Unified authority management system and method for object storage in zero-trust scene
By introducing permission management modules and fault recovery modules into the object storage system, efficient management of complex permissions and rapid fault recovery are achieved under the zero-trust architecture, solving the business stability and data security issues of the object storage system in the event of a failure, and improving the reliability and security of data access.
Patent Information
- Application Number
- CN202510708229.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-10-17
AI Technical Summary
Under the zero-trust architecture, object storage systems cannot guarantee business stability and data security when data reading services fail. This is especially true in complex permission structures and large-scale data environments, where permission management is difficult and data security and system availability face challenges in failure scenarios.
A unified permission management system for object storage in a zero-trust scenario is designed, including a permission management module and a fault recovery module. The permission management module ensures data security through multi-level permission verification and risk assessment. The fault recovery module backs up key permission metadata to ensure rapid recovery of permission management in the event of a fault.
It realizes complex permission management of hundreds of millions of objects under the zero-trust architecture, ensures business stability and data security, prevents unauthorized access and data leakage, provides an efficient fault recovery mechanism, and reduces the system's sensitivity to failures.
Smart Images

Figure CN120803341A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of distributed storage, in particular to an object storage unified permission management system and method in a zero trust scenario. BACKGROUND
[0002] Object storage is an ideal storage solution for massive unstructured data, but it often contains sensitive information, and unauthorized access or permission service failure can cause serious loss. With the increase in data volume and the complexity of attack methods, the security of object storage has become a key point in enterprise IT strategy.
[0003] Zero trust architecture has been applied to object storage to improve data security and management efficiency, but in actual application, the related architecture cannot guarantee the stability of the business and the security of the data when the data reading service fails. SUMMARY
[0004] Therefore, the present application provides an object storage unified permission management system and method in a zero trust scenario to solve the problem that the related architecture cannot guarantee the stability of the business and the security of the data when the data reading service fails.
[0005] In a first aspect, the present application provides an object storage unified permission management system in a zero trust scenario, which comprises a permission management module and a fault recovery module; wherein the fault recovery module is connected with the permission management module;
[0006] The permission management module is configured to receive a user request sent by a client, perform permission verification of multiple storage levels on the user request, perform target data reading based on the user request if the permission verification is passed, and send the target data to the client.
[0007] The fault recovery module is configured to backup key permission metadata in the permission management module, perform target data reading based on the user request when the permission management module fails, and send the target data to the client.
[0008] The object storage unified permission management system in a zero trust scenario provided by the present embodiment receives a user request sent by a client through the permission management module, performs permission verification of multiple storage levels on the user request, performs target data reading based on the user request if the permission verification is passed, and sends the target data to the client. The fault recovery module is used to backup key permission metadata in the permission management module, receive a user request when the permission management module fails, verify the user request using the key permission metadata, perform target data reading based on the user request if the verification is passed, and send the target data to the client, thereby ensuring the stability of the business and improving the security of the data.
[0009] In an optional implementation, the permission management module comprises: an internal permission management unit, a risk assessment unit and a risk decision unit connected in sequence; wherein the internal permission management unit is connected with the client;
[0010] The internal permission management unit is configured to acquire a user request, perform cluster read-write permission verification on the user request, send the user request to the risk assessment unit if the cluster read-write permission verification is passed, receive the user request sent by the risk assessment unit, perform user level, bucket level and user level permission verification on the user request, perform target data reading based on the user request if the permission verification is passed, and send the target data to the client;
[0011] The risk assessment unit is configured to perform information security assessment on the user request, send the user request to the risk decision unit if the information security assessment is passed, receive the user request sent by the risk decision unit, perform storage pool read-write permission verification on the user request, and send the user request to the internal permission management unit if the storage pool read-write permission verification is passed.
[0012] The risk decision unit is configured to perform attack operation detection on the user request, and send the user request to the risk assessment unit if the user request does not exist attack operation.
[0013] The object storage unified permission management system in the zero trust scenario provided by the embodiment performs cluster read-write permission verification on the user request through the internal permission management unit, receives the user request sent by the risk assessment unit, and performs user level, bucket level and user level permission verification on the user request, thereby realizing multiple level permission verification on the user request, improving the security of data in the zero trust scenario, performing information security assessment on the user request through the risk assessment unit, realizing security detection of the user request, improving the reliability of data access, and performing attack operation detection on the user request through the risk decision unit, further ensuring the security of data access.
[0014] In an optional implementation, the internal permission management unit comprises: an identity management subunit, an authentication subunit, an integrated operation subunit, an authorization subunit and an access control subunit connected in sequence; wherein the access control subunit is connected with the risk assessment unit and the client respectively, and the identity management subunit is connected with the risk assessment unit;
[0015] The identity management subunit is configured to receive the user request sent by the risk assessment unit, perform identity authentication on the user request, and send the user request to the authentication subunit if the identity authentication is passed.
[0016] The authentication subunit is configured to perform MFA and anti-link theft verification on the user request, and send the user request to the integrated operation subunit if the MFA and anti-link theft verification are passed.
[0017] an integrated operation subunit configured to perform third-party application access permission verification on the user request, and send the user request to the authorization subunit if the third-party application access permission verification is passed;
[0018] an authorization subunit configured to perform permission policy verification on the user request, and send the user request to the access control subunit if the permission policy verification is passed;
[0019] an access control subunit configured to obtain the user request, perform cluster read-write permission verification on the user request, send the user request to the risk assessment unit if the cluster read-write permission verification is passed, and perform user read-write permission verification, bucket read-write permission verification and object read-write permission verification on the user request sent by the authorization subunit, and perform target data reading based on the user request if the verification is passed, and send the target data to the client.
