Method of access control, control plane, service grid proxy, medium, computer program

By generating verification codes on the control surface, the access control process between microservices is simplified, the verification process redundancy and data traffic consumption are solved, the performance of the service mesh agent is improved, and the first packet attack is avoided.

CN120582801APending Publication Date: 2025-09-02ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410874031.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-06-29
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

There are problems in existing microservice access control with redundant verification process, large data traffic consumption, serious performance loss and first packet attacks.

Method used

Authorization verification is performed through the control surface, verification code is generated, and verification is completed by simple interaction between service grid agents, simplifying the verification process, reducing data traffic consumption, and avoiding first-packet attacks.

Benefits of technology

It has realized simplified verification process, reduced data traffic consumption, avoided first packet attacks, and improved the performance of service mesh agents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582801A_ABST
    Figure CN120582801A_ABST
Patent Text Reader

Abstract

The invention provides an access control method, which is executed by a control plane, and comprises the following steps: receiving an access request from a first service grid agent; the access request is a request that the first service grid agent accesses a second service grid agent, the first service grid agent corresponds to a first micro-service, and the second service grid agent corresponds to a second micro-service; performing authorization verification on the first micro-service and the second micro-service; and sending a verification code generated at least based on a first identifier of the first micro-service, a second identifier of the second micro-service and a preset key to the first service grid agent in response to the passing of the authorization verification. The invention also provides an access control method, a control plane, a first service grid agent, a second service grid agent, a computer readable medium and a computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of access control for microservices, and in particular to an access control method, a control plane, a first service mesh agent, a second service mesh agent, a computer-readable medium, and a computer program product. Background Art

[0002] Microservices (such as cloud-native microservices) need to be verified before accessing each other to implement access control. However, existing access control has problems such as redundant verification processes, large data traffic consumed by verification, large performance loss on service grid agents, and easy occurrence of attacks. Summary of the Invention

[0003] The present disclosure provides an access control method, a control plane, a first service grid agent, a second service grid agent, a computer-readable medium, and a computer program product.

[0004] In a first aspect, an embodiment of the present disclosure provides an access control method, performed by a control plane, the method comprising:

[0005] Receive an access request from a first service mesh proxy, wherein the access request is a request by the first service mesh proxy to access a second service mesh proxy, the first service mesh proxy corresponding to a first microservice, and the second service mesh proxy corresponding to a second microservice;

[0006] Performing authorization verification on the first microservice and the second microservice;

[0007] In response to the authorization verification being passed, a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key is sent to the first service grid agent.

[0008] In a second aspect, an embodiment of the present disclosure provides an access control method, performed by a first service grid agent, the method comprising:

[0009] Sending an access request to the control plane; the access request is a request for the first service mesh proxy to access the second service mesh proxy, the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to the second microservice;

[0010] Receive a verification code sent by the control plane; the verification code is generated based on at least a first identifier of the first microservice, a second identifier of the second microservice, and a preset key;

[0011] Sending the verification code and the first identifier to the second service grid agent;

[0012] Establish a connection with the second service mesh proxy.

[0013] In a third aspect, an embodiment of the present disclosure provides an access control method, performed by a second service grid agent, the method comprising:

[0014] Receiving a verification code and a first identifier of a first microservice from a first service mesh proxy; the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to a second microservice, the verification code being generated based on at least the first identifier, the second identifier of the second microservice, and a preset key;

[0015] generating a local verification code based at least on the received first identifier, the second identifier, and the preset key;

[0016] In response to the local verification code being identical to the verification code, establishing a connection with the first service mesh proxy.

[0017] In a fourth aspect, an embodiment of the present disclosure provides a control plane, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0018] In a fifth aspect, an embodiment of the present disclosure provides a first service grid agent, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0019] In a sixth aspect, an embodiment of the present disclosure provides a second service grid agent, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0020] In a seventh aspect, an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processor, it implements any one of the access control methods of the embodiments of the present disclosure.

[0021] In an eighth aspect, an embodiment of the present disclosure provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements any access control method of the embodiment of the present disclosure.

