Multi-cloud scene access method and device

The method addresses the challenge of unified access control in multi-cloud environments by dynamically adjusting permissions based on risk assessments, ensuring consistent security across platforms and reducing management complexity.

CN120321020APending Publication Date: 2025-07-15CHINA UNICOM SMART CONNECTION TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510630551.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

In multi-cloud environments, the lack of unified security standards and specifications has led to increased complexity and cost of access control and encryption management, making it difficult to achieve consistent access control and encryption management, and traditional role permission management cannot adapt to dynamically changing business needs.

Method used

By obtaining the access characteristics of the target object, conducting risk assessment, dynamically adjusting access permissions, and sending risk warning messages to associated devices when the risk level exceeds the preset level, in order to achieve consistency of access control policy across cloud platforms.

Benefits of technology

It realizes secure and reliable access to target objects in multi-cloud environments, timely and dynamically adjusts access permissions, ensures consistency of access control policies in cross-cloud environments, and reduces security management complexity and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321020A_ABST
    Figure CN120321020A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-cloud scene access method and device, and belongs to the technical field of cloud computing and communication. The method comprises the steps of obtaining an access feature of a target object during a period of accessing a target device, wherein the target device is a device of a first cloud platform; performing risk assessment on the target object according to the access features to obtain a risk assessment result; dynamically adjusting the access authority of the target object for the target equipment according to the risk assessment result; and when the risk level represented by the risk assessment result exceeds a preset level, a risk prompt message is sent to an associated device, the risk prompt message is used for indicating the associated device to adjust the access permission of the target object, and the associated device is a device of the second cloud platform. According to the method, uniform and safe access control management in a multi-cloud environment can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of cloud computing and communication technologies, and particularly relates to an access method and device for a multi-cloud scenario. Background Art

[0002] When facing a multi-cloud environment, there are differences in security settings, interfaces, protocols, etc. of different cloud platforms, and there is a lack of unified standards and specifications. Therefore, it is difficult to achieve unified access control and encryption management in a multi-cloud environment, increasing the complexity and cost of security management in a multi-cloud scenario. Summary of the Invention

[0003] For this reason, the present invention provides an access method and device for a multi-cloud scenario to achieve secure and reliable access for users in a multi-cloud environment.

[0004] To achieve the above object, a first aspect of the present invention provides an access method for a multi-cloud scenario, and the access method includes:

[0005] Obtain access characteristics of a target object during access to a target device, where the target device is a device of a first cloud platform;

[0006] Perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result;

[0007] Dynamically adjust the access permission of the target object for the target device according to the risk assessment result; and,

[0008] In a case where a risk level represented by the risk assessment result exceeds a preset level, send a risk prompt message to an associated device, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform.

[0009] Further, before obtaining the access characteristics of the target object during access to the target device, the method further includes:

[0010] Receive an access request sent by the target object;

[0011] Determine the access permission of the target object for the target device based on the user role, user attributes, resource attributes, and environmental attributes of the target object, for the target object to access the target device based on the access permission;

[0012] Wherein, the user attributes, resource attributes, and environmental attributes are metadata attributes applicable to multiple cloud platforms;

[0013] The performing a risk assessment on the target object according to the access characteristics to obtain a risk assessment result includes:

[0014] When the preset conditions are met, perform a risk assessment on the target object according to the access characteristics to obtain the risk assessment result;

[0015] The preset conditions include at least one of the following: reaching a preset assessment period, receiving an assessment request, and receiving a warning message.

[0016] Furthermore, the access characteristics at least include identity characteristics, behavior characteristics, attribute security characteristics, and data security characteristics;

[0017] Performing the risk assessment on the target object according to the access characteristics to obtain the risk assessment result includes:

[0018] Determine the identity credibility of the target object according to the identity characteristics;

[0019] Determine the behavior deviation degree of the target object according to the behavior characteristics and the benchmark behavior characteristics of the target object;

[0020] Determine the attribute security level according to the attribute security characteristics;

[0021] Determine the data security level according to the data security characteristics;

[0022] Obtain the risk assessment result according to at least one of the identity credibility, the behavior deviation degree, the attribute security level, and the data security level.

[0023] Furthermore, the identity characteristics include role sub-characteristics and terminal sub-characteristics, and the terminal sub-characteristics correspond to the terminal used by the target object to access the target device;

[0024] Determining the identity credibility of the target object according to the identity characteristics includes:

[0025] Determine the role credibility according to the role sub-characteristics;

[0026] Determine the terminal credibility according to the terminal sub-characteristics;

[0027] Obtain the identity credibility of the target object according to the role credibility and the terminal credibility.

[0028] Furthermore, the method further includes:

[0029] Obtain the behavior characteristics of the target object within the first preset time period;

[0030] Obtain the benchmark behavior characteristics of the target object according to the behavior characteristics of the target object within the first preset time period.

[0031] Further, determining the behavior deviation degree of the target object according to the behavior feature and the benchmark behavior feature of the target object includes:

[0032] Inputting the behavior feature into a user behavior baseline model to obtain the behavior deviation degree of the target object;

[0033] Wherein, the user behavior baseline model is obtained by training an initial user behavior baseline model according to the behavior features of the target object within a first preset time period.

[0034] Further, the attribute security feature includes the user attribute feature of the target object, the resource attribute feature of the accessed data, the environmental attribute feature of the target object, and the operation attribute feature of the target object for the accessed data;

[0035] Determining the attribute security degree according to the attribute security feature includes:

[0036] Obtaining a first sub-security value according to the matching degree between the user attribute feature of the target object and the resource attribute feature of the accessed data;

[0037] Obtaining a second sub-security value according to the matching degree between the environmental attribute feature of the target object and the resource attribute feature of the target object;

[0038] Obtaining a third sub-security value according to the operation attribute feature of the target object for the accessed data;

[0039] Obtaining the attribute security degree according to the first sub-security value, the second sub-security value, and the third sub-security value.

[0040] Further, the data security feature includes the security level of the accessed data;

[0041] Determining the data security degree according to the data security feature includes:

[0042] In the case that the access frequency of the accessed data within a second preset time period is less than or equal to a preset access frequency threshold, determining the data security degree according to the security level of the accessed data;

[0043] In the case that the access frequency of the accessed data within a second preset time period is greater than the preset access frequency threshold, adjusting the security level of the accessed data based on a preset adjustment strategy, and determining the data security degree according to the adjusted security level.