[0020] The object storage unified permission management system in the zero trust scenario provided in the embodiment performs identity authentication on the user request through the identity management subunit, prevents unauthorized operations, improves the security of data, performs MFA and anti-stealing link verification on the user request through the authentication subunit, can prevent unauthorized access and data leakage, and at the same time ensures that resources are called by legal requests, performs third-party application access permission verification on the user request through the integrated operation subunit, ensures that the third-party application can only access the data resources permitted by it, effectively prevents overreach operations and data leakage, and at the same time improves the security and efficiency of cross-system collaboration, performs permission policy verification on the user request through the authorization subunit, ensures that data operations always comply with security rules, effectively blocks overreach behaviors and maintains the principle of least privilege of the system, at the same time provides a standardized basis for audit tracing, performs permission verification at multiple storage levels through the access control subunit, realizes precise access control, prevents both horizontal overreach and vertical overreach, and finally achieves a dynamic balance between security and availability.
[0021] In an optional implementation, the risk decision unit is further configured to detect attack operations on the user request, and perform emergency permission recovery on the user request if the user request has attack operations, and generate a risk notification.
[0022] The object storage unified permission management system in the zero trust scenario provided in the embodiment detects attack operations on the user request through the risk decision unit, detects and intercepts malicious instructions in real time, effectively defends against attacks on data integrity and availability, at the same time reduces the misjudgment rate through behavior analysis, and builds a proactive security protection layer for the storage system.
[0023] In an optional implementation, the permission management module further comprises:
[0024] The notification alarm unit is connected with the risk decision unit and is configured to receive a risk notification and perform a permission risk warning based on the risk notification.
[0025] The object storage unified permission management system under the zero trust scenario provided by the embodiment can perform a permission risk warning based on a risk notification through the notification alarm unit, thereby providing effective support for the disposal of data security problems and systematically reducing the possibility of data leakage and misuse.
[0026] In an optional implementation, the risk assessment unit comprises a risk prediction subunit and a database configuration subunit; the risk prediction subunit is connected with the internal permission management unit and the database configuration subunit respectively, and the database configuration subunit is connected with the risk decision unit;
[0027] The risk prediction subunit is configured to perform abnormal behavior detection on the user request, and if no abnormal behavior exists in the user request, the user request is sent to the database configuration subunit.
[0028] The database configuration subunit is configured to obtain high-risk attack data, compare the high-risk attack data with the user request, and if no high-risk attack data exists in the user request, the user request is sent to the risk decision unit.
[0029] The object storage unified permission management system under the zero trust scenario provided by the embodiment can perform abnormal behavior detection through the risk assessment unit, accurately identify abnormal behavior of the user request, provide strong support for data security, and detect whether high-risk attack data exists in the user request through the database configuration subunit, thereby reducing the risk of collapse caused by high-risk attack data and enhancing the security of the data portal.
[0030] In an optional implementation, the fault recovery module comprises a traffic migration unit, a permission backup unit and a backup service unit; the permission backup unit is connected with the permission management module, the traffic migration unit is connected with the client, and the backup service unit is connected with the permission backup unit and the client respectively;
[0031] The permission backup unit is configured to obtain key permission metadata and backup the key permission metadata.
[0032] The traffic migration unit is configured to, when the permission management module fails, receive a user request and send the user request to the backup service unit.
[0033] The backup service unit is configured to read the key permission metadata in the permission backup unit, use the read key permission metadata to verify the user request, and if the verification is passed, perform target data reading based on the user request and send the target data to the client.
[0034] The object storage unified permission management system in the zero trust scenario provided by the embodiment, through the permission backup unit, backs up the key permission metadata, ensures that the permission management can be quickly restored when the permission management module fails or is misoperated by human, avoids the global unauthorized risk caused by the loss of key metadata, through the traffic migration unit, sends the user request to the backup service unit when the permission management module fails, ensures the continuity of the service and the stability of the user experience, through the backup service unit, reads the key permission metadata in the permission backup unit, and uses the key permission metadata to verify the user request, ensures the security and availability of the business data.
[0035] In an optional implementation, the permission backup unit is further configured to obtain change information corresponding to the permission metadata, and backup the permission metadata based on the change information corresponding to the permission metadata.
[0036] The object storage unified permission management system in the zero trust scenario provided by the embodiment, through the permission backup unit, backs up the key permission metadata based on the change information corresponding to the permission metadata, ensures the real-time consistency of the permission control, and improves the security and operation and maintenance efficiency of the object storage.
[0037] In an optional implementation, the permission backup unit is further configured to construct a permission metadata tree graph based on the key permission metadata, and store data by using the permission metadata tree graph.
[0038] The object storage unified permission management system in the zero trust scenario provided by the embodiment, through the permission backup unit, constructs a permission metadata tree graph based on the key permission metadata, reduces the complexity of permission verification by using the permission relationship between different storage levels in the hierarchy, and improves the efficiency of permission verification in the zero trust scenario.
