the login control policy A1 can be a mandatory access policy, such as SCP.

[0101] In one example, the login control policy A1 can be as follows.

[0102]

[0103]

[0104] When the above-mentioned login control policy A1 is configured to the root node in the organization 300, the login control policy A1 takes effect for all users in the organization 300. The login control policy A1 allows all users in the organization 300 to log in only in the way of federated login with the SAML protocol. The login control policy A1 enables login protection such as MFA.

[0105] The cloud management platform 100 can execute step 402. The cloud management platform 100 obtains the login request C1 sent by the user 310 through the login interface 110. The login request C1 is used for the user 310 to request to log in to the cloud management platform 100.

[0106] When the user 310 needs to access the cloud resource 210, the user 310 can send a login request C1 to the cloud management platform 100. Among them, the login request C1 can include the identity information of the user 310 and other information, such as the indication information of the login method, as well as the source IP address, the login security information of the login device, etc. Among them, the indication information of the login method indicates the login method adopted by the login request C1, that is, the indication information of the login method indicates in what way the user 310 sends the login request C1.

[0107] The login interface 110 can receive the login request C1 sent by the user 310. Exemplarily, the destination IP address of the login request C1 can be set to the address of the login interface 110. Through this destination IP address, the login interface 110 can receive the login request C1.

[0108] Step 403, the cloud management platform 100 allows or rejects the user to log in to the cloud management platform 100 through the login request C1 based on the login indication information A11 and the login method adopted by the login request C1.

[0109] When receiving the login request C1, the cloud management platform 100 can obtain the login indication information A11 from the login control policy (i.e., the login control policy A1) bound by the user 310. In some embodiments, the cloud management platform 100 can obtain the identity information of the user 310 from the login request C1. Then, based on the identity information of the user 310, the cloud management platform 100 identifies the login control policy A1 from the login control policies recorded in the cloud management platform 100.

[0110] The cloud management platform 100 can obtain the login method used in the login request C1. In some embodiments, as described above, the login request C1 includes indication information of the login method. The cloud management platform 100 can obtain the login method used in the login request C1 based on this indication information. In some embodiments, the message formats of login requests using different login methods are different, and the login method used in the login request C1 can be obtained based on the message format of the login request C1.

[0111] The cloud management platform 100 can determine whether the login method indicated by the login indication information A11 is consistent with the login method used in the login request C1 to obtain a determination result. Then, based on the determination result, the user 310 is allowed or denied to log in to the cloud management platform 100 through the login request C1.

[0112] In some embodiments, the login indication information A11 indicates the allowed login method of the user 310. If the determination result indicates that the login method indicated by the login indication information A11 is consistent with the login method used in the login request C1, the user 310 is allowed to log in to the cloud management platform 100 through the login request C1. Otherwise, the user 310 is denied to log in to the cloud management platform 100 through the login request C1.

[0113] In some embodiments, the login indication information A11 indicates the prohibited login method of the user 310. If the determination result indicates that the login method indicated by the login indication information A11 is consistent with the login method used in the login request C1, the user 310 is denied to log in to the cloud management platform 100 through the login request C1. Otherwise, the user 310 is allowed to log in to the cloud management platform 100 through the login request C1.

[0114] If the cloud management platform 100 allows the user 310 to log in to the cloud management platform 100 through this login request, the user can log in to the cloud management platform 100 in the case where the user 310 passes the identity verification. If the cloud management platform 100 rejects the user's login to the cloud management platform 100 through this login request, then even if the user 310 passes the identity verification, the user 310 cannot log in to the cloud management platform 100.

[0115] In some embodiments, before step 403, the cloud management platform 100 may first authenticate the login request C1. Specifically, the cloud management platform 100 records the identity information of each user in the organization 100. The login request C1 includes the identity information of the user 310. The cloud management platform 100 authenticates the login request C1 based on the identity information of the user 310 recorded by itself and the identity information of the user 310 in the login request C1, and obtains an authentication result. If the authentication result indicates that the login request C1 passes the authentication, step 403 is executed. If the authentication result indicates that the login request C1 fails to pass the authentication, there is no need to execute step 403 anymore, and the login request C1 can be directly rejected.