[0044] Further, dynamically adjusting the access permission of the target object for the target device according to the risk assessment result includes:

[0045] When the risk level characterized by the risk assessment result is the first level, full access rights to the target device are granted to the target object;

[0046] When the risk level characterized by the risk assessment result is the second level, first restricted access rights to the target device are granted to the target object;

[0047] When the risk level characterized by the risk assessment result is the third level, an identity authentication operation for the target object is initiated, and second restricted access rights to the target device are granted to the target object when the target object passes the identity authentication.

[0048] To achieve the above object, a second aspect of the present invention provides an access device for a multi-cloud scenario. The access device includes:

[0049] An acquisition module, configured to acquire access characteristics of a target object during access to a target device, where the target device is a device of a first cloud platform;

[0050] An evaluation module, configured to perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result;

[0051] An adjustment module, configured to dynamically adjust the access rights of the target object to the target device according to the risk assessment result;

[0052] A prompt module, configured to send a risk prompt message to an associated device when the risk level characterized by the risk assessment result exceeds a preset level, where the risk prompt message is used to instruct the associated device to adjust the access rights of the target object, and the associated device is a device of a second cloud platform.

[0053] The present invention has the following advantages:

[0054] The access method for a multi-cloud scenario provided by the present invention acquires access characteristics of a target object during access to a target device, where the target device is a device of a first cloud platform; performs a risk assessment on the target object according to the access characteristics to obtain a risk assessment result; dynamically adjusts the access rights of the target object to the target device according to the risk assessment result; and, when the risk level characterized by the risk assessment result exceeds a preset level, sends a risk prompt message to an associated device, where the risk prompt message is used to instruct the associated device to adjust the access rights of the target object, and the associated device is a device of a second cloud platform.

[0055] It can be seen therefrom that the present application can perform risk assessment on a target object during the access of the target object to a target device, obtain corresponding risk assessment results, thereby dynamically adjusting access permissions in a timely manner according to the risk assessment results, and sending a risk prompt message to associated devices in other cloud platforms when the risk is relatively high, so that target objects with risks can be synchronized in a timely manner among multiple cloud platforms, ensuring the consistency of the access control policy for target objects in a cross-cloud environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification, and are used together with the following specific embodiments to explain the present invention, but do not constitute a limitation to the present invention.

[0057] Figure 1 It is a flowchart of an access method for a multi-cloud scenario provided by an embodiment of the present invention;

[0058] Figure 2 It is a schematic diagram of the architecture of a multi-cloud scenario provided by an embodiment of the present invention;

[0059] Figure 3 It is a schematic flow diagram of an access method for a multi-cloud scenario provided by an embodiment of the present invention;

[0060] Figure 4 It is a block diagram of the composition of an access device for a multi-cloud scenario provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0061] The following details the specific embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining and understanding the present invention, and are not used to limit the present invention.

[0062] Many cloud service providers support integrated management of role-based access control and encryption, such as AWS, Azure, etc. Enterprises can flexibly set roles and permissions according to their own business needs and organizational structures to achieve secure management of multi-cloud data.

[0063] The general implementation method is to determine the access permissions of a user to data based on the user's role in the organization, and at the same time protect the data by combining encryption technology. Through role division, a certain degree of access control and data isolation can be achieved. Different roles can only access the data within their responsibilities, improving the security of the data. And in a multi-cloud environment, corresponding encryption keys and access permissions are assigned to different roles. Only when a user has the corresponding role can they obtain the keys and access permissions required to decrypt the data, thereby achieving access control and encryption management of the data.

[0064] When facing a multi-cloud environment, there are differences in security settings, interfaces, protocols, etc. among different cloud platforms, and there is a lack of unified standards and specifications, making it difficult to achieve unified access control and encryption management in a multi-cloud environment, and increasing the complexity and cost of security management.

[0065] Moreover, the roles of users are usually defined based on fixed positions or responsibilities, making it difficult to adapt to the dynamically changing business requirements and flexible adjustment of user permissions in a multi-cloud environment. When multi-party collaboration is involved in a large-scale system, vertical permission slicing based on traditional roles cannot meet the actual requirements of permission management according to horizontal business domains, and ultimately often leads to unreasonable permission allocation or over-authorization. In addition, role-based access control is relatively coarse-grained and cannot meet the more refined access control requirements for data and resources. For some special business scenarios, such as in cross-border collaboration scenarios, limited by requirements such as territorial compliance and data security, more precise permission management may be required.

[0066] Furthermore, in a multi-cloud environment, discrete authorization and management processes, pre-audit and refined management are difficult, and it is easy to cause users' roles to be over-promoted or permissions to be misallocated. On the one hand, it may actually cause unauthorized access and increase the risk of permission abuse. On the other hand, since users with the same role usually have the same permissions, once the account of one of the users is stolen or maliciously operated, it may pose a threat to the security of the entire system. In summary, it is difficult to achieve unified access control and encryption management in a multi-cloud environment, and the complexity and cost of security management are relatively high.

[0067] In view of this, the present application provides an access method and device for a multi-cloud scenario.

[0068] In an embodiment of the present application, access characteristics of a target object during access to a target device are obtained, where the target device is a device of a first cloud platform; a risk assessment is performed on the target object according to the access characteristics to obtain a risk assessment result; according to the risk assessment result, the access permission of the target object for the target device is dynamically adjusted; and, in the case where the risk level characterized by the risk assessment result exceeds a preset level, a risk prompt message is sent to an associated device, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform. The second cloud platform is a cloud platform other than the first cloud platform that the target object can access, and the number of second cloud platforms can be one or more. It can be seen from this that the present application can perform a risk assessment on a target object during the target object's access to a target device, obtain a corresponding risk assessment result, thereby dynamically adjusting the access permission in a timely manner according to the risk assessment result, and sending a risk prompt message to an associated device in another cloud platform when the risk is relatively high, so that multiple cloud platforms can synchronize in a timely manner the target objects with risks, ensuring the consistency of the access control policy for the target object in a cross-cloud environment.

[0069] The first aspect of the present application provides an access method for a multi-cloud scenario.

[0070] Figure 1 It is a flowchart of an access method for a multi-cloud scenario provided by an embodiment of the present application. As Figure 1 shown, the method may include the following steps.

[0071] Step S11, obtain access characteristics of a target object during access to a target device, where the target device is a device of a first cloud platform.

[0072] In some optional embodiments, the target object is an object that initiates an access request to the target device. The target device may be a server of the first cloud platform or an edge node device of the first cloud platform, and the embodiments of the present disclosure do not limit this.

