Multi-cloud platform access method and device, electronic equipment, storage medium and program product

Through the management platform, the unified processing of user identity information and the use of a unified account to log in to various cloud platforms is solved, and the complexity of login and management caused by the dispersion of cloud platforms in different business services is achieved, and centralized control and operation simplification of multiple cloud platforms is achieved.

CN120223367APending Publication Date: 2025-06-27BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510281907.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the group business, cloud platforms of different businesses are scattered on multiple cloud platforms, making it difficult to achieve global control and statistics on login and background management.

Method used

A multi-cloud platform access method is proposed, which uniformly processes user identity information through the management platform, uses a pre-registered unified account to log in on each cloud platform, and determines the cloud platform and controllable objects that users can access. The method includes steps such as login request analysis, multi-cloud platform login, controllable information determination, operation command conversion and control execution.

Benefits of technology

It enables users to access and manage multiple cloud platforms without using multiple sets of login information, reduces the complexity of login and facilitates unified control of each cloud platform through the management platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223367A_ABST
    Figure CN120223367A_ABST
Patent Text Reader

Abstract

The invention provides a multi-cloud platform access method and device, electronic equipment, a storage medium and a program product, and relates to the technical field of cloud platforms, hybrid clouds, unified management and control and the like. The method comprises the following steps: extracting target identity information from a received login request initiated by a target user; in response to the fact that the target identity information is a legal identity, logging in each cloud platform through a unified account respectively used by each cloud platform through the registration request in advance; determining an accessible cloud platform corresponding to the target identity information and a controllable object under the accessible cloud platform in each successfully logged-in cloud platform; converting an operation instruction initiated by the target user for the target controllable object into an actual operation instruction for an actual object under the cloud platform; and controlling the cloud platform to execute the actual operation instruction on the actual object. By applying the method, the user does not need to use multiple sets of login information to respectively log in different cloud platforms, so that the login complexity is reduced, excessive login accounts do not need to be exposed to the user, and the management and control of each cloud platform can be conveniently and uniformly realized through the management platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, specifically to technical fields such as cloud platforms, hybrid clouds, and unified management and control. In particular, it relates to a method, device, electronic device, computer-readable storage medium, and computer program product for accessing multi-cloud platforms. Background Art

[0002] In the business content of a group, different services are often scattered on different cloud platforms. When developing and operating and maintaining, R & D personnel often need to use different cloud platforms, and different cloud platforms require different login accounts, making it difficult to achieve global management and statistics for both login behavior and background control behavior. Summary of the Invention

[0003] Embodiments of the present disclosure propose a method, device, electronic device, computer-readable storage medium, and computer program product for accessing multi-cloud platforms.

[0004] In a first aspect, embodiments of the present disclosure propose a method for accessing multi-cloud platforms, including: extracting target identity information from a login request received from a target user; in response to the target identity information being legal identity, logging in to each cloud platform respectively through a unified account that each cloud platform has previously used through a registration request; determining, among the successfully logged-in cloud platforms, the accessible cloud platforms corresponding to the target identity information and the controllable objects under the accessible cloud platforms; converting an operation instruction initiated by the target user for a target controllable object into an actual operation instruction for an actual object under the affiliated cloud platform; controlling the affiliated cloud platform to execute the actual operation instruction on the actual object.

[0005] In a second aspect, embodiments of the present disclosure propose a device for accessing multi-cloud platforms, including: a login request parsing unit configured to extract target identity information from a login request received from a target user; a multi-cloud platform login unit configured to, in response to the target identity information being legal identity, log in to each cloud platform respectively through a unified account that each cloud platform has previously used through a registration request; a controllable information determination unit configured to determine, among the successfully logged-in cloud platforms, the accessible cloud platforms corresponding to the target identity information and the controllable objects under the accessible cloud platforms; an operation instruction conversion unit configured to convert an operation instruction initiated by the target user for a target controllable object into an actual operation instruction for an actual object under the affiliated cloud platform; a control execution unit configured to control the affiliated cloud platform to execute the actual operation instruction on the actual object.

[0006] In a third aspect, an embodiment of the present disclosure provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to implement the multi-cloud platform access method described in the first aspect.

[0007] In a fourth aspect, an embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions, which are used to enable a computer to implement the multi-cloud platform access method described in the first aspect when executed.

[0008] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program, and when the computer program is executed by a processor, each step of the multi-cloud platform access method described in the first aspect can be implemented.

[0009] The multi-cloud platform access solution provided by the present disclosure, by adding a management platform for docking different cloud platforms, and pre-configuring corresponding unified accounts for different cloud platforms and registering them on the management platform, enables the management platform to log in to and access each cloud platform using each unified account. Furthermore, when a user successfully logs in to the management platform, the management platform can determine the accessible cloud platforms corresponding to the logged-in user and the controllable objects under the accessible cloud platforms, so that the user does not need to use multiple sets of login information to log in to different cloud platforms respectively, reducing the login complexity and not exposing too many login accounts to the user, and at the same time facilitating the unified control of each cloud platform through the management platform.

[0010] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objectives, and advantages of the present disclosure will become more apparent:

[0012] Figure 1 is an exemplary system architecture to which the present disclosure can be applied;

[0013] Figure 2 is a flowchart of a multi-cloud platform access method provided by an embodiment of the present disclosure;

[0014] Figure 3 is a flowchart of a method for constructing and using a login information table provided by an embodiment of the present disclosure;

[0015] Figure 4 A flowchart of a method for creating and using a control interface provided by an embodiment of the present disclosure;

[0016] Figure 5 A flowchart of a method for statistics and risk assessment provided by an embodiment of the present disclosure;

[0017] Figures 6-1 to 6-3 A schematic diagram of a multi-cloud platform access method in an application scenario provided by an embodiment of the present disclosure;

[0018] Figure 7 A structural block diagram of a multi-cloud platform access device provided by an embodiment of the present disclosure;

[0019] Figure 8 A structural schematic diagram of an electronic device suitable for executing the multi-cloud platform access method provided by an embodiment of the present disclosure. Detailed implementation manners

[0020] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted below. It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0021] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, and disclosure of user personal information complies with the provisions of relevant laws and regulations and does not violate public order and good customs.