[0022] In the disclosed embodiment, when the first microservice wants to access the second microservice, the first service grid agent only needs to send an access request to the control plane (the second service grid agent does not need to send a request), and the control plane only needs to send the verification code to the first service grid agent based on the result of the authorization verification, and then complete the verification and establish a connection through simple interaction between the first service grid agent and the second service grid agent, thereby simplifying the verification process, eliminating redundancy in the verification process, and reducing the data traffic consumed by the verification. Since the verification between the first service grid agent and the second service grid agent is implemented through the verification code, the first packet of the first service grid agent can directly send the verification code to the second service grid agent, so there is no first packet attack problem. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In the accompanying drawings of the embodiments of the present disclosure:

[0024] Figure 1 A flowchart of a method for access control of a control plane provided in an embodiment of the present disclosure;

[0025] Figure 2 A flowchart of a method for access control of a first service grid proxy provided by an embodiment of the present disclosure;

[0026] Figure 3 A flowchart of a method for access control of a second service grid proxy provided by an embodiment of the present disclosure;

[0027] Figure 4 A block diagram of the composition of a control plane provided in an embodiment of the present disclosure;

[0028] Figure 5 A block diagram of a first service grid proxy provided in an embodiment of the present disclosure;

[0029] Figure 6 A block diagram of the composition of a second service grid proxy provided in an embodiment of the present disclosure;

[0030] Figure 7 A block diagram of a computer-readable medium according to an embodiment of the present disclosure;

[0031] Figure 8 This is a schematic diagram of the service grid architecture;

[0032] Figure 9 A logic process diagram of a control method in the related art;

[0033] Figure 10 A logical process diagram of another access control method provided by an embodiment of the present disclosure;

[0034] Figure 11A signaling diagram of a TLS connection establishment process in another access control method provided by an embodiment of the present disclosure;

[0035] Figure 12 A logical process diagram of another access control method provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0036] To enable those skilled in the art to better understand the technical solution of the present disclosure, the access control method, control plane, first service grid agent, second service grid agent, computer-readable medium, and computer program product provided in the embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0037] The present disclosure will be described more fully hereinafter with reference to the accompanying drawings, but the illustrated embodiments may be embodied in different forms, and the present disclosure should not be construed as limited to the embodiments set forth below. Rather, these embodiments are provided so that the present disclosure will be thorough and complete and will fully understand the scope of the present disclosure to those skilled in the art.

[0038] The accompanying drawings of the embodiments of the present disclosure are used to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the detailed embodiments, they are used to explain the present disclosure and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art by describing the detailed embodiments with reference to the accompanying drawings.

[0039] The present disclosure may be described with reference to plan views and / or cross-sectional views by way of ideal schematic views of the present disclosure. Therefore, the exemplary illustrations may be modified according to manufacturing techniques and / or tolerances.

[0040] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.

[0041] The terms used in this disclosure are only used to describe specific embodiments and are not intended to limit the disclosure. As used in this disclosure, the term "and / or" includes any and all combinations of one or more related enumerated items. As used in this disclosure, the singular forms "a" and "the" are also intended to include plural forms, unless the context clearly indicates otherwise. As used in this disclosure, the terms "comprising" and "made of" specify the presence of the features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof.

[0042] Unless otherwise defined, all terms (including technical and scientific terms) used in this disclosure have the same meanings as those commonly understood by those skilled in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined in this disclosure.

[0043] The present disclosure is not limited to the embodiments shown in the drawings, but includes modifications of the configurations formed based on the manufacturing process. Therefore, the regions illustrated in the drawings have schematic properties, and the shapes of the regions shown in the drawings illustrate the specific shapes of the regions of the elements, but are not intended to be limiting.

[0044] A microservice is a small, independent service that communicates through a software-defined API (application programming interface) and can be used in applications such as cloud environments (such as cloud-native microservices).

[0045] Service mesh is an infrastructure layer used to implement communication between microservices. Figure 8 , each microservice can be deployed with a corresponding service grid proxy, so that communication between microservices can be achieved through communication between corresponding service grid proxies.

[0046] Among them, in order to achieve traffic management and security monitoring, different microservices need to be verified before accessing each other, that is, there must be a certain access control process.

[0047] In some related technologies, the Istio architecture can be used to manage service grids and microservices based on the mTLS (Mutual Transport Layer Security) protocol.

[0048] Reference Figure 8 According to the Istio architecture, the control plane (specifically, the device on the control plane) includes the Mixer component and the Pilot component.

[0049] Among them, the Mixer component can perform authorization verification (first-layer security policy detection) on microservices through its Istio-policy module, that is, authenticate and limit microservices according to predefined rules to ensure that only microservices that comply with the rules can be authorized. Authorization verification can specifically include blacklist and whitelist checks, log checks, quota resource checks, authorization model (such as RBAC, ABAC, etc.) checks, etc.

[0050] The Pilot component can distribute network policies customized by the user API of the Kubernetes platform to the service mesh proxy on the data plane through the Network API module. For example, it can distribute access control lists (ACLs) (which can be pre-set by the administrator or dynamically distributed during communication) to the ACL module of the service mesh proxy for sidecar proxying. An ACL is a list of multi-attribute tags based on identity that the service mesh proxy understands, such as a YAML file with executable authorization types for Kubernetes.

