Attribute-based access control method and system and related equipment

By using the interval format to describe the attribute condition value in the access control policy, the problems of lengthy policies and low authentication efficiency caused by too many condition values ​​in the existing technology are solved, and more concise and efficient access control is achieved.

CN120602105APending Publication Date: 2025-09-05HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410244661.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In existing access control policies, the excessive number of conditional values ​​leads to lengthy policies, increases administrator workload, reduces authentication efficiency, and fails to effectively restrict port number ranges.

Method used

The interval format is used to describe the attribute condition value in the access control policy. By comparing the target value with the upper and lower bounds of the interval, it is determined whether to allow or deny the operation, which simplifies the policy configuration and authentication process.

Benefits of technology

It reduces the workload of administrators in configuring access control policies, shortens the length of policies, and improves authentication efficiency and simplicity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602105A_ABST
    Figure CN120602105A_ABST
Patent Text Reader

Abstract

The invention provides an attribute-based access control method and system and related equipment, and the method comprises the steps that access control equipment determines an access control strategy according to an identifier of a first operation in a received authentication request, then determines an authentication result according to the authentication request and the access control strategy, and sends the authentication result to resource providing equipment. Wherein the authentication request comprises an identifier of the first operation and a target value of the first attribute; the access control strategy comprises an identifier of the first operation, an interval upper bound and an interval lower bound of a first value interval of the first attribute and a comparison mode, and the comparison mode indicates that the resource providing device is allowed / rejected to execute the first operation when the target value is within the first value interval; whether the target value is within the first value interval is determined by comparing the target value with an interval upper bound and an interval lower bound of the first value interval; the authentication result is used for indicating whether the resource providing equipment executes the first operation. According to the scheme, the access control strategy can be simplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of access control, and in particular to an attribute-based access control method, system, and related equipment. Background Art

[0002] Access control is a security mechanism that allows only authorized entities to access resources (such as computing resources, communication resources, and information resources) and prevents unauthorized entities from accessing resources. Attribute-based access control (ABAC) defines a model for implementing access control. It first collects the target values ​​of the attributes used for authentication (referred to as authentication attribute information). Then, based on the collected authentication attribute information and the access control policy established by the administrator, it evaluates whether the entity is authorized to perform the corresponding operation.

[0003] Access control policies can usually be formulated using an access policy language. Access control policies include operation identifiers, conditional operators, attributes (such as identity attributes, environment attributes, or resource attributes. Administrators can select appropriate attributes based on control requirements), and corresponding conditional values ​​for the attributes. The operation identifier is used to indicate which operation the access control policy targets. The conditional operator is used to indicate the comparison method between the target value of the attribute in the authentication attribute information and the conditional value of the same attribute in the access control policy. Currently, the access policy language provides six semantic conditional operators: equal, unequal, less than, less than or equal to, greater than, and greater than or equal to. Since the current syntax of the access policy language requires that the conditional values ​​of the attributes in the access control policy be listed one by one, when the number of conditional values ​​is too large, the access control policy will be too lengthy.

[0004] For example, an administrator creates an access control policy for a virtual private cloud (VPC) scenario that includes "vpc:firewalls:update," "NumberEquals," "vpc:FirewallAllowDestinationPort," and [443,444,445]. "vpc:firewalls:update" identifies the firewall update operation within the VPC; "vpc:FirewallAllowDestinationPort" is an attribute representing the destination port number allowed by the firewall; [443,444,445] is an array listing the three conditional values ​​443, 444, and 445 for the aforementioned attribute; and "NumberEquals" is a conditional operator representing "numeric equality." Therefore, this access control policy restricts the firewall update operation within the VPC. During actual authentication, the target value of the aforementioned attribute in the authentication attribute information is compared with the conditional value of the same attribute in the access control policy to determine whether the two satisfy "NumberEquals," thereby determining whether the subject is authorized to perform the operation.

[0005] As can be seen, the above example restricts port numbers 443 to 445. Given that the network port range is 0 to 65535, if the administrator wants to impose similar restrictions on port numbers 10000 to 20000, then the access control policy must list all port numbers in the range as an array. This not only increases the administrator's workload but also makes the access control policy overly lengthy, increasing the complexity of authentication decisions based on the access control policy and reducing authentication efficiency.

[0006] Due to the grammatical requirements of the current access policy language, the statement blocks containing different conditional operators in the access control policy use "AND" operation logic, resulting in the inability to achieve the above-mentioned restriction purpose on all port numbers in the range of 10000 to 20000 even by combining multiple conditional operators.

[0007] For example, an access control policy in a VPC scenario includes "vpc:firewalls:update" (an operation identifier) ​​and two statement blocks. The first statement block includes "vpc:firewalls:update," "NumberGreaterThanEquals" (a conditional operator indicating greater than or equal to), "vpc:FirewallAllowDestinationPort" (an attribute), and the conditional value 10000 for that attribute. This determines whether the target value of the attribute in the authentication attribute information and the conditional value 10000 of the attribute in the access control policy satisfy "NumberGreaterThanEquals." The second statement block includes "vpc:firewalls:update," "NumberlessThanEquals" (a conditional operator indicating less than or equal to), "vpc:FirewallAllowDestinationPort" (an attribute), and the conditional value of 20000 for this attribute. This determines whether the target value of the attribute in the authentication attribute information satisfies the "NumberlessThanEquals" condition with the conditional value of 20000 for this attribute in the access control policy. Because the statement blocks containing different conditional operators use "AND" logic, actual authentication based on the access control policy determines whether the target value of the attribute in the authentication attribute information is greater than or equal to the conditional value of 10000 for this attribute in the first statement block, and also whether the target value of the attribute in the authentication attribute information is less than or equal to the conditional value of 20000 for this attribute in the second statement block. If both of these determinations are "yes," the authentication result based on the access control policy is a rejection.

[0008] Assume that the authentication attribute information contains two target values ​​for the aforementioned attribute, given as an array: [9999, 20001]. Based on the above access control policy, authentication is performed. Since 20001 in [9999, 20001] is greater than 10000, it satisfies the first block's requirements. Furthermore, since 9999 in [9999, 20001] is less than 20000, it also satisfies the second block's requirements, resulting in a denied authentication result. However, ports 9999 and 20001 are not within the administrator's intended restriction range of 10000 to 20000. Therefore, operations on these ports should be permitted. Therefore, the above access control policy fails to achieve the administrator's intended restriction. Summary of the Invention

[0009] The present application provides an attribute-based access control method, system, and related devices that can simplify access control policies and thereby improve authentication efficiency.

[0010] In the first aspect, the present application provides an attribute-based access control method, which is applied to an access control device. Specifically, the access control device first receives an authentication request sent by a resource provision device, then determines an access control policy based on the identifier of the first operation in the authentication request, and then determines an authentication result based on the authentication request and the access control policy, and sends the authentication result to the resource provision device. The authentication request includes the identifier of the first operation and the target value of the first attribute; the access control policy includes the identifier of the first operation, the upper bound and the lower bound of the first value interval of the first attribute, and a comparison method. The comparison method indicates that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicates that the resource provision device is denied to perform the first operation when the target value is within the first value interval. Whether the target value is within the first value interval is determined by comparing the target value with the upper bound and the lower bound of the first value interval; the authentication result is used to indicate whether the resource provision device performs the first operation.

[0011] It should be understood that the above-mentioned first attribute is an attribute used for authentication, which can be one or more attributes and is not specifically limited here. In the access control policy of this solution, the conditional value of the first attribute is described in an interval format, and the upper and lower bounds of the first value interval of the first attribute are specifically given. The values ​​within the first value interval are all conditional values ​​of the first attribute. Compared with the traditional solution of listing the corresponding conditional values ​​of attributes one by one in the form of an array in the access control policy, this solution provides a more concise and effective way to configure the access control policy, giving the corresponding conditional values ​​of the attributes in the form of an interval, which can not only reduce the workload of the administrator when configuring the access control policy, but also shorten the length of the access control policy.

[0012] Moreover, when the resource providing device makes an authentication decision based on the access control policy in the present application, it only needs to compare the target value of the first attribute in the authentication request with the upper and lower limits of the first value interval, without having to compare the target value with all the conditional values ​​in the access control policy one by one as in the traditional scheme, thereby reducing the complexity of the authentication decision based on the access control policy and improving the authentication efficiency.

[0013] Optionally, the access control policy includes upper bounds and lower bounds of multiple value intervals of the first attribute. These multiple value intervals may or may not have intersections. The above-mentioned first value interval may be any one of these multiple value intervals. At this time, the access control policy indicates that as long as the target value is within any one of these multiple value intervals, the resource providing device is allowed / denied to perform the first operation.