[0022] Figure 1 An exemplary system architecture 100 is shown in which embodiments of the multi-cloud platform access method, device, electronic device, and computer-readable storage medium of the present disclosure can be applied.

[0023] As Figure 1 shown, the system architecture 100 may include terminal devices 101, 102, 103, a management platform 104, and cloud platforms 105, 106, 107. The network is used to provide a communication link between the terminal devices 101, 102, 103, the management platform 104, and the cloud platforms 105, 106, 107, and may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0024] Users can use terminal devices 101, 102, and 103 to interact with the management platform 104 via the network. The management platform 104 can, in turn, respond to requests sent by the terminal devices 101, 102, and 103 and interact with cloud platforms 105, 106, and 107 via the network to receive or send messages, etc. Various applications for implementing information communication between them can be installed on the terminal devices 101, 102, 103, the management platform 104, and the cloud platforms 105, 106, and 107, such as cloud platform management applications, multi-cloud platform comprehensive access applications, instant messaging applications, etc.

[0025] The terminal devices 101, 102, 103, the management platform 104, and the cloud platforms 105, 106, and 107 can be either hardware or software. When the terminal devices 101, 102, 103 are hardware, they can be various electronic devices with a display screen, including but not limited to smartphones, tablets, laptop portable computers, and desktop computers, etc.; when the terminal devices 101, 102, 103 are software, they can be installed in the above-listed electronic devices, and can be implemented as multiple software or software modules, or can be implemented as a single software or software module, and no specific limitation is made here. When the management platform 104 and the cloud platforms 105, 106, and 107 are hardware, they can be implemented as a distributed server cluster composed of multiple servers, or can be implemented as a single server; when the management platform 104 and the cloud platforms 105, 106, and 107 are software, they can be implemented as multiple software or software modules, or can be implemented as a single software or software module, and no specific limitation is made here.

[0026] The management platform 104 can provide various services through various built-in applications. Taking the multi-cloud platform comprehensive access application that can provide users with comprehensive access services to multi-cloud platforms with access permissions as an example, when the management platform 104 runs this multi-cloud platform comprehensive access application, the following effects can be achieved: First, receive a login request initiated by the target user through the terminal devices 101, 102, and 103 via the network, and extract the target identity information from this login request; then, when determining that the target identity information is legal, log in to the cloud platforms 105, 106, and 107 respectively through the unified accounts previously used by the cloud platforms 105, 106, and 107 through registration requests; then, determine the accessible cloud platforms and the controllable objects under the accessible cloud platforms corresponding to the target identity information in the successfully logged-in cloud platforms 105, 106, and 107; next, convert the operation instructions initiated by the target user for the target controllable objects into actual operation instructions for the actual objects under the affiliated cloud platform; finally, control the affiliated cloud platform to execute this actual operation instruction on the actual objects.

[0027] The multi-cloud platform access methods provided in subsequent embodiments of the present disclosure are generally executed by a management platform 104 with relatively strong computing capabilities and more computing resources between the terminal device and the cloud platform. Correspondingly, the multi-cloud platform access device is generally also disposed in the management platform 104.

[0028] It should be understood that Figure 1 the numbers of the terminal devices, the management platform, and the cloud platform in

[0029] Please refer to Figure 2 , Figure 2 which is a flowchart of a multi-cloud platform access method provided in an embodiment of the present disclosure. The process 200 includes the following steps:

[0030] Step 201: Extract target identity information from the login request received from the target user;

[0031] The purpose of this step is for the execution entity of the multi-cloud platform access method (such as Figure 1 the management platform 104 shown) to extract the information that can uniquely identify the user's identity (such as username, mobile phone number, email, ID number, employee number, etc.) from the login data submitted by the user when the user attempts to log in to the management platform, for subsequent verification, permission allocation, or recording.

[0032] Specifically, the target user can send a login request to the management platform by filling in a login form through a client (such as a web page, App) or using third-party authentication. The management platform parses out the key identity identifier from the login data submitted by the target user. For example: 1) Plaintext transmission: Extract the username (such as username=john) or mobile phone number (such as phone=13800138000) from the form fields; 2) Encrypted transmission: If the data is encrypted (such as HTTPS, Hypertext Transfer Protocol Secure), it needs to be decrypted first and then extracted; 3) Token parsing: If JWT (JSON Web Token, a token for securely transmitting information in JSON format) or OAuth token (a credential for verifying the user's identity and access rights in the OAuth authorization process) is used, the user identity field (such as the sub field) in the token needs to be decoded; and the extracted target identity information can verify the identity and legitimacy of the target user through database comparison, log recording, or multi-factor authentication, etc.

[0033] In a special case, multiple fields may be used in a login request to record multiple different identity information. For example, different levels of identity information corresponding to the target user can be extracted from different fields in the login request, and then the obtained identity information of different levels are spliced ​​according to the preset hierarchical order, and the spliced ​​complete identity information is used as the target identity information.

[0034] For example, when extracting the primary identity information and the secondary identity information, the secondary identity information can be spliced ​​at the end of the primary identity information in the preset order from high to low, and then the complete identity information is obtained. The primary level is higher than the secondary level, and the complete identity information is finally used as the target identity information. That is, through layered and graded design, the same user can show different identities and thus have different access rights.