[0039] In a second aspect, the present application provides an object storage unified permission management method in a zero trust scenario, which is applied to the object storage unified permission management system in the zero trust scenario of the first aspect or any of the corresponding embodiments, and the method comprises:
[0040] The permission management module receives the user request sent by the client, performs permission verification of multiple storage levels on the user request, if the permission verification is passed, reads target data based on the user request, and sends the target data to the client;
[0041] The fault recovery module backs up the key permission metadata in the permission management module, reads target data based on the user request when the permission management module fails, and sends the target data to the client. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the specific embodiments of the present application or the prior art, the drawings required to be used in the specific embodiments or prior art description will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0043] Figure 1 is a structural block diagram of an object storage unified permission management system in a zero trust scenario according to an embodiment of the present application;
[0044] Figure 2 is a structural block diagram of an internal permission management unit according to an embodiment of the present application;
[0045] Figure 3 is a workflow schematic diagram of a risk decision unit according to an embodiment of the present application;
[0046] Figure 4 is a process schematic diagram of permission management recovery after failure of a permission management module according to an embodiment of the present application;
[0047] Figure 5 is a workflow schematic diagram of a failure recovery module according to an embodiment of the present application;
[0048] Figure 6 is a structural block diagram of failure recovery metadata according to an embodiment of the present application;
[0049] Figure 7 is a structural block diagram of retrieval metadata according to an embodiment of the present application;
[0050] Figure 8 is a workflow schematic diagram of a permission management module according to an embodiment of the present application;
[0051] Figure 9 is a process schematic diagram of a unified permission management method for object storage in a zero trust scenario according to an embodiment of the present application. DETAILED DESCRIPTION
[0052] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0053] Object storage can provide a stable and scalable data storage environment, and is the best storage solution for massive unstructured data such as pictures and audio and video. Unstructured data usually contains a large amount of sensitive information, including customer data, financial records, and intellectual property, and unauthorized access or service failure will cause serious economic losses and legal consequences. Object storage is an object-centered storage method that stores data as objects rather than files, and has the advantages of high reliability, high scalability and high performance.
[0054] With the increase of object storage data and the complexity of attack means, how to ensure the security of object storage has become an important focus in enterprise IT (Information Technology) strategy that cannot be ignored, so the zero trust architecture has become a common architecture for object storage. Based on the principle of "never trust, always verify": ensure that even if the user request comes from the internal network, it will not be trusted by default, which can significantly improve the security and management efficiency of data. Zero trust is a network security concept that believes that all access requests in any network should not be automatically trusted, even requests from internal networks. Each access request needs to be strictly verified and authorized, regardless of where the request comes from or what resources it wants to access.
[0055] In a large-scale cloud environment, object storage needs to handle hundreds of TB (TeraByte) to hundreds of PB (Petabyte) of data, and object storage has multiple levels of complex permission levels such as user level, bucket level and object level. Each permission rule has a different life cycle, resulting in a large amount of data and the complexity of the permission structure, making it difficult to manage object permissions. Especially in failure scenarios, data security, system availability and business continuity also face great challenges. A storage bucket (Bucket) is a "container" in object storage that stores objects, and the "container" has no upper limit on capacity. Objects are stored in a flat structure in the storage bucket, and users can choose to store objects in a single or multiple storage buckets. An object (Object) is the basic unit of object storage and can be understood as any format type of data, such as pictures, documents and audio and video files.
[0056] Permission management refers to controlling access and operations on data stored in the system. Through fine-grained permission management, only authorized users and applications can access or operate specific data objects, thereby protecting the security and privacy of data.
[0057] The object storage unified permission management method follows the standards and mechanisms of AWS (an object storage permission management mechanism) object storage permission management, including: AK (Access Key, public access key) and SK (Secret Access, private encryption key): used to generate signatures for authentication and authorization, which are the basic credentials for accessing object storage services, policy: used to define and manage access permissions for users, buckets and objects, providing detailed and flexible permission management functions, allowing to define accessible resources, and allowing or denying operations, which can be controlled based on multiple conditions (such as time, IP (Internet Protocol) address), ACL (Access Control List, access control list): used to provide basic permission setting options, including read and write permissions for users, storage buckets and objects, etc., suitable for simple permission management needs, role temporary permission and pre-signed URL (Uniform Resource Locator, Uniform Resource Locator): temporary permission allows users or applications to access or operate storage resources within a limited time, suitable for scenarios that require temporary access permissions, such as file sharing, temporary data processing or temporary authorized access, master and sub-account: the master account is used to define detailed permission rules, grant or restrict the operations of the sub-account, MFA: used to enhance security by requiring users to provide additional verification factors to access resources, read, write, modify and delete permissions: define whether the cluster and storage pool have read, write, modify and delete permissions, anti-hotlinking: a security measure to prevent unauthorized websites or users from directly referencing and using resources (such as pictures, videos, files, etc.) stored in the object storage service, capability-based access control (CAPS): used for fine-grained permission control to ensure that only users with the correct capabilities can access or operate specific storage objects, users with corresponding CAPS can operate not only the user's buckets, objects and other users, and can be considered as having some kind of administrator's permission, third-party application access integration permission, including OAuth2.0 (an open standard that allows users to allow third-party applications to access their photos, videos, contact lists, etc. without exposing their credentials) and OpenID Connect (an identity verification protocol based on protocol, designed to provide a standardized way to verify user identity and obtain their basic information) and other third-party application access resource permission management.
[0058] To solve the above technical problems, in the embodiment, a unified permission management system for object storage in a zero trust scenario is provided, which sets a permission management module and a fault recovery module in an object storage gateway, realizes efficient and clear management of complex permissions for hundreds of millions of objects under a zero trust architecture, and when the permission management module fails, the fault recovery module is used to safely and quickly recover the business, avoiding affecting the business under the zero trust architecture.