[0051] Therefore, the ACL module of the service grid agent can perform ACL verification (second-layer security policy detection) on the inbound and outbound traffic based on the ACL, that is, check whether the microservice generating the traffic is allowed to access in the ACL.

[0052] At the same time, the service grid agent also includes a communication module, which can communicate with the communication modules of other service grid agents and communicate with the Mixer component.

[0053] It should be understood that the above service grid architecture may also include other components, modules, etc.

[0054] For example, the control plane can also include Galley components, which can be used for configuration verification (verifying the Istio API configuration written by the user to ensure the correctness and validity of the configuration), configuration extraction / processing / distribution (obtaining user configuration from the K8S platform and processing it into a format that can be understood and used by other Istio components, and then distributing it to each required component) and other tasks.

[0055] For example, the control plane can also be verified (third-layer security policy detection) through models such as third-party engines (such as the open source tool OPA GateKeeper), providing a more fine-grained access control mechanism.

[0056] Reference Figure 9 When the first microservice wants to access the second microservice, the verification process includes:

[0057] A000 and the Pilot component send corresponding ACLs (ACL1 and ACL2) to each service grid agent (the first service grid agent and the second service grid agent).

[0058] A001. When the first microservice wants to access the second microservice, it sends an access request to the Mixer component through the first service grid proxy.

[0059] A002. The Mixer component performs authorization verification on the first microservice based on the access request.

[0060] A003. The Mixer component sends a response (approval or rejection) to the access request to the first service grid agent.

[0061] A004. If passed, the first service grid agent performs ACL verification on the second microservice based on its own ACL1.

[0062] A005. If successful, the first service mesh proxy initiates a TLS (Transport Layer Security) connection to the second service mesh proxy of the second microservice.

[0063] A006. The second service grid agent sends an access request to the Mixer component.

[0064] A007. The Mixer component performs authorization verification on the second microservice based on the access request.

[0065] A008. The Mixer component sends a response (approval or rejection) to the access request to the second service grid proxy.

[0066] A009. If passed, the second service grid agent performs ACL verification on the first microservice based on its own ACL2.

[0067] A010. If successful, the second service mesh proxy issues its own TLS certificate (cert2) to the first service mesh proxy.

[0068] After subsequent certificate verification (such as an X.509 certificate or a CA certificate, etc.), a TLS connection can be established between the first service mesh proxy and the second service mesh proxy.

[0069] Among them, after passing the verification, each service grid agent can also report logs, monitoring and other data to the Mixer component to complete the audit work.

[0070] However, according to the above verification method, the first service mesh agent and the second service mesh agent must request authorization from the control plane respectively, which causes redundant verification process. The data traffic consumed by verification (including data traffic within the data plane and data traffic between the data plane domain and the control plane) is also large, which has a great impact on the performance of the service mesh agent. In particular, as the interaction between microservices becomes more and more frequent and the number of verifications increases, the above problems will become more and more serious. Moreover, the first service mesh agent can initiate a connection to the second service mesh agent only after passing the authorization verification. Otherwise, it will cause a first-packet attack (such as a first-packet DDoS attack).

[0071] In a first aspect, an embodiment of the present disclosure provides an access control method, which is performed by a control plane.

[0072] Reference Figure 1 The access control method of the embodiment of the present disclosure includes:

[0073] S101. Receive an access request from a first service grid agent.

[0074] The access request is a request from the first service mesh proxy to access the second service mesh proxy, the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to the second microservice.

[0075] S102: Perform authorization verification on the first microservice and the second microservice.

[0076] S103: In response to the authorization verification being passed, a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key is sent to the first service grid proxy.

[0077] The disclosed embodiments are used for a control plane (such as a device on the control plane) to perform access control on multiple microservices. Each microservice has a corresponding service mesh proxy, and microservices, as well as microservices and the control plane, can interact through the service mesh proxy.

[0078] Among them, each microservice has a corresponding identifier, that is, a tag that can uniquely indicate the identity of the microservice, such as an identity identifier (SVID, Service Identity). Therefore, each microservice and its service mesh agent "know" its own identifier, and the control plane knows the identifiers of all microservices.

[0079] Among them, the control plane will also pre-send the preset key (MSK) to each service grid agent.

[0080] It should be understood that the first microservice (first service grid agent) and the second microservice (second service grid agent) in the embodiments of the present disclosure are respectively the source service and the destination service in a "one" access process, rather than permanent identities. That is, a microservice (service grid agent) may be the first microservice (first service grid agent) in some access processes and the second microservice (second service grid agent) in other access processes, and is not involved in other access processes.