[0035] Step 202: In response to the target identity information being a legitimate identity, log in to each cloud platform through a unified account that is used in advance by each cloud platform through registration requests;

[0036] Based on step 201, this step aims to automatically log in to these cloud platforms on behalf of the user after the above-mentioned execution subject has verified the legality of the target user's identity, using a unified account pre-registered for different cloud platforms (which can also be understood as a special account created by the management platform in each major cloud platform, and the special account is actively provided to the management platform by the cloud platform). The goal of this step is to enable users to centrally operate multiple cloud resources through a management platform without having to manually log in to each cloud platform.

[0037] Specifically, this step is actually divided into the following steps:

[0038] 1) Manage the platform to pre-register a cloud platform account

[0039] As an "intermediary", the management platform pre-accepts registration requests from various cloud platforms that the target user may use, and records the "unified account" carried in the registration request as the login account for logging into the corresponding cloud platform. It should be noted that the registration process described in this step needs to be completed in advance. Once the registration is completed, it does not need to be performed again during the subsequent login process.

[0040] 2) User login management platform

[0041] The user initiates a login request to the management platform (for example, entering a username and password or scanning a QR code for authentication), and the management platform verifies the legitimacy of the user's identity (such as verifying the password, multi-factor authentication).

[0042] 3) Call the pre-registered cloud platform unified account

[0043] After the user passes the authentication, the management platform automatically calls the unified account of the associated cloud platform according to the user's permissions (such as reading the API key stored in encrypted form, Application Programming Interface), and through the API or SSO (Single Sign On) protocol of each cloud platform, simulates the user's login behavior to establish a session or obtain a temporary access token.

[0044] Step 203: Determine the accessible cloud platforms corresponding to the target identity information and the manageable objects under the accessible cloud platforms among the successfully logged-in cloud platforms;

[0045] Based on Step 202, this step aims to, after the above-mentioned execution entity logs in to multiple cloud platforms through the pre-registered unified account, filter out the cloud platforms that the user has the right to access (such as Cloud Platform X1 and Cloud Platform X2) according to the identity permissions of the target user, and further determine the specific resources that can be operated in these cloud platforms (such as virtual machines, storage buckets). The goal of this step is to achieve fine-grained permission control to ensure that the user can only access and manage the authorized cloud resources.

[0046] Specifically, this step is actually subdivided into the following steps:

[0047] 1) Map user identity and cloud platform permissions

[0048] The management platform maintains the association relationship between user identities (such as user ID, role) and cloud platform permissions. For example: User A can access Cloud Platform X1 and Cloud Platform X2, but can only view the ECS (Elastic Compute Service) instances of Cloud Platform X1 and manage the S3 storage buckets (an object storage service) of Cloud Platform X2, and User B can only access Cloud Platform X1 and can only operate cloud databases and cloud functions.

[0049] 2) Filter out accessible cloud platforms

[0050] According to the permission configuration of the target user, filter out the allowed platforms from the list of logged-in cloud platforms. For example, if it is found through Step 1) that User A can only access Cloud Platform X1 and Cloud Platform X2, the management platform only retains the sessions of these two cloud platforms.

[0051] 3) Call the cloud platform API to list resources

[0052] For each accessible cloud platform, call its API to obtain a list of resources (such as virtual machines, buckets, databases). For example, query all instances through the ECS API of cloud platform X1: DescribeInstances, and list buckets through the S3 API of cloud platform X2: ListBuckets.

[0053] 4) Filter manageable objects according to user permissions

[0054] Filter the resource list in combination with user permission policies (such as read-only, read-write, specific resource tags). Dynamic permission verification: Call the IAM service interface of the cloud platform (such as GetEffectivePermissions) to verify the user's operation permissions on resources in real time.

[0055] 5) Return the authorized resource list

[0056] Show the user the cloud platforms and corresponding resources that they can manage, and hide or intercept unauthorized operations.

[0057] Step 204: Convert the operation instruction initiated by the target user for the target manageable object into an actual operation instruction for the actual object under the affiliated cloud platform;

[0058] Based on step 203, this step aims to convert the user's abstract operation request into a specific API call or console operation of the corresponding cloud platform and ensure that the operation permissions and parameters are adapted when the above-mentioned execution entity initiates a specific operation on a certain cloud resource (such as starting a virtual machine, deleting a bucket) on the interface provided by the user on the management platform. This process needs to solve problems such as cross-cloud platform API differences, permission mapping, and operation atomicity.

[0059] Specifically, this step is actually divided into the following steps:

[0060] 1) Receive the user operation instruction

[0061] Input form: The user can send operation instructions (such as "restart instance", "create bucket") through the Web (web page) interface, CLI (Command-Line Interface) tool or API of the management platform.

[0062] Instruction content: Includes operation type (action), target resource identifier (such as instance ID, bucket name), parameters (such as virtual machine specifications, bucket permission configurations).

[0063] 2) Parse the operation instruction

[0064] Resource ownership verification: Confirm that the target resource (such as instance ID i-1234567890abcdef0) actually belongs to the cloud platform (such as cloud platform X1) that the user has the right to access.

[0065] Furthermore, it can also include secondary permission verification, that is, even if the resource has been shown to the user, it is still necessary to dynamically verify whether the user has the right to perform the operation (such as calling the cloud platform IAM interface, Identity and Access Management), in order to improve security.

[0066] 3) Map to the cloud platform API

[0067] That is, convert the API instructions of the user on the management platform into specific fields of the affiliated cloud platform, so that it can be actually executed in the affiliated cloud platform.