[0059] In the embodiment, a unified permission management system for object storage in a zero trust scenario is provided, as shown in the figure, which includes a permission management module 101 and a fault recovery module 102; wherein the fault recovery module 102 is connected with the permission management module 101. Figure 1
[0060] The permission management module 101 is used to receive a user request sent by a client, perform permission verification of multiple storage levels on the user request, if the permission verification is passed, perform target data reading based on the user request, and send the target data to the client.
[0061] Specifically, to quickly find the reason for insufficient permissions in a complex permission structure, detailed permission logs need to be recorded in each unit in the permission management module 101, so as to track and analyze permission-related problems, analyze user behavior, and ensure the security and compliance of the service.
[0062] The fault recovery module 102 is used to backup the key permission metadata in the permission management module 101, and when the permission management module 101 fails, perform target data reading based on the user request, and send the target data to the client.
[0063] Specifically, the permission management module 101 and the fault recovery module 102 are in a parallel relationship, but also in a mutually dependent relationship. The permission management module 101 relies on the fault recovery module 102 to provide permission management services in a fault scenario. The fault recovery module 102 backs up the key permission metadata in the permission management module 101, ensuring the high availability of distributed storage.
[0064] The unified permission management system for object storage in a zero trust scenario provided in the embodiment receives a user request sent by a client through the permission management module, performs permission verification of multiple storage levels on the user request, if the permission verification is passed, performs target data reading based on the user request, and sends the target data to the client, and uses the fault recovery module to backup the key permission metadata in the permission management module. When the permission management module fails, the user request is received, the key permission metadata is used to verify the user request, if the verification is passed, target data reading is performed based on the user request, and the target data is sent to the client, ensuring the stability of the business and improving the security of the data.
[0065] In an optional implementation, the permission management module 101 comprises: an internal permission management unit 1011, a risk assessment unit 1012 and a risk decision unit 1013 connected in sequence; and the internal permission management unit 1011 is connected with the client.
[0066] The internal permission management unit 1011 is configured to acquire a user request, perform cluster read-write permission verification on the user request, send the user request to the risk assessment unit 1012 if the cluster read-write permission verification is passed, receive the user request sent by the risk assessment unit 1012, perform user level, bucket level and user level permission verification on the user request, perform target data reading based on the user request if the permission verification is passed, and send the target data to the client.
[0067] Specifically, after the client issues a user request to the object storage gateway, the internal permission management unit 1011 is used to verify the cluster read-write permission, and after the verification, the user request is issued to the risk assessment unit 1012 to assess the security of the user request.
[0068] The risk assessment unit 1012 is configured to perform information security assessment on the user request, send the user request to the risk decision unit 1013 if the information security assessment is passed, receive the user request sent by the risk decision unit 1013, perform storage pool read-write permission verification on the user request, and send the user request to the internal permission management unit 1011 if the storage pool read-write permission verification is passed.
[0069] Specifically, the risk assessment unit 1012 performs information security assessment on the user request, and performs storage pool read-write permission verification on the user request after confirming that there is no risk.
[0070] The risk decision unit 1013 is configured to detect attack operation of the user request, and send the user request to the risk assessment unit 1012 if the user request does not exist attack operation.
[0071] The object storage unified permission management system in the zero trust scenario provided by the embodiment performs cluster read-write permission verification on the user request by the internal permission management unit, receives the user request sent by the risk assessment unit, performs user level, bucket level and user level permission verification on the user request, realizes multiple level permission verification on the user request, improves the security of data in the zero trust scenario, realizes security detection of the user request by the risk assessment unit performing information security assessment on the user request, improves the reliability of data access, and further improves the security of data access by the risk decision unit detecting attack operation of the user request.
[0072] In an alternative embodiment, the internal permission management unit 1011, as shown, includes: an identity management sub-unit 10111, an authentication sub-unit 10112, an integrated operation sub-unit 10113, an authorization sub-unit 10114 and an access control sub-unit 10115 connected in sequence; wherein the access control sub-unit 10115 is connected with the risk assessment unit 1012 and the client respectively, and the identity management sub-unit 10111 is connected with the risk assessment unit 1012. Figure 2
[0073] The identity management sub-unit 10111 is configured to receive the user request sent by the risk assessment unit 1012, perform identity authentication on the user request, and send the user request to the authentication sub-unit 10112 if the identity authentication is passed.
[0074] Specifically, the identity management sub-unit 10111 performs identity authentication on the user request, and the content of the identity authentication includes AK, SK, role and pre-signature; wherein the AK is used to uniquely identify the identity of the user in the storage system, the SK is used to sign the user request to ensure the integrity and legality of the request, the role is used to decouple the user identity / service identity and the actual permission, and the pre-signature allows a third party to access a private resource within a specified time without exposing a permanent key.
[0075] The authentication sub-unit 10112 is configured to perform MFA and anti-hotlinking verification on the user request, and send the user request to the integrated operation sub-unit 10113 if the MFA and anti-hotlinking verification are passed.
[0076] Specifically, the MFA verification is used to enhance the security of permission verification, and the anti-hotlinking verification is used to prevent unauthorized websites or users from directly referencing and using resources (such as pictures, videos, files, etc.) stored in the object storage service.