[0081] In the embodiment of the present disclosure, when the first microservice (source service) wants to access the second microservice (destination service), an access request can be sent to the control plane (such as the Mixer component) through the first service mesh agent, and the control plane can perform authorization verification (such as blacklist and whitelist check, log check, quota resource check, authorization model check, etc.) on the first microservice and the second microservice based on the access request.

[0082] If the above authorization verification is passed, the control plane can calculate a verification code (code) according to the first identifier (SVID1) of the first microservice, the second identifier (SVID2) of the second microservice, and the preset key (MSK) according to a certain algorithm (such as a hash operation), and send the verification code to the first service grid agent.

[0083] Therefore, if the first service mesh proxy can receive the verification code, it means that the verification of the first microservice and the second microservice has passed, and the verification code can continue to be used to connect to the second service mesh proxy.

[0084] In the disclosed embodiment, when the first microservice wants to access the second microservice, the first service grid agent only needs to send an access request to the control plane (the second service grid agent does not need to send a request), and the control plane only needs to send the verification code to the first service grid agent based on the result of the authorization verification, and then complete the verification and establish a connection through simple interaction between the first service grid agent and the second service grid agent, thereby simplifying the verification process, eliminating redundancy in the verification process, and reducing the data traffic consumed by the verification. Since the verification between the first service grid agent and the second service grid agent is implemented through the verification code, the first packet of the first service grid agent can directly send the verification code to the second service grid agent, so there is no first packet attack problem.

[0085] In some embodiments, sending a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key to the first service mesh proxy (S103) includes:

[0086] S103A: Send a verification code generated based on the anti-replay parameter, the first identifier, the second identifier, and the preset key to the first service grid proxy.

[0087] As one method of an embodiment of the present disclosure, when generating a verification code, an "anti-replay parameter" may be used as one of the generation factors, so that the calculated verification code can resist replay attacks.

[0088] The anti-replay parameter refers to a parameter that can make the calculated verification code have an anti-replay property, such as a timestamp, a serial number, etc.

[0089] In some embodiments, sending a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key to the first service mesh proxy (S103) includes:

[0090] S1031. Perform ACL verification on the second microservice according to the first access control list of the first microservice, and perform ACL verification on the first microservice according to the second access control list of the second microservice.

[0091] S1032: In response to the ACL verification being passed, sending a verification code generated based on at least the first identifier, the second identifier, and the preset key to the first service grid proxy.

[0092] As a method of an embodiment of the present disclosure, the control plane (such as the Pilot component) can also perform ACL verification on the second microservice and the first microservice according to the first access control list (ACL1) and the second access control list (ACL2), that is, verify whether the two microservices are in each other's access control list, and only send a verification code to the first service grid agent if the ACL verification is also passed.

[0093] Therefore, in the embodiment of the present disclosure, the ACL verification of the microservice is actually performed by the control plane (such as the Pilot component). As long as the service grid agent can receive the verification code, it means that the ACL verification has passed, and thus it does not need to perform ACL verification itself, which reduces the amount of calculation and data transmission on the data plane and improves the performance of the service grid agent.

[0094] There are various ways for the control plane to perform the above ACL verification.

[0095] For example, after the Mixer component passes the authorization verification, it can notify the Pilot component, and the Pilot component then performs ACL verification. If it passes, it calculates the verification code and sends it.

[0096] For another example, the Mixer component may directly calculate the verification code after the authorization verification is passed and send it to the Pilot component, and the Pilot component may then perform ACL verification. If it passes, the verification code will be sent, otherwise, no verification code will be sent.

[0097] For example, authorization verification, ACL verification, verification code calculation, etc. can also be implemented by a multifunctional component in the verification surface.

[0098] In some embodiments, the method of the present disclosure further includes:

[0099] S1001. In response to the target microservice having an independent verification requirement, authorization verification is performed on the target microservice.

[0100] S1002: In response to the authorization verification being passed, a real-time access control list corresponding to the target microservice is generated according to the real-time situation.

[0101] S1003. Update the target access control list of the target microservice according to the real-time access control list.

[0102] As one embodiment of the present disclosure, any microservice (which may be the first microservice or the second microservice mentioned above, or other microservices) can be independently verified when needed (independent verification requirement); when there is such an independent verification requirement, the control plane (such as the Mixer component) can perform authorization verification on the corresponding target microservice. After the authorization verification is passed, it continues to calculate the real-time access control list (ACL0) for the current situation based on some current specific circumstances of the target microservice; thereafter, the control plane can update the original access control list of the target microservice based on the real-time access control list, such as the Pilot component merging ACL0 with the original ACL1 of the first microservice to obtain a new ACL1, which is then sent to the first service grid agent, so that the access control list of the microservice can be continuously changed according to the specific circumstances of the microservice.