[0014] Optionally, the method of the first aspect can be applied to the cloud domain. The resource provision device is used to access cloud service resources, which may be stored in the infrastructure provided by the cloud service provider. The infrastructure may include at least one cloud data center, each of which includes at least one server. The types of cloud service resources and servers are not specifically limited herein. The resource provision device may determine whether to perform an operation to access cloud service resources for the user based on the authentication result provided by the access control device.

[0015] Based on the first aspect, in a possible implementation scheme, the authentication request further includes user information. The access control device can determine the access control policy based on the identifier of the first operation in the authentication request and the user information. The access control policy and the user information have a corresponding relationship. In other words, the access control device can also determine the access control policy required for this authentication process in combination with the user information. The access control device records the corresponding relationship between the access control policy and the user information. For example, an administrator can create different access control policies on the access control device. Different access control policies can correspond to the same or different user information. The user information can be a user identifier (ID), a user group, etc., which is not specifically limited here.

[0016] Based on the first aspect, in a possible implementation scheme, the authentication request includes multiple values ​​for the first attribute, and the target value is any one or all of the multiple values. For example, if the target value is any one of the multiple values, then the access control policy at this time indicates that as long as there is a value of the first attribute in the authentication request that is within the first value range set in the access control policy, the resource provision device is allowed / denied from performing the first operation. For another example, if the target value is all of the multiple values, then the access control policy at this time indicates that only if all values ​​of the first attribute in the authentication request are within the first value range set in the access control policy, the resource provision device is allowed / denied from performing the first operation.

[0017] Based on the first aspect, in a possible implementation scheme, the authentication request includes the upper limit of the second value interval of the first attribute and the lower limit of the second value interval, and the target value includes the upper limit and / or lower limit of the second value interval.

[0018] That is, similar to the conditional value of the first attribute given in interval format in the access control policy (i.e., the upper and lower bounds of the first value interval are given), another value interval of the first attribute can also be given in interval format in the authentication request (i.e., the second value interval, the upper and lower bounds of the second value interval are given), and the target value includes the upper and / or lower bounds of the second value interval. At this time, the authentication decision is made based on the access control policy and the authentication request, which is equivalent to comparing the first value interval of the first attribute with the second value interval. For example, if the target value includes the upper / lower bound of the second value interval, then the access control policy at this time indicates that as long as there is an intersection between the second value interval and the first value interval, that is, as long as the upper / lower bound of the second value interval can fall into the first value interval (by comparing with the upper and lower bounds of the first value interval), the resource provision device is allowed / denied to perform the first operation. For example, if the target value includes both the upper and lower limits of the second value interval, the access control policy indicates that the resource provision device is permitted / denied from performing the first operation only if the second value interval is a subset of the first value interval, i.e., all values ​​within the second value interval are within the first value interval. Furthermore, compared to traditional approaches that list attribute values ​​one by one in an array in an authentication request, this approach provides a more concise and efficient way to construct an authentication request, presenting attribute values ​​in interval form within the authentication request. This shortens the length of the authentication request and reduces the communication load and overhead between the access control device and the resource provision device.

[0019] Based on the first aspect, in a possible implementation, the access control device may receive an access control policy created by an administrator, store the access control policy if the access control policy passes verification, and provide the administrator with a notification of successful creation of the access control policy. Specifically, the access control device may receive the access control policy sent by the administrator, verify the access control policy, such as to see whether the format and values ​​of the access control policy are legal or comply with regulations, and provide the administrator with a notification of successful creation if the verification passes.

[0020] Based on the first aspect, in a possible implementation scheme, the type of the target value is a numerical value, a date, or an Internet Protocol (IP) address.

[0021] Based on the first aspect, in a possible implementation scheme, the above-mentioned first attribute includes at least one of identity attribute, environment attribute, and resource attribute. That is, appropriate attributes can be selected for authentication in the access control policy according to actual needs).

[0022] Based on the first aspect, in a possible implementation scheme, the interval type of the first value interval is an open interval, a closed interval, or a half-open interval.

[0023] In a second aspect, the present application also provides an attribute-based access control method, which is applied to a resource provision device. Specifically, the resource provision device first receives an execution request for a first operation initiated by a user, then collects authentication attribute information based on the execution request, generates an authentication request based on the authentication attribute information, then sends the authentication request to the access control device, and then receives the authentication result sent by the access control device, and then determines whether to execute the first operation for the user based on the authentication result. The authentication attribute information includes the upper bound and the lower bound of the second value interval of the first attribute; the authentication request includes the identifier of the first operation and the authentication attribute information.

[0024] In this solution, the resource provider can describe the second value range of the first attribute in an interval format in the authentication request, specifically providing the upper and lower bounds of the second value range. This allows the access control device to make authentication decisions based on these upper and lower bounds and the corresponding access control policy. Compared to traditional solutions that list the corresponding target values ​​of attributes in an array format in the authentication request, this solution provides a more concise and efficient way to generate authentication requests. By providing the corresponding target values ​​of attributes in interval format, it can effectively shorten the length of the authentication request and thus improve authentication efficiency.

[0025] Based on the second aspect, in a possible implementation, the authentication request further includes user information of the user. In other words, the authentication request may also carry user information for the access control device to determine a corresponding access control policy for authentication.

[0026] Based on the second aspect, in a possible implementation scheme, the type of the upper bound of the second value interval is a number, a date, or an IP address.

[0027] Based on the second aspect, in a possible implementation scheme, the first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

[0028] Based on the second aspect, in a possible implementation scheme, the interval type of the second value interval is an open interval, a closed interval, or a half-open interval.

[0029] In a third aspect, the present application also provides an access control device, comprising a transceiver module and a determination module. The transceiver module is used to receive an authentication request sent by a resource provision device, wherein the authentication request includes an identifier of a first operation and a target value of a first attribute. The determination module is used to determine an access control policy based on the identifier of the first operation in the authentication request, wherein the access control policy includes the identifier of the first operation, an upper bound and a lower bound of a first value interval of the first attribute, and a comparison method, wherein the comparison method indicates that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicates that the resource provision device is denied to perform the first operation when the target value is within the first value interval, and whether the target value is within the first value interval is determined by comparing the target value with the upper bound and the lower bound of the first value interval. The determination module is also used to determine an authentication result based on the authentication request and the access control policy, and send the authentication result to the resource provision device, wherein the authentication result is used to indicate whether the resource provision device performs the first operation.

[0030] The access control device may also include more or fewer units / modules, which is not specifically limited here. The access control device in the second aspect is specifically used to execute the method of any implementation scheme in the first aspect, which can be seen in the above introduction and will not be repeated here.

[0031] In a fourth aspect, the present application also provides a resource provision device, including a resource provision device, including a transceiver module, an acquisition module and a processing module. The transceiver module is used to receive an execution request for a first operation initiated by a user. The acquisition module is used to collect authentication attribute information according to the execution request, wherein the authentication attribute information includes the upper limit and the lower limit of the second value interval of the first attribute. The processing module is used to generate an authentication request based on the authentication attribute information and send the authentication request to the access control device, wherein the authentication request includes the identifier of the first operation and the authentication attribute information. The transceiver module is also used to receive the authentication result sent by the access control device. The processing module is also used to determine whether to perform the first operation for the user based on the authentication result.

[0032] The resource providing device may also include more or fewer units / modules, which is not specifically limited here. The resource providing device in the second aspect is specifically used to execute the method of any implementation scheme in the second aspect, which can be referred to the above description and will not be repeated here.

[0033] In the fifth aspect, the present application also provides an access control system, including an access control device and a resource providing device. The access control device is specifically used to execute a method as in any implementation scheme in the first aspect, and the resource providing device is specifically used to execute a method as in any implementation scheme in the second aspect. For details, please refer to the previous introduction and will not be repeated here.

[0034] In a sixth aspect, the present application further provides a computing device cluster, comprising at least one computing device, each computing device comprising a processor and a memory. The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method of any one of the embodiments of the first or second aspects.

[0035] In the seventh aspect, the present application also provides a computer-readable storage medium comprising computer program instructions. When the above-mentioned computer program instructions are executed by a computing device cluster (including at least one computing device), the computing device cluster executes the method of any embodiment in the first aspect or the second aspect.

[0036] In an eighth aspect, the present application further provides a computer program product comprising instructions. When the instructions are executed by a computing device cluster (including at least one computing device), the computing device cluster executes the method of any one of the embodiments of the first aspect or the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for describing the embodiments.