[0077] The integrated operation sub-unit 10113 is configured to perform third-party application access permission verification on the user request, and send the user request to the authorization sub-unit 10114 if the third-party application access permission verification is passed.
[0078] Specifically, the content of the third-party application access permission verification includes OAuth2.0 (an open standard that allows users to allow third-party applications to access their photos, videos, contact lists, etc. without exposing their credentials) and OpenID Connect and other third-party application access permission verifications.
[0079] The authorization sub-unit 10114 is configured to perform permission policy verification on the user request, and send the user request to the access control sub-unit 10115 if the permission policy verification is passed.
[0080] Specifically, the policy verification is used to define and manage the access rights of users, buckets and objects, and provides detailed and flexible rights management functions, allowing to define which resources a user can access and which operations are allowed or denied, and the rights can be verified based on multiple conditions (such as time, IP address).
[0081] Further, the authorization subunit 10114 also includes verification of the master sub-account in the process of verifying the rights policy. The master sub-account uniformly manages the sub-account rights in the distributed storage through the master account, and realizes resource isolation and fine access control in combination with the IAM (Identity and Access Management) service, to ensure data security and operation compliance. The master account can define detailed rights rules to grant or restrict the operations of the sub-account.
[0082] The access control subunit 10115 is configured to obtain a user request, perform cluster read-write permission verification on the user request, send the user request to the risk assessment unit if the cluster read-write permission verification is passed, receive the user request sent by the authorization subunit 10114, perform user read-write permission verification, bucket read-write permission verification and object read-write permission verification on the user request, and perform target data reading based on the user request if the verification is passed, and send the target data to the client.
[0083] Specifically, the user read-write permission verification, the bucket read-write permission verification and the object read-write permission verification on the user request include CapBAC (Capability-Based Access Control) and ACL. The CapBAC is used for fine-grained rights control, to ensure that only users with correct capabilities can access or operate specific storage objects, and users with corresponding CAP (Consistency Avalibility Partition tolerance) can operate not only the buckets and objects belonging to the user himself, but also other users, which can be regarded as having the rights of an administrator. The ACL is used to provide basic rights setting options, including read and write rights of users, storage buckets and objects, and is suitable for simple rights management requirements.
[0084] The object storage unified permission management system in the zero trust scenario provided by the embodiment prevents the occurrence of unauthorized operations and improves the security of data by performing identity verification on the user request through the identity management subunit. The user request is subjected to MFA and anti-link theft verification through the authentication subunit, which can prevent unauthorized access and data leakage while ensuring that resources are called by legitimate requests. The user request is subjected to third-party application access permission verification through the integration operation subunit, which ensures that third-party applications can only access the data resources they are permitted to access, effectively preventing unauthorized operations and data leakage while improving the security and efficiency of cross-system collaboration. The user request is subjected to permission policy verification through the authorization subunit, which ensures that data operations always comply with security rules, effectively blocking unauthorized behavior and maintaining the principle of least privilege in the system while providing standardized basis for audit tracing. The access control subunit performs permission verification at multiple storage levels, achieving precise access control, preventing both horizontal and vertical unauthorized access, and ultimately achieving a dynamic balance between security and availability.
[0085] In an optional implementation, the risk decision unit 1013 is further configured to detect attack operations of the user request, and if the user request has attack operations, the user request is subjected to emergency permission withdrawal, and a risk notification is generated.
[0086] Specifically, as shown in Figure 3 The process of the risk decision unit 1013 detecting attack operations of the user request includes: 1) determining whether the user is a non-authorized user; 2) determining whether the interface to be accessed is a sensitive interface; 3) comparing the user request with data in the vulnerability database; 4) predicting the vulnerability risk based on the user request (i.e., detecting attack operations); 5) if the user request does not have attack operations, the user request is sent to the internal permission management unit 1011; 6) if the user request has attack operations, the user request is subjected to emergency permission withdrawal, and a risk notification is generated.
[0087] The object storage unified permission management system in the zero trust scenario provided by the embodiment detects and blocks malicious instructions in real time through the risk decision unit detecting attack operations of the user request, effectively defending against attacks on data integrity and availability, while reducing the false positive rate through behavior analysis, thereby building a proactive security protection layer for the storage system.
[0088] In an optional implementation, the permission management module further includes:
[0089] The notification alarm unit 1014 is connected with the risk decision unit 1013 and is configured to receive the risk notification and perform permission risk early warning based on the risk notification.
[0090] The object storage unified permission management system in the zero trust scenario provided by the embodiment provides permission risk early warning based on risk notification through the notification alarm unit, provides effective support for the disposal of data security problems, and systematically reduces the possibility of data leakage and abuse.
[0091] In an optional implementation, the risk assessment unit 1012 includes a risk prediction sub-unit 10121 and a database configuration sub-unit 10122, as shown. Figure 4 The risk prediction sub-unit 10121 is connected with the internal permission management unit 1011 and the database configuration sub-unit 10122 respectively, and the database configuration sub-unit 10122 is connected with the risk decision unit 1013.
[0092] The risk prediction sub-unit 10121 is configured to perform abnormal behavior detection on the user request, and if no abnormal behavior exists in the user request, the user request is sent to the database configuration sub-unit 10122.
[0093] Specifically, the risk prediction sub-unit 10121 detects abnormal behavior by analyzing features such as operation frequency, access mode, and abnormal behavior using models such as deep autoencoder and variational autoencoder, and if no abnormal behavior exists in the user request, the user request is sent to the database configuration sub-unit 10122, and if abnormal behavior exists in the user request, such as identifying abnormal and high-risk events in the user request, an emergency process is started in time, and emergency permission is recovered.