[0103] Among them, the specific situations of "the target microservice has independent verification requirements" are diverse.

[0104] For example, a microservice may send an independent verification request to the control plane when it is deployed, updated, or when a predetermined period is reached.

[0105] Alternatively, the control plane (such as the Mixer component) can monitor each microservice and perform independent verification when certain conditions are met (such as when the microservice is deployed, updated, or reaches a predetermined period).

[0106] In a second aspect, an embodiment of the present disclosure provides a method for access control, which is performed by a first service grid agent.

[0107] Reference Figure 2 The access control method of the embodiment of the present disclosure includes:

[0108] S201. Send an access request to the control plane.

[0109] The access request is a request from the first service mesh proxy to access the second service mesh proxy, the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to the second microservice.

[0110] S202: Receive a verification code sent by the control plane.

[0111] The verification code is generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key.

[0112] S203: Send the verification code and the first identifier to the second service grid proxy.

[0113] S204. Establish a connection with the second service grid proxy.

[0114] In the embodiment of the present disclosure, when the first microservice (source service) wants to access the second microservice (destination service), it can send an access request to the control plane (such as the Mixer component) through the first service grid agent. If it can subsequently receive the verification code issued by the control plane, it means that the authorization verification of itself and the second microservice is passed. Therefore, the verification code (code) and its own first identifier (SVID1) can be sent to the second service grid agent. The first service grid agent will continue to verify based on this information. If it passes, it can establish a connection with the second service grid agent (such as establishing a TLS connection through certificate verification).

[0115] In some embodiments, sending the verification code and the first identifier to the second service mesh proxy (S203) includes:

[0116] S2031. Perform ACL verification on the second microservice according to the local first access control list.

[0117] S2032: In response to the ACL verification being passed, send the verification code and the first identifier to the second service grid agent.

[0118] As one method of an embodiment of the present disclosure, the first service grid agent may also perform ACL verification on the second microservice based on a first access control list (ACL1) issued in advance (such as issued by the Pilot component), and send a verification code only after passing.

[0119] It should be understood that if the control plane (such as the Pilot component) directly performs ACL verification, then the first service mesh proxy (and the second service mesh proxy) do not need to perform ACL verification.

[0120] It should be understood that the first microservice in the embodiment of the present disclosure may also serve as a target microservice to trigger independent verification by the control plane.

[0121] In a third aspect, an embodiment of the present disclosure provides an access control method, which is performed by a second service grid agent.

[0122] Reference Figure 3 The access control method of the embodiment of the present disclosure includes:

[0123] S301: Receive a verification code and a first identifier of a first microservice from a first service mesh agent.

[0124] The first service grid agent corresponds to the first microservice, the second service grid agent corresponds to the second microservice, and the verification code is generated based on at least the first identifier, the second identifier of the second microservice, and a preset key.

[0125] S302: Generate a local verification code based on at least the received first identifier, the second identifier, and the preset key.

[0126] S303: In response to the local verification code being the same as the verification code, establish a connection with the first service grid proxy.

[0127] In the embodiment of the present disclosure, when the first microservice (source service) wants to access the second microservice (destination service), it can send an access request to the control plane (such as the Mixer component) through the first service mesh agent, receive the verification code (code) issued by the control plane, and then send it together with the first identifier (SVID1) to the second service mesh agent.

[0128] Therefore, after receiving the verification code and the first identifier, the second service grid agent can calculate a local verification code (code') according to the first identifier and its own second identifier (SVID2) and the preset key (MSK) according to the same algorithm (such as hash operation), and compare the local verification code with the received verification code. If the two are the same, it indicates that the access request of the first microservice is legitimate, and thus a connection can be established with the first service grid agent (such as establishing a TLS connection through certificate verification).

[0129] In some embodiments, the verification code is generated based on the anti-replay parameter, the first identifier, the second identifier, and the preset key; generating the local verification code (S302) based on at least the received first identifier, the second identifier, and the preset key includes:

[0130] S302A: Generate a local verification code according to the anti-replay parameter, the received first identifier, the second identifier, and the preset key.

[0131] As one embodiment of the present disclosure, when the generation factors of the verification code also include anti-replay parameters (such as timestamp, sequence number), the anti-replay parameters are also added when calculating the corresponding local verification code.