[0038] Figure 1 This is a schematic diagram of the basic structure of an access control strategy provided by an embodiment of the present application;

[0039] Figure 2 is a schematic diagram of an access control condition provided in an embodiment of the present application;

[0040] Figure 3 This is a schematic diagram of an access control policy in a virtual private cloud scenario provided by an embodiment of the present application;

[0041] Figure 4 This is a schematic diagram of another access control policy in a virtual private cloud scenario provided by an embodiment of the present application;

[0042] Figure 5 This is an architecture diagram of an access control system provided by an embodiment of the present application;

[0043] Figure 6 This is a flow chart of an attribute-based access control method provided in an embodiment of the present application;

[0044] Figure 7 This is a schematic diagram of another access control policy in a virtual private cloud scenario provided by an embodiment of the present application;

[0045] Figure 8 This is a schematic diagram of an authentication request provided by an embodiment of the present application;

[0046] Figure 9 This is a schematic diagram of part of the content in another authentication request provided in an embodiment of the present application;

[0047] Figure 10 This is a schematic diagram of an authentication process provided by an embodiment of the present application;

[0048] Figure 11 This is another authentication process diagram provided by an embodiment of the present application;

[0049] Figure 12 This is a schematic diagram of the structure of an access control device provided in an embodiment of the present application;

[0050] Figure 13 This is a schematic diagram of the structure of a resource providing device provided in an embodiment of the present application;

[0051] Figure 14 is a structural diagram of a computing device provided in an embodiment of the present application;

[0052] Figure 15 is a schematic diagram of a computing device cluster provided in an embodiment of the present application;

[0053] Figure 16 This is a schematic diagram of interaction between two computing devices via a network provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] In order to facilitate understanding of the technical solutions in the embodiments of the present application, some terms and concepts involved in the embodiments are briefly introduced below.

[0055] 1. Unified Identity and Access Management (IAM)

[0056] Identity and Access Management (IAM) is a security measure that provides permission management, access control, and identity authentication. You can use IAM to create and manage users and user groups, and then authorize or deny their access to cloud services and resources. You can also set access control policies through IAM to improve the security of accounts and resources, while providing a variety of secure access credentials.

[0057] 2. Attribute-Based Access Control (ABAC)

[0058] ABAC defines an IAM access control model that determines whether the subject's operation is authorized by evaluating associated attributes such as the subject, resource, requested operation, and current environment.

[0059] The process of determining whether an access request is authorized based on ABAC can be briefly summarized as follows: first, translate the request into an input attribute set {AttributeKey1=Value1,AttributeKey2=Value2,...}, where AttributeKey1 represents a condition key (i.e., attribute), and value1 represents the value corresponding to AttributeKey1. An input attribute set can include multiple different condition keys and corresponding values. Then, the access control evaluation result of the input attribute set is calculated based on the relevant access control policy set by the administrator, that is, allow (Allow) or deny (Deny), thereby determining whether the request is authorized.

[0060] Access control is a security mechanism that controls the subjects who make resource access requests based on access control policies, allowing only authorized subjects to perform corresponding operations to access resources (such as computing resources, communication resources, information resources, etc.) and preventing unauthorized subjects from accessing resources.

[0061] Access control policies are usually described using access policy language. For example, Figure 1The basic structure of an access control policy described by an access policy language is given as an example, including a policy version number (Version) and a policy permission statement (Statement). There can be one or more Statements, representing different authorization items. A Statement can include an identifier of the operation behavior (Action), a resource description (Resource), an access control condition (Condition), and an effective result (Effect). Among them, Action and Effect are required, while Condition and Resource are optional. Action is used to refer to an operation, indicating which specific operation behavior is to be accessed; Resource is used to indicate the specific resource to be accessed; Condition is used to describe the specific judgment condition / judgment logic of access control; Effect is used to indicate the effective result of the Statement, which can be one of the results of Allow (Allow) or Deny (Deny). Assume that there are multiple Statements in an access control policy, and the content of the Action in these multiple Statements is the same, that is, for the same operation, the effective result of some Statements is "Allow" and the effective result of other Statements is "Deny". Regardless of whether the conditions specified in the "Allow" statement are met, as long as the conditions specified in any "Deny" statement are met, the authentication result given by this access control policy is "Deny." An "Allow" authentication result is only given if the conditions specified in any "Deny" statement are not met and the conditions specified in the "Allow" statement are met. In other words, when conflicting statements are reached, the "Deny" option takes precedence over the "Allow" option.

[0062] It should be noted that the Chinese and English names of the various elements in the policy structure described above are only examples. Other names can be used to represent them in actual scenarios, and the embodiments of this application do not make specific limitations.

[0063] Specifically, a Condition consists of a condition key and a condition operator. The condition key is the attribute (or condition attribute) required to construct an access control condition. You can set a corresponding condition value for the condition key in the Condition. The condition operator represents the comparison method for the condition value of the condition key and can include numeric operators and date operators. Taking numeric operators as an example, as shown in Table 1, Table 1 exemplifies the six numeric operators provided by the current access policy language and their corresponding semantic descriptions.

[0064] Table 1 Six numerical operators and their corresponding semantic descriptions

[0065] Numeric operators Semantic Description NumberEquals equal NumberNotEquals Not equal NumberLessThan Less than NumberLessThanEquals Less than or equal to NumberGreaterThan Greater than NumberGreaterThanEquals Greater than or equal to

[0066] Below is Figure 2 Taking the access control condition (Condition) as an example, the operation logic of the access control condition specified by the current access policy language is explained.

[0067] like Figure 2 As shown, two conditional operators are used in the Condition, namely conditional operator 1 and conditional operator 2. Among them, two condition keys are set in the statement block where conditional operator 1 is located (represented by a box in the figure), namely conditional key 1 and conditional key 2, and each condition key is set with a corresponding conditional value. The current access policy language syntax requires that the conditional values ​​of the conditional keys be listed one by one in numerical form. The operation logic between different conditional values ​​of the same conditional key defaults to "OR", and the "AND" operation logic is used between different conditional keys corresponding to the same conditional operator. For example, Figure 2 The condition key 1 in is set with corresponding condition value 1A, condition value 1B, ..., condition value 1C. These condition values ​​are listed one by one in an array format, and the relationship between these condition values ​​is "OR".

[0068] The current access policy language syntax also stipulates that the statement blocks containing different operators in the access control policy are "AND" operation logic. For example, Figure 2 The operation logic between the statement block where conditional operator 1 is located and the statement block where conditional operator 2 is located is "AND". Therefore, during the authentication process, the above two statement blocks need to be satisfied at the same time to meet the access control condition.

[0069] You can also add a prefix of ForAllValues ​​or ForAnyValue before the conditional operator to indicate a set operation.

[0070] ForAllValues: Determines whether each value of the condition key in the authentication request can satisfy the relationship represented by the condition operator with at least one condition value of the same condition key in the access control policy.

[0071] ForAnyValue: Determines whether at least one of all the values ​​of the condition key in the authentication request (there may be one or more values) can satisfy the relationship represented by the condition operator with at least one condition value of the same condition key in the access control policy.

[0072] For example, Figure 3 An access control policy in a virtual private cloud (VPC) scenario is given as an example. The policy version number (Version) in the access control policy is "5.0". The access control policy has a policy permission statement (Statement). The Action in the Statement is specifically "vpc:firewalls:update", which is used to identify the operation of updating the firewall under the VPC. The Effect in the Statement is specifically "Deny", indicating that the effective result of the Statement is rejection. The "vpc:FirewallAllowDestinationPort" in the Condition in the Statement is a condition key (i.e., an attribute), which indicates the destination port number allowed by the firewall, and the three condition values ​​of the condition key are given in the form of an array in the Condition, i.e., [443,444,445]. NumberEquals in the Condition is a numerical operator, which means "numerical equality". There is also a prefix "ForAnyValue" in front of NumberEquals. The semantics of this prefix can be referred to the previous description. In summary, Figure 3 The access control policy restricts firewall updates in the VPC. During authentication, the attribute values ​​in the authentication request must be compared with the conditional values ​​for the same attributes in the access control policy to determine whether they satisfy the relationship between "ForAnyValue" and "NumberEquals." This determines whether the subject is authorized to perform the operation.

[0073] As can be seen, the above example restricts port numbers 443 to 445. Given that the network port range is 0 to 65535, if the administrator wants to impose similar restrictions on port numbers 10000 to 20000, then the access control policy must list all port numbers in the range as an array. This not only increases the administrator's workload but also makes the access control policy overly lengthy, increasing the complexity of authentication decisions based on the access control policy and reducing authentication efficiency.