[0094] The database configuration sub-unit 10122 is configured to obtain high-risk attack data, compare the high-risk attack data with the user request, and if no high-risk attack data exists in the user request, send the user request to the risk decision unit 1013.
[0095] Specifically, the database configuration sub-unit 10122 stores known high-risk attack data, and compares it with the user request to confirm whether the access is safe.
[0096] The object storage unified permission management system in the zero trust scenario provided by the embodiment performs abnormal behavior detection through the risk assessment unit, accurately identifies the abnormal behavior of the user request, provides strong support for data security, and detects whether high-risk attack data exists in the user request through the database configuration sub-unit, reduces the risk of collapse caused by high-risk attack data by intercepting high-risk attack data, and enhances the security of the data portal.
[0097] In an optional implementation, the fault recovery module 102 comprises: a traffic migration unit 1021, an authority backup unit 1022, and a backup service unit 1023; the authority backup unit 1022 is connected with the authority management module 101, the traffic migration unit 1021 is connected with the client, and the backup service unit 1023 is connected with the authority backup unit 1022 and the client respectively.
[0098] The authority backup unit 1022 is configured to acquire the key authority metadata and backup the key authority metadata.
[0099] Specifically, as shown in FIG. 2, the key authority metadata is encoded and stored in the authority backup unit 1022 in a fault scenario, the authority backup unit 1022 provides a key authority metadata query interface and a bucket-level authority context retrieval interface for a user of the key authority metadata to analyze the authority metadata in a fault scenario. Figure 5
[0100] The traffic migration unit 1021 is configured to receive a user request and send the user request to the backup service unit 1023 when the authority management module 101 fails.
[0101] Specifically, the traffic migration unit 1021 completes service availability in a fault scenario (i.e., when the authority management module 101 fails) by connecting the backup service unit 1023, the traffic migration unit 1021 writes traffic to a new storage pool after the backup service unit 1023 is started after receiving the user request, read traffic loads the key authority metadata through the backup service unit 1023 to temporarily access the object storage resource by the client, and the read traffic is cut back to the normal service after the service is restored (i.e., when the function of the authority management module 101 is restored).
[0102] The backup service unit 1023 is configured to read the key authority metadata in the authority backup unit, verify a user request by using the read key authority metadata, and send target data to the client based on the user request if the verification is passed.
[0103] The object storage unified authority management system in a zero-trust scenario provided by the embodiment backs up the key authority metadata through the authority backup unit, ensures quick recovery of authority management when the authority management module fails or is misoperated by a human, avoids global unauthorized risk caused by loss of key metadata, sends a user request to the backup service unit through the traffic migration unit when the authority management module fails, ensures continuity of service and stability of user experience, reads the key authority metadata in the authority backup unit through the backup service unit, and verifies a user request by using the key authority metadata, thereby ensuring security and availability of business data.
[0104] In an optional implementation, the permission backup unit 1022 is further configured to obtain modification information corresponding to the permission metadata, and backup the permission metadata based on the modification information corresponding to the permission metadata.
[0105] Specifically, the permission backup unit 1022 is triggered to backup when the key permission metadata at the cluster level, the storage pool level and the user level is modified, the key permission metadata at the bucket level is backed up at a fixed time when the load is low, and the key permission metadata at the object level is not backed up. Although a small part of data permission loss is refused to access, it is the most secure and reliable backup solution in the scene of hundreds of millions of objects.
[0106] The object storage unified permission management system in the zero trust scenario provided by the embodiment ensures real-time consistency of permission control and improves the security and operation and maintenance efficiency of the object storage by the permission backup unit backing up the permission metadata based on the modification information corresponding to the permission metadata.
[0107] In an optional implementation, the permission backup unit 1022 is further configured to construct a permission metadata tree graph based on the key permission metadata, and store data by using the permission metadata tree graph.
[0108] Specifically, as shown in Figures 6-7 The permission backup unit 1022 establishes a user-level permission metadata tree graph: the hierarchical structure of the permission metadata tree graph is used for subsequent analysis and understanding of the permission structure.
[0109] The object storage unified permission management system in the zero trust scenario provided by the embodiment reduces the complexity of permission verification and improves the efficiency of permission verification in the zero trust scenario by the permission backup unit constructing a permission metadata tree graph based on the key permission metadata and the permission relationship between different storage levels in the hierarchical structure.
[0110] The working process of the object storage unified permission management system in the zero trust scenario will be described below by an embodiment.
[0111] Embodiment 1
[0112] The specific steps of implementing the object storage unified permission management in the zero trust scenario include:
[0113] 1) Set the default permission when creating a cluster, a storage pool, creating a user and the like, the default permission follows the principle of least privilege, and the permission modification and creation behaviors will trigger the permission backup unit to backup the modified key permission metadata.
[0114] 2) The client sends a user request, which needs to access the identity management subunit, the authentication subunit, the authorization subunit, the access control subunit, the integrated operation subunit, the risk assessment unit, and the risk decision subunit to perform permission verification at the cluster level, the storage pool level, the user level, the bucket level, and the object level to meet the security requirements of data in the zero trust scenario.