[0068] Step 205: Control the affiliated cloud platform to execute the actual operation instruction on the actual object.

[0069] Based on step 204, this step aims to ensure that after the management platform converts the user's operation instruction into a specific API request of the cloud platform, the request is correctly sent to the target cloud platform, monitor its execution process, handle possible errors or exceptions, and finally feedback the result to the user.

[0070] The multi-cloud platform access method provided by the embodiments of the present disclosure, by adding a management platform for docking different cloud platforms, and pre-configuring corresponding unified accounts for different cloud platforms and registering them on the management platform, enables the management platform to log in to and access each cloud platform using each unified account. Furthermore, when the user only needs to successfully log in to the management platform, the management platform can determine the accessible cloud platforms corresponding to the logged-in user and the controllable objects under the accessible cloud platforms, so that the user does not need to use multiple sets of login information to log in to different cloud platforms respectively, reducing the login complexity and not exposing too many login accounts to the user, and also facilitating the unified control of each cloud platform through the management platform.

[0071] Please refer to Figure 3 , Figure 3 which is a flowchart of a method for constructing and using a login information table provided by the embodiments of the present disclosure, where process 300 includes the following steps:

[0072] Step 301: Receive the registration requests initiated by each cloud platform, and extract the unified accounts corresponding to each cloud platform from each registration request;

[0073] This step aims to have the above-mentioned execution entity respectively receive the registration requests initiated by each cloud platform, and respectively extract the unified accounts corresponding to each cloud platform from the received registration requests.

[0074] Step 302: Establish the correspondence between different cloud platforms and different unified accounts to obtain a login information table;

[0075] Based on Step 301, the purpose of this step is for the above-mentioned execution entity to establish the correspondence between different cloud platforms and different unified accounts as a login information table for subsequent use. Further, to enhance security, the information in the login information table can also be encrypted, and the encryption method should be held only by the management platform with the corresponding decryption method and not exposed to other objects.

[0076] Step 303: Obtain the unified accounts corresponding to each cloud platform respectively through the login information table;

[0077] Based on Step 302, the purpose of this step is for the above-mentioned execution entity to obtain the unified accounts corresponding to each cloud platform respectively through the login information table pre-constructed according to the above steps when verifying that the target user sending the login request is a legitimate user.

[0078] Step 304: Log in to the corresponding cloud platforms through each unified account.

[0079] Based on Step 303, the purpose of this step is for the above-mentioned execution entity to log in to the corresponding cloud platforms through each unified account.

[0080] It should be noted that if it is possible to also initiate a login behavior only to the cloud platforms with access permissions before logging in to each cloud platform, based on the pre-recorded different user identity information, the cloud platform information authorized to be accessed, and the cloud resources authorized to be accessed under this cloud platform.

[0081] This embodiment provides a specific solution for legitimate users to log in to each cloud platform through Steps 301 - 304. Among them, Steps 301 - 302 are the pre-registration process, which only needs to be executed once, while Steps 303 - 304 are the regular login operations, based on the completion of the registration in Steps 301 - 302.

[0082] Based on the above embodiment, to facilitate the management platform to control each cloud platform, the management platform can also configure parameters for each successfully registered cloud platform according to preset management configuration parameters. The management configuration parameters include configuration parameters of management policies, and the management policies can include at least one of: label management policy, user management policy, group management policy, permission management policy, and authorization management policy, to accommodate various actual needs.

[0083] Specifically, step 203 above can be adaptively adjusted as follows: Through the user management policy and / or the permission management policy, determine the accessible cloud platforms corresponding to the target identity information and the controllable objects under the accessible cloud platforms among the successfully logged-in cloud platforms. That is, the user management policy and / or the permission management policy can be used to help the management platform determine the cloud platforms with access permissions and the corresponding controllable objects based on the user's identity information.

[0084] Furthermore, when performing policy configuration, the above-mentioned execution subject can also determine the attribution information between the controllable objects under each successfully registered cloud platform and the business, the authorization information between the controllable objects and the users, and the attribute information according to the label management policy and / or the authorization management policy, so as to facilitate the subsequent real-time on-demand adjustment of the attribution information, authorization information, and attribute information of each cloud resource, so that the adjusted cloud resources are removed from or added to the authorization access list of certain users.

[0085] Even further, when receiving a registration request for a newly added cloud platform, a corresponding relationship between the newly added cloud platform and the corresponding unified account can be added to the login information table, and the parameter configuration of the management policy can be performed for the newly added cloud platform according to the management configuration parameters, that is, the range of accessible cloud platforms can be increased without the user's awareness.

[0086] Correspondingly, if a deletion request for an original cloud platform is received, the unified account corresponding to the corresponding cloud platform can also be removed from the login information table, so that the user can no longer access the corresponding cloud platform.

[0087] Please refer to Figure 4 , Figure 4 which is a flowchart of a method for creating and using a control interface provided by an embodiment of the present disclosure, and its process 400 includes the following steps:

[0088] Step 401: Create control interfaces consistent with the number of accessible cloud platforms, and present the controllable objects under each accessible cloud platform on the corresponding control interface;

[0089] Step 402: Receive an operation request initiated by a target user for a target controllable object under a target control interface;

[0090] Step 403: Determine the target cloud platform corresponding to the target control interface;

[0091] Step 404: Convert the operation instruction initiated by the target user for the target controllable object into an actual operation instruction for the corresponding actual object under the target cloud platform.