[0074] Due to the grammatical requirements of the current access policy language, the statement blocks containing different conditional operators in the access control policy use "AND" operation logic, resulting in the inability to achieve the above-mentioned restriction purpose on all port numbers in the range of 10000 to 20000 even by combining multiple conditional operators.

[0075] For example, Figure 4 This section provides another example of an access control policy in a VPC scenario. Figure 4 The Version, Action, and Effect in this access control policy are Figure 3 The difference lies in the specific content of Condition. Figure 4 The first three lines in Condition are the first statement block. The condition key in this statement block is "vpc:FirewallAllowDestinationPort", the corresponding condition value is 10000, and the condition operator is set to "NumberGreaterThanEquals" with the prefix "ForAnyValue". Therefore, this statement block determines whether at least one of the values ​​of the above condition key given in the authentication request is greater than or equal to 10000. Figure 4The last three lines within the Condition block are the second statement block. The condition key in this block is "vpc:FirewallAllowDestinationPort," the corresponding condition value is 20000, and the condition operator is "NumberLessThanEquals," prefixed with "ForAnyValue." Therefore, this statement block determines whether at least one of the values ​​for the condition key given in the authentication request is less than or equal to 20000. Because the "AND" operation logic is specified between the two blocks, the overall semantics of this condition block are: Determine whether at least one of the values ​​for the condition key given in the authentication request is greater than or equal to 10000, and determine whether at least one of the values ​​for the condition key given in the authentication request is less than or equal to 20000. If both judgments are "yes," the authentication result given based on this access control policy is deny.

[0076] Assume that the two values ​​of the condition key "vpc:FirewallAllowDestinationPort" in the authentication request are [9999, 20001]. Based on the above access control policy, the authentication decision is made. Since 20001 in [9999, 20001] is greater than 10000, it satisfies the first block of the authentication. Furthermore, since 9999 in [9999, 20001] is less than 20000, it also satisfies the second block of the authentication. This results in an authentication rejection. However, ports 9999 and 20001 are not within the administrator's intended restriction range of 10000 to 20000. Therefore, the above operations on these ports should be permitted. Therefore, the access control policy fails to achieve the administrator's intended restriction.

[0077] To simplify the access control policy, the present application provides an attribute-based access control method: the access control device first receives an authentication request sent by the resource provision device, then determines the access control policy based on the identifier of the first operation in the authentication request, then determines the authentication result based on the authentication request and the access control policy, and sends the authentication result to the resource provision device. The authentication request includes the identifier of the first operation and the target value of the first attribute; the access control policy includes the identifier of the first operation, the upper and lower bounds of the first value interval of the first attribute, and a comparison method. The comparison method indicates that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicates that the resource provision device is denied to perform the first operation when the target value is within the first value interval. Whether the target value is within the first value interval is determined by comparing the target value with the upper and lower bounds of the first value interval; the authentication result is used to indicate whether the resource provision device performs the first operation. It should be understood that compared to the traditional solution of listing the conditional values ​​corresponding to the attributes one by one in the form of an array in the access control policy, the present application provides a more concise and effective way to configure the access control policy, giving the conditional values ​​corresponding to the attributes in the form of intervals (giving the upper and lower bounds of the value interval), which can not only reduce the workload of the administrator when configuring the access control policy, but also shorten the length of the access control policy.

[0078] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a system architecture involved in the embodiments of the present application is first introduced below.

[0079] See Figure 5 , Figure 5 Schematic diagram of an access control system provided by an embodiment of the present application, including an access control device 100 and a resource providing device 200. A communication connection can be established between the access control device 100 and the resource providing device 200, which can be a wired connection or a wireless connection, which is not specifically limited in the embodiment of the present application. The resource providing device 200 that establishes a communication connection with the access control device 100 can be one or more ( Figure 5 Taking a resource providing device 200 as an example), the embodiment of the present application does not specifically limit this.

[0080] The access control device 100 supports the creation of access control policies and implements access control (including authentication) based on the access control policies. Figure 5 As shown, the administrator (actually also a user with higher authority than ordinary users) can add one or more access control policies to the access control device 100 according to actual application requirements. The access control device 100 stores these access control policies. This application does not specifically limit the storage location of the access control policies (such as storage in a database). Subsequently, the access control device 100 can implement corresponding access control based on the stored access control policies.

[0081] Optionally, the access control device 100 can be deployed on a computing device, a computing device cluster consisting of multiple computing devices, and / or a terminal device. The computing device can be a physical server, a virtual machine, a container, or an edge computing device. A virtual machine refers to a complete computer system with complete hardware system functions that is simulated by software and runs in a completely isolated environment. When creating a virtual machine in a computing device, part of the hard disk and memory capacity of the physical machine needs to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent basic input / output system (CMOS), hard disk, and operating system, and can be operated like a physical machine. A container is a portable software unit that can combine an application and all its dependencies into a single software package that is not restricted by the underlying host operating system. This eliminates the need to build a complex environment and simplifies the process from application development to deployment. An edge computing device refers to a device that is closer to the data source and end user and has low latency and high bandwidth characteristics, such as an intelligent router, edge server, etc., which is not specifically limited in the embodiments of this application. A terminal device can be a laptop, tablet computer, smartphone, wearable device, vehicle-mounted device, or smart conferencing device, etc., which is not specifically limited in the embodiments of this application.

[0082] The embodiment of the present application does not specifically limit the interaction method between the administrator and the access control device 100.

[0083] In a possible implementation, the administrator may call an application programming interface (API) provided by the access control device 100 to interact with the access control device 100 in a programmatic manner.

[0084] In another possible implementation, the administrator can interact with the access control device 100 through a client. The above-mentioned client can be deployed on a terminal device or a computing device. Among them, the terminal device can be a smart phone, a wearable device, a laptop, a tablet computer, a vehicle-mounted device or a smart conference device, etc., and the computing device can be a server, a personal computer (PC), etc., which are not specifically limited in the embodiments of the present application. Optionally, the above-mentioned client can be an application (application, APP) client / mobile client running on a mobile terminal such as a smart phone, a wearable device, etc., or it can be a software or application running on a computing device (such as a PC client), or it can be a web client accessed based on a web browser, or it can be a front-end console (console) of a cloud platform, which can provide a visual interface for the administrator to operate, which is not specifically limited in the embodiments of the present application.

[0085] Optionally, the client and access control device 100 can be deployed on the same terminal device or computing device; alternatively, the client can be deployed on a terminal device, and the access control device 100 can be deployed on a computing device or computing device cluster. It should be understood that the above examples are for illustration only, and the specific deployment of the client and access control device 100 can be determined based on actual application scenarios.

[0086] The above-mentioned resource providing device 200 is used to provide service resources, and allows or denies users (who have lower authority than administrators and can be considered as ordinary users) to perform corresponding operations to access resources by obtaining authentication results from the access control device 100. The embodiment of the present application does not specifically limit the type of resources provided by the resource providing device 200. For example, it can be one or more of computing resources, communication resources, information resources, etc. The number of resource providing devices 200 can be one or more, and different resource providing devices 200 can provide the same or different types of resources. Users can send resource access requests to the corresponding resource providing device 200 according to the type of resources they need to access. The embodiment of the present application does not make specific limitations. For example, assuming that the resource providing device 200 is used to provide a certain cloud service, the user can send a resource access request to the resource providing device 200 to request access to the service resources of the cloud service.

[0087] Optionally, the resource providing device 200 can be deployed on a computing device, a computing device cluster consisting of multiple computing devices, and / or a terminal device. For computing devices and terminal devices, please refer to the previous description and will not be repeated here.

[0088] The embodiments of the present application do not specifically limit the manner in which a user interacts with the access control device 100. In one possible implementation, a user may programmatically interact with the resource provision device 200 based on an application programming interface (API) provided by the resource provision device 200 to request access to corresponding resources and perform corresponding operations. In another possible implementation, a user may interact with the resource provision device 200 through a client and send corresponding resource access requests. For details about the client, please refer to the previous description and will not be repeated here.

[0089] Optionally, the client and resource provision device 200 can be deployed on the same terminal device or computing device; alternatively, the client can be deployed on a terminal device, and the resource provision device 200 can be deployed on a computing device or computing device cluster. Alternatively, the access control device 100 and resource provision device 200 can be deployed on the same or different terminal devices or computing devices. It should be understood that the above examples are for illustrative purposes only, and specific deployment scenarios may be determined based on actual application scenarios.