[0132] In some embodiments, establishing a connection with the first service mesh proxy (S303) includes:

[0133] S3031. Perform ACL verification on the first microservice according to the local second access control list.

[0134] S3032. In response to the ACL verification being passed, establish a connection with the first service grid proxy.

[0135] As one method of an embodiment of the present disclosure, the second service grid agent can also perform ACL verification on the first microservice based on a second access control list (ACL2) issued in advance (such as issued by the Pilot component), and only establish a connection with it after passing the ACL verification.

[0136] It should be understood that if the control plane (such as the Pilot component) directly performs ACL verification, the second service mesh proxy (and the first service mesh proxy) do not need to perform ACL verification.

[0137] It should be understood that the second microservice in the embodiment of the present disclosure may also serve as a target microservice to trigger independent verification by the control plane.

[0138] Fourthly, refer to Figure 4 The embodiment of the present disclosure provides a control plane, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0139] Fifth, refer to Figure 5 The embodiment of the present disclosure provides a first service grid agent, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0140] Sixth aspect, refer to Figure 6 The embodiment of the present disclosure provides a second service grid agent, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any access control method of the embodiment of the present disclosure.

[0141] Seventh aspect, refer to Figure 7 The embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon. When the computer program is executed by a processor, any access control method of the embodiment of the present disclosure is implemented.

[0142] In an eighth aspect, an embodiment of the present disclosure provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements any access control method of the embodiment of the present disclosure.

[0143] Among them, the processor is a device with data processing capabilities, including but not limited to the central processing unit (CPU); the memory is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically such as SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) is connected between the processor and the memory, which can realize information exchange between the memory and the processor, including but not limited to the data bus (Bus), etc.

[0144] Example 1:

[0145] The following is an exemplary introduction to a specific access control method according to an embodiment of the present disclosure.

[0146] The access control method of the embodiment of the present disclosure can refer to Figure 8 Ist io architecture implementation.

[0147] Among them, the control plane (such as the equipment on the control plane) includes the Mixer component and the Pilot component; the Mixer component can perform authorization verification (first-layer security policy detection) on microservices through its Istio-policy module, such as blacklist and whitelist checks, log checks, quota resource checks, authorization model checks, etc.; the Pilot component of the control plane can send the access control list (ACL) (which can be preset by the administrator or dynamically sent during the communication process) to the ACL module of the service grid agent for sidecar proxying.

[0148] There are multiple microservices in the data plane, and each microservice has a corresponding service mesh agent. The service mesh agent includes an ACL module for ACL verification (second-layer security policy detection) and a communication module for communication.

[0149] In any specific access process, the microservice corresponding to the source service is called the first microservice, which corresponds to the first service grid agent, and the microservice corresponding to the destination service is called the second microservice, which corresponds to the second service grid agent.

[0150] The access control method of the embodiment of the present disclosure may include:

[0151] B0011. When the first microservice is deployed, the communication module of the first service grid agent sends an independent verification request to the Mixer component (there is an independent verification requirement).

[0152] B0012. The Mixer component performs authorization verification on the first microservice. If it passes, it generates an ACL0 (real-time access control list) for the first microservice based on the current situation and synchronizes the ACL0 to the Pilot component.

[0153] B0013. The Pilot component generates the full set of access control lists for the first microservice based on Network Policy, combining the received ACL0 and its own existing ACL1 corresponding to the first microservice, that is, updates ACL1, and sends the updated ACL1 to the first service grid agent through the Network API.

[0154] B0021. When the second microservice is deployed, the communication module of the second service grid agent sends an independent verification request to the Mixer component.

[0155] B0022. The Mixer component performs authorization verification on the second microservice. If it passes, it generates an ACL0 for the second microservice based on the current situation and synchronizes the ACL0 to the Pilot component.

[0156] B0023. The Pilot component generates the full set of access control lists for the second microservice based on Network Policy, combining the received ACL0 and its own existing ACL2 corresponding to the second microservice. That is, it updates ACL2 and sends the updated ACL2 to the second service grid agent through the Network API.

[0157] It should be understood that any microservice in the embodiments of the present disclosure can perform the above steps, and only the first microservice and the second microservice are used as examples for illustration.

[0158] It should be understood that microservices may also issue independent verification requests in other situations such as when updating, at a predetermined period, or the Mixer component may monitor each microservice to trigger subsequent work.

[0159] It should be understood that the above steps are executed when the preset conditions are met, and the description order and numbering order of the above steps and other steps do not represent the order in which they must occur in practice.

[0160] B003. The Mixer component periodically generates a preset root key MSK (preset key) and sends it to each grid service agent.