[0092] This embodiment aims to dynamically generate multiple control interfaces by the above-mentioned execution entity according to user permissions (each interface corresponds to an accessible cloud platform), display the controllable resources that the user has the right to access under the control interface, and after the user initiates an operation through the interface, convert the operation instruction into an API call of the corresponding cloud platform and ensure that the operation is correctly executed. That is, the solution provided by the embodiment is mainly used to realize the unified control of multi-cloud resources, while shielding the differences of the underlying cloud platforms.

[0093] Please refer to Figure 5 , Figure 5 which is a flowchart of a statistical and risk assessment method provided by an embodiment of the present disclosure. Its process 500 includes the following steps:

[0094] Step 501: Obtain login operations, access operations, and modification operations within a preset time period;

[0095] Specifically, the above operations can be obtained by obtaining the operation logs of the management platform. Among them, the login operation is mainly used to record the user login time, IP address, login method (such as password, etc.); the access operation is mainly used to record the resources accessed by the user (such as virtual machines, storage buckets) and the operation types (such as read, write); the modification operation is mainly used to record the modifications made by the user to the resources (such as deleting instances, modifying configurations).

[0096] The preset time period can be set according to the requirements to analyze the time range (such as the past 24 hours, the past 7 days).

[0097] Step 502: Determine risk assessment information corresponding to sensitive data and / or sensitive behaviors according to the login operations, access operations, and modification operations;

[0098] Specifically, sensitive data can be defined as: resources containing sensitive information (such as S3 storage buckets storing personal data, databases containing keys). For example, storage buckets with names containing "personal-data" or "backup", and database tables with table names containing "credit_card" or "password".

[0099] The definition of sensitive behavior can be defined as: high-risk operations (such as deleting resources, modifying permissions, accessing sensitive data). For example, operation types of "delete" or "modify_permission" and accessing resources with the resource label "sensitive=true".

[0100] Step 503: Determine users with risk behaviors according to the risk assessment information, and attach risk marks and alarms to the users with risk behaviors.

[0101] Specifically, risk scores can be calculated based on the following risk indicators and then used to identify users with risk behaviors: 1) Abnormal login: such as multiple login failures or logging in from a different location; 2) Abnormal access: such as overly frequent access to sensitive data; Abnormal modification: such as deleting a large number of resources in a short period of time; 3) Risk score: Calculate the risk score based on the operation behavior. For example, the number of login failures > 5 times → risk score + 10, the number of deleted resources > 3 → risk score + 20, accessing sensitive data → risk score + 30. The risk levels can also be divided according to the risk scores (such as low risk, medium risk, high risk).

[0102] Then, users with risk scores exceeding the threshold (such as risk score > 50) can be identified as users with risk behaviors, and then a risk marker can be added to the user information (such as risk_level: high), and the warning methods can include: sending emails, text messages, or notifying the management platform.

[0103] Furthermore, appropriate measures can be taken to deal with them at an appropriate time, such as temporarily freezing the account, forcing secondary authentication, notifying the administrator, etc.

[0104] This embodiment provides a specific statistical analysis solution, that is, by analyzing the operation logs of users (including login, access, and modification), identifying operations that may involve sensitive data or high-risk behaviors, evaluating their risk levels, and marking and warning high-risk users. That is, the solution provided by the embodiment is mainly used for operation monitoring, risk assessment, and risk handling.

[0105] To deepen the understanding, the present disclosure also gives a specific implementation solution in combination with a specific application scenario:

[0106] To facilitate the unified management and operation of cloud resources within the group, improve the efficiency of migrating to the cloud, support solving the problem of resource ownership change caused by business adjustment, and eliminate the cost of opening network dedicated lines that may be encountered by each business when using cloud resources, this embodiment designs a group cloud migration solution based on a unified account. If there are requirements for multiple cloud platforms, this solution also supports the ability to manage and use multiple cloud platforms. To achieve the following effects:

[0107] 1) Centralized management: The group can centrally manage the cloud resources used by all businesses, facilitating subsequent provision of capabilities such as budget management and demand orchestration; 2) Flexible customization: Support customization requirements within the group through this solution, such as resource ownership changes caused by organizational structure adjustment or business adjustment; 3) Cloud migration efficiency: Shield the account permission system of the cloud platform from the business, reuse the existing resource operation mechanism of the group, achieve a consistent cloud usage experience, and improve the cloud migration efficiency of the business; 4) Multi-cloud unified management: It can achieve unified management of permissions, resources, etc. of multiple cloud platforms.

[0108] The solution provided in this embodiment is implemented by sharing a single cloud account across the entire group. The internal management platform within the group combines the APIs provided by the cloud platform (tag management, user management, group management, permission policy management, authorization management) to achieve isolation of permissions and resources through tags and custom permission policies based on tags. The following explains each of the concepts mentioned:

[0109] Tag: Used to identify the resource ownership and achieve isolation of resource permissions; Custom permission policy: Defines the permissions to control visible tags and visible resources; Sub-user: Distinguishes the user identities under different group resource accounts and logs in to use cloud platform products according to the granted permissions; User group: A carrier for batch user permission authorization; Authorization management: Completes the binding or unbinding of the relationship between users or user groups and permission policies.

[0110] As detailed in the implementation of the solution, it can be clarified in combination with, for example Figure 6-1 as follows:

[0111] 1) Obtain the system-level permission policies corresponding to all products through the open API for permission policies on the cloud platform, and save them to the internal management platform, indicating that the product permission policies correspond to the cloud platform, and synchronize and update them daily.

[0112] 2) There are many resource accounts provided by the internal management platform within the group for various businesses within the group. Under the resource accounts, there are users and user groups (multiple users).

[0113] 3) For each resource account within the group, create a tag with a key of "resource account ID" and a value of "actual ID of the internal resource account within the group" through the open API for creating tags on the cloud platform. And create a custom permission policy to control whether this tag is visible, and save the relationship between the group resource account ID and this corresponding custom permission policy to the internal management platform.