[0090] Optionally, the above-mentioned access control device 100 can be further divided into a policy administration point (PAP) and a policy decision point (PDP), and the resource provision device 200 can be further divided into a policy enforcement point (PEP) and a resource location point. Among them, the PAP is used to store and manage the access control policies added by the administrator. The PDP is used to obtain the access control policy required for authentication from the PAP, and make a decision based on the obtained access control policy to obtain the authentication result, and then send the authentication result to the PEP (that is, the PDP provides an authentication function to the PEP). The PEP is used to send an authentication request to the PDP, and then determine whether to execute the resource access request sent by the user / perform the corresponding operation based on the authentication result fed back by the PDP. The resource location point is the location of the resource that the user requests to access, and the embodiments of the present application do not make specific limitations.

[0091] It should be understood that there is a communication connection between the above-mentioned PEP and the PDP, and the number of PEPs that have a communication connection with the PDP can be one or more, and different PEPs can access the same or different resources (resource locations), which is not specifically limited in the embodiments of the present application. Similarly, there is a communication connection between the above-mentioned PAP and the PDP, and the number of PDPs that have a communication connection with the PAP can be one or more, and different PDPs can provide authentication functions for the same or different PEPs. Optionally, the above-mentioned PAP and PDP can be deployed on the same device or on different devices. Similarly, the above-mentioned PEP and resource location can be deployed on the same device or on different devices. PAP, PDP and PEP can be deployed on the same device or on different devices, that is, deployed separately.

[0092] based on Figure 5 With reference to the system architecture, the following describes an embodiment of the attribute-based access control method provided by this application.

[0093] See Figure 6 , Figure 6 This is a flow chart of an attribute-based access control method provided in an embodiment of the present application, including the following steps S601 to S606.

[0094] S601: The resource providing device 200 receives an execution request for a first operation initiated by a user, and collects authentication attribute information according to the execution request.

[0095] The authentication attribute information includes a target value of a first attribute. The embodiment of the present application does not specifically limit the types of the first attribute and the first operation.

[0096] It should be understood that when the resource providing device 200 receives the above-mentioned execution request, it can collect information of various attributes (i.e., authentication attribute information) for authentication. The collected attributes may include identity attributes, environment attributes, resource attributes, etc. The collection method and collection location of these attributes are not specifically limited in the embodiment of this application. Among them, identity attributes are information used to describe the identity of the user, such as user identifier (ID), user group, etc.; environment attributes are information used to describe the application environment, such as source IP, destination IP, user login method (such as through a browser, calling an API, etc.); resource attributes are information used to describe resource characteristics, such as resource type, resource owner, resource update time, etc., which are not specifically limited in the embodiment of this application. Optionally, the first attribute may include at least one of identity attributes, environment attributes, and resource attributes.

[0097] For example, suppose the first attribute is "vpc:FirewallAllowDestinationPort," which represents the destination port allowed by the VPC firewall. Assume that the user-initiated execution request contains two values ​​for this attribute in array form: [443, 20001]. This indicates that the user intends to change the destination ports allowed by the firewall to 443 and 20001. In this case, resource provision device 200 can collect the target value of the first attribute from the execution request.

[0098] S602 : The resource providing device 200 generates an authentication request according to the authentication attribute information, and sends the authentication request to the access control device 100 .

[0099] Correspondingly, the access control device 100 receives the authentication request sent by the resource providing device 200 , where the authentication request includes authentication attribute information (including the target value of the first attribute) and an identifier of the first operation.

[0100] S603: The access control device 100 determines an access control policy according to the identifier of the first operation in the authentication request.

[0101] Among them, the access control policy includes the identifier of the first operation, the upper limit and lower limit of the first value interval of the first attribute, and a comparison method, which indicates that when the target value of the first attribute in the above authentication request is within the first value interval, the resource provision device 200 is allowed / denied to perform the first operation.

[0102] Optionally, the access control policy may include multiple value ranges for the first attribute. Each of these multiple value ranges has a corresponding upper and lower bound. The first value range can be any one of these multiple value ranges, meaning that multiple value ranges corresponding to the same attribute are logically ORed. Any two of these multiple value ranges may or may not intersect. Administrators can configure the appropriate number and size of value ranges in the access control policy as needed.

[0103] Optionally, the first value interval can be an open interval, a closed interval, or a half-open interval (either a left half-open interval or a right half-open interval). Unless otherwise specified, the following description uses a closed interval as an example, but this does not necessarily mean that it must be a closed interval. It should be understood that providing the range of the conditional value of the first attribute in interval format eliminates the need to enumerate all conditional values ​​within the range, helping to shorten the length of the access control policy and thereby improve authentication efficiency.

[0104] For example, assuming that the authentication request includes "vpc:firewalls:update," which identifies an operation to update the firewall in the VPC (corresponding to the first operation), the access control device 100 determines an access control policy based on the identifier of the first operation in the received authentication request. The access control policy also includes the identifier of the first operation.

[0105] For example, Figure 7 An access control policy in a VPC scenario is shown, and the policy version number (Version) in the access control policy is "5.0". The access control policy has a policy permission statement (Statement), and the Action in the Statement is specifically "vpc:firewalls:update", which is used to identify the operation of updating the firewall under the VPC. The Effect in the Statement is specifically "Deny", indicating that the effective result of the Statement is rejection. The "vpc:FirewallAllowDestinationPort" in the Condition in the Statement is an attribute (corresponding to the first attribute mentioned above), which indicates the destination port number allowed by the firewall, and the condition value of the first attribute is given in the form of an interval in the Condition, that is, the first value interval [10000,20000], where 10000 is the lower bound of the interval and 20000 is the upper bound of the interval. The "NumberInRange" in the Condition is a numerical operator provided in an embodiment of the present application, which means "the value falls within the interval". There is also a prefix "ForAnyValue" in front of "NumberInRange". The semantics of this prefix can be referred to the previous description. In summary, Figure 7 The access control policy restricts firewall updates in a VPC. The overall semantics of this policy are: Check whether at least one of the values ​​of the attribute specified in the authentication request is within the first range [10000, 20000]. If so, the authentication result given by this access control policy is a rejection.

[0106] Assume that Figure 7 The value of "Effect" in the access control policy is changed from "Deny" to "Allow", and the others remain unchanged. The semantics of the modified access control policy are: determine whether at least one value among all the values ​​of the above-mentioned first attribute given in the authentication request is within the first value interval [10000,20000]. If so, the authentication result given based on the access control policy is allowed.

[0107] It should be understood that the name "NumberInRange" is merely an example and does not constitute a specific limitation. In practical applications, other names can be used to express the same meaning, such as "NumberBetween" or "NumberFromTo." It should also be understood that since the value type of the first attribute is a numeric value, the conditional operator selected is a numeric operator. The "Number" in the numeric operator indicates that it is used for numeric operations. For other types of values, such as dates and IP addresses, the corresponding conditional operators can be constructed in a similar manner. The form of the conditional operator is {Type}InRange / {Type}Between / {Type}FromTo, where Type represents the type of value the conditional operator targets. For example, if the operation is performed on dates, the corresponding conditional operators can be DateInRange / DateBetween / DateFromTo, indicating "date falls within a range"; if the operation is performed on IP addresses, the corresponding conditional operators can be IPInRange / IPBetween / IPFromTo, indicating "IP address falls within a range."

[0108] Optionally, the authentication request may also include user information. The access control device 100 then determines an access control policy based on the user information and the identifier of the first operation for subsequent authentication. It should be understood that an administrator can establish different access control policies on the access control device 100 for different user information. Thus, the access control device 100 can select a corresponding access control policy from multiple access control policies based on the user information in the authentication request for authentication.

[0109] Optionally, before step S603, the administrator can send one or more access control policies to the access control device 100 as needed, and then the access control device 100 verifies each access control policy. The verification here can be a legality verification of the format, value, etc. of the access control policy, which is not specifically limited in the embodiment of the present application. In the case where the access control policy verification passes, the access control policy is stored, and feedback is given to the administrator that the access control policy has been successfully created. Regarding the specific location for storing the access control policy, the embodiment of the present application does not make specific limitations. For example, it can be stored inside or outside the access control device 100, or in a database or other location. In the case where the access control policy verification fails, the access control device 100 can feedback to the administrator that the access control policy creation failed, and can further provide the specific reason for the creation failure. Regarding the interaction method between the administrator and the access control device 100, please refer to Figure 5 The relevant introduction is not repeated here.

[0110] S604: The access control device 100 determines an authentication result according to the authentication request and the access control policy.