[0073] In some optional embodiments, the access characteristics may reflect the characteristics of the target object when accessing the target device, and may include the identity under which the target object initiates access to the target device, the locations of the target device to which the target object initiates access, the data of the target device to which the target object initiates access, the access operations performed by the target object on the data of the target device, etc.

[0074] In some optional embodiments, the access characteristics at least include an identity characteristic, a behavior characteristic, an attribute security characteristic, and a data security characteristic. Among them, the identity characteristic is a characteristic used to represent the identity information of the target object, the behavior characteristic reflects the access behavior information of the target object to the target device, the attribute security characteristic focuses on reflecting the perspective of attribute security, and the data security characteristic reflects the security of the accessed data.

[0075] Exemplarily, the identity feature can reflect the identity information of the target object from two perspectives: user identity and terminal identity. For example, the identity feature can include a role sub-feature and a terminal sub-feature. Among them, the role sub-feature is a feature used to reflect the user role corresponding to the target object, and the terminal sub-feature is a feature regarding the terminal used by the target object to access the target device.

[0076] For example, the role sub-feature corresponds to "senior engineer", and the terminal sub-feature corresponds to "installed with a preset digital certificate" and "the number of terminal device vulnerabilities is 5".

[0077] Exemplarily, the behavior feature can include the location of accessing data, the type of accessed data, the access time, the access frequency, the access path, the type of access operation, etc.

[0078] Exemplarily, the attribute security feature is a security feature in the attribute dimension. Among them, the attributes include metadata such as user attributes, resource attributes, environmental attributes, and operation attributes. By setting attributes as shared metadata for multiple cloud platforms, the field differences of different cloud platforms can be unified, which is more convenient for centralized management and control.

[0079] For example, the attribute security feature includes the user attribute feature of the target object, the resource attribute feature of the accessed data, the environmental attribute feature of the target object, and the operation attribute feature of the target object for the accessed data, etc. Among them, the environmental attribute feature includes the access time, access location, terminal type, etc., and the operation attribute feature includes the risk identification of the access operation. The risk identification can indicate whether the access operation is a dangerous operation and the risk level of the dangerous operation.

[0080] Exemplarily, the data security feature can characterize the security level of the accessed data.

[0081] It should be noted that the above examples of access features are only for illustration, and the embodiments of the present disclosure do not limit this.

[0082] Step S12: Perform a risk assessment on the target object according to the access feature to obtain a risk assessment result.

[0083] Among them, the risk assessment is mainly used to determine whether the target object poses a security threat to the target device.

[0084] In some optional embodiments, performing a risk assessment on the target object according to the access feature to obtain a risk assessment result includes: under the condition of meeting a preset condition, performing a risk assessment on the target object according to the access feature to obtain a risk assessment result; the preset condition includes at least one of the following: reaching a preset assessment period, receiving an assessment request, receiving a warning message.

[0085] It can be seen from this that when the preset evaluation period is reached, risk assessment can be performed on the target object, or risk assessment can be executed after receiving an evaluation request sent externally, or risk assessment can be executed when a warning message is received. Among them, the evaluation request and the warning message can be requests initiated by the administrator according to business requirements. In other words, the risk assessment of the target object is not a one-time processing process, but an operation that can be started at any time according to requirements.

[0086] It should be noted that the above preset conditions for triggering risk assessment are only examples, and the embodiments of the present disclosure do not limit this.

[0087] In some optional embodiments, the access features at least include identity features, behavior features, attribute security features, and data security features; correspondingly, risk assessment is performed on the target object according to the access features to obtain a risk assessment result, including: determining the identity credibility of the target object according to the identity features; determining the behavior deviation degree of the target object according to the behavior features and the benchmark behavior features of the target object; determining the attribute security degree according to the attribute security features; determining the data security degree according to the data security features; obtaining a risk assessment result according to at least one of the identity credibility, behavior deviation degree, attribute security degree, and data security degree.

[0088] It can be seen from this that risk identification can be carried out on the target object from four dimensions of identity security, behavior security, attribute security, and data security, so as to obtain a more comprehensive and accurate risk assessment result.

[0089] In some optional embodiments, the identity features include role sub-features and terminal sub-features, and the terminal sub-features correspond to the terminal used by the target object to access the target device; correspondingly, determining the identity credibility of the target object according to the identity features includes: determining the role credibility according to the role sub-features; determining the terminal credibility according to the terminal sub-features; obtaining the identity credibility of the target object according to the role credibility and the terminal credibility.

[0090] Exemplarily, the role credibility, terminal credibility, and identity credibility can be characterized in the form of scores.

[0091] For example, if the role sub-feature corresponds to "senior engineer", the identity credibility of the target object can be determined as "30 points". If the terminal sub-feature corresponds to "installed with a preset digital certificate" and "the number of high-risk vulnerabilities of the terminal device is 2", the terminal credibility can be determined as "20 points" and "-10 points", and based on this, the role credibility can be determined as "40 points". Among them, "installed with a preset digital certificate" corresponds to a terminal credibility of "20 points", and "the number of high-risk vulnerabilities of the terminal device is 2" corresponds to a terminal credibility of "-10 points".

[0092] In some alternative embodiments, when performing a risk assessment on the access behavior of a target object based on behavioral characteristics, it can be determined according to the difference between the current access behavior of the target object and its past access behaviors, that is, to determine whether the target object has unconventional access behaviors, and / or, what is the difference between the current access behavior of the target object and the conventional access behavior.

[0093] Exemplarily, the method may further include: obtaining the behavioral characteristics of the target object within a first preset time period; obtaining the baseline behavioral characteristics of the target object according to the behavioral characteristics of the target object within the first preset time period. Wherein, the first preset time period may be a certain historical time period, that is, the baseline behavioral characteristics of the target object are obtained based on the behavioral characteristics of the historical time period. This baseline behavioral characteristic can be regarded as the conventional behavioral characteristic of the target object.

[0094] For example, it is possible to obtain the behavioral characteristics of the target object's last 200 executions of application programming interface (API) calls, align and integrate the above-mentioned behavioral characteristics, and determine the baseline behavioral characteristics based on the aligned and integrated behavioral characteristics. After obtaining the current behavioral characteristics, the behavioral similarity between the current behavioral characteristics and the baseline behavioral characteristics is determined based on the dynamic time warping (DTW) method, so as to obtain the behavioral deviation degree of the target object.

[0095] In some alternative embodiments, the behavioral deviation degree of the target object can be conveniently obtained based on a model-based approach.