[0116] In some embodiments, as described above, the login control policy A2 includes preset login protection information. When the cloud management platform 100 receives the login request C1, it can also obtain the current login protection information when the user 310 issues the login request C1. Among them, the current login protection information corresponds to the preset login protection information, and may include at least one of the following: network environment information of the login request C1, user attribute information of the user 310, login setting information of the user 310, and login behavior information of the user 310. For specific reference, please refer to the above introduction and will not be elaborated here.

[0117] Then, the cloud management platform 100 allows or rejects the user 310 to log in to the cloud management platform 100 through the login request C1 based on the preset login protection information and the current login protection information. The cloud management platform 100 can determine whether the preset login protection information and the current login protection information are consistent, and obtain a determination result. Then, based on the determination result, the cloud management platform 100 allows or rejects the user 310 to log in to the cloud management platform 100 through the login request C1.

[0118] In some embodiments, the preset login protection information is permission login protection information. If the determination result indicates that the current login protection information is consistent with the preset login protection information, the user 310 is allowed to log in to the cloud management platform 100 through the login request C1. If they are inconsistent, the user 310 is rejected from logging in to the cloud management platform 100 through the login request C1.

[0119] In some embodiments, the login protection information is rejection login protection information. If the determination result indicates that the current login protection information is consistent with the preset login protection information, the user 310 is rejected from logging in to the cloud management platform 100 through the login request C1. If they are inconsistent, the user 310 is allowed to log in to the cloud management platform 100 through the login request C1.

[0120] In some embodiments, the login control policy A1 can be compatible with existing access control policies (e.g., discretionary access control (DAC) policies). Specifically, it can be configured in the cloud management platform 100 so that the login control policy A1 takes effect without an explicit declaration of allow. Additionally, when there is an explicit declaration of deny for the login control policy A1, the login control policy A1 is deactivated. Moreover, the login control policy A1 can be configured to be controlled by mandatory access policies such as the SCP of user 310 (e.g., SCP). In this way, it is avoided that when the login control policy A1 is configured for user 310, if there is no explicit declaration of allow for the login control policy A1, all login methods of user 310 are prohibited.

[0121] Among them, when the login control policy A1 and the existing access control policy take effect simultaneously, the cloud management platform 100 can identify the control result under the login control policy A1 and the control result under the access control policy. Then, take the intersection of the two control results to obtain the combined control result, and finally execute the combined control result. Thus, the compatibility between the login control policy A1 and the existing access control policy is achieved.

[0122] In one example, the combination of control results can be achieved by calling the "check-permission API" function. For example, if the data "local_dac_allow = true" is passed into the "check-permission API", it can be known that the control result of the DAC policy is allow. If the control result of the login control policy A1 is also allow. Then the cloud management platform 100 allows user 310 to log in.

[0123] Administrators in the organization 300 can configure login control policies for different users in the organization. Among them, the login control policies configured for different users are independent of each other, and they can be the same or different. When each user requests to log in to the cloud management platform 100, the cloud management platform 100 can control the login of the user based on the user's login control policy.

[0124] For example, an administrator in the organization 300 can also configure a login control policy A2 for the user 320. The login control policy A2 includes login indication information A21. The login indication information A21 is used to indicate the allowed or prohibited login method of the user 320; among them, the allowed or prohibited login method of the user 320 can be different from the allowed or prohibited login method of the user 310. The cloud management platform 100 can obtain a login request C2 sent by the user 320 through the login interface 110, and the login request C2 is used for the user 320 to request to log in to the cloud management platform 100. The cloud management platform 100 can allow or reject the user 320 to log in to the cloud management platform 100 through the login request C2 based on the login indication information A21 and the login method adopted by the login request C2. Specifically, reference can be made to the Figure 4 implementation manner shown above, which will not be elaborated here.

[0125] In summary, in the method provided in the embodiments of the present application, the administrator of the organization can configure a login control policy for the users in the organization. When the user requests to log in to the cloud management platform, the cloud management platform controls the user's login based on the login control policy configured by the administrator. Thus, the administrator of the organization can flexibly and finely control the login method of the users in the organization to log in to the cloud management platform through the login control policy.