[0111] The authentication result is used to indicate whether the resource providing device 200 performs the first operation.

[0112] In a possible implementation, the authentication request includes multiple values ​​of the first attribute, and the target value may be any one or all of the multiple values.

[0113] For example, Figure 8 This is a schematic diagram of part of the content of an authentication request provided in an embodiment of the present application, where "request" represents a request, "vpc:firewalls:update" is the identifier of the operation of updating the firewall under the VPC, and "attributes" represents an attribute set (i.e., authentication attribute information). The attribute set includes the attribute "vpc:FirewallAllowDestinationPort" (indicating the destination port number allowed by the firewall) and the two values ​​corresponding to the attribute, which are 443 and 20001 respectively. It can be seen that the above two values ​​in the authentication attribute here are listed one by one in the form of an array. Therefore, the authentication request represents a request to perform the operation of updating the firewall under the VPC, and it is expected to change the destination port number allowed by the firewall to 443 and 20001.

[0114] When the authentication management device 100 receives the above authentication request, it determines the operation ID in the authentication request. Figure 7 The access control policy is then used to make authentication decisions based on the access control policy. Figure 7 The overall semantics of the access control policy is: determine whether at least one value among all the values ​​of the above attribute given in the authentication request is within the first value interval [10000, 20000]. If so, the authentication result given based on the access control policy is rejection. In other words, among all the values ​​of the attribute given in the authentication request, as long as any one value (corresponding to the target value) can be within the first value interval [10000, 20000], the authentication result is determined to be rejection. At this time, the target value can be either 443 or 20001. By comparing the target value with the upper and lower bounds of the first value interval, it can be determined whether the target value is within the first value interval, and then the authorization result can be determined.

[0115] For example, suppose Figure 7The "ForAnyValue" in the access control policy is modified to "ForAllValues", and the others remain unchanged. The semantics of the modified access control policy are: determine whether all the values ​​of the above attributes given in the authentication request are within the first value interval [10000, 20000]. If so, the authentication result given based on the access control policy is rejection. In other words, among all the values ​​of the attribute given in the authentication request, as long as any one value (corresponding to the target value) can be within the first value interval [10000, 20000], the authentication result is determined to be rejection. At this time, the target value can be either 443 or 20001. By comparing the target value with the upper and lower bounds of the first value interval, it can be determined whether the target value is within the first value interval, and then the authorization result is determined.

[0116] In another possible implementation, the authentication request includes the upper bound and lower bound of the second value interval of the first attribute. In this case, the target value may include the upper bound and / or the lower bound of the second value interval.

[0117] For example, Figure 9 This is a schematic diagram of part of the content in another authentication request provided by an embodiment of the present application, wherein "request", "vpc:firewalls:update", "attributes" and "vpc:FirewallAllowDestinationPort" are Figure 8 The description is the same as that of the Authentication Request, the difference lies in the way the value of the attribute "vpc:FirewallAllowDestinationPort" is given in the authentication request. Figure 9 As shown in the figure, "Range" indicates that the value of the attribute above is given in interval format (corresponding to the second value range). "From" under "Range" indicates that the upper bound of the second value range is 10000, and "To" under "Range" indicates that the lower bound of the second value range is 20000, that is, the second value range is [10000, 20000]. Therefore, this authentication request indicates a request to update the firewall in the VPC, hoping to change the destination port numbers allowed by the firewall to 10000-20000.

[0118] When the authentication management device 100 receives the above authentication request, it determines the operation ID in the authentication request. Figure 7 The access control policy is then used to make authentication decisions based on the access control policy. Figure 7The overall semantics of the access control policy is: determine whether at least one value among all the values ​​of the above attribute given in the authentication request is within the first value interval [10000, 20000]. If so, the authentication result given based on the access control policy is rejection. In other words, among all the values ​​of the attribute given in the authentication request, as long as any one value (corresponding to the target value) can be within the first value interval [10000, 20000], the authentication result is determined to be rejection. At this time, the target value can be any one of the upper and lower bounds of the second value interval mentioned above. By comparing the target value with the upper and lower bounds of the first value interval, it can be determined whether the target value is within the first value interval, and then the authorization result is determined.

[0119] by Figure 7 Taking the access control policy as an example, Table 2 shows the corresponding authentication results of different authentication requests.

[0120] Table 2 Authentication results of different authentication requests

[0121]

[0122] It should be understood that if the value of the first attribute in the authentication request is given in an interval format, that is, the upper and lower bounds of the second value interval are specifically given, and the conditional values ​​of the first attribute in the access control policy are listed one by one (not given in an interval format), then when making an authentication decision, it is necessary to compare the value in the second value interval with the conditional value of the same attribute in the access control policy. The specific comparison method is determined by the conditional operator and the corresponding prefix in the access control policy, thereby determining the authentication result. For example, assuming that the conditional operator is "NumberEquals" and the prefix "ForAnyValue" is added before the conditional operator, it is necessary to determine whether there is at least one value in the second value interval that is equal to at least one conditional value of the same attribute in the access control policy. For another example, assuming that the conditional operator is "NumberEquals" and the prefix "ForAllValues" is added before the conditional operator, it is necessary to determine whether each value in the second value interval is equal to at least one conditional value of the same attribute in the access control policy.

[0123] S605 : The access control device 100 sends the authentication result to the resource providing device 200 .

[0124] Correspondingly, the resource providing device 200 receives the authentication result sent by the access control device 100 .

[0125] S606: The resource providing device 200 determines whether to execute the first operation according to the authentication result.

[0126] Specifically, if the authentication result is permission, the resource providing device 200 performs the first operation according to the user's execution request; if the authentication result is rejection, the resource providing device 200 does not perform the first operation and feeds back unauthorized information to the user.

[0127] In summary, Figure 6 In the attribute-based access control method provided in this embodiment, the conditional value of the first attribute in the access control policy is described in interval format, specifically providing the upper and lower bounds of the first value interval of the first attribute. All values ​​within this first value interval are conditional values ​​of the first attribute. Compared to the traditional approach of listing the corresponding conditional values ​​of attributes in an array format within the access control policy, this approach provides a more concise and effective way to configure the access control policy. By providing the corresponding conditional values ​​of attributes in interval format, this approach not only reduces the workload of administrators when configuring the access control policy, but also shortens the length of the access control policy.

[0128] Moreover, when the resource providing device makes an authentication decision based on the access control policy in the present application, it only needs to compare the target value of the first attribute in the authentication request with the upper and lower limits of the first value interval, without having to compare the target value with all the conditional values ​​in the access control policy one by one as in the traditional scheme, thereby reducing the complexity of the authentication decision based on the access control policy and improving the authentication efficiency.

[0129] Next, combine Figure 10 and Figure 11 ,right Figure 6 The method of the embodiment is specifically illustrated with examples.

[0130] See Figure 10 , Figure 10 This is a schematic diagram of an authentication process provided in an embodiment of the present application.

[0131] First, an administrator can add a user-written access control policy to the policy management point (PAP) through the PAP's request interface. Specifically, the PAP can be accessed programmatically through the front-end console or through an API interface. On the front-end console, the access control policy can be edited using JSON (JavaScript Object Notation) or through a visual view on the user interface (UI), although this embodiment of the application does not limit this.

[0132] When the policy management point PAP receives the access control policy added by the user, it can verify the access control policy and perform policy storage if the verification passes, such as storing the access control policy in the policy library, and can also provide feedback to the administrator that the policy creation is successful.

[0133] Subsequently, when the user sends a user request to the policy enforcement point PEP, the user request instructs to perform a first operation on the service resource. Then, the PEP collects authentication attribute information (including the value of the first attribute) for authentication based on the user request, including the values ​​of identity attributes, environment attributes, and resource attributes, and then constructs an authentication request based on the collected attributes. The specific construction method of the authentication request can be referred to Figure 6 The authentication request is then sent to the policy decision point PDP.

[0134] The Policy Decision Point (PDP) parses the authentication request from the PEP and obtains the authentication attribute information. Based on the authentication request, the PDP also requests the Policy Administration Point (PAP) to obtain the corresponding access control policy for authentication. The PAP retrieves the corresponding access control policy from the policy repository for this authentication and sends it to the PDP. The PDP parses the received access control policy, obtains the corresponding attribute condition values, and then matches them with the values ​​of the same attributes in the authentication request to generate an authentication result. It should be understood that when PDP parses the authentication request, it supports parsing the values ​​of attributes given in array form in the traditional way, and also supports parsing the values ​​of attributes given in interval format in the embodiment of the present application. Similarly, when PDP parses the access control policy, it supports parsing the six semantic conditional operators of equality, inequality, less than, less than or equal to, greater than, and greater than or equal to given by the access control policy, and also supports parsing the semantic conditional operators of "falling within the interval" provided in the embodiment of the present application (such as {Type}InRange, {Type}Between, {Type}FromTo, etc. described above), and has good compatibility.