[0115] The process of verifying the user request in the permission management module is shown in FIG. 2, which includes the following steps: Figure 8 As shown in FIG. 2, the process of verifying the user request in the permission management module includes the following steps: the access identity management subunit performs cluster read-write permission verification on the user request, the risk assessment unit performs data security assessment on the user request after the verification is passed, the risk decision unit performs attack operation detection on the user request if the user request has no data security problem, the internal permission management unit performs user level, bucket level, and object level permission verification on the user request if the user request has no attack operation, and the target data is read based on the user request after the verification is passed, and the target data is sent to the client.
[0116] 3) When the permission management module fails, the permission backup unit is responsible for periodically or real-time backup of the key permission metadata in the system to ensure that the permission configuration can be quickly restored in case of data loss, configuration error, or system failure, preventing data loss and security risks; the traffic migration unit is used to safely migrate user access traffic to the available cluster during permission failure processing to ensure service continuity and user experience stability; the backup service subsystem is responsible for managing the recovery permission service to ensure the security and availability of business data.
[0117] Embodiment 2
[0118] The specific workflow of the unified permission management system for object storage in the zero trust scenario includes the following steps:
[0119] The permission management module includes an identity management subunit, an authentication subunit, an authorization subunit, an access control subunit, an integrated operation subunit, a risk assessment unit, a risk decision unit, and a notification alarm unit. After the client issues a user request to the object storage gateway, the cluster read-write permission verification is first verified, the user request is then issued to the risk assessment unit after passing the verification, the information security of the user request is assessed, and the user request is detected to determine whether it contains attack operations. If attack operations are identified, the administrator is fed back through the notification alarm unit, and the emergency permission is withdrawn. The storage pool read-write permission is verified after the verification is passed.
[0120] The complexity of the permissions mainly comes from the diversified authorization needs of the users. The units of the permission management module superimpose on the users to form more complex access strategies. By establishing a user-level permission metadata tree diagram, the hierarchy of the permissions is stored for subsequent analysis and understanding of the permission structure. The bucket-level permission verification and the object-level permission verification only have the Policy, ACL, and resource inheritance permission structure, which complies with the AWS permission standard. The key permission metadata is written into the metadata attributes of the buckets and objects. In order to quickly find the reason for the lack of permissions in the complex permission structure, detailed permission logs are recorded in each unit to track and analyze permission-related problems and analyze user behavior to ensure the security and compliance of the system.
[0121] The fault recovery module includes a permission backup unit, a traffic migration unit, and a backup service unit. The permission backup unit only backs up the key permission metadata of the cluster, the storage pool, and the user level to reduce the consumption of system resources. For the metadata that is not backed up, the initialization permissions are processed. Although this may cause a certain range of permission loss, it consumes the least resources and recovers the fastest while ensuring the safety of the data in the zero-trust scenario. The traffic migration unit schedules the cluster write traffic to the available cluster in the fault scenario. For the inventory read traffic, the backup service unit is used to interface the object storage data service to provide read query capabilities for users. The backup service unit reads the key permission metadata in the permission backup unit to provide a permission engine and security assurance for object storage data reading.
[0122] The permission management module and the fault recovery module are in a parallel relationship but also depend on each other. The permission management module relies on the fault recovery module to provide permission management services in the fault scenario. The fault recovery module backs up the key permission metadata of the permission management module to ensure the high availability of the object storage unified permission management system in the zero-trust scenario.
[0123] The above-mentioned embodiments have the following beneficial effects:
[0124] 1) The permission management module and the fault recovery module are set in the object storage gateway to provide an efficient and clear management scheme for the complex permissions of objects in the zero-trust architecture. In the event of service failure, a safe and fast recovery scheme is provided to avoid affecting the business in the zero-trust architecture.
[0125] 2) The function modules of the permission management module are modularized and decoupled from the business logic. The user-level permission metadata tree diagram, the fault scenario permission metadata query interface, the user and bucket-level permission context retrieval interface, and other auxiliary tools are introduced to improve the efficiency and accuracy of permission management.
[0126] 3) Key permission metadata is backed up to avoid loss, and non-key permission metadata is initialized to the lowest operating permission according to the principle of least privilege. When the permission management module fails or is attacked, the permission configuration is quickly restored to maintain the security and normal operation of the system.
[0127] 4) Separate the key permission metadata related to permission management from the core logic of the object storage system and design it into multiple modular components, making permission management more flexible, scalable and easy to maintain.
[0128] In this embodiment, a unified permission management method for object storage in a zero-trust scenario is provided, which is applied to a unified permission management system for object storage in a zero-trust scenario. Figure 9 As shown, the method includes:
[0129] Step S901: The rights management module receives a user request sent by a client and performs multiple storage level rights checks on the user request.
[0130] Step S902: If the authority check is passed, the target data is read based on the user request and the target data is sent to the client.
[0131] Step S903: The fault recovery module backs up the key rights metadata in the rights management module. When a fault occurs in the rights management module, the fault recovery module reads the target data based on the user's request and sends the target data to the client.
[0132] This embodiment provides a unified object storage permission management method in a zero-trust scenario, which is applied to Figure 1 In the embodiment shown, a unified object storage rights management system in a zero-trust scenario is provided. Therefore, the specific implementation of steps S901 to S903 can refer to the above. Figure 1 The corresponding description of the illustrated embodiment will not be repeated here.
[0133] It is understood that the effects and beneficial effects of the method of this embodiment are similar to those of Figure 1 The functions and beneficial effects of the unified object storage permission management system in a zero-trust scenario in the illustrated embodiment correspond to each other and will not be repeated here.