[0126] Refer to Figure 9 , the embodiments of the present application also provide a cloud management platform 900. The cloud management platform 900 is used to manage cloud resources deployed in the infrastructure; among them, the infrastructure includes at least one cloud data center, and each cloud data center includes multiple servers; among them, the cloud resources are deployed in at least one server in the infrastructure, and the cloud resources belong to the organization. The cloud management platform 900 is used to provide a login interface for the users in the organization to log in to the cloud management platform, and the cloud management platform 900 is used to allow the users who log in to the cloud management platform 900 to access the cloud resources. As Figure 9 shown, the cloud management platform 900 includes:

[0127] A first acquisition module 910, configured to acquire a first login control policy for a first user in the organization configured by the administrator of the organization, where the first login control policy includes first login indication information, and the first login indication information is used to indicate the allowed or prohibited login method of the first user;

[0128] A second acquisition module 920, configured to acquire a first login request sent by the first user through the login interface, where the first login request is used for the first user to request to log in to the cloud management platform;

[0129] A control module 930, configured to allow or reject the first user to log in to the cloud management platform 900 through the first login request based on the first login indication information and the login method adopted by the first login request.

[0130] In some embodiments, the first obtaining module 910 is further configured to: obtain a second login control policy configured by the administrator for a second user in the organization, where the second login control policy includes second login indication information for indicating an allowed or prohibited login method for the second user; wherein the allowed or prohibited login method for the second user is different from the allowed or prohibited login method for the first user;

[0131] The second obtaining module 920 is further configured to: obtain, through the login interface, a second login request sent by the second user, where the second login request is for the second user to request to log in to the cloud management platform;

[0132] The control module 920 is further configured to: allow or reject the second user to log in to the cloud management platform through the second login request based on the second login indication information and the login method adopted by the second login request.

[0133] In some embodiments, the first login control policy further includes preset login protection information for the first user; the first obtaining module 910 is further configured to: obtain the current login protection information of the first user when the first login request is sent; the control module 920 is further configured to: allow or reject the first user to log in to the cloud management platform through the first login request based on the preset login protection information and the current login protection information.

[0134] In an example of this embodiment, the current login protection information includes at least one of: network environment information of the first login request, user attribute information of the first user, login setting information of the first user, and login behavior information of the first user.

[0135] In some embodiments, the first login control policy is configured at the root node of the organization or the leaf node corresponding to the first user.

[0136] In some embodiments, the allowed or prohibited login method for the first user includes at least one of: cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login.

[0137] In some embodiments, the cloud resources include at least one of virtual machines, bare metal servers, containers, database instances, and data warehouse instances.

[0138] Among them, the first acquisition module 910, the second acquisition module 920, and the control module 930 can all be implemented by software or by hardware. Exemplarily, next, taking the first acquisition module 910 as an example, the implementation manner of the first acquisition module 910 will be introduced. Similarly, the implementation manners of the second acquisition module 920 and the control module 930 can refer to the implementation manner of the first acquisition module 910.

[0139] As an example of a software functional unit, the first acquisition module 910 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the first acquisition module 910 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone AZ or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.

[0140] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same VPC or in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0141] As an example of a hardware functional unit, the first acquisition module 910 may include at least one computing device, such as a server, etc. Alternatively, the first acquisition module 910 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0142] The multiple computing devices included in the first acquisition module 910 may be distributed in the same region or in different regions. The multiple computing devices included in the first acquisition module 910 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the first acquisition module 910 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), and generic array logic (GALs).

[0143] It should be noted that in other embodiments, the first acquisition module 910 may be used to execute Figure 4 any step in the method shown, the second acquisition module 920 may be used to execute Figure 4 any step in the method shown, and the control module 930 may be used to execute Figure 4 any step in the method shown. The steps to be implemented by the first acquisition module 910, the second acquisition module 920, and the control module 930 can be specified as needed, and all functions of the cloud management platform 900 are implemented by separately implementing Figure 4 different steps in the method shown.

[0144] This application also provides a computing device 1000. As Figure 10 shown, the computing device 1000 includes: a bus 1002, a processor 1004, a memory 1006, and a communication interface 1008. The processor 1004, the memory 1006, and the communication interface 1008 communicate with each other through the bus 1002. The computing device 1000 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1000.