[0135] Finally, the PDP sends the authentication result to the Policy Enforcement Point (PEP). The PEP determines whether the authentication result is allowed. If so, it executes the user request and accesses the corresponding service resources. If not, it returns an unauthorized error to the user and does not execute the user request.

[0136] See Figure 11 , Figure 11 This is another authentication process diagram provided in an embodiment of the present application.

[0137] First, the user requests access to the cloud service from the policy enforcement point. The interaction between the user and the policy enforcement point is described previously and will not be repeated here. The policy enforcement point collects authentication attribute information (which can include identity attributes, resource attributes, and environment attributes) based on the user's request. It then generates an authentication request based on this authentication attribute information. The format of the authentication request is described previously and will not be repeated here. The authentication request is then sent to the policy decision point.

[0138] Based on the received authentication request, the policy decision point requests the access control policy from the policy management point. The policy management point then returns the access control policy to the policy decision point. The policy decision point then performs authentication by parsing the access control policy and returns the authentication result to the policy enforcement point. If the authentication result is a rejection, the policy enforcement point returns an "unauthorized" message to the user, indicating that the user is not authorized to access the cloud service. If the authentication result is a permission, the policy enforcement point executes the user's request and accesses the cloud service resources. The cloud service then returns a response to the user.

[0139] See Figure 12 , Figure 12 1 is a schematic diagram of the structure of an access control device 100 provided in an embodiment of the present application, including a transceiver module 101 and a determination module 102. The access control device 100 may correspond to Figure 1 The access control device 100 is specifically used to perform Figure 6 Method steps on the access control device 100 side in.

[0140] The transceiver module 101 is configured to receive an authentication request sent by a resource providing device, wherein the authentication request includes an identifier of a first operation and a target value of a first attribute.

[0141] The determination module 102 is used to determine the access control policy based on the identifier of the first operation in the authentication request, wherein the access control policy includes the identifier of the first operation, the upper bound and the lower bound of the first value interval of the first attribute, and a comparison method, the comparison method indicates that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicates that the resource provision device is denied to perform the first operation when the target value is within the first value interval, and whether the target value is within the first value interval is determined by comparing the target value with the upper bound and the lower bound of the first value interval.

[0142] The determination module 102 is further configured to determine an authentication result according to the authentication request and the access control policy, and send the authentication result to the resource providing device, wherein the authentication result is used to indicate whether the resource providing device performs the first operation.

[0143] Optionally, the authentication request further includes user information. The determining module 102 is specifically configured to determine an access control policy according to the identifier of the first operation in the authentication request and the user information. The access control policy corresponds to the user information.

[0144] Optionally, the authentication request includes multiple values ​​of the first attribute, and the target value is any one or all of the multiple values.

[0145] Optionally, the authentication request includes an upper bound and a lower bound of the second value interval of the first attribute, and the target value includes an upper bound and / or a lower bound of the second value interval.

[0146] Optionally, the access control device 100 also includes a storage module 103. Before the determination module 102 determines the access control policy based on the identifier of the first operation in the authentication request, the transceiver module 101 is also used to receive the access control policy created by the administrator. When the access control module passes the verification (the corresponding verification can be performed by the determination module 102), the storage module 103 is used to store the access control policy. The transceiver module is also used to feedback to the administrator that the access control policy is successfully created.

[0147] Optionally, the target value type can be a number, date, or IP address.

[0148] Optionally, the first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

[0149] Optionally, the interval type of the first value interval is an open interval, a closed interval, or a half-open interval.

[0150] It should be noted that the transceiver module 101, the determination module 102, and the storage module 103 can all be implemented via software or hardware. For example, the implementation of the determination module 102 will be described below using the determination module 102 as an example. Similarly, the implementation of the other modules described above can refer to the implementation of the determination module 102.

[0151] As an example of a software functional unit, the module 102 can be determined to include code running on a computing instance. The computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance can be one or more. For example, the module 102 can be determined to include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code can be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Typically, a region can include multiple AZs.

[0152] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.

[0153] As an example of a hardware functional unit, determination module 102 may include at least one computing device, such as a server. Alternatively, determination module 102 may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0154] The multiple computing devices included in the determination module 102 can be distributed in the same region or in different regions. The multiple computing devices included in the determination module 102 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the determination module 102 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.

[0155] It should also be noted that Figure 12 The division method provided is only an example and does not constitute a specific limitation on the embodiments of the present application. The access control device 100 may further include more or fewer unit modules, such as splitting one or more modules among the above-mentioned transceiver module 101, determination module 102, and storage module 103 into multiple functional modules, or merging two or more modules among the above-mentioned transceiver module 101, determination module 102, and storage module 103.

[0156] See Figure 13 , Figure 13This is a schematic diagram of the structure of a resource providing device 200 provided in an embodiment of the present application, including a transceiver module 201, an acquisition module 202 and a processing module 203. The resource providing device 200 corresponds to Figure 1 The resource providing device 200 is specifically used to perform Figure 6 The method steps on the resource providing device 200 side.

[0157] The transceiver module 201 is configured to receive a request for executing a first operation initiated by a user.

[0158] The acquisition module 202 is configured to collect authentication attribute information according to the execution request, wherein the authentication attribute information includes an upper bound and a lower bound of a second value interval of the first attribute.

[0159] The processing module 203 is configured to generate an authentication request according to the authentication attribute information, and send the authentication request to the access control device, wherein the authentication request includes an identifier of the first operation and the authentication attribute information.

[0160] The transceiver module 201 is further configured to receive an authentication result sent by the access control device.

[0161] The processing module 203 is further configured to determine whether to perform the first operation for the user according to the authentication result.

[0162] Optionally, the authentication request also includes user information of the user.

[0163] Optionally, the type of the upper bound of the second value interval is a number, a date, or an Internet Protocol IP address.

[0164] Optionally, the first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

[0165] Optionally, the interval type of the second value interval is an open interval, a closed interval, or a half-open interval.

[0166] It should be noted that the above-mentioned transceiver module 201, acquisition module 202 and processing module 203 can be implemented by software or by hardware. For hardware implementation and software implementation, please refer to the relevant introduction above and will not be repeated here. It should also be noted that Figure 13 The division method in the example is only an example and does not constitute a specific limitation to the embodiments of the present application. The resource providing device 200 may also include more or fewer unit modules.

[0167] See Figure 14The present application also provides a computing device 1400, including a bus 1402, a processor 1404, a memory 1406, and a communication interface 1408. The processor 1404, the memory 1406, and the communication interface 1408 communicate with each other via the bus 1402. The computing device 1400 can be a server, a laptop computer, a desktop computer, an edge device, etc., and the embodiments of the present application do not specifically limit this. The embodiments of the present application do not limit the number of processors and memories in the computing device 1400.

[0168] The bus 1402 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 14 The bus 1402 may include a path for transmitting information between various components of the computing device 1400 (eg, memory 1406, processor 1404, communication interface 1408).

[0169] The processor 1404 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0170] The memory 1406 may include volatile memory, such as random access memory (RAM). The processor 1404 may also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0171] The memory 1406 stores executable program codes. The processor 1404 executes the executable program codes to implement Figure 12 The functions of the transceiver module 101, the determination module 102 and the storage module 103 in the present application are realized. Figure 6Alternatively, the processor 1404 executes the executable program code to respectively implement Figure 13 The functions of the transceiver module 201, the acquisition module 202 and the processing module 203 in the present invention are realized. Figure 6 Steps on the resource providing device 200 side.

[0172] The communication interface 1408 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1400 and other devices or a communication network.

[0173] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0174] like Figure 15 As shown, the computing device cluster includes at least one computing device 1400. The memory 1406 in one or more computing devices 1400 in the computing device cluster may store the same Figure 6 Instructions of the method of embodiment.

[0175] In some possible implementations, the memory 1406 of one or more computing devices 1400 in the computing device cluster may also store the memory 1406 for executing the above Figure 6 In other words, the combination of one or more computing devices 1400 can jointly execute the method for Figure 6 Instructions of the method of embodiment.