[0161] Among them, the security boundary granularity of MSK can be distinguished by namespace granularity or by role-binding service account (Service Count) of the RBAC mechanism.

[0162] Reference Figure 10 The access control method of the embodiment of the present disclosure further includes:

[0163] B101. The first microservice needs to access the second microservice (needs to establish a TLS connection), so it sends an access request to the Mixer component through the communication module of the first service grid proxy.

[0164] B102. The Mixer component determines whether the quota resources of the first microservice are met, and checks the first microservice and the second microservice according to the blacklist and whitelist and authorization model to determine whether the first microservice can access the second microservice (authorization verification).

[0165] B103. If possible, the Mixer component performs a hash operation on the anti-replay parameters (such as timestamp and sequence number), the identity identifier SVID1 of the first microservice, the SVID2 of the second microservice, and the MSK to obtain a code (verification code).

[0166] B104. The Mixer component sends the code to the communication module of the first service grid agent.

[0167] B105. The ACL module of the first service grid agent checks whether the protocol protocol and parameter argument of the second microservice are in ACL1 according to the pre-issued ACL1, and determines whether to allow the traffic of the second microservice (ACL verification).

[0168] B106. If allowed, the first service grid proxy initiates a TLS connection to the second service grid proxy through the communication module, and carries the code and its own SVID1 in the message.

[0169] B107. The first service grid agent performs a first-security attack check on the received message, receives the code and SVID1, performs a hash operation on the received SVID1 and the local anti-replay parameters, SVID2, and MSK to obtain code' (local verification code), and compares code' with the received code to see if they are the same.

[0170] B108. If they are the same, the ACL module of the second service grid agent checks whether the protocol protocol and parameter argument of the first microservice are in ACL2 according to the pre-issued ACL2, and determines whether to allow the traffic of the first microservice.

[0171] B109. If allowed, the second service mesh proxy continues to establish a TLS connection with the first service mesh proxy.

[0172] Reference Figure 11 The process of establishing a TLS connection between the first service mesh proxy and the second service mesh proxy may specifically include:

[0173] (Previous step) B106. The first service mesh proxy initiates a TLS connection to the second service mesh proxy through the communication module.

[0174] B1091. The second service mesh proxy sends the TLS certificate cert2 of the second microservice to the first service mesh proxy.

[0175] B1092. The first service grid agent verifies the received cert2.

[0176] If ACL1 exists in the ACL module of the first service grid agent, ACL1 can be used to perform ACL verification on cert2 first; if ACL1 does not exist, cert2 can be directly verified.

[0177] B1093. If successful, the first service mesh proxy sends the TLS certificate cert1 of the first microservice to the second service mesh proxy.

[0178] B1094. The second service grid agent verifies the received cert1.

[0179] Among them, if ACL2 exists in the ACL module of the second service grid agent, ACL2 can be used to perform ACL verification on cert1 first; if ACL2 does not exist, cert1 can be directly verified.

[0180] B1095. If successful, a TLS connection is established between the first service mesh proxy and the second service mesh proxy, and the Diffie-Hellman protocol is used to derive a symmetric key to encrypt data transmitted in the TLS connection.

[0181] B1096. In subsequent communications, the first service mesh agent and the second service mesh agent may decrypt incoming data using the symmetric key.

[0182] Among them, if the corresponding ACL exists in the ACL module of each service grid agent, the ACL can be used to verify the data before decryption; if it does not exist, it can be decrypted directly.

[0183] Example 2:

[0184] The following is an exemplary introduction to a specific access control method of an embodiment of the present disclosure, which is similar to Example 1.

[0185] The difference is that in Example 2, ACL verification is performed by the Pilot component on the control plane, so the service mesh proxy on the data plane does not need to directly perform ACL verification, and the Pilot component does not need to deliver the ACL.

[0186] Reference Figure 12 The access control method of the embodiment of the present disclosure includes:

[0187] C101: The first microservice needs to access the second microservice (needs to establish a TLS connection), so it sends an access request to the Mixer component through the communication module of the first service grid proxy.

[0188] C102, the Mixer component determines whether the quota resources of the first microservice are met, and checks the first microservice and the second microservice according to the blacklist and whitelist and the authorization model to determine whether the first microservice can access the second microservice.

[0189] C103. If so, the Mixer component sends the verification result to the Pilot component.

[0190] C104. The Pilot component checks whether the protocol protocol and parameter argument of the second microservice are in ACL1, and checks whether the protocol protocol and parameter argument of the first microservice are in ACL2.

[0191] C105. If all checks pass, the Pilot component performs a hash operation on the anti-replay parameters, SVID1, SVID2, and MSK to obtain the code.