[0114] 4) A user has a unique internal user ID under the resource account within the group. Create a uniquely corresponding sub-user under the unified cloud account through the open API for creating sub-users on the cloud platform. By default, grant the custom permission to control whether this resource account tag is visible to this sub-user.

[0115] 5) When a user is granted permissions to a certain cloud product under a certain resource account within the group, a custom permission policy with conditions of the group's internal resource account tag will be created according to the system permission policy of this cloud product (which has been saved to the internal management platform within the group), and this permission will be granted to the corresponding sub-user. When the permission is deleted, the internal management platform within the group deletes the relationship between the internal user and the system permission policy, and at the same time deletes the authorization relationship between the sub-user mapped to the cloud platform and the corresponding custom permission policy.

[0116] 6) For user group authorization, a user group created on the group management platform is created as a corresponding user group under the unified cloud account, and the corresponding relationship is saved to the internal management platform. When authorizing, the group internal management platform adds both the user and the permission policy to the user group, and at the same time adds the corresponding sub-users and permission policies mapped to the unified cloud account to the user group mapped under the cloud account. When adding members or permission policies to the user group, that is, adding the sub-users mapped to the cloud account or the custom permission policies based on tags to the user group under the cloud account, and the same applies to removing permissions.

[0117] 7) For service users within the group, they are actually sub-users with restricted access to the cloud platform, and a certain scope of authorized AKSK (a key combination for identity authentication, mainly used for security verification of system - to - system interface calls, where the Access Key is the public access key identifier and the Secret Key is the private key that needs to be strictly confidential) is provided for the group's business to use the APIs on the cloud platform. The authorization and removal of authorization are the same as for users, and the difference lies in creating a pair of AKSK for using the cloud platform's APIs.

[0118] 8) When placing an order to purchase resources on the cloud platform, the user selects the only visible resource account tag, and then the resource will be bound to this tag. After the resource is created, users with the corresponding product - based tag - custom permissions can view and manage the resource according to the actual permissions.

[0119] 9) When organizational structure adjustments or other situations that require changing the resource ownership occur, it only needs to change the corresponding tag on the resource to the new resource account of the ownership. This solves the problem that resources of multiple cloud accounts cannot be migrated and the ownership cannot be changed.

[0120] 10) When performing multi - cloud management expansion, it is necessary to synchronize the product permission policies of multiple cloud platforms, and according to the differences in cloud platforms, dock the management capabilities (tag management, user management, group management, permission policy management, authorization management) of multiple cloud platforms in the group internal management platform. According to the granted permission policies, call the corresponding cloud platform's API to complete relevant operations.

[0121] The corresponding relationships of the data models mentioned above are as Figure 6-2 shown:

[0122] One resource account corresponds to one tag under the unified account of the cloud platform;

[0123] The system permission policy of the products enabled by one resource account corresponds to one custom permission policy based on tags under the unified account of the cloud platform, that is, resource account + product system permission policy = one custom permission policy based on tags;

[0124] A user under a resource account corresponds to a sub - user under a unified account, that is, the same user within the group corresponds to different sub - users on the cloud under different resource accounts;

[0125] A user group under a resource account corresponds to a user group under a unified account of a cloud platform.

[0126] The permission synchronization processing flow during authorization mentioned above is as Figure 6-3 shown:

[0127] Group permission management includes user permissions, user - group permissions, and service - user permissions. The permission management synchronization and adaptation process needs to go through creating account tags, creating permission policies, creating sub - users, associating permission policies, creating user groups, and associating user permissions in sequence before it can be completed. Among them, creating user groups and associating users and permissions with user groups are only executed when authorizing through the user - group method.

[0128] For further reference Figure 7 , as an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a multi - cloud - platform access device. The embodiment in the multi - cloud - platform access device 700 corresponds to the Figure 2 method embodiment shown, and the multi - cloud - platform access device 700 can be specifically applied to various electronic devices.

[0129] As Figure 7 shown, the multi - cloud - platform access device 700 of this embodiment may include: a login request parsing unit 701, a multi - cloud - platform login unit 702, a manageable information determination unit 703, an operation instruction conversion unit 704, and a control execution unit 705. Among them, the login request parsing unit 701 is configured to extract target identity information from the received login request initiated by a target user; the multi - cloud - platform login unit 702 is configured to log in to each cloud platform respectively through the unified account used by each cloud platform in advance through a registration request in response to the target identity information being a legal identity; the manageable information determination unit 703 is configured to determine the accessible cloud platforms and the manageable objects under the accessible cloud platforms corresponding to the target identity information among the successfully logged - in cloud platforms; the operation instruction conversion unit 704 is configured to convert the operation instruction initiated by the target user for the target manageable object into an actual operation instruction for the actual object under the belonging cloud platform; the control execution unit 705 is configured to control the belonging cloud platform to execute the actual operation instruction on the actual object.

[0130] In this embodiment, in the multi - cloud - platform access device 700: the specific processing of the login request parsing unit 701, the multi - cloud - platform login unit 702, the manageable information determination unit 703, the operation instruction conversion unit 704, and the control execution unit 705 and the technical effects brought by them can be respectively referred to Figure 2The related descriptions of steps 201-205 in the corresponding embodiments will not be elaborated here.

[0131] In some other implementation manners of this embodiment, the multi-cloud platform access device 700 may further include:

[0132] A registration request processing unit, configured to receive registration requests initiated by each cloud platform and extract unified accounts corresponding to each cloud platform from each registration request;

[0133] A login information table establishment unit, configured to establish a correspondence between different cloud platforms and different unified accounts to obtain a login information table;

[0134] Correspondingly, the multi-cloud platform login unit 702 is further configured to:

[0135] Obtain the unified accounts corresponding to each cloud platform respectively through the login information table;

[0136] Log in to the corresponding cloud platforms through each unified account.