[0096] Exemplarily, determining the behavioral deviation degree of the target object according to the behavioral characteristics and the baseline behavioral characteristics of the target object includes: inputting the behavioral characteristics into a user behavior baseline model to obtain the behavioral deviation degree of the target object; wherein, the user behavior baseline model is obtained by training an initial user behavior baseline model according to the behavioral characteristics of the target object within the first preset time period.

[0097] In other words, the behavioral characteristics of the target object within the historical time period can be used to train a model to obtain a user behavior baseline model, and then this user behavior baseline model can be used to determine whether the current access behavior is normal.

[0098] In some alternative embodiments, the attribute security features include the user attribute features of the target object, the resource attribute features of the accessed data, the environmental attribute features of the target object, and the operation attribute features of the target object for the accessed data; correspondingly, determining the attribute security level according to the attribute security features includes: obtaining a first sub-security value according to the matching degree between the user attribute features of the target object and the resource attribute features of the accessed data; obtaining a second sub-security value according to the matching degree between the environmental attribute features of the target object and the resource attribute features of the target object; obtaining a third sub-security value according to the operation attribute features of the target object for the accessed data; and obtaining the attribute security level according to the first sub-security value, the second sub-security value, and the third sub-security value.

[0099] Exemplarily, policy rules can be formulated in advance, in which the matching degree between the user attribute features and the resource attribute features of the accessed data, and the matching degree between the environmental attribute features of the target object and the resource attribute features of the target object are defined. Based on this, after determining the user attribute features of the target object, the environmental attribute features of the target object, and the resource attribute features of the accessed data, the corresponding first sub-security value and second sub-security value can be obtained.

[0100] Further, for the operation attribute features, if the operation attribute features correspond to non-dangerous operation features, the third sub-security value is determined to be "10 points", and if the operation attribute features correspond to dangerous operation features, the third sub-security value is determined to be "-10 points".

[0101] After obtaining the first sub-security value, the second sub-security value, and the third sub-security value, the attribute security level can be obtained.

[0102] In some alternative embodiments, the data security features include the security level of the accessed data; correspondingly, determining the data security level according to the data security features includes: when the access frequency of the accessed data in the second preset period is less than or equal to the preset access frequency threshold, determining the data security level according to the security level of the accessed data; when the access frequency of the accessed data in the second preset period is greater than the preset access frequency threshold, adjusting the security level of the accessed data based on a preset adjustment policy, and determining the data security level according to the adjusted security level.

[0103] Exemplarily, the preset adjustment policy can include: if the access frequency of the accessed data in the second preset period is greater than the preset access frequency threshold, increasing the security level of the accessed data by one level.

[0104] For example, the security levels of access data from low to high are level 1, level 2, level 3, and level 4, corresponding to data security scores of "100 points", "80 points", "60 points", and "40 points" respectively. If the security level of access data date1 is level 1, and three times the daily access volume of access data date1 is determined as the preset access frequency threshold thr. Correspondingly, if the access frequency of the target object to access data date1 within the second preset time period is less than or equal to the preset access frequency threshold thr, since the security level of access data date1 is level 1, the data security score is determined to be "100 points"; if the access frequency of the target object to access data date1 within the second preset time period is greater than the preset access frequency threshold thr, and since the security level of access data date1 is level 1, the security level of access data date1 is adjusted from level 1 to level 2. Based on this, the data security score can be determined to be "80 points".

[0105] For example, the security levels of access data from low to high are level 1, level 2, level 3, and level 4, corresponding to data security scores of "L1", "L2", "L3", and "L4" respectively. Similarly, if the access frequency of the target object to access data date1 within the second preset time period is less than or equal to the preset access frequency threshold thr, since the security level of access data date1 is level 1, the data security score is determined to be "L1"; if the access frequency of the target object to access data date1 within the second preset time period is greater than the preset access frequency threshold thr, and since the security level of access data date1 is level 1, the security level of access data date1 is adjusted from level 1 to level 2. Based on this, the data security score can be determined to be "L2".

[0106] In other words, if the access frequency to the access data is normal, the data security score can be directly determined according to the security level of the access data. If the access frequency to the access data exceeds the normal access frequency, the security level of the access data can be increased based on the preset adjustment strategy, and the data security score can be determined based on the adjusted security level.

[0107] It should be noted that the score, percentage, or coding, etc. can be flexibly selected according to actual needs as the representation methods of identity credibility, behavior deviation degree, attribute security degree, and data security degree. The four can use the same dimension or different dimensions. This application does not limit this.

[0108] Step S13: Dynamically adjust the access permission of the target object for the target device according to the risk assessment result.

[0109] In some optional embodiments, the risk assessment result may include a risk level. The risk level may reflect the degree of risk. If the risk level is higher, the possibility of risk is greater. Conversely, if the risk level is lower, the possibility of risk is smaller.

[0110] In some optional embodiments, if the current risk assessment result is different from the previous risk assessment result, it is necessary to adjust the access rights of the target object to the target device to improve the access security to the target device.

[0111] For example, if the previous risk assessment result indicates that the risk level is level 1 and the access right is determined to be Access1, then if the current risk assessment result indicates that the risk level is level 2, the access right is adjusted from Access1 to Access2, wherein the access right of Access2 is lower than the access right of Access1.

[0112] In some optional embodiments, the target object's access rights to the target device are dynamically adjusted based on the risk assessment result, including: when the risk level represented by the risk assessment result is the first level, granting the target object full access rights to the target device; when the risk level represented by the risk assessment result is the second level, granting the target object first restricted access rights to the target device; when the risk level represented by the risk assessment result is the third level, initiating an identity authentication operation for the target object, and granting the target object second restricted access rights to the target device if the target object passes the identity authentication.

[0113] For example, a new engineer initiates an export request for a section of control code during non-working hours (such as 2 a.m.). After risk assessment, a third-level risk assessment result is given. Based on this, the engineer's access rights are first reduced to preview mode, code downloading is prohibited, and then the iris authentication process is forced to start to confirm the identity of the operator.

[0114] It should be noted that in order to further improve access security, a progressive permission recovery strategy can be adopted. That is, after the access rights of a target object are restricted, when restoring its access rights, it can be restored step by step in combination with its credit history, rather than restoring it to the original level of access rights all at once.

[0115] Step S14, when the risk level represented by the risk assessment result exceeds the preset level, a risk warning message is sent to the associated device, the risk warning message is used to instruct the associated device to adjust the access rights of the target object, and the associated device is a device of the second cloud platform.

[0116] Among them, the preset level can be flexibly set according to actual requirements, etc. For example, if a higher security requirement is needed, a lower level can be set as the preset level.