[0176] It should be noted that the memory 1406 in different computing devices 1400 in the computing device cluster can store different instructions, and the instructions stored in the memory 1406 in different computing devices 1400 can be implemented. Figure 12 Alternatively, the memory 1406 in different computing devices 1400 in the computing device cluster may store different instructions, and the instructions stored in the memory 1406 in different computing devices 1400 may implement Figure 13 The functions of one or more modules in the transceiver module 201, the acquisition module 202 and the processing module 203.

[0177] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network, which may be a wide area network or a local area network. Figure 16 A possible implementation is shown. Figure 16 As shown, two computing devices 1400A and 1400B are connected via a network. Specifically, the connection to the network is achieved through a communication interface in each computing device. In this possible implementation, the memory 1406 in computing device 1400A stores instructions for executing the functions of transceiver module 101. Simultaneously, the memory 1406 in computing device 1400B stores instructions for executing the functions of determination module 102 and storage module 103.

[0178] It should be understood that Figure 16 The functions of the computing device 1400A shown in FIG. 14 may also be jointly performed by multiple computing devices 1400. Similarly, the functions of the computing device 1400B may also be jointly performed by multiple computing devices 1400.

[0179] The present application embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similarly referred to as Figure 16 The difference is that the memory 1406 of one or more computing devices 1400 in the computing device cluster may store the same memory 1406 for executing the above Figure 6 The method instruction.

[0180] In some possible implementations, the memory 1406 of one or more computing devices 1400 in the computing device cluster may also store a program for executing the executable program. Figure 6 In other words, the combination of one or more computing devices 1400 can jointly execute the instructions for implementing Figure 6 The method instruction.

[0181] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct a computing device cluster (including at least one computing device) to execute Figure 6 Method on the access control device 100 / resource providing device 200 side in the embodiment.

[0182] The present application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes Figure 6 Method on the access control device 100 / resource providing device 200 side in the embodiment.

[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present invention.

Claims

1. An attribute-based access control method, characterized in that: The method is applied to an access control device, and includes: receiving an authentication request sent by a resource providing device, wherein the authentication request includes an identifier of the first operation and a target value of the first attribute; determining an access control policy based on an identifier of the first operation in the authentication request, wherein the access control policy includes the identifier of the first operation, an upper bound and a lower bound of a first value interval of the first attribute, and a comparison method, the comparison method indicating that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicating that the resource provision device is denied to perform the first operation when the target value is within the first value interval, and whether the target value is within the first value interval is determined by comparing the target value with the upper bound and the lower bound of the first value interval; An authentication result is determined according to the authentication request and the access control policy, and the authentication result is sent to the resource providing device, wherein the authentication result is used to indicate to the resource providing device whether to perform the first operation.

2. The method according to claim 1, characterized in that The authentication request further includes user information, and determining the access control policy according to the identifier of the first operation in the authentication request includes: The access control policy is determined according to the identifier of the first operation in the authentication request and the user information, and the access control policy has a corresponding relationship with the user information.

3. The method according to claim 1 or 2, characterized in that The authentication request includes multiple values ​​of the first attribute, and the target value is any one or all of the multiple values.

4. The method according to claim 1 or 2, characterized in that The authentication request includes an upper bound and a lower bound of a second value interval of the first attribute, and the target value includes an upper bound and / or a lower bound of the second value interval.

5. The method according to any one of claims 1 to 4, characterized in that Before determining the access control policy according to the identifier of the first operation in the authentication request, the method further includes: receiving the access control policy created by an administrator; If the access control policy passes the verification, the access control policy is stored, and a feedback indicating that the access control policy is successfully created is sent to the administrator.

6. The method according to any one of claims 1 to 5, characterized in that The type of the target value is a numerical value, a date or an Internet Protocol (IP) address.

7. The method according to any one of claims 1 to 6, characterized in that The first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

8. The method according to any one of claims 1 to 7, characterized in that The interval type of the first value interval is an open interval, a closed interval, or a half-open interval.

9. An attribute-based access control method, characterized in that: The method is applied to a resource providing device, and includes: Receiving an execution request for a first operation initiated by a user, and collecting authentication attribute information according to the execution request, wherein the authentication attribute information includes an upper bound and a lower bound of a second value interval of the first attribute; generating an authentication request according to the authentication attribute information, and sending the authentication request to the access control device, wherein the authentication request includes an identifier of the first operation and the authentication attribute information; Receive an authentication result sent by the access control device, and determine whether to perform the first operation for the user according to the authentication result.

10. The method according to claim 9, characterized in that The authentication request also includes user information of the user.

11. The method according to claim 9 or 10, characterized in that The type of the upper bound of the second value interval is a numerical value, a date, or an Internet Protocol IP address.

12. The method according to any one of claims 9 to 11, characterized in that The first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

13. The method according to any one of claims 9 to 12, characterized in that The interval type of the second value interval is an open interval, a closed interval, or a half-open interval.

14. An access control device, characterized in that: include: a transceiver module, configured to receive an authentication request sent by a resource providing device, wherein the authentication request includes an identifier of the first operation and a target value of the first attribute; a determination module, configured to determine an access control policy based on an identifier of the first operation in the authentication request, wherein the access control policy includes the identifier of the first operation, an upper bound and a lower bound of a first value interval of the first attribute, and a comparison method, the comparison method indicating that the resource provision device is allowed to perform the first operation when the target value is within the first value interval, or indicating that the resource provision device is denied to perform the first operation when the target value is within the first value interval, and whether the target value is within the first value interval is determined by comparing the target value with the upper bound and the lower bound of the first value interval; The determination module is further configured to determine an authentication result based on the authentication request and the access control policy, and send the authentication result to the resource providing device, wherein the authentication result is used to indicate whether the resource providing device performs the first operation.

15. The device according to claim 14, characterized in that The authentication request also includes user information, and the determination module is specifically configured to: The access control policy is determined according to the identifier of the first operation in the authentication request and the user information, and the access control policy has a corresponding relationship with the user information.

16. The device according to any one of claims 14 or 15, characterized in that The authentication request includes multiple values ​​of the first attribute, and the target value is any one or all of the multiple values.

17. The device according to claim 14 or 15, characterized in that The authentication request includes an upper bound and a lower bound of a second value interval of the first attribute, and the target value includes an upper bound and / or a lower bound of the second value interval.

18. The apparatus according to any one of claims 14 to 17, characterized in that The device also includes a storage module, Before the determining module determines the access control policy according to the identifier of the first operation in the authentication request, the transceiver module is further configured to receive the access control policy created by the administrator; In the case that the access control module passes the verification, the storage module is used to store the access control policy, and the transceiver module is further used to feedback to the administrator that the access control policy is successfully created.

19. The apparatus according to any one of claims 14 to 18, characterized in that The type of the target value is a numerical value, a date or an Internet Protocol (IP) address.

20. The apparatus according to any one of claims 14 to 19, characterized in that The first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

21. The apparatus according to any one of claims 14 to 20, characterized in that The interval type of the first value interval is an open interval, a closed interval, or a half-open interval.

22. A resource providing device, characterized in that: include: a transceiver module, configured to receive a request for executing a first operation initiated by a user; an acquisition module, configured to collect authentication attribute information according to the execution request, wherein the authentication attribute information includes an upper bound and a lower bound of a second value interval of the first attribute; a processing module, configured to generate an authentication request according to the authentication attribute information, and send the authentication request to an access control device, wherein the authentication request includes an identifier of the first operation and the authentication attribute information; The transceiver module is further configured to receive the authentication result sent by the access control device; The processing module is further configured to determine whether to perform the first operation for the user based on the authentication result.

23. The device according to claim 22, characterized in that The authentication request also includes user information of the user.

24. The device according to claim 22 or 23, characterized in that The type of the upper bound of the second value interval is a numerical value, a date, or an Internet Protocol IP address.

25. The apparatus according to any one of claims 22 to 24, characterized in that The first attribute includes at least one of an identity attribute, an environment attribute, and a resource attribute.

26. The apparatus according to any one of claims 22 to 25, characterized in that The interval type of the second value interval is an open interval, a closed interval, or a half-open interval.

27. An access control system, characterized in that: The method comprises an access control device and a resource providing device, wherein the access control device is used to execute the method according to any one of claims 1 to 8, and the resource providing device is used to execute the method according to any one of claims 9 to 13.

28. A computing device cluster, characterized in that: The system comprises at least one computing device, each computing device comprising a processor and a memory, wherein the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1-8 or 9-13.

29. A computer-readable storage medium, characterized in that The method comprises computer program instructions, which, when executed by a computing device cluster, perform the method according to any one of claims 1-8 or 9-13.

30. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster is caused to perform the method according to any one of claims 1-8 or 9-13.