[0137] In some other implementation manners of this embodiment, the multi-cloud platform access device 700 may further include:

[0138] A management parameter configuration unit, configured to perform parameter configuration for each successfully registered cloud platform according to preset management configuration parameters; wherein, the management configuration parameters include configuration parameters of management policies, and the management policies include at least one of a label management policy, a user management policy, a group management policy, a permission management policy, and an authorization management policy.

[0139] In some other implementation manners of this embodiment, the manageable information determination unit 703 is further configured to:

[0140] Determine accessible cloud platforms corresponding to the target identity information and manageable objects under the accessible cloud platforms in each successfully logged-in cloud platform through the user management policy and / or the permission management policy.

[0141] In some other implementation manners of this embodiment, the management parameter configuration unit is further configured to:

[0142] Determine the attribution information between the business, the authorization information between the user, and the attribute information for the manageable objects under each successfully registered cloud platform according to the label management policy and / or the authorization management policy.

[0143] In some other implementation manners of this embodiment, the multi-cloud platform access device 700 may further include:

[0144] A new request processing unit, configured to, in response to receiving a registration request for a new cloud platform, add a corresponding relationship between the new cloud platform and the corresponding unified account in the login information table, and configure parameter settings for the management policy of the new cloud platform according to the management configuration parameters;

[0145] A deletion request processing unit, configured to, in response to receiving a deletion request for an original cloud platform, remove the unified account corresponding to the corresponding cloud platform from the login information table.

[0146] In some other implementation manners of this embodiment, the multi-cloud platform access device 700 may further include:

[0147] A management control interface creation and presentation unit, configured to create management control interfaces that are consistent with the number of accessible cloud platforms, and present the manageable objects under each accessible cloud platform on the corresponding management control interface;

[0148] An operation request receiving unit, configured to receive an operation request initiated by a target user for a target manageable object under a target management control interface;

[0149] Correspondingly, the operation instruction conversion unit 704 is further configured to:

[0150] Determine a target cloud platform corresponding to the target management control interface;

[0151] Convert the operation instruction initiated by the target user for the target manageable object into an actual operation instruction for the corresponding actual object under the target cloud platform.

[0152] In some other implementation manners of this embodiment, the login request parsing unit 701 includes:

[0153] An extraction subunit, configured to respectively extract different levels of identity information corresponding to the target user from different fields in the login request;

[0154] A splicing subunit, configured to splice the obtained different levels of identity information according to a preset hierarchical arrangement order, and extract the spliced complete identity information as the target identity information.

[0155] In some other implementation manners of this embodiment, the splicing subunit is further configured to:

[0156] In response to extracting the first-level identity information and the second-level identity information, splice the second-level identity information at the end of the first-level identity information according to a preset arrangement order from high to low to obtain the complete identity information; wherein, the level of the first level is higher than that of the second level;

[0157] Use the complete identity information as the target identity information.

[0158] In some other implementation manners of this embodiment, the multi-cloud platform access device 700 may further include:

[0159] An operation statistics unit, configured to obtain login operations, access operations, and modification operations within a preset time period;

[0160] A risk assessment unit, configured to determine risk assessment information corresponding to sensitive data and / or sensitive behaviors according to the login operations, access operations, and modification operations;

[0161] A risk user determination and marking processing unit, configured to determine risk behavior users according to the risk assessment information, and attach risk marks and alarms to the risk behavior users.

[0162] This embodiment exists as a device embodiment corresponding to the above method embodiment. The multi-cloud platform access device provided in this embodiment, by adding a management platform for docking different cloud platforms, and pre-configuring corresponding unified accounts for different cloud platforms and registering them in the management platform, enables the management platform to log in to and access each cloud platform using each unified account. Furthermore, when a user only needs to successfully log in to the management platform, the management platform can determine the accessible cloud platforms corresponding to the logged-in user and the controllable objects under the accessible cloud platforms, so that the user does not need to use multiple sets of login information to log in to different cloud platforms respectively. This reduces the login complexity and does not need to expose too many login accounts to the user, and at the same time facilitates the unified control of each cloud platform through the management platform.

[0163] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to implement the multi-cloud platform access method described in any of the above embodiments.

[0164] According to an embodiment of the present disclosure, the present disclosure also provides a readable storage medium, which stores computer instructions for enabling a computer to implement the multi-cloud platform access method described in any of the above embodiments when executed.

[0165] According to an embodiment of the present disclosure, the present disclosure also provides a computer program product, which can implement the multi-cloud platform access method described in any of the above embodiments when executed by a processor.

[0166] Figure 8FIG. shows a schematic block diagram of an exemplary electronic device 800 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0167] As Figure 8 shown, the device 800 includes a computing unit 801 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0168] A plurality of components in the device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0169] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 executes the various methods and processes described above, such as the multi-cloud platform access method. For example, in some embodiments, the multi-cloud platform access method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the multi-cloud platform access method described above can be executed. Alternatively, in other embodiments, the computing unit 801 can be configured to execute the multi-cloud platform access method by any other suitable means (e.g., by means of firmware).

[0170] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0171] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0172] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0173] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0174] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0175] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system to address the defects of difficult management and weak business scalability existing in traditional physical hosts and virtual private servers (VPS).