[0117] In some alternative embodiments, the risk levels include a first level, a second level, and a third level, and the preset level is determined to be the second level. Based on this, if the risk assessment result is the third level, a risk prompt message needs to be sent to the associated device. After receiving the risk prompt message, the associated device can adjust its access permission for the target object to achieve unified control of cross-cloud access security and improve access security in a multi-cloud scenario.

[0118] That is to say, for a multi-cloud scenario, if the risk assessment result of a certain cloud platform for the target object indicates a high risk, a risk prompt needs to be sent to other cloud platforms so that other cloud platforms can timely learn that there is a security threat to the current target object, and then make corresponding adjustments to the access permission of the current target object to avoid insecurity in access caused by information asynchronization between multiple clouds.

[0119] In some alternative embodiments, in the initial stage of the multi-cloud platform going online, technologies such as real-time mirroring can be used to control access permissions. For example, in the initial stage of the multi-cloud platform going online, real-time mirroring of high-risk operations is performed, and the access request is forwarded to the sandbox environment for execution through traffic replication technology, and the complete operation chain is recorded. The process is manually reviewed to determine whether it is normal and reasonable, and whether the processing of access permissions is reasonable, and operations such as exception approval and permission restoration for incorrect permissions are performed.

[0120] Exemplarily, technologies such as big data analysis and artificial intelligence algorithms can be used to achieve intelligent auditing of the multi-cloud platform. First, data such as the access behavior of the target object is obtained, and these data are summarized, analyzed, and mined using big data analysis technology to find potential abnormal behavior patterns.

[0121] For example, when it is found that a certain user frequently attempts to access data at different sensitive levels within a short period of time, and the access behavior is significantly different from the user's previous behavior pattern, a warning message is timely sent to notify the administrator for handling, thereby effectively preventing the risk of data leakage and ensuring data security in a multi-cloud environment.

[0122] In some alternative embodiments, artificial intelligence algorithms such as isolation forest can be used to analyze data such as access behavior to accurately identify abnormal permission behaviors.

[0123] For example, first, features are extracted from data such as the user's access behavior, and features such as access time, sensitivity level of the accessed resource, access frequency, etc. are obtained. Then, these features are input into the trained isolation forest model. The isolation forest model constructs a tree structure and calculates the isolation degree of each data point. When the model detects that the isolation degree of data such as a certain user's access behavior exceeds the set threshold, it determines that this behavior belongs to an abnormal permission behavior, and thus issues a warning message to notify the administrator for further investigation and handling.

[0124] In some alternative embodiments, the detection module can also be configured by means of building in Personally Identifiable Information (PII) and other information, and real-time detection and masking processing of sensitive information in structured (JSON data, KV data, golang map) and unstructured data (such as multilingual strings) are realized through techniques such as keyword matching, regular expression engines, Natural Language Processing (NLP), and machine learning models.

[0125] For example, if it is detected that a user accesses the system log and the unstructured string therein contains the Vehicle Identification Number (VIN) or email information of the end user, the detection module can automatically perform desensitization processing according to the preset masking policy.

[0126] In some alternative embodiments, data collection points can be set at the key business systems and data access interfaces of each cloud platform to collect data such as the user's access behavior in real time, including information such as access time, accessed user, accessed resource, operation type, etc. The collected data is transmitted to the audit center through a secure network channel. In the audit center, big data storage technologies (such as the Hadoop distributed file system) are used to store the massive access behavior data.

[0127] Furthermore, a big data analysis framework (such as Apache Spark, a large-scale data computing engine) can also be used to perform real-time analysis and offline analysis on the stored data. Among them, real-time analysis is mainly used to analyze the user's real-time access behavior and promptly discover abnormal behaviors. For example, by setting thresholds such as access frequency thresholds and access resource type change thresholds, when the user's access behavior exceeds these thresholds, further analysis and alerts are triggered. Offline analysis is mainly used to deeply mine historical access data to discover potential security risks and abnormal behavior patterns. For example, through clustering analysis algorithms, the historical access behaviors of users can be clustered into different clusters, the behavior characteristics of each cluster are analyzed, and clusters with significant differences from the normal behavior pattern are found and regarded as potential abnormal behaviors for key attention.

[0128] It should be noted that the relevant information involved in the embodiments of the present disclosure is all information obtained after user authorization, and the information collection method, information storage method, etc. all comply with relevant regulations.

[0129] In summary, in the embodiments of the present disclosure, access characteristics of a target object during accessing a target device are obtained, where the target device is a device of a first cloud platform; a risk assessment is performed on the target object according to the access characteristics to obtain a risk assessment result; according to the risk assessment result, the access permission of the target object for the target device is dynamically adjusted; and, in the case where the risk level represented by the risk assessment result exceeds a preset level, a risk prompt message is sent to an associated device, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform. It can be seen from this that the present application can perform a risk assessment on a target object during the target object's access to the target device to obtain a corresponding risk assessment result, so as to dynamically adjust the access permission in a timely manner according to the risk assessment result, and send a risk prompt message to an associated device in another cloud platform when the risk is relatively high, so that target objects with risks can be synchronized in a timely manner among multiple cloud platforms, ensuring the consistency of the access control policy for the target object in a cross-cloud environment.

[0130] Figure 2 is a schematic architecture diagram of a multi-cloud scenario provided by an embodiment of the present application. As Figure 2 shown, the architecture of the multi-cloud scenario is a unified multi-cloud security management architecture including a data collection layer, a protocol conversion layer, a policy management layer, and a user interaction layer. Among them, the data collection layer is responsible for collecting data from each cloud platform; the protocol conversion layer is used to convert the protocols of different cloud platforms into a unified format for subsequent processing; the policy management layer is used to formulate and manage unified security policies (for example, access permission management policies); the user interaction layer provides an intuitive operation interface for administrators to achieve centralized control. Through this architecture, data distributed in different cloud platforms can be integrated and uniformly managed, providing a basis for subsequent security management.

[0131] In some alternative embodiments, for the data collection layer, data collection agents can be deployed at the edge nodes of each cloud platform. These data collection agents are based on a distributed architecture and cooperate with each other to collect various types of data (such as firewall logs, user login information, resource access records, etc.) of the cloud platform where they are located in parallel. Through the distributed parallel collection method, the efficiency of data collection can be effectively improved, and compared with the centralized collection method, the collection time can be significantly shortened.