[0192] C106. The Pilot component sends the code to the communication module of the first service grid agent.

[0193] C107 . The first service mesh proxy initiates a TLS connection to the second service mesh proxy through the communication module, and carries the code and SVID1 in the message.

[0194] C108. The first service grid agent performs a first-security attack check on the received message, receives the code and SVID1, performs a hash operation on the received SVID1 and the local anti-replay parameters, SVID2, and MSK to obtain code' (local verification code), and compares code' with the received code to see if they are the same.

[0195] C109. If they are the same, the second service mesh proxy continues to establish a TLS connection with the first service mesh proxy.

[0196] Those skilled in the art will appreciate that all or some of the steps, systems, and functional modules / units in the apparatus disclosed above may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0197] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may be performed by several physical components in cooperation.

[0198] Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit (CPU), a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH) or other disk storage; compact disc (CD-ROM), digital versatile disc (DVD) or other optical disc storage; magnetic cassettes, tapes, disk storage or other magnetic storage; any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0199] The present disclosure has disclosed example embodiments, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.

Claims

1. A method for access control, performed by a control plane, comprising: receiving an access request from a first service mesh proxy; The access request is a request from the first service mesh proxy to access the second service mesh proxy, the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to the second microservice; Performing authorization verification on the first microservice and the second microservice; In response to the authorization verification being passed, a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key is sent to the first service grid agent.

2. The method according to claim 1, wherein The sending of a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key to the first service grid proxy includes: Perform ACL verification on the second microservice according to the first access control list of the first microservice, and perform ACL verification on the first microservice according to the second access control list of the second microservice; In response to the ACL verification being passed, the verification code generated based on at least the first identifier, the second identifier, and the preset key is sent to the first service grid agent.

3. The method according to claim 1, wherein Also includes: In response to the target microservice having an independent verification requirement, performing authorization verification on the target microservice; In response to the authorization verification being passed, generating a real-time access control list corresponding to the target microservice according to the real-time situation; According to the real-time access control list, the target access control list of the target microservice is updated.

4. The method according to claim 1, wherein The sending of a verification code generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key to the first service grid proxy includes: Send the verification code generated based on the anti-replay parameter, the first identifier, the second identifier, and the preset key to the first service grid agent.

5. A method of access control, performed by a first service grid agent, the method comprising: Send access request to the control plane; The access request is a request from the first service mesh proxy to access the second service mesh proxy, the first service mesh proxy corresponds to the first microservice, and the second service mesh proxy corresponds to the second microservice; Receiving a verification code sent by the control plane; The verification code is generated based on at least the first identifier of the first microservice, the second identifier of the second microservice, and a preset key; Sending the verification code and the first identifier to the second service grid agent; Establish a connection with the second service mesh proxy.

6. The method according to claim 5, wherein: The sending the verification code and the first identifier to the second service grid agent includes: Perform ACL verification on the second microservice according to the local first access control list; In response to the ACL verification being passed, sending the verification code and the first identifier to the second service grid agent.

7. A method of access control, performed by a second service grid agent, the method comprising: Receive a verification code and a first identifier of the first microservice from the first service mesh proxy; The first service grid agent corresponds to the first microservice, the second service grid agent corresponds to the second microservice, and the verification code is generated based on at least the first identifier, the second identifier of the second microservice, and a preset key; generating a local verification code based at least on the received first identifier, the second identifier, and the preset key; In response to the local verification code being identical to the verification code, establishing a connection with the first service mesh proxy.

8. The method according to claim 7, wherein: Establishing a connection with the first service grid proxy includes: Perform ACL verification on the first microservice according to the local second access control list; In response to the ACL verification being passed, establishing a connection with the first service grid proxy.

9. The method according to claim 7, wherein: The verification code is generated based on the anti-replay parameter, the first identifier, the second identifier, and the preset key; Generating a local verification code at least based on the received first identifier, the second identifier, and the preset key includes generating the local verification code based on the anti-replay parameter, the received first identifier, the second identifier, and the preset key.

10. A control plane comprising a memory and a processor; the memory stores a computer program executable by the processor, and the computer program, when executed by the processor, implements the access control method according to any one of claims 1 to 4.

11. A first service grid agent, comprising a memory and a processor; the memory stores a computer program executable by the processor, and the computer program implements the access control method according to claim 5 or 6 when executed by the processor.

12. A second service grid agent, comprising a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements the access control method described in any one of claims 7 to 9.

13. A computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the access control method according to any one of claims 1 to 9 is implemented.

14. A computer program product comprising a computer program, wherein when the computer program is executed by a processor, the access control method according to any one of claims 1 to 9 is implemented.