[0176] According to the technical solution of the embodiment of the present disclosure, by adding a management platform for docking different cloud platforms and pre-configuring corresponding unified accounts for different cloud platforms and registering them in the management platform, the management platform can use each unified account to log in to and access each cloud platform. Furthermore, when a user successfully logs in to the management platform, the management platform can determine the accessible cloud platform corresponding to the logged-in user and the controllable objects under the accessible cloud platform, so that the user does not need to use multiple sets of login information to log in to different cloud platforms respectively. This reduces the login complexity and does not need to expose too many login accounts to the user. At the same time, it is also convenient to uniformly manage and control each cloud platform through the management platform.

[0177] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution disclosed in the present disclosure can be achieved. No limitations are imposed herein.

[0178] The above specific embodiments do not limit the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present disclosure shall be included within the protection scope of the present disclosure.

Claims

1. A multi-cloud platform access method, comprising: Extracting target identity information from a login request received from a target user; In response to the target identity information being a legitimate identity, logging into each of the cloud platforms respectively through a unified account previously used by each cloud platform through registration requests; Determine, in each successfully logged-in cloud platform, an accessible cloud platform corresponding to the target identity information and a controllable object under the accessible cloud platform; Converting the operation instruction initiated by the target user on the target controllable object into an actual operation instruction for the actual object under the cloud platform; Control the cloud platform to execute the actual operation instruction on the actual object.

2. The method according to claim 1, further comprising: Receiving registration requests initiated by each of the cloud platforms, and extracting a unified account corresponding to each of the cloud platforms from each of the registration requests; Establish the corresponding relationship between different cloud platforms and different unified accounts, and obtain the login information table; Correspondingly, the unified account used by each cloud platform in advance through the registration request is used to log in to each cloud platform respectively, including: Obtaining the unified accounts corresponding to the cloud platforms respectively through the login information table; Log in to the corresponding cloud platforms through the unified accounts.

3. The method according to claim 2, further comprising: Parameter configuration is performed for each successfully registered cloud platform according to preset management configuration parameters; wherein the management configuration parameters include configuration parameters of management policies, and the management policies include: at least one of tag management policy, user management policy, group management policy, permission management policy and authorization management policy.

4. The method according to claim 3, wherein: The step of determining the accessible cloud platforms and the controllable objects under the accessible cloud platforms corresponding to the target identity information in each successfully logged-in cloud platform includes: Through the user management strategy and / or the authority management strategy, the accessible cloud platforms corresponding to the target identity information and the controllable objects under the accessible cloud platforms are determined in each successfully logged-in cloud platform.

5. The method according to claim 3, wherein: The parameter configuration for each successfully registered cloud platform according to the preset management configuration parameters includes: For the successfully registered managed objects under each cloud platform, the attribution information between the business, the authorization information between the user and the attribute information are determined according to the tag management strategy and / or the authorization management strategy.

6. The method according to any one of claims 3 to 5, further comprising: In response to receiving a registration request for a newly added cloud platform, adding a correspondence between the newly added cloud platform and the corresponding unified account in the login information table, and performing parameter configuration of the management policy for the newly added cloud platform according to the management configuration parameters; In response to receiving a deletion request from the original cloud platform, the unified account corresponding to the corresponding cloud platform is removed from the login information table.

7. The method according to claim 1, further comprising: Creating a management and control interface that is consistent with the number of the accessible cloud platforms, and presenting the controllable objects under each of the accessible cloud platforms on the corresponding management and control interface; Receiving an operation request initiated by the target user for a target controllable object in the target control interface; Correspondingly, converting the operation instruction initiated by the target user on the target controllable object into an actual operation instruction for the actual object under the cloud platform includes: Determine a target cloud platform corresponding to the target control interface; The operation instruction initiated by the target user on the target controllable object is converted into an actual operation instruction of the corresponding actual object under the target cloud platform.

8. The method according to claim 1, wherein: The step of extracting target identity information from a login request received from a target user includes: Extracting identity information of different levels corresponding to the target user from different fields in the login request; The acquired identity information of different levels are spliced ​​according to a preset hierarchical arrangement order, and the spliced ​​complete identity information is extracted as the target identity information.

9. The method according to claim 8, wherein: The acquired identity information of different levels is spliced ​​according to a preset level order, and the spliced ​​complete identity information is extracted as the target identity information, including: In response to extracting the primary identity information and the secondary identity information, the secondary identity information is spliced ​​onto the end of the primary identity information in a preset order of high to low levels to obtain the complete identity information; wherein the primary level is higher than the secondary level; The complete identity information is used as the target identity information.

10. The method according to claim 1, further comprising: Obtain login operations, access operations, and modification operations within a preset time period; Determining risk assessment information corresponding to sensitive data and / or sensitive behavior according to the login operation, the access operation, and the modification operation; The risky behavior users are determined according to the risk assessment information, and risk tags and warnings are added to the risky behavior users.

11. A multi-cloud platform access device, comprising: A login request parsing unit, configured to extract target identity information from a login request received from a target user; A multi-cloud platform login unit is configured to log in to each of the cloud platforms respectively through a unified account that each cloud platform has used in advance through registration requests in response to the target identity information being a legitimate identity; A controllable information determining unit is configured to determine, from each successfully logged-in cloud platform, an accessible cloud platform corresponding to the target identity information and a controllable object under the accessible cloud platform; An operation instruction conversion unit, configured to convert the operation instruction initiated by the target user on the target controllable object into an actual operation instruction for the actual object under the cloud platform; The control execution unit is configured to control the cloud platform to execute the actual operation instruction on the actual object.

12. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the multi-cloud platform access method described in any one of claims 1-10.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable the computer to execute the multi-cloud platform access method according to any one of claims 1 to 10.

14. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the steps of the multi-cloud platform access method according to any one of claims 1 to 10 are implemented.