[0132] Exemplarily, first analyze the network topology of the cloud platform to determine the appropriate positions of edge nodes. These edge nodes should have good network connections and computing resources to ensure the stable operation of the data collection agent. Then, customize and develop the data collection agent software according to the operating systems and environmental requirements of different cloud platforms to automatically discover and connect to cloud platform data sources. For example, relevant files can be configured or an automatic scanning mechanism can be set in the data collection agent to identify the firewall log file path, database table structure, etc., so as to achieve data collection.

[0133] During the data collection process, multi-threading and asynchronous processing technologies can be adopted to enable the data collection agent to simultaneously process the collection tasks of multiple data sources. For example, when collecting firewall logs, new generated log lines are read in real time while the collected log data is preliminarily processed and cached. In addition, to ensure the integrity and accuracy of data, a data verification mechanism can also be set. For example, a hash algorithm can be used to verify the collected data to ensure that the data has not been tampered with during transmission and storage.

[0134] In some alternative embodiments, for the protocol conversion layer, an intelligent protocol parsing system combining a rule library and a machine learning model can be constructed to achieve protocol conversion. For some common or known network protocols (such as HTTP, FTP, SMTP, etc.), detailed parsing rules can be formulated in advance. When the collected data conforms to the above network protocols, it can be parsed quickly and accurately. Exemplarily, key features can be extracted for common protocols and parsing rules can be determined. The parsing rules cover the syntax structure, semantic understanding, and context relationship of the protocol, etc. For example, for the HTTP protocol, rules such as request methods, URL formats, and meanings of header fields can be predefined in advance and stored in the rule library in a structured manner so that they can be quickly retrieved and matched when parsing data, thereby achieving data parsing.

[0135] In addition, for newly emerged or complex network protocols, machine learning algorithms (such as neural network algorithms in deep learning) can be used to perform pattern recognition and analysis on them, and then protocol conversion can be achieved. Exemplarily, when encountering a new private protocol for an Internet of Things device to communicate with a cloud platform, a machine learning model constructed by a machine learning algorithm can be used to learn the sample data based on the private protocol, gradually master the characteristics and structure of the private protocol, and thus achieve the parsing of the private protocol.

[0136] Among them, in some optional embodiments, when training a machine learning model, a large number of protocol data samples, including normal data and abnormal data, can be collected first. Then, the above-mentioned protocol data samples are preprocessed (such as data cleaning, feature extraction, and annotation, etc.), and the preprocessed samples are divided into a training set, a validation set, and a test set. At the same time, a deep learning framework (such as TensorFlow) is used, and a suitable model structure (such as a convolutional neural network or a recurrent neural network) is selected according to the characteristics of the protocol data to obtain an initial machine learning model. During the training process, the model parameters of the machine learning model are iteratively adjusted to optimize the model performance, and the accuracy and generalization ability of the model are evaluated through the validation set. Finally, a machine learning model that can accurately parse new protocols and complex protocols is obtained.

[0137] In some optional embodiments, for the policy management layer, a data conversion and mapping mechanism can be established based on the principle of data warehouse technology (Extract-Transform-Load, ETL). Exemplarily, the data formats collected from each cloud platform are different, and extraction operations are required. Before extraction, conversion operations are needed first. In the conversion stage, the collected data can be cleaned, filtered, and format-adjusted according to a predefined data model. For example, different field names and data types of user permission data from different cloud platforms are uniformly converted into a predefined standard format. After the conversion is completed, through the mapping relationship, the converted data can be loaded into the unified security management platform database to ensure the consistency and availability of the data. Through the above processing, no matter which cloud platform the data comes from, it can be stored and managed in a unified format, which is convenient for the subsequent formulation and execution of security policies.

[0138] Exemplarily, in the data extraction stage, according to the characteristics of different cloud platform data sources, corresponding technical means can be used for data extraction. For example, for relational databases, SQL query statements can be used to extract the required data; for log files, file reading and parsing tools can be used to extract key information according to specific format rules.

[0139] Exemplarily, during the data conversion process, a data conversion script can be written or a special data conversion tool (such as Apache NiFi) can be used to implement data conversion.

[0140] Exemplarily, when performing data mapping, a data mapping table can be established to clarify the correspondence between source data fields and target data fields. For example, map the "permission_level" field of user permission data in the AWS cloud platform to the "privilege_level" field in the unified data model. Through the data mapping table, the converted data can be accurately inserted into the corresponding tables and fields of the security management platform database during the data loading process. At the same time, to ensure data integrity and consistency, data verification can also be performed before data loading, such as checking whether required fields are empty and whether data types match, etc.

[0141] In some alternative embodiments, for the user interaction layer, the QUIC protocol based on UDP can be adopted for data transmission, and the transmitted data can be compressed. Exemplarily, at the data sending end, the QUIC protocol can be used to establish a high-speed connection to package and send the collected and converted data. At the same time, data compression algorithms (such as ZIP, GZIP, etc.) are used to compress the data to reduce the data transmission volume. Correspondingly, at the receiving end, the compressed data can be decompressed first and then subsequent processing can be performed. In this way, the data transmission time can be significantly shortened, improving the speed and reliability of data transmission, thereby ensuring that data can be transmitted to the security management platform in a timely manner, providing guarantee for real-time security monitoring and management.

[0142] For example, at the data sending end, first initialize the QUIC protocol stack, configure relevant parameters (such as connection timeout time, maximum transmission unit (MTU), etc.), and then encapsulate the collected and converted data in the format of the QUIC protocol, adding necessary header information and check fields. During the data encapsulation process, appropriate packet sizes and fragmentation strategies can be selected according to the size and characteristics of the data to improve transmission efficiency. At the same time, start a data compression thread to compress the encapsulated data. And, appropriate compression algorithms can be dynamically selected according to the type and characteristics of the data; for example, the GZIP algorithm can be used for text-type security log data to obtain better compression effects. During the data transmission process, the QUIC protocol utilizes its multiplexing feature to simultaneously transmit multiple data streams on the same connection, avoiding the head-of-line blocking problem in the TCP protocol. At the same time, through the fast retransmission and forward error correction mechanisms, reliable data transmission is guaranteed. At the receiving end, first receive the compressed data, and then call the corresponding decompression algorithm to decompress the data. The decompressed data is parsed by the QUIC protocol and restored to the original data format. Finally, the parsed data is passed to subsequent processing modules, such as the data storage module or real-time analysis module of the security management platform.

[0143] In summary, the embodiments of the present disclosure adopt an efficient data acquisition and protocol conversion engine, and use distributed data acquisition technology to deploy agents at the edge nodes of each cloud platform, so as to be able to collect a large amount of security data in parallel. At the same time, intelligent protocol parsing, data conversion and mapping, and high-speed data transmission technologies work together to break the security management barriers between cloud platforms, so as to be able to achieve centralized security control across clouds and achieve one-stop multi-cloud security management. Compared with the decentralized management mode in the related technologies, the security management efficiency is greatly improved, the labor cost of security management is effectively reduced, and the operation efficiency of administrators can also be improved.