[0134] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of this application.
[0135] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the system, device and unit described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0136] In several embodiments provided in the embodiments of the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic, and the division of units is merely a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or other forms.
[0137] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.
[0138] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be a physically independent unit, or two or more units can be integrated in one unit.
[0139] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or say the parts that make contributions to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0140] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A unified object storage rights management system in a zero-trust scenario, characterized in that: The system includes: a rights management module and a fault recovery module; wherein the fault recovery module is connected to the rights management module; The rights management module is configured to receive a user request sent by a client, perform a plurality of storage level rights checks on the user request, and if the rights check passes, read the target data based on the user request and send the target data to the client; The fault recovery module is used to back up the key rights metadata in the rights management module, and when a fault occurs in the rights management module, read the target data based on the user request and send the target data to the client.
2. The system according to claim 1, wherein: The authority management module includes: an internal authority management unit, a risk assessment unit, and a risk decision unit connected in sequence; wherein the internal authority management unit is connected to the client; The internal permission management unit is configured to obtain the user request, perform cluster read and write permission verification on the user request, send the user request to the risk assessment unit if the cluster read and write permission verification passes, receive the user request sent by the risk assessment unit, perform user-level, bucket-level, and user-level permission verification on the user request, and read the target data based on the user request if the permission verification passes, and send the target data to the client; The risk assessment unit is configured to perform an information security assessment on the user request, and if the information security assessment passes, send the user request to the risk decision unit; receive the user request sent by the risk decision unit, perform a storage pool read and write permission check on the user request, and if the storage pool read and write permission check passes, send the user request to the internal permission management unit; The risk decision unit is configured to perform an offensive operation detection on the user request, and if the user request does not contain any offensive operation, send the user request to the risk assessment unit.
3. The system according to claim 2, characterized in that The internal authority management unit includes: an identity management subunit, an authentication subunit, an integrated operation subunit, an authorization subunit, and an access control subunit connected in sequence; wherein the access control subunit is connected to the risk assessment unit and the client, respectively, and the identity management subunit is connected to the risk assessment unit; The identity management subunit is configured to receive the user request sent by the risk assessment unit, perform identity authentication on the user request, and send the user request to the authentication subunit if the identity authentication succeeds; The authentication subunit is configured to perform MFA and anti-hotlink verification on the user request, and if the MFA and anti-hotlink verifications pass, send the user request to the integrated operation subunit; The integrated operation sub-unit is configured to perform third-party application access permission verification on the user request, and send the user request to the authorization sub-unit if the third-party application access permission verification passes; The authorization subunit is configured to perform a rights policy check on the user request, and if the rights policy check passes, send the user request to the access control subunit; The access control sub-unit is used to obtain the user request, perform cluster read and write permission verification on the user request, send the user request to the risk assessment unit if the cluster read and write permission verification passes, and receive the user request sent by the authorization sub-unit, perform user read and write permission verification, bucket read and write permission verification and object read and write permission verification on the user request, and if the verification passes, read the target data based on the user request and send the target data to the client.
4. The system according to claim 2, wherein: The risk decision unit is further configured to perform an offensive operation detection on the user request. If the user request contains an offensive operation, emergency authority is revoked for the user request and a risk notification is generated.
5. The system according to claim 4, characterized in that The rights management module further includes: The notification alarm unit is connected to the risk decision unit and is used to receive the risk notification and issue an authority risk warning based on the risk notification.
6. The system according to claim 2, wherein: The risk assessment unit includes: a risk prediction subunit and a database configuration subunit; wherein the risk prediction subunit is connected to the internal authority management unit and the database configuration subunit respectively, and the database configuration subunit is connected to the risk decision unit; The risk prediction subunit is configured to perform abnormal behavior detection on the user request, and if no abnormal behavior exists in the user request, send the user request to the database configuration subunit; The database configuration subunit is configured to obtain high-risk attack data, compare the high-risk attack data with the user request, and send the user request to the risk decision unit if the user request does not contain the high-risk attack data.
7. The system according to claim 1, wherein: The fault recovery module includes: a traffic migration unit, a permission backup unit and a backup service unit; wherein the permission backup unit is connected to the permission management module, the traffic migration unit is connected to the client, and the backup service unit is connected to the permission backup unit and the client respectively; The permission backup unit is used to obtain the key permission metadata and back up the key permission metadata; The traffic migration unit is configured to receive the user request and send the user request to the backup service unit when the authority management module fails; The backup service unit is used to read the key permission metadata in the permission backup unit, and use the read key permission metadata to verify the user request. If the verification passes, the target data is read based on the user request and the target data is sent to the client.
8. The system according to claim 7, characterized in that The rights backup unit is further configured to obtain change information corresponding to the rights metadata, and back up the rights metadata based on the change information corresponding to the rights metadata.
9. The system according to claim 7, wherein: The rights backup unit is further configured to construct a rights metadata tree diagram based on the key rights metadata, and utilize the rights metadata tree diagram for data storage.
10. A method for unified object storage permission management in a zero-trust scenario, characterized in that: Applied to a unified object storage rights management system in a zero-trust scenario according to any one of claims 1 to 9, the method comprising: The rights management module receives a user request sent by a client, performs a multiple storage level rights check on the user request, and if the rights check passes, reads the target data based on the user request and sends the target data to the client; The fault recovery module backs up the key rights metadata in the rights management module, and when a fault occurs in the rights management module, reads the target data based on the user request and sends the target data to the client.