[0145] The bus 1002 may be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 10 only one line is shown in, but it does not mean that there is only one bus or one type of bus. The bus 1002 may include a path for transmitting information between various components (such as the memory 1006, the processor 1004, and the communication interface 1008) of the computing device 1000.

[0146] The processor 1004 may include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0147] The memory 1006 may include a volatile memory, such as a random access memory (RAM). The memory 1006 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0148] The memory 1006 stores executable program codes, and the processor 1004 executes the executable program codes to implement the functions of the foregoing first acquisition module 910, second acquisition module 920, and control module 930 respectively, so as to implement Figure 4 the method shown. That is, the memory 1006 stores instructions for executing Figure 4 the method shown.

[0149] The communication interface 1008 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1000 and other devices or communication networks.

[0150] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0151] As Figure 11 shown, the computing device cluster includes at least one computing device 1000. Instructions for executing Figure 4 the method shown may be stored in the memory 1006 of one or more computing devices 1000 in the computing device cluster.

[0152] In some possible implementation manners, instructions for executing Figure 4Portions of the instructions of the method shown. In other words, a combination of one or more computing devices 1000 can jointly execute for performing Figure 4 the instructions of the method shown.

[0153] It should be noted that the memories 1006 in different computing devices 1000 in the computing device cluster can store different instructions, respectively for performing partial functions of the cloud management platform 900. That is to say, the instructions stored in the memories 1006 of different computing devices 1000 can implement the functions of one or more of the first acquisition module 910, the second acquisition module 920, and the control module 930.

[0154] In some possible implementation manners, one or more computing devices in the computing device cluster can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 12 Shows a possible implementation manner. As Figure 12 shown, two computing devices 1000A and 1000B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation manner, the memory 1006 in the computing device 1000A stores instructions for performing the function of the first acquisition module 910. At the same time, the memory 1006 in the computing device 1000B stores instructions for performing the functions of the second acquisition module 920 and the control module 930.

[0155] It should be understood that Figure 12 the functions of the computing device 1000A shown in

[0156] can also be completed by multiple computing devices 1000. Similarly, the functions of the computing device 1000B can also be completed by multiple computing devices 1000. Figure 11 and Figure 12 the connection manner of the computing device cluster. The difference is that the memories 1006 in one or more computing devices 1000 in this computing device cluster can store the same instructions for performing Figure 4 the method shown.

[0157] In some possible implementation manners, the memories 1006 of one or more computing devices 1000 in this computing device cluster can also respectively store instructions for performing Figure 4 portions of the method shown. In other words, a combination of one or more computing devices 1000 can jointly execute for performing Figure 4 the instructions of the method shown.

[0158] The embodiments of the present application also provide a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute Figure 4 the method shown

[0159] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computing device or a host migration device such as a data center containing one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute Figure 4 the method shown

[0160] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or equivalently replace some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present application.

Claims

1. A login control method based on cloud technology, characterized in that: The method is applied to a cloud management platform, the cloud management platform is used to manage cloud resources deployed in an infrastructure; wherein the infrastructure includes at least one cloud data center, each cloud data center includes multiple servers; wherein the cloud resources are deployed in at least one server in the infrastructure, the cloud resources belong to an organization, the cloud management platform is used to provide a login interface for users in the organization to log in to the cloud management platform, and the cloud management platform is used to allow the users logged in to the cloud management platform to access the cloud resources; the method comprises: The cloud management platform obtains a first login control policy configured by an administrator of the organization for a first user in the organization, wherein the first login control policy includes first login indication information, and the first login indication information is used to indicate a permitted or prohibited login mode for the first user; The cloud management platform obtains, through the login interface, a first login request sent by the first user, where the first login request is used by the first user to request to log in to the cloud management platform; The cloud management platform allows or denies the first user to log in to the cloud management platform through the first login request based on the first login indication information and the login method adopted by the first login request.

2. The method according to claim 1, characterized in that The method comprises: The cloud management platform obtains a second login control policy configured by the administrator for a second user in the organization, wherein the second login control policy includes second login indication information, and the second login indication information is used to indicate a method of allowing or prohibiting login for the second user; wherein the method of allowing or prohibiting login for the second user is different from the method of allowing or prohibiting login for the first user; The cloud management platform obtains, through the login interface, a second login request sent by the second user, where the second login request is used by the second user to request to log in to the cloud management platform; The cloud management platform allows or denies the second user to log in to the cloud management platform through the second login request based on the second login indication information and the login method adopted by the second login request.