[0144] In the field of access control, on the basis of the deep integration of ABAC and RBAC, multi-vendor compatibility is achieved based on a unified policy model and a policy compatibility layer. A dynamic user behavior and system data security degree model is introduced to construct a dynamic adaptive permission management model. Further, dynamic permission determination is performed in combination with multi-dimensional user attributes, user behaviors, data security degrees, etc., effectively alleviating the problem of permission abuse. In addition, intelligent audit technology is introduced, and technologies such as NLP and machine learning models are used to achieve real-time detection and automatic mask desensitization of PII information, and real-time detection and accurate identification of abnormal permission behaviors. This mode can reduce the occurrence of data leakage risks and permission abuse events compared with static access control and simple audit modes, and effectively improves the data security protection ability in a multi-cloud environment.

[0145] Figure 3 It is a schematic flowchart of a method for accessing in a multi-cloud scenario provided by an embodiment of the present application. As Figure 3 shown, the method may include the following steps.

[0146] Step S301, receive an access request sent by a target object.

[0147] Among them, the target object may be the terminal device of a user, and the embodiments of the present application do not limit this. For example, if a user wants to access a target device in the first cloud platform, the user may send the access request through his work terminal.

[0148] It should be noted that when a user sends an access request through a terminal device, the user needs to perform operations such as logging in on the terminal device so that the terminal device initiates the access request in the name of the user. In other words, if different users use the same terminal device to initiate access requests, the target device receiving the access requests can clearly know that the two access requests correspond to different users, so as to be able to allocate matching access permissions.

[0149] Step S302, determine the access permission of the target object for the target device based on the user role, user attributes, resource attributes, and environmental attributes of the target object, so that the target object can access the target device based on the access permission.

[0150] Among them, user role refers to a user identity assigned based on the user's position and ability in the business system. Attributes can generally refer to some inherent characteristics of things themselves. Specifically, user attributes are mainly used to describe the user's own characteristics, which can include the user's business experience, location, business field, etc. Resource attributes are mainly used to describe the attributes of the data resources to be accessed, which can include the security level of the data, the business field to which it belongs, etc. Environmental attributes are mainly used to describe some contextual information related to access, which can include geographic location, network address, whether the device is a controlled machine, etc.

[0151] From this, we can see that when determining the access rights of the target object to the target device, it is not based solely on the user role, but is determined in combination with user attributes, resource attributes, and environmental attributes. It is a permission determination method that integrates role-based access control (RBAC) and attribute-based access control (ABAC).

[0152] In some optional embodiments, a role database may be established first to store information of various user roles and their corresponding basic access rights. For example, in a role database of a certain enterprise, the stored user roles include ordinary employees and department heads, among which ordinary employees can perform daily business operation rights such as account query and transaction record viewing, and department heads have business approval, employee performance viewing and other rights in addition to the rights of ordinary employees. On this basis, a user attribute database may also be established to collect and store multi-dimensional attribute information of users, such as time of employment, business experience level, geographical location of the branch, business expertise, etc. In addition, a resource attribute database and an environmental attribute database may also be established, and data such as the security level of data and the category of the R&D project may be recorded in the resource attribute database, and data such as the geographical location, network address, and whether the device belongs to a controlled machine may be recorded in the environmental attribute database. When the target object initiates an access request, its basic access rights may be determined first according to the user role, and then the authority evaluation may be performed based on the pre-established policy rules and in combination with the user attributes, resource attributes, and environmental attributes, and finally the access rights of the target object may be determined.

[0153] Exemplarily, the policy rules include: Only the department heads with more than 5 years of work experience and in specific high-risk business regions have the right to access high-risk business data. Based on this, when a target object initiates an access request for a certain data (such as high-risk business data), the access permissions that the target object can obtain are judged based on user roles, user attributes, resource attributes, and environmental attributes, and in combination with the policy rules. For example, when the target object initiates an access request for high-risk business data, if the user role corresponding to the target object is a department head with more than 5 years of work experience and the work location is in a specific high-risk business region, it is allowed to access the high-risk business data; another example is that when the target object initiates an access request for high-risk business data, if the user role corresponding to the target object is an ordinary employee with more than 5 years of work experience and the work location is in a specific high-risk business region, it is not allowed to access the high-risk business data.

[0154] Step S303, obtain the access characteristics of the target object during the access to the target device.

[0155] Step S304, determine the identity credibility of the target object according to the identity characteristics.

[0156] Step S305, determine the behavior deviation degree of the target object according to the behavior characteristics and the benchmark behavior characteristics of the target object.

[0157] Step S306, determine the attribute security degree according to the attribute security characteristics.

[0158] Step S307, determine the data security degree according to the data security characteristics.

[0159] Step S308, obtain the risk assessment result according to at least one of the identity credibility, behavior deviation degree, attribute security degree, and data security degree.

[0160] Step S309, dynamically adjust the access permissions of the target object for the target device according to the risk assessment result.

[0161] Exemplarily, the access permissions of the target object for the target device can be determined based on the following methods.

[0162] if identity credibility ≥ 70 && behavior deviation degree ≤ 0.3 && attribute security degree ≥ 80:

[0163] Grant the complete RBAC+ABAC permissions

[0164] elseif identity credibility ≥ 60 && data security degree ≤ L3:

[0165] Grant the first restricted access permission (download speed ≤ 2MB / s), and prohibit access to restricted files

[0166] else if the attribute security control value < 60 || the behavior deviation degree > 0.7:

[0167] Trigger secondary authentication (face authentication + SMS verification)

[0168] else:

[0169] Block access and start traceability auditing

[0170] Step S310, when the risk level characterized by the risk assessment result exceeds the preset level, send a risk prompt message to the associated device. The risk prompt message is used to instruct the associated device to adjust the access permission of the target object. The associated device is a device of the second cloud platform.

[0171] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs, but without changing the core design of its algorithm and process, are within the protection scope of this patent.

[0172] The second aspect of this application provides an access device for a multi-cloud scenario.

[0173] Figure 4 It is a block diagram of the composition of an access device 400 for a multi-cloud scenario provided by an embodiment of this application. As Figure 4 shown, the access device 400 for the multi-cloud scenario includes the following modules.

[0174] The acquisition module 401 is used to acquire the access characteristics of the target object during the access to the target device. The target device is a device of the first cloud platform.

[0175] The evaluation module 402 is used to perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result.

[0176] The adjustment module 403 is used to dynamically adjust the access permission of the target object for the target device according to the risk assessment result.

[0177] The prompt module 404 is used to send a risk prompt message to the associated device when the risk level characterized by the risk assessment result exceeds the preset level. The risk prompt message is used to instruct the associated device to adjust the access permission of the target object. The associated device is a device of the second cloud platform.

[0178] The access device for the multi-cloud scenario provided in this embodiment includes an acquisition module configured to acquire the access characteristics of a target object during the access to a target device, where the target device is a device of a first cloud platform; an evaluation module configured to perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result; an adjustment module configured to dynamically adjust the access permission of the target object for the target device according to the risk assessment result; and a prompt module configured to send a risk prompt message to an associated device when the risk level indicated by the risk assessment result exceeds a preset level, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform. It can be seen that this application can perform a risk assessment on the target object during the access of the target object to the target device to obtain a corresponding risk assessment result, so as to dynamically adjust the access permission in a timely manner according to the risk assessment result, and send a risk prompt message to an associated device in another cloud platform when the risk is relatively high, so that multiple cloud platforms can synchronize the target objects with risks in a timely manner, ensuring the consistency of the access control policy for the target object in a cross-cloud environment.

[0179] It is worth mentioning that each module involved in this embodiment is a logical module. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovative part of the present invention, units that are not closely related to solving the technical problems proposed by the present invention are not introduced in this embodiment, but this does not mean that there are no other units in this embodiment.

[0180] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principle of the present invention, and the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.

Claims

1. An access method for a multi-cloud scenario, characterized in that, Including: Obtain the access characteristics of a target object during its access to a target device, where the target device is a device of a first cloud platform; Perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result; Dynamically adjust the access permission of the target object for the target device according to the risk assessment result; And, When the risk level characterized by the risk assessment result exceeds a preset level, send a risk prompt message to an associated device, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform.

2. The method according to claim 1, wherein Before obtaining the access characteristics of the target object during its access to the target device, the method further includes: Receive an access request sent by the target object; Determine the access permission of the target object for the target device based on the user role, user attributes, resource attributes, and environmental attributes of the target object, so that the target object can access the target device based on the access permission; Wherein, the user attributes, resource attributes, and environmental attributes are metadata attributes applicable to multiple cloud platforms; The performing a risk assessment on the target object according to the access characteristics to obtain a risk assessment result includes: When preset conditions are met, perform a risk assessment on the target object according to the access characteristics to obtain the risk assessment result; The preset conditions include at least one of the following: reaching a preset assessment period, receiving an assessment request, receiving a warning message.

3. The method according to claim 1, characterized in that, The access characteristics at least include identity characteristics, behavior characteristics, attribute security characteristics, and data security characteristics; The performing a risk assessment on the target object according to the access characteristics to obtain a risk assessment result includes: Determine the identity credibility of the target object according to the identity characteristics; Determine the behavior deviation degree of the target object according to the behavior characteristics and the baseline behavior characteristics of the target object; Determine the attribute security degree according to the attribute security characteristics; Determine the data security degree according to the data security characteristics; Obtain the risk assessment result according to at least one of the identity credibility, the behavior deviation degree, the attribute security degree, and the data security degree.

4. The method according to claim 3, wherein The identity characteristics include role sub-characteristics and terminal sub-characteristics, and the terminal sub-characteristics correspond to the terminal used by the target object to access the target device; The determining the identity credibility of the target object according to the identity characteristics includes: Determine the role credibility according to the role sub-characteristics; Determine the terminal credibility according to the terminal sub-characteristics; Obtain the identity credibility of the target object according to the role credibility and the terminal credibility.

5. The method according to claim 3, wherein The method further includes: Obtain the behavior characteristics of the target object within a first preset time period; Obtain the baseline behavior characteristics of the target object according to the behavior characteristics of the target object within the first preset time period.

6. The method according to claim 5, characterized in that The determining the behavior deviation degree of the target object according to the behavior characteristics and the baseline behavior characteristics of the target object includes: Input the behavior characteristics into a user behavior baseline model to obtain the behavior deviation degree of the target object; Among them, the user behavior baseline model is obtained by training an initial user behavior baseline model according to the behavior characteristics of the target object within a first preset time period.

7. The method according to claim 3, wherein The attribute security features include the user attribute features of the target object, the resource attribute features of the accessed data, the environmental attribute features of the target object, and the operation attribute features of the target object on the accessed data; Determining the attribute security degree according to the attribute security features includes: Obtaining a first sub-security value according to the matching degree between the user attribute features of the target object and the resource attribute features of the accessed data; Obtaining a second sub-security value according to the matching degree between the environmental attribute features of the target object and the resource attribute features of the target object; Obtaining a third sub-security value according to the operation attribute features of the target object on the accessed data; Obtaining the attribute security degree according to the first sub-security value, the second sub-security value, and the third sub-security value.

8. The method according to claim 3, wherein The data security features include the security level of the accessed data; Determining the data security degree according to the data security features includes: When the access frequency of the accessed data within a second preset time period is less than or equal to a preset access frequency threshold, determining the data security degree according to the security level of the accessed data; When the access frequency of the accessed data within a second preset time period is greater than the preset access frequency threshold, adjusting the security level of the accessed data based on a preset adjustment strategy, and determining the data security degree according to the adjusted security level.

9. The method according to claim 1, wherein Dynamically adjusting the access permission of the target object for the target device according to the risk assessment result includes: When the risk level represented by the risk assessment result is the first level, granting the target object full access permission for the target device; When the risk level represented by the risk assessment result is the second level, granting the target object a first restricted access permission for the target device; When the risk level represented by the risk assessment result is the third level, initiating an identity authentication operation for the target object, and granting the target object a second restricted access permission for the target device when the target object passes the identity authentication.

10. An access device for a multi-cloud scenario, characterized in that, It includes: An acquisition module, configured to acquire the access characteristics of a target object during accessing a target device, where the target device is a device of a first cloud platform; An evaluation module, configured to perform a risk assessment on the target object according to the access characteristics to obtain a risk assessment result; An adjustment module, configured to dynamically adjust the access permission of the target object for the target device according to the risk assessment result; A prompt module, configured to send a risk prompt message to an associated device when the risk level represented by the risk assessment result exceeds a preset level, where the risk prompt message is used to instruct the associated device to adjust the access permission of the target object, and the associated device is a device of a second cloud platform.