3. The method according to claim 1 or 2, characterized in that: The first login control policy also includes preset login protection information for the first user; The method further comprises: Acquire current login protection information of the first user when issuing the first login request; The cloud management platform allows or denies the first user to log in to the cloud management platform through the first login request based on the preset login protection information and the current login protection information.

4. The method according to claim 3, characterized in that The current login protection information includes: At least one of network environment information of the first login request, user attribute information of the first user, login setting information of the first user, and login behavior information of the first user.

5. The method according to any one of claims 1 to 4, characterized in that The first login control policy is configured at the root node of the organization or the leaf node corresponding to the first user.

6. The method according to any one of claims 1 to 5, characterized in that The allowed or prohibited login methods of the first user include: at least one of: cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login.

7. The method according to any one of claims 1 to 6, characterized in that The cloud resources include at least one of a virtual machine, a bare metal server, a container, a database instance, and a data warehouse instance.

8. A cloud management platform, characterized in that: The cloud management platform is used to manage cloud resources deployed in an infrastructure; wherein the infrastructure includes at least one cloud data center, each cloud data center includes a plurality of servers; wherein the cloud resources are deployed in at least one server in the infrastructure, the cloud resources belong to an organization, the cloud management platform is used to provide a login interface for users in the organization to log in to the cloud management platform, and the cloud management platform is used to allow the users who log in to the cloud management platform to access the cloud resources; the cloud management platform includes: A first acquisition module, configured to acquire a first login control policy for a first user in the organization configured by an administrator of the organization, wherein the first login control policy includes first login indication information, and the first login indication information is used to indicate a permitted or prohibited login mode for the first user; A second acquisition module, configured to acquire, through the login interface, a first login request issued by the first user, where the first login request is used by the first user to request to log in to the cloud management platform; A control module is used to allow or deny the first user to log in to the cloud management platform through the first login request based on the first login indication information and the login method adopted by the first login request.

9. The cloud management platform according to claim 8, characterized in that: The first acquisition module is further used to: acquire a second login control policy configured by the administrator for a second user in the organization, wherein the second login control policy includes second login indication information, and the second login indication information is used to indicate a method of allowing or prohibiting login for the second user; wherein the method of allowing or prohibiting login for the second user is different from the method of allowing or prohibiting login for the first user; The second acquisition module is further used to: acquire, through the login interface, a second login request issued by the second user, where the second login request is used by the second user to request to log in to the cloud management platform; The control module is also used to: based on the second login indication information and the login method adopted by the second login request, allow or deny the second user to log in to the cloud management platform through the second login request.

10. The cloud management platform according to claim 8 or 9, characterized in that: The first login control policy also includes preset login protection information for the first user; The first acquisition module is further used to: acquire the current login protection information of the first user when issuing the first login request; The control module is also used to: based on the preset login protection information and the current login protection information, allow or deny the first user to log in to the cloud management platform through the first login request.

11. The cloud management platform according to claim 10, characterized in that: The current login protection information includes: At least one of network environment information of the first login request, user attribute information of the first user, login setting information of the first user, and login behavior information of the first user.

12. The cloud management platform according to any one of claims 8 to 11, characterized in that: The first login control policy is configured at the root node of the organization or the leaf node corresponding to the first user.

13. The cloud management platform according to any one of claims 8 to 12, characterized in that: The allowed or prohibited login methods of the first user include: at least one of: cloud account login, federated login, user-defined identity proxy login, identity management and access control IAM identity center login, and third-party account login.

14. The cloud management platform according to any one of claims 8 to 13, characterized in that: The cloud resources include at least one of a virtual machine, a bare metal server, a container, a database instance, and a data warehouse instance.

15. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 7.

16. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method as claimed in any one of claims 1 to 7.

17. A computer program product comprising instructions, characterized in that When the instructions are executed by a computer device cluster, the computer device cluster executes the method according to any one of claims 1